What Antimalware Service Executable does, and why you might want to disable it
Antimalware Service Executable is the Windows process that runs Windows Defender in the background. It scans your files, monitors your system for threats, and blocks suspicious activity. The process shows up in Task Manager as "MsMpEng.exe" and typically uses a small but noticeable amount of CPU and disk space, especially during scheduled scans.
Most people should leave it running. But if you use a different antivirus program, run an older computer with limited resources, or need to troubleshoot a specific problem, you may want to turn it off. Disabling it means Windows Defender stops protecting your system, so you need another security tool in place first — or you need to know exactly why you are doing this and accept the risk.
Key Takeaways
- Antimalware Service Executable is Windows Defender running in the background, and disabling it removes your built-in malware protection.
- If you use a third-party antivirus like Norton, McAfee, or Kaspersky, Windows Defender should turn off automatically when you install it, but you can disable it manually if it does not.
- You can turn off real-time protection temporarily through Settings, or disable the service entirely through Services or Group Policy — the method depends on your Windows version and what you are trying to fix.
- Disabling Windows Defender permanently requires you to have another antivirus tool running, or your computer will be unprotected.
Disable real-time protection temporarily through Settings
This is the safest way to turn off Antimalware Service Executable for a short time — it pauses Windows Defender but does not remove it. Open Settings, go to Privacy & Security, then click Windows Security. Inside Windows Security, select Virus & threat protection, then click Manage settings under "Virus & threat protection settings."
Toggle off Real-time protection. Windows will ask you to confirm. After you toggle it off, the Antimalware Service Executable process will stop running. Windows will automatically turn real-time protection back on after a restart, or you can turn it back on manually by toggling the same switch.
This method works on all recent Windows versions and does not require administrator access beyond what you already have. Use this if you are installing software that conflicts with Windows Defender, running a one-time scan with a different tool, or troubleshooting a specific problem.
Disable Windows Defender entirely through Services
If you want to turn off Antimalware Service Executable permanently, you can disable the Windows Defender service itself. Right-click the Start button and select Run, then type "services.msc" and press Enter. This opens the Services window, which lists every background service on your computer.
Scroll down to find Windows Defender Advanced Threat Protection Service or WinDefend — the exact name varies by Windows version. Right-click it and select Properties. In the Startup type dropdown, select Disabled. Click Apply, then OK. You may need to restart your computer for the change to take effect.
This method disables the service permanently until you change it back. It requires administrator access. After you disable it, Windows Defender will not run even after a restart, and Antimalware Service Executable will not appear in Task Manager. Make sure you have another antivirus tool running before you do this.
Turn off Windows Defender using Group Policy (Windows Pro and Enterprise only)
If you use Windows Pro, Enterprise, or Education edition, you can disable Windows Defender through Group Policy, which gives you more control over the setting. Right-click Start and select Run, type "gpedit.msc", and press Enter. This opens the Group Policy Editor.
Navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Find the policy called Turn off Microsoft Defender Antivirus and double-click it. Select Enabled, then click Apply and OK. Restart your computer.
Group Policy changes override the Services method and prevent users from turning Windows Defender back on through Settings. This is useful if you manage multiple computers or want to enforce the setting across your system. Windows Home edition does not include Group Policy Editor, so this method does not work on that version.
What happens when you disable Antimalware Service Executable
Once you turn off Windows Defender, your computer loses its built-in malware protection. Windows will show a warning in Settings that your device is not protected. If you do not have another antivirus program running, malware can infect your system without you knowing.
Disabling Windows Defender also removes real-time scanning, which means files are not checked when you download or open them. Scheduled scans stop running. Windows Security alerts disappear. The only reason to accept this is if you have a different antivirus tool installed and running — Norton, McAfee, Kaspersky, Bitdefender, or another reputable program.
If you disabled Windows Defender to troubleshoot a problem and the problem is fixed, turn it back on. Use the same method you used to disable it: toggle real-time protection back on in Settings, change the service back to Automatic in Services, or disable the Group Policy rule.
When you should not disable Antimalware Service Executable
Do not disable Windows Defender if you do not have another antivirus program installed. Do not disable it to speed up your computer — the performance gain is usually small, and the security risk is large. Do not disable it because a website or forum told you to without understanding why.
If Antimalware Service Executable is using too much CPU or disk space, the problem is usually a scheduled scan running at a bad time, not the service itself. You can change when scans run by opening Windows Security, going to Virus & threat protection, clicking Manage settings, and scrolling down to Scheduled scan. Set it to run at a time when you are not using your computer.
If you installed a third-party antivirus and Windows Defender is still running, that antivirus should have disabled it automatically. If it did not, check the antivirus settings first — most have an option to disable Windows Defender. Only disable it manually if the antivirus program does not offer that option.
How to turn Windows Defender back on
If you disabled real-time protection through Settings, open Settings, go to Privacy & Security > Windows Security > Virus & threat protection > Manage settings, and toggle Real-time protection back on.
If you disabled the service through Services, open Services again, find WinDefend or Windows Defender Advanced Threat Protection Service, right-click it, select Properties, change Startup type to Automatic, and click OK. Restart your computer.
If you disabled it through Group Policy, open Group Policy Editor again, navigate to the same location, find Turn off Microsoft Defender Antivirus, double-click it, select Not Configured, and click OK. Restart your computer.
Frequently Asked Questions
Will disabling Antimalware Service Executable make my computer faster?
It may reduce CPU and disk usage slightly, but the performance gain is usually small — often less than 5 percent. The security risk of running without antivirus protection is much larger than the speed benefit. If your computer is slow, the problem is usually something else: too many startup programs, a full hard drive, or outdated hardware.
Can I disable it just during gaming?
Yes, you can toggle real-time protection off through Settings before you play, then turn it back on after. This is safer than disabling it permanently because you are only unprotected for a short time. Some antivirus programs, including Windows Defender, have a "gaming mode" that reduces background activity without turning off protection entirely.
What if I have Norton or McAfee installed — does Windows Defender turn off automatically?
It should. Most third-party antivirus programs disable Windows Defender when you install them. Check your antivirus settings to confirm it is running. If Windows Defender is still active, your antivirus program may have a setting to disable it, or you can disable it manually through Services or Settings.
Is it safe to disable Antimalware Service Executable if I do not go online much?
No. You do not need to be actively browsing the internet to get infected. Malware spreads through email attachments, USB drives, software downloads, and network connections. Even if you rarely go online, you should have antivirus protection running at all times.
What should I do if Windows Defender keeps turning back on?
If you disabled it through Services but it keeps restarting, Windows may be re-enabling it automatically. Check that you set the startup type to Disabled, not just Manual. If you are using Group Policy, make sure you set the policy to Enabled. If it still keeps turning on, a third-party antivirus program or Windows Update may be re-enabling it — check your antivirus settings or temporarily pause Windows Update.