MSFT: I finally fingered it out. Go finger.
Can one prevent Antimalware Executable to start hogging CPU for extended periods each time some network adapter gets active?
One of the most annoying habits in Windows 8 is, that the built-in "Antimalware Service Executable" (part of "Windows Defender") starts hogging my device's CPU with 60-70% (and 100% disk) for extended periods EACH AND EVERY time after I wake it up.
I wouldn't mind if it starts doing its business IN THE BACKGROUND but when I wake my device up from standby it's usually to get something done NOW and thus I find it increasingly unacceptable, that the system is always taken over by Window's defender exactly then and for up to several minutes! If I don't find a solution soon to throttle this beast, then I will disable Defender altogether!
What I noticed is, that this process seems to be actually triggered not by the system waking up, but by the network adapter becoming active. And actually, this happens each and every time ANY network adapter gets active! E.g. if my system has NO network connection at all and I plugin the network cable the Antimalware Service Executable starts. When - after it has settled again - I additionally enable Bluetooth then the Antimalware Service Executable starts its hogging business again. And if I then additionally enable the WLAN a few minutes later, it will AGAIN start to consume CPU!
So: can one decouple this? Running a scan ONCE after (re-)starting it is definitely enough, especially if Defender hasn't downloaded any new signatures since the last run! And, second, can one make Defender convince to strictly run in the background ONLY?
Michael
[Moved from Windows]
Windows for home | Previous Windows versions | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
146 answers
Sort by: Newest
-
Anonymous
2014-09-20T14:55:34+00:00 -
Anonymous
2014-09-20T14:37:28+00:00 This problem and it solutions are so Microosoft. I am the admin and only user of this PC. It will not let me check or uncheck any of the conditions boxes suggested above. ?
-
Anonymous
2014-09-11T19:49:26+00:00 If Automatic Maintenance is running the Windows Defender scheduled scan while you’re using your PC (if you see the Automatic Maintenance “clock” superimposed on the Action Center icon (the white flag in the notification tray)), and this is interfering with your work, then I would suggest scanning for system corruption:
If the Automatic Maintenance scan isn’t yielding to user activity the way it’s supposed to, then you can work around the issue by rescheduling Automatic Maintenance (in the Action Center) for a time when the PC isn’t in use, or you can disable the Windows Defender Scheduled Scan task in Task Scheduler (right-click on the task and select “disable"). If the issue isn’t directly related to the Automatic Maintenance scan, but appears to be related to problems with the Windows Defender antimalware engine (MsMpEng.exe) per se, i.e., if you observe excessive CPU usage for MsMpEng.exe (in Task Manager) when the scheduled scan isn’t running, this is most frequently caused by conflicting (real-time) antimalware products, remnants thereof, or by utilities with high read/write activity levels, which can sometimes be identified with Task Manager or Process Monitor. If you see this “free-floating” excessive CPU usage for MsMpEng.exe, the first thing you need to do is remove any other real-time AV products that might be installed, and also run the removal tools for any AV products that were packaged with the PC, or that you previously installed:
If that doesn’t eliminate the problem, then the issue could possibly be the result of undetected malware, so you should scan with multiple second-opinion antimalware scanners:
http://www.surfright.nl/en/hitmanpro
https://www.malwarebytes.org/free/
http://www.kaspersky.com/downloads/kaspersky-virus-removal-tool
http://support.kaspersky.com/viruses/disinfection/5350
http://www.pandasecurity.com/homeusers/solutions/activescan/
http://www.bitdefender.com/scanner/online/free.html
http://www.eset.com/us/online-scanner/
If that doesn’t do it, then you should just go ahead and install a third-party AV product. The Windows 8/8.1 operating system is designed to shut down Windows Defender automatically when any other real-time AV product is installed – and third-party AV products not only seem to be less prone to conflicts; they also appear to have better detection rates:
http://www.av-test.org/en/home/?avtest\[type\]=3
But be advised that the final verdict isn’t in yet, because the analysis changes radically when it’s based on Microsoft’s own prevalence data:
http://www.av-comparatives.org/microsoft-prevalence-based-analysis-file-detection-tests/
GreginMich
-
Anonymous
2014-09-10T10:47:09+00:00 In that case I suggest you actually read the fora in search for your answers, I doubt others will be better slaves to your needs.
-
Anonymous
2014-09-10T07:34:15+00:00 Excuse me? The fact that I think I am smarter than you has nothing to do with this, but you have proven me right at every turn so far. Moreover, I didn't imply that at all; I implied that you are lazy. I have pointed you straight towards the answer after which you