MpCmdRun.exe & MsMpEng.exe?

G

Guest

Can someone explain what MsMpEng.exe and MpCmdRun.exe are for? Obviously they
are components of WinDefender but why are they constantly trying to access
the internet? Why do they need to acces the internet? Spynet? I have already
allowed MSASCui.exe Internet access.
 
B

Bill Sanderson

Here's my picture -- it's not from any deep study or information everyone
else doesn't have, so it may not be completely accurate.

msmpeng.exe =windefend=windows defender Service. This is a system service,
started at boot, which provided Real-Time protection.

MpCmdRun.exe is a command-line user mode executable which does two things:
1) it initiates and monitors requests for signature updates, and 2) it does
scanning--both scheduled and on-demand or custom scans.

MSASCui.exe is the user interface that talks to the other two, which really
do the work.

MPCmdRun talks to the Internet to get signatures before a scan, if your
settings request that, and to report scan results to spynet at the end of a
scan, if you've chosen to take part in spynet.
The Real-time protection service I would expect to need information from
Spynet each time it finds something not yet classified. and to report
finding known malware, again, of spynet reporting is enabled. These are
just my thoughts--I don't have inside information about exactly when and why
each of these executables talks out or accesses information across the
Internet.

This is not the old Microsoft Antispyware--it is quite a bit more
sophisticated. Also note that the icon is associated with MSASCui.exe,
which is not the app providing real-time protection nor the app doing the
scans. It just provides an interface to control and communicate with them.
 
G

Guest

Well from what I gather from your explantation and others on different
forums, is exactly what you explain. So now i can tell zonealarm to stop
having heart attacks everytime they try to go online. Thanks
 
G

Guest

Also I found that if you kill them in Task Manager, they autoload
theirselves. It always bogs down Internet for me but I have still kept WD
installed. I believe that soon they will give another patch that will cause
WD to behave more unintrusively. They should make the WD to be an on-demand
application, rather than the way it operates now. But overall I hope that it
will detect more than other commercial AV/Malware softs, this is the reason
why I have kept from uninstalling it all together.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top