If you have opened Task Manager and noticed Antimalware Service Executable using a large amount of CPU, memory, or disk resources, you may be wondering how to disable it in Windows 11. Antimalware Service Executable is part of Microsoft Defender Antivirus, so stopping it completely is not the same as closing an ordinary background application.
In this guide, we will explain how to disable Antimalware Service Executable in Windows 11, why it may use high CPU or disk resources, safer alternatives to completely disabling Microsoft Defender, and how to turn protection back on when you are finished.
Important: Microsoft Defender helps protect Windows from viruses, malware, ransomware, and other threats. Turning off real-time protection leaves your PC more vulnerable. Microsoft also notes that Defender can automatically turn itself back on when no other compatible security product is protecting the device. (Microsoft Support)
What Is Antimalware Service Executable in Windows 11?
Antimalware Service Executable is the process associated with Microsoft Defender Antivirus. Its executable is commonly shown as MsMpEng.exe in Task Manager.
Microsoft Defender runs in the background to scan files, applications, downloads, and other activity for potential threats.
You may see it in Task Manager under:
Task Manager → Processes → Antimalware Service Executable
When Defender is performing a scan, CPU, memory, and disk usage can temporarily increase. A Microsoft Q&A discussion also notes that higher resource usage is common while Defender performs a full scan. (Microsoft Learn)
Why Is Antimalware Service Executable Using High CPU?
There are several possible reasons.
Common causes include:
- Microsoft Defender is performing a full or scheduled scan.
- Real-time protection is scanning files as they are opened or changed.
- A large number of files are being accessed.
- A particular application repeatedly triggers Defender scans.
- Large development, database, or game folders are being scanned.
- Another application is repeatedly causing on-demand scans.
- Windows Defender has recently updated its security intelligence.
- A background task is running a scheduled scan.
High usage during an active scan does not necessarily mean something is wrong.
If the process remains unusually busy for a long period, it is generally better to investigate what Defender is scanning instead of immediately disabling antivirus protection.
Should You Disable Antimalware Service Executable?
Usually, no.
Antimalware Service Executable is part of Windows’ built-in security protection. Disabling Microsoft Defender can reduce your protection against malware.
A better approach is:
- Wait for an active scan to finish.
- Restart Windows.
- Install pending Windows updates.
- Check whether a specific application or folder is causing repeated scanning.
- Use a targeted exclusion only when you understand the security implications.
- Temporarily disable real-time protection only when necessary.
Microsoft specifically warns that your device can become vulnerable when Microsoft Defender Antivirus is disabled without another security product protecting it. (Microsoft Support)
How to Disable Antimalware Service Executable in Windows 11
There is an important distinction here.
You generally cannot treat Antimalware Service Executable like a normal application and permanently end it from Task Manager. Instead, you manage the Microsoft Defender protection that runs the process.
The simplest supported method is to temporarily turn off Real-time protection.
Method 1: Temporarily Disable Microsoft Defender Real-Time Protection
This is the easiest method for most Windows 11 users.
Step 1: Open Windows Security
Press:
Windows + S
Type:
Windows Security
Then select Windows Security from the search results.
Step 2: Open Virus & threat protection
In Windows Security, select:
Virus & threat protection
This section contains Microsoft Defender Antivirus settings.
Step 3: Open Manage settings
Under Virus & threat protection settings, find:
Manage settings
Click it.
Step 4: Turn Off Real-Time Protection
Find:
Real-time protection
Switch the toggle to:
Off
Windows may display a User Account Control or security confirmation depending on your configuration.
Microsoft documents this as the standard way to temporarily enable or disable Defender Antivirus real-time protection. (Microsoft Support)
Step 5: Check Task Manager
Now press:
Ctrl + Shift + Esc
to open Task Manager.
Look for:
Antimalware Service Executable
You may notice that CPU, memory, or disk activity decreases.
Keep in mind that turning off real-time protection does not mean you should leave it disabled permanently.
How to Turn Microsoft Defender Back On
After completing whatever task required Defender to be disabled:
- Open Windows Security.
- Select Virus & threat protection.
- Click Manage settings.
- Find Real-time protection.
- Turn it On.
It is strongly recommended to restore real-time protection as soon as possible.
Method 2: Add a Targeted Exclusion Instead of Disabling Defender
If your real problem is high CPU usage caused by a particular trusted application or folder, an exclusion may be more appropriate than disabling Defender completely.
For example, developers sometimes have large folders containing source code, build files, databases, or virtual machine files that are repeatedly scanned.
How to Add an Exclusion
- Open Windows Security.
- Select Virus & threat protection.
