How to disable the Windows Defender Antivirus service. How to disable Windows Defender

The built-in Windows Defender utility protects your PC from viruses and malware that can be “picked up” on the Internet when downloading files or connecting other users’ flash cards to the device. If you are completely satisfied with the performance of your antivirus program, then you need to know how to disable Windows 10 Defender permanently. This is written about in this article.

Disable and enable

Using the Settings app

Good to know! The built-in protection will turn off for a while (approximately 15 minutes). After this, the system will automatically launch Windows Defender.

In the Local Group Policy Editor


After this, any attempt to launch the built-in defender will display an error.

Good to know! If you set the parameter to “Not set”, it will begin to function normally.

In the Registry Editor


Important! If you don't find this setting in the registry, create it yourself: RMB on the “Windows Defender” folder → create → DWORD value (32 bits) → enter the name “DisableAntiSpyware” → set its value to “1”.

If you decide to run Defender again, set the parameter to "0" in .

Video

The video shows in detail how to completely disable Windows Defender using the Local Group Policy Registry and Registry Editor.

Third party programs

In addition to standard tools, you can disable the built-in defender using special free programs.

The program was originally developed to disable the function of updates that are performed automatically. But it “can do” much more: it turns the OS defender on and off, and has a Russified interface.

The utility disables tracking in the OS. But when using the advanced setup mode, the option to disable Windows Defender is available.

Activation

To activate Defender in Windows 10, you do not need to perform any action - click on the message that is in the notification center and the system will do everything automatically.

If Windows Defender was deactivated through the Registry Editor or Local Group Policy Editor, then repeat the same steps as when disabling it, only launch Internal Defender.

Making exceptions

Conclusion

Windows Defender protects your computer from viruses and malware. If necessary, you can disable or enable it, and also configure it by adding the necessary files, folders and programs to the exclusion list.

The latest version of Microsoft's operating system comes with its own built-in Defender antivirus, or Defender. This program is already fully configured and enabled by default. However, Defender's level of protection is significantly inferior to third-party antiviruses.

Of course, if you do not visit dubious sites and do not download files from unverified sources, then basic protection should be enough. But many still prefer to use more familiar programs. So, let's look at how to disable antivirus on Windows 10.

There are three ways to disable the antivirus. The first method only lasts 15 minutes. But this is enough if you need to install some applications, and Defender complains. The second and third methods disable the antivirus permanently.

First way

As mentioned, this option only disables the antivirus for 15 minutes, or until the computer restarts. The actions will be as follows:

That's all. Now let's look at more definitive options.

Second way

This case is best suited for more or less advanced users, since actions will have to be performed through the registry. But we will describe the entire procedure step by step, so even a beginner can figure it out if desired. So:


After this, you can close the editor. You can check whether everything was done correctly through the computer settings. If the Defender antivirus settings become inactive, then everything went well. You can check even easier by launching the Defender program itself. If it is disabled, the message “This application has been disabled by Group Policy” will pop up.

If you wish, you can start the antivirus again; to do this, you just need to delete the DisableAntiSpyware parameter you created, or simply replace its value from “1” to “0”.

Third way

If all these registries are too incomprehensible, then a separate program, NoDefender, comes to the rescue, which we will study in the third method. It is worth noting that this is a third-party program, and Microsoft does not support such options.

Therefore, perform installation and manipulation at your own peril and risk..

So, download the utility from an open source (surely Defender will protect you from downloading viruses), unpack it and install it on your computer. Below is the list again:

  1. We launch the program, and in the window that opens, click “Next” or “further”.
  2. Next, click Open Windows Defender Settings, the settings will open in the computer settings.
  3. disable three items: real-time protection, cloud protection, automatic sending of samples.
  4. In the NoDefender program, click “Next” again and Disable Windows Defender.
  5. “Next” again and finally “Exit”

The result of these simple steps can be checked if, when you try to start the antivirus, the “Application is disabled” notification appears.

