Hi, I noticed that most binaries that belong to MC are not digitally signed. As far as I looked only PackageInstaller.exe and JRService.exe are signed. Since you already own a certificate you could just sign all binaries that ship with MC.
Afaik AV-Software tend to monitor unsigned binaries more intense, which leads to more problems, unstability, etc.
Is there any reason, why you don't sign all binaries?