- Select Manage settings.
- Scroll to Exclusions.
- Select Add or remove exclusions.
- Select Add an exclusion.
- Choose the appropriate type.
- Select the trusted file, folder, process, or other item.
Microsoft’s Defender policy documentation supports path exclusions, but exclusions reduce the areas Defender scans, so they should be used carefully. (Microsoft Learn)
Important Security Tip
Do not randomly exclude:
C:\- your entire Windows folder
- the entire Program Files directory
- your Downloads folder
- unknown applications
- suspicious files
- the entire Defender installation directory
Only exclude a specific, trusted workload when you have a clear reason.
Method 3: Limit Defender’s CPU Usage During Scans
If your main problem is CPU usage rather than antivirus protection itself, you may be able to limit CPU usage during Defender scans.
Windows provides the ScanAvgCPULoadFactor setting for controlling the average CPU load factor used during scans.
Microsoft Q&A documentation describes this option as a way to limit CPU usage during scans. It does not mean that real-time protection itself will necessarily stop using CPU. (Microsoft Learn)
For example, administrators can configure Defender’s scan CPU load through PowerShell.
A commonly used command is:
Set-MpPreference -ScanAvgCPULoadFactor 50
This sets the scan CPU load factor to 50.
Important: This is not a complete “disable Antimalware Service Executable” command. It controls scan behavior rather than removing Microsoft Defender.
Method 4: Use Group Policy to Control Defender Scan CPU Usage
If you have Windows 11 Pro, Enterprise, or Education, Group Policy provides additional Defender management options.
Step 1: Open Group Policy Editor
Press:
Windows + R
Type:
gpedit.msc
Press Enter.
Step 2: Navigate to Microsoft Defender
Go to:
Computer Configuration → Administrative Templates → Windows Components → Microsoft Defender Antivirus → Scan
Step 3: Find the CPU Usage Policy
Look for:
Specify the maximum percentage of CPU utilization during a scan
Open the policy.
Step 4: Enable the Policy
Select:
Enabled
Then specify an appropriate CPU percentage.
Select:
Apply → OK
This approach is preferable when the problem is scan-related CPU usage rather than a need to remove antivirus protection.
Can You Permanently Disable Antimalware Service Executable?
For normal Windows 11 installations, permanently disabling Microsoft Defender is not recommended.
Modern Windows security features are designed to protect security settings from unauthorized changes. Microsoft also uses Tamper Protection to help prevent applications and malware from changing important security settings. (Microsoft Support)
Because of this, many old internet tutorials involving registry changes, Task Scheduler tricks, or forcibly stopping Defender services may no longer work reliably and can create security problems.
Avoid following guides that tell you to:
- delete Defender system files;
- modify random registry entries;
- disable Windows security services permanently;
- disable security through unknown scripts;
- add massive Defender exclusions;
- download third-party “Defender remover” utilities.
Why Doesn’t Task Manager Let Me Permanently End Antimalware Service Executable?
You may right-click Antimalware Service Executable in Task Manager and discover that you cannot simply terminate it like a normal application.
That’s intentional.
Microsoft Defender is a security component rather than an ordinary desktop application. Windows protects important security processes from being casually terminated.
Therefore, repeatedly trying to kill MsMpEng.exe is not a good solution.
Instead, manage Defender through Windows Security or appropriate administrative policies.
How to Fix High CPU Usage Without Disabling Defender
If Antimalware Service Executable is consuming excessive resources, try these solutions first.
1. Wait for the Scan to Finish
Open:
Windows Security → Virus & threat protection
Check whether a scan is currently running.
A full scan can use significant CPU and memory while it is active. (Microsoft Learn)
2. Restart Your Computer
A simple restart can clear temporary background activity.
After restarting:
- Wait several minutes.
- Open Task Manager.
- Check CPU usage.
- Monitor Antimalware Service Executable.
If usage returns to normal, the earlier activity may have been temporary.
3. Update Windows 11
Go to:
Settings → Windows Update
Select:
Check for updates
Install available updates and restart the computer.
Also make sure Microsoft Defender’s security intelligence updates are current.
4. Check Which Application Is Triggering Defender
If CPU usage remains high, look for an application that repeatedly accesses large numbers of files.
Examples include:
- development tools;
- database applications;
- virtual machines;
- file synchronization software;
- game launchers;
- backup applications;
- large build directories.
Microsoft recommends using Defender performance analysis tools to identify workloads responsible for excessive scanning rather than blindly adding broad exclusions. (Microsoft Learn)
How to Check Antimalware Service Executable in Task Manager
You can monitor it easily.