We hope that all three methods will not be difficult for you, at least it’s definitely worth a try. Don't forget to make backup copies of your system - this will help if you suddenly do something wrong.

At the beginning of this year, we learned about the Windows 10 Creators Update, and we also learned that the Windows Defender Security Center has been completely redesigned. There were talks that with the improvement of Windows 10 Defender, third-party antiviruses would not be required. In the new security center we already have access to firewall, device performance and status, network protection and application and browser control.

However, some users trust other antivirus products, which you can also look at here. My observations of Windows Defender impressed me. I've been using it for about 4 months now, and I'm very active in Internet surfing. I scan every week with an antivirus scanner, which is very popular in scanning. As a result, Windows 10 Defender blocked all the threats that I came across and after scanning I have no viruses on my computer. But for lovers and fans of third-party antiviruses, we will explain how to forever disable windows 10 defender, security center, and remove the windows 10 defender icon from the tray.

How to disable windows 10 defender permanently

The easiest way to disable the built-in antivirus from Microsoft is to simply disable it in the settings, but after a while it will turn back on. Go Protection against viruses and threats(Shield icon) > Antivirus and other threat protection settings> Turn off two sliders. If you want to disable it completely, then read below.

Step 1. In this tutorial, we will disable Windows 10 Defender using Registry Editor. (It is advisable to disable it before the procedure, as described above).

  • Click Win+R, we write regedit to enter the system registry and follow the path:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender

  1. Browse to folder windows defender.
  2. Create a new value named DisableAntiSpyware and meaning 1 .
  3. To create a value, right-click on the empty field on the right and select Create > DWORD value (32 bits).

To enable protection back, set the value back to 0, delete the key, then the partition (folder).

Step 2. Now create a new partition Real-Time Protection(folder) with the key DisableBehaviorMonitoring and meaning 1 .

  • Right click on the folder Windows defender > Create > Chapter.
  • Name the new partition (folder) Real-Time Protection.

Step 3. In the newly created section Real-Time Protection you will need to create three new keys with the value 1 .

  • Select a section (folder) on the right Real-Time Protection and right click on the empty field with the right mouse button Create > Chapter > DWORD value (32 bits).
  • Create three keys like this with a DWORD (32-bit) value: DisableBehaviorMonitoring, DisableOnAccessProtection, DisableScanOnRealtimeEnable.

Step 4. Set the value 1 to all three created keys DisableBehaviorMonitoring, DisableOnAccessProtection, DisableScanOnRealtimeEnable.

  • Double-click any of the three keys and enter a number in the “Value” field in the window that opens 1 .

Restart your computer and Windows 10 Defender will be disabled completely.

  • After that, you can open the antivirus and look.

How to remove windows 10 defender icon from tray

If anyone has not lost the icon, then launch the task manager by pressing the buttons Ctrl+Alt+Delete. Go to the tab, find windows defender and disable it by right-clicking on it.

How to disable Windows Defender Security Center in Windows 10

Click Windows + R and enter regedit to open the Registry Editor. Go to the following path:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecurityHealthService
  • We are looking for a value with a name on the right Start, click on it twice and enter the number in the field 4 .

Windows 10 Antivirus, known today as Windows Defender, is an anti-malware tool developed in-house by Microsoft. It was originally called Microsoft AntiSpyware, then renamed Windows Defender, and under this name it appeared in Windows Vista as a system component designed to provide protection against spyware.

In 2009, Microsoft Security Essentials was released, which was already a full-fledged antivirus (including a network system for detecting intrusions), and during installation it disabled the built-in Defender. And with the release of Windows 8, Windows Defender appeared, which took the old name and, like its predecessor, was integrated into the system, although in essence it is the same Security Essentials, only with improved protection against rootkits.

Despite its long history of development, numerous tests show that Microsoft's built-in software is inferior in quality to third-party antivirus software. In addition, on weak computers, Defender can be inconvenient due to the load on the disk and processor during regular scanning. Disabling it is not the easiest task. For example, it is useless to try to do this through the Security Center interface. After some time, it will turn back on on its own, which is warned about in the parameter description. Let's consider other possible methods.

