Windows Defender blocked C:UsersjktraDownloadsSolstice.dll and identified it as Trojan:Win32/Ulthar.A!ml, saying it could execute commands from an attacker. I don't remember intentionally downloading anything and was only playing Minecraft when the alert appeared. The file seems connected to a Minecraft Bedrock hack client, even though I don't use Bedrock. Someone had previously sent me a message asking me to test a mod, and I clicked the link to look at it but didn't knowingly download anything. Could that have caused the file to appear later, or is this possibly a false positive? What should I do to make sure my computer is safe?
4 Answers
A file appearing in the Downloads folder usually means something on the computer saved it, even if there was no obvious download prompt. Clicking a link can sometimes trigger a download, and the file may have been saved earlier but only detected when Defender scanned it. Don’t run or restore the DLL; leave it quarantined and delete it if Defender allows.
The detection name alone doesn’t prove exactly how the file got there, and antivirus tools can occasionally flag unusual or packed files incorrectly. However, a random DLL associated with a cheat or mod client is not something to ignore. Uploading the file to a reputable multi-engine scanner can help confirm the result, but only do that if the file is already quarantined and never execute it.
The fact that you were playing Minecraft when the notification appeared doesn’t necessarily mean Minecraft created the file. Defender may have scanned it on a schedule or when another process accessed the Downloads folder. Review what applications were running and check whether the suspicious message, launcher, or mod tool had permission to download files.
Treat the detection as real until proven otherwise. Run a full Microsoft Defender scan, then run Defender Offline or a second reputable malware scanner. Check browser download history, recently installed programs, startup items, scheduled tasks, and the message or launcher that contained the link. If you entered any passwords after clicking it, change them from a clean device and enable two-factor authentication.

That could explain the delayed alert. I clicked the link nearly two weeks ago but never opened the file or intentionally downloaded anything.