Step 1
Press:
Ctrl + Shift + Esc
Step 2
Select:
Processes
Step 3
Find:
Antimalware Service Executable
Step 4
Check:
- CPU
- Memory
- Disk
- Network
You can click a column heading to sort processes by resource usage.
What Is MsMpEng.exe?
MsMpEng.exe is the executable associated with Microsoft Defender Antivirus’s antimalware engine.
You may see Antimalware Service Executable in the Processes tab while seeing MsMpEng.exe under the Details tab.
They refer to the Defender antimalware process.
If you see a suspicious executable with a similar name in an unusual location, do not assume it is legitimate simply because its name resembles MsMpEng.exe.
How to Tell If Antimalware Service Executable Is Causing the Slowdown
Use Task Manager to determine whether the process is actually responsible.
- Press Ctrl + Shift + Esc.
- Select Processes.
- Sort by CPU.
- Find Antimalware Service Executable.
- Check its CPU usage.
- Check the Disk column.
- Monitor it for several minutes.
If the process is consuming significant resources while Defender is actively scanning, the scan may explain the temporary slowdown.
If it remains unusually high when no obvious scan is running, investigate further rather than immediately disabling protection.
How to Reduce Defender CPU Usage During Gaming
Gamers may notice Defender activity while installing, updating, or launching games because these operations can involve thousands of files.
Before adding an exclusion, try:
- Update Windows.
- Update the game.
- Restart Windows.
- Let Defender finish any active scan.
- Check Task Manager.
- Identify the specific game or folder causing repeated activity.
If a trusted game installation directory is confirmed to be responsible, you can consider a narrow, targeted exclusion rather than disabling Defender entirely.
Remember that exclusions reduce scanning coverage.
How to Reduce Defender CPU Usage for Developers
Developers working with large repositories, package caches, databases, virtual machines, or build directories can sometimes experience repeated scanning.
Instead of excluding an entire drive, identify the specific workload.
For example, a trusted project directory might be considered for exclusion if Defender performance analysis shows that it is responsible for excessive scanning.
Microsoft’s performance guidance emphasizes identifying the specific files, paths, or processes responsible before applying exclusions. (Microsoft Learn)
Should You Disable Defender While Installing Software?
Usually, no.
If Windows Security blocks a legitimate application, first verify that the software came from a trustworthy source.
Do not disable antivirus protection simply because an unknown installer requests it.
If an installer genuinely requires Defender to be temporarily disabled, verify the publisher and download source before proceeding, and immediately restore protection afterward.
What Happens When You Turn Off Real-Time Protection?
When real-time protection is turned off, Defender’s continuous monitoring is reduced.
That means malicious files may not be detected as quickly when they are downloaded, opened, or executed.
Microsoft explicitly warns that disabling Defender without another security product can leave the device vulnerable. (Microsoft Support)
For this reason, treat the setting as a temporary troubleshooting option, not a permanent performance optimization.
Does Disabling Antimalware Service Executable Improve PC Performance?
It can reduce Defender-related CPU or disk activity while protection is disabled, but that does not necessarily mean it is the best performance solution.
If Defender is consuming excessive resources, the better long-term solution is to determine why it is scanning so much.
Possible solutions include:
- finishing a pending scan;
- updating Windows;
- identifying a problematic application;
- using a targeted exclusion;
- configuring scan CPU usage;
- troubleshooting third-party software.
Can I Delete Antimalware Service Executable?
No.
Do not attempt to delete MsMpEng.exe or other Microsoft Defender system files.
They are components of Windows security. Removing or modifying system security files can cause errors and reduce protection.
Can I Uninstall Microsoft Defender From Windows 11?
Microsoft Defender Antivirus is integrated into Windows 11 and is not something you should try to remove manually.
If you install another compatible antivirus product, Windows can change how Defender’s antivirus protection operates. Microsoft states that Defender can automatically turn itself back on if another security product is removed or no longer provides protection. (Microsoft Support)
What If I Have Another Antivirus Installed?
If you use another antivirus product, check Windows Security to confirm which security provider is active.
Avoid running multiple full antivirus products simultaneously unless the products are specifically designed to work together.
Microsoft warns that having multiple antivirus or antispyware programs can cause performance problems, instability, or unexpected restarts. (Microsoft Support)
How to Re-Enable Microsoft Defender After Disabling It
If you temporarily turned off real-time protection:
- Open Windows Security.
- Select Virus & threat protection.
- Select Manage settings.
- Turn Real-time protection back On.
- Confirm that protection is active.