If your OS version is Pro and higher, then launch the Group Policy Management snap-in. Press Win and R at the same time, and in the “Run” line write gpedit.msс.

We see the editor equipment. In the “Computer Configuration” branch, open:

  1. Administrative Templates.
  2. Windows components.
  3. Windows Defender antivirus program.
  4. Turn off your antivirus program

We double-click on this parameter, we see that it is not specified by default. Select “Enabled” and click “Apply”, thereby enabling the policy.

Registry

On a note! If you have a Home version of the system, there is no group policy management. Therefore, the only way is to edit the registry.

Press Win + R, only now we type regedit.

A window appears where we are interested in a section called HKEY_LOCAL_MACHINE. There we need the path SOFTWARE/ Policies/ Microsoft/ Windows Defender. Now you need to add a few parameters yourself. This is done like this: right-click on an empty space, select “Create” in the context menu, then “DWORD 32-bit value”. Give it the name DisableAntiSpyware and press Enter. Double-click to open the parameter and set the value to one (hexadecimal).

Below we create two more parameters. They will be called ServiceKeepAlive and AllowFastServiceStartup. We do not touch their values. We return to the panel on the left and click on the Windows Defender section. For it we create a subsection Real-Time Protection. Now we make three more parameters in the newly created section (all DWORD 32 bits):

  • DisableBehaviorMonitoring;
  • DisableOnAccessProtection;
  • DisableScanOnRealtimeEnable;

We assign the value one to each of them.

Getting rid of notifications

Important! Whichever method you choose, registry or policy, after the reboot you will be greeted by a red exclamation mark on the tray icon.

“Security Center” notifies you in this way that the antivirus program is installed. If you don’t want to see this reminder every time, you can remove it along with the icon. In the task manager, select the “Startup” tab. We find there the Windows Defender notification icon. In the context menu, click “Disable”.

A little trick

And finally, if there is no desire or opportunity to edit the registry or change policies, there is another way to minimize. In the Security Center, find the “Exceptions” item, click “+”, select “folder” and add system drive C as a folder (if desired, you can other drives, if available).

Important! In this case, although Defender remains turned on, it does not scan or check downloaded and launched files.

Video - How to turn off antivirus on Windows 10








Introduction

Windows Defender is the basic antivirus protection in Windows 8, 8.1 and 10. Unlike its counterpart in Windows XP, Vista and 7, the version for Windows 8/8.1/10 protects against viruses and other types of malware, not just spyware . The product is reminiscent of Microsoft Security Essentials for Windows XP, Vista and 7, but unlike it does not have several features such as the ability to select the time or limit the CPU resources used for scheduled scans using a graphical interface, quick scan launch using the context menu, displaying an icon in the notification area of ​​the taskbar, etc.

Windows Defender uses Windows Update to download new virus signatures once a day. If the update process fails, you will need to reinstall Windows updates.

Please note that you cannot install Microsoft Security Essentials on Windows 8, 8.1 or 10. If you install a third-party antivirus program (such as Avast Free Antivirus), Windows Defender will turn off automatically - there is no point in consuming extra system resources by using multiple antivirus solutions .

Setting up Windows Defender in Windows 10, 8.1 and 8

To launch Windows Defender in Windows 8 and 8.1, open the application search bar by pressing the key combination - Windows key and Q, enter the phrase “Defender” in the search bar and click on the result.

In Windows 10, open the Cortana Start menu or Search by pressing the Windows key + S key combination, enter “Defender” in the search bar and select “Windows Defender Settings.” Since all Windows Defender settings are now located in the new universal interface, there is no point in opening the main program window.

