Jump to content
Medved Trader Forums

Recent MS Defender Security Alert When Starting MT


LogicalSpock2

Recommended Posts

Hello! Beginning this past Monday, 9/12, I have started receiving a security notification from MS Windows 10 when starting up Medved Trader about every other day. MS Defender is apparently uploading a couple of temp dll files, created when MT starts, for further scrutiny to its cloud service. I use MT daily on weekdays and the notification never occurred prior to Monday on my PC and only appears when starting MT. The notification appears only once within seconds of starting MT with an audible pop-up then remains present in the notifications slide-out from the right side of the screen (until deleted). No threats have been reported after further Defender cloud scrutiny.

The notification reads "Security Scan Required: Your administrator requires a security scan of this item. The scan could take up to 10 seconds."

Looking in the Windows 10 Event Viewer there are 1 or 2 DLL files that trigger the security alert notification under Event ID 2050.

- When starting MT this morning (Sat 9/17) the details of the two alert events at 10:37:11 AM and 10:37:17 AM (EDT) were as follows:

Microsoft Defender Antivirus has uploaded a file for further analysis.
     Filename: C:\Users\[my user name]\AppData\Local\Temp\mxxhq2h4.dll
     Sha256: db3e02a70e8b2b3e418f856c4f01877c5f7d786abd5cfda871da54fb67c69f41

&

Microsoft Defender Antivirus has uploaded a file for further analysis.
     Filename: C:\Users\[my user name]\AppData\Local\Temp\44p3r5lz.dll
     Sha256: 932700f9df0c4972b3a76e8c0a303eb983933335c1450a03a26ac6af8b1cb048

- Yesterday, 9/16, this did not occur starting MT around 9:10 AM.

- On 9/15 at 9:10:30 AM:

Microsoft Defender Antivirus has uploaded a file for further analysis.
     Filename: C:\Users\[my user name]\AppData\Local\Temp\ddx4pwfr.dll
     Sha256: e84166db04323ea38c3cc49428fd7a717fd24d99eb19f0d9fb5791c5c5c3c2d5

- On 9/14 at 9:08:11 AM and 9:08:15 AM:

Microsoft Defender Antivirus has uploaded a file for further analysis.
     Filename: C:\Users\[my user name]\AppData\Local\Temp\apnvqi1b.dll
     Sha256: 199e79385b024704a0c5a5a60de310c95f9ce1173fafd2e4037c92201d0bf606

&

Microsoft Defender Antivirus has uploaded a file for further analysis.
     Filename: C:\Users\[my user name]\AppData\Local\Temp\xhli5msw.dll
     Sha256: 44b3d9d9a4bd43b526d877b9bb2a6106b98261400642c230268a37a3693a0daf

- On 9/13 no events around 9:10 AM

- On 9/12 at 9:06:55 AM:

Microsoft Defender Antivirus has uploaded a file for further analysis.
     Filename: C:\Users\[my user name]\AppData\Local\Temp\5rsibetw.dll
     Sha256: 0bf27a6ea455dce76f1d761351b131bdbb6898109115e9bd7f20c36e5c6d75fb

 

 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...