You should also check that Cloud-delivered protection and Automatic sample submission are enabled when appropriate. Microsoft recommends keeping these protections enabled for optimal protection. (Microsoft Support)
What Is the Safest Alternative to Disabling Antimalware Service Executable?
For most people, the safest approach is:
Do not permanently disable Defender.
Instead:
Find the cause → reduce unnecessary scanning → use a narrow exclusion if appropriate → keep real-time protection enabled.
This gives you a better balance between Windows performance and security.
Quick Comparison: Your Options
| Method | Reduces Defender Activity | Security Impact | Recommended? |
|---|---|---|---|
| Wait for scan to finish | Yes | None | Yes |
| Restart Windows | Sometimes | None | Yes |
| Update Windows | Sometimes | None | Yes |
| Targeted exclusion | Often | Some | Only when necessary |
| Limit scan CPU usage | Can help during scans | Low | Good option |
| Temporarily disable real-time protection | Yes | High while disabled | Temporary use only |
| Permanently disable Defender | Yes | High | Not recommended |
| Delete Defender files | Unpredictable | Very high | Never |
Frequently Asked Questions
Is Antimalware Service Executable a virus?
No. Antimalware Service Executable is normally a legitimate component of Microsoft Defender Antivirus. The legitimate Defender process is associated with Microsoft’s built-in antivirus protection.
Why does Antimalware Service Executable use 100% CPU?
It may happen while Microsoft Defender is performing a scan or repeatedly scanning files accessed by another application. Check Windows Security and Task Manager before assuming that the process is malfunctioning.
Can I stop Antimalware Service Executable from Task Manager?
You generally should not try to permanently stop it through Task Manager. It is a security component of Microsoft Defender. Manage Defender through Windows Security or supported administrative settings instead.
How do I temporarily disable Antimalware Service Executable in Windows 11?
Open Windows Security → Virus & threat protection → Manage settings, then turn Real-time protection off. Microsoft documents this as the standard method for temporarily disabling Defender Antivirus real-time protection. (Microsoft Support)
Will Antimalware Service Executable turn back on automatically?
It can. Microsoft states that if no other security product is protecting the device, Microsoft Defender Antivirus can automatically turn itself back on. (Microsoft Support)
Is it safe to disable Windows Defender permanently?
It is not recommended. Disabling Defender can leave your computer vulnerable to malware if another security solution is not providing protection.
Does Windows 11 automatically scan my files?
Yes. Microsoft Defender provides real-time and scheduled antivirus protection, which can involve scanning files and processes in the background.
Why is Antimalware Service Executable using disk instead of CPU?
Defender may be reading and scanning many files. During scans, disk activity can increase even when CPU usage is relatively moderate.
Should I add MsMpEng.exe to Defender exclusions?
Generally, do not add the Defender process or its installation directories to exclusions simply because you see high CPU usage. First determine what is actually causing the scanning activity. Broad exclusions can reduce your security protection.
Can I disable Defender only while gaming?
You can temporarily turn off real-time protection, but it is safer to keep protection enabled whenever possible. If a specific trusted game directory repeatedly causes excessive scanning, a carefully chosen exclusion may be a better approach.
Does limiting Defender CPU usage turn off antivirus protection?
No. CPU-limiting settings are intended to control scan resource usage rather than completely disable Defender protection. Microsoft documentation distinguishes scan CPU controls from real-time protection. (Microsoft Learn)
What should I do if Defender keeps using high CPU after restarting?
Check whether a scan is running, install Windows updates, and identify which applications or folders are being accessed repeatedly. For persistent problems, Microsoft’s Defender performance-analysis tools can help identify the workload causing the excessive scanning. (Microsoft Learn)
Final Thoughts
Knowing how to disable Antimalware Service Executable in Windows 11 can be useful when troubleshooting high CPU, memory, or disk usage, but permanently disabling Microsoft Defender is rarely the best solution.
For a quick temporary test, you can turn off Real-time protection through Windows Security. If the problem is persistent, however, investigate what Defender is scanning and consider a targeted solution such as reducing scan CPU usage or adding a carefully selected exclusion.
Most importantly, remember to turn real-time protection back on after troubleshooting. Antivirus protection is one of the most important security layers on a Windows 11 PC.
Key Takeaways
- Antimalware Service Executable is part of Microsoft Defender Antivirus.
- High CPU usage can occur during scans.
- You can temporarily disable real-time protection through Windows Security.
- Permanently disabling Defender is not recommended.
- Targeted exclusions may help with trusted workloads that trigger excessive scanning.
- Do not delete
MsMpEng.exeor other Defender files. - CPU usage can be limited during Defender scans using supported configuration options.
- Always restore real-time protection after troubleshooting.