If you previously uninstalled a third-party antivirus, you will see a dialog box stating that Windows Defender is disabled. In this case, open the Action Center using the icon in the notification area of ​​the taskbar and in the “Security” section, enable the “Virus protection” and “Spyware and unwanted software protection” options. Alternatively, you can open Control Panel (Windows key + X), type “Center” in the search bar, and then toggle the options under “Security” to “On.” Please remember that in Windows 8 and 8.1, Action Center may not display a red icon in the notification area for several days after uninstalling a third-party antivirus product.

Windows Defender Settings in Windows 8 and 8.1

When the main Windows Defender window opens, go to the Settings tab and make sure that the “Turn on real-time protection (recommended)” checkbox is checked. These measures are sufficient to activate Windows Defender Antivirus protection in Windows 8 and 8.1 after uninstalling third-party free and paid antivirus solutions.

If something is blocking activation, run Rkill to kill malicious processes and services that may be preventing Windows Defender from starting. Then repeat the operation without restarting the computer.

The following 3 tabs in the “Options” section work with exceptions: the user can prevent scanning of certain files and locations (folders), file types and processes. These settings should be used by experienced PC users who clearly understand why scanning of certain objects should be excluded.

Click on “Details” in the menu on the left. Enable the “Scan archived files” and “Scan removable media” options. The first option allows you to scan compressed folders (files with the .zip extension) for malware. The second setting allows you to scan connected USB devices during a full scan. This is very important because malware can spread in these ways.

Then check the “Create a system restore point” checkbox. In this case, a system restore checkpoint will be created each time a detected virus or malware is removed or quarantined. If your computer becomes unstable after deletion, you can return it to its original state using the system recovery tool.

If you want all PC users (and not just administrators) to be able to view detected objects on the “Log” tab, activate the “Allow all users to view the results of all scans” option. Set the value of the “Delete quarantined files after” parameter to “3 months”. This measure will free up some space on your hard drive.

In Windows 8.1, there is another settings item here - “Automatically send sample files if further analysis is required.” When you enable this option, the system antivirus will display fewer annoying alerts, so it is recommended to enable this feature.

If you are seriously concerned about the privacy of your personal information, go to the “MAPS” tab and select the “I do not want to join the MAPS service” option. In this case, information about detected objects will not be sent to Microsoft. Other users can leave the “Basic participation level” item active.

Finally, open the Administrator tab and make sure that the “Turn on Windows Defender” (in Windows 8) or “Turn on an app” (in Windows 8.1) option is enabled. Click the “Save Changes” button.

The settings will be saved. You can now safely close Windows Defender by pressing ALT + F4. Defender will run in the background and will monitor files and settings. The program will automatically update virus and spyware signatures once a day when Windows Update is running.

Windows Defender Settings in Windows 10

Windows 10 makes it even easier to interact with Windows Defender settings and uses the universal Settings app for customization.

First, enable the Real-time Protection option to enable Windows Defender. If the option is disabled, the remaining parameters will be unavailable (grayed out).

Cloud Security enhances security for most users. Only if you are seriously concerned about privacy, disable this option.

"Automatically send samples" is very similar to the previous setting, so it's worth leaving this option enabled.

If you are not a professional IT specialist, it is better not to touch Exceptions.

You can now close the Settings app.

Windows Defender messages in Windows 8, 8.1 and 10

In Windows 8 and 8.1, Windows Defender does not have an icon in the taskbar notification area (system tray), so the best solution is to periodically check the status of the Action Center icon (white flag). If a checkbox has a red circle with an “X” on it, something has gone wrong. Click the icon to view a list of detected issues - these may not be related to Windows Defender.

In Windows 10, the Windows Defender icon has been brought back. The icon works stably, nothing blocks it. To open the program itself, right-click on the icon and select "Open".

If the icon has a red circle with a white cross, something has gone wrong, for example a malicious infection has occurred and the user’s attention is required to clean it up.

If a green circle is displayed next to the icon, a scan is in progress - no action needs to be taken.

If Windows Defender needs to scan your computer, a corresponding alert will appear in the Action Center, just click on it to start the scan. The program conducts an automatic scan every day at 3:00 by default, and the user will see notifications if the system antivirus has missed several scans.

If Action Center displays the "Update your antivirus protection (Important)" and "Update your antispyware protection (Important)" alerts, click them to open Windows Defender to download the latest signature definitions.

If you see the messages “Turn on virus protection (Important)” or “Turn on spyware protection (Important),” click on either of them and wait for Windows Defender to load. The computer status in the main Windows Defender window should soon turn green, after which you can safely close the window. These messages typically appear when Windows Defender real-time protection or services are disabled.

If you see the message “The Windows Defender service cannot start,” the antivirus protection service has been stopped or disabled. Click the “Close” button.

In Windows 8 and 8.1, open search (Windows key + W), enter the phrase “services” and select the “View local services” utility. In Windows 10, open the Start menu or Cortana search (Windows keyboard shortcut + S).

Scroll down the list of services to “Windows Defender Service” and check if the “Startup type” field is set to “Disabled”.

Windows 8 only: Call the context menu of the disabled service and select the “Properties” menu item.

In Windows 8.1 and 10, you cannot change Windows Defender service settings normally.

Then only in Windows 8, in the Windows Defender service settings window, change the startup type to “Automatic”. Then click the “Run” button and then “OK”.

In Windows 8.1 and 10, you need to boot into Safe Mode. After authorization, the start screen and start menu will open, enter the command regedit, Right-click on the result and select the "Run as administrator" option.

Go to section HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services and click on the entry WinDefend. Select entry Start in the right panel . If the parameter value is 0x00000004 (4), the service has been disabled. Double click on the entry Start.

Enter the value 2 and make sure the number is in hexadecimal, then click OK. The Windows Defender service will now start automatically.

Then repeat the same step for the WdNisSvc (Windows Defender Inspection Service) service.

Save the changes and restart your computer normally, Windows Defender should now work correctly.

If Windows Defender cannot start, first run Rkill and then perform a full scan with Malwarebytes Anti-Malware without restarting your computer.

If Action Center displays the message “Update your virus protection” or “Update your antispyware protection,” click either to launch Windows Defender and download the latest antivirus databases.

If the signature update fails, try reinstalling Windows updates.

When a malicious program is detected, a message (pop-up notification) appears in the upper right part of the screen. You do not need to do anything, because Windows Defender automatically removes or quarantines threats it finds.

The pop-up alert closes automatically. If no other messages appear, your computer was cleaned successfully.

If you need to restart your computer to complete the cleanup, you will see the following notification. Click it to launch Windows Defender.

Click the large “Restart now” button in the Windows Defender window.

Just like with Microsoft Security Essentials, a confirmation window appears. Click “Yes” to restart your computer.

Your computer will restart and Windows Defender will remove any remaining traces of the malware.

If you receive repeated messages about malware detection and/or removal, run RKill to kill the malicious processes, then run a full system scan with Malwarebytes Anti-Malware.

Manage quarantined items in Windows Defender in Windows 8, 8.1, and 10

By default, most infected objects are quarantined - a safe place where malware cannot harm the real system. Windows Defender removes items after three months (if the option is selected). To scan and manage quarantined objects, in Windows 8 and 8.1, open the search bar (Windows key + Q), enter the phrase “defender” in the search bar and click the result.

Users of touch screen devices can open the sidebar on the right side of the screen and then select the Search option.

In Windows 10, open the Start menu, type "defender" and select the top result, "Windows Defender."

Click the “Log” tab and make sure that “Quarantined objects” is selected. If you haven't enabled the “Allow all users to view the results of all scans” option (available in Windows 8 and 8.1) in Windows Defender settings, you need to first click the “View details” button (even if you are a device administrator).

It is usually recommended to select the “Delete all” option - all objects have been added to quarantine for some reason. If you are curious and want to know more information about the files added to quarantine, you can click on an item in the list to view the description and original location. You can also select any detected object by checking the box on the left side of the list. Then you can delete the selected files using the “Delete” button.

You can also restore an object to its original location using the “Restore” button. Be extremely careful - false positives are rare. Never restore objects with a strict, high or medium alert level!

Set up scheduled scans and updates in Windows Defender in Windows 8, 8.1 and 10

Unlike Microsoft Security Essentials, Windows Defender does not have scheduled scanning settings in the program's graphical interface, but the user still has the option of automating a quick or full system scan.

In Windows 8.1 and 10, Quick Scan runs daily (at 3 a.m. by default) along with Windows feature updates and other tasks. If an operation was skipped or canceled due to shutting down or restarting the computer, the scan will run the next time the computer is turned on or restarted. You will see a clock icon next to the Action Center icon in the taskbar notification area (system tray) during maintenance.

If a scan has not run for an extended period of time, Action Center will notify you with the message “Windows Defender needs to scan your computer.”

To schedule a Windows Defender scan, in Windows 8 and 8.1, open the search bar (Windows key + W), type “schedule” and select the “Schedule tasks” object.

In Windows 10, open the Start menu, type “scheduler” and select the top result “Task Scheduler”.

Users of touch screen devices can bring up the Charms panel by swiping from the right side of the screen and then selecting the “Search” option.

Right-click on “Task Scheduler (Local)” and select the “Create simple task” option.

The Create a Simple Task Wizard will open. Provide a name and descriptions for the scan task and click Next.

If you want to run quick system scans weekly, select the “Weekly” option (in Windows 8.1, quick scans are scheduled by default).

Since full checks can take a long time, you should use the “Monthly” value for these purposes.

On the next screen you can set the day of the week and time for performing quick checks, as well as the months, days and times for full checks. Since there is no limit on the use of CPU resources, it is recommended to select the time when the computer is most likely to be idle - the scanning process reduces the performance of the computer.

When selecting the desired action, select the “Run a program” option.

Click the “Browse...” button.

Go to folder C:\Program Files\Windows Defender and double click on the MpCmdRun.exe file. This executable allows you to run basic tasks in Windows Defender.

To perform a quick scan, in the “Add arguments (optional)” field: write “-Scan -ScanType 1”, and to perform a full scan enter “ -Scan -ScanType 2”.

The setup process is almost complete. Enable the “Open Properties window” option for this task after clicking the “Finish” button.

The properties window will open with the “General” tab active. Click the “Change...” button in the “Use the following user account when performing tasks” option in the “Security Settings” section.

In the “Enter names of selected objects” field, enter “SYSTEM” in capital letters and click the “Check names” button. The title should be underlined. Click the “OK” button. This way, the account with the highest priority and user rights will be selected.

Return to the “General” tab of the scheduler settings and check the “Run with highest rights” checkbox. This will run Windows Defender with elevated rights, ensuring that complex malware removal will be successful.

Open the “Settings” tab and enable the “Run task immediately if scheduled launch is missed” option. If the computer was turned off when it was time for a scheduled scan, the scan will be performed the next time you turn on the computer and log in to your account. Click “OK” in the “Options” window.

During scheduled operations, a command prompt window will be launched. It will close automatically when scanning is complete.

Update Windows Defender more than once a day

If you are unhappy with the fact that Windows Defender updates its databases only when it checks for Windows Update updates (that is, once a day), you can follow these steps. Create a new simple task, specify the execution frequency as “Daily” and set the time to 12:00 AM (0:00). On the “Action” screen, specify the same file MpCmdRun.exe but with the new argument “- SignatureUpdate”.

After creating a task and opening its properties, select the “Triggers” tab, select an existing schedule and click the “Edit” button.

Enable the “Repeat task every” option and specify the value “4 hours”. This value is not initially listed, but you can select “1 hour” and then manually change it to “4”. Click “OK” and close the task properties window.

Windows Defender will now update its databases every 4 hours. Each time the command prompt window will open and close automatically.

Keep in mind that this does not mean that the Windows Update service will run every 4 hours - the operations done only apply to Windows Defender updates.

Found a typo? Highlight and press Ctrl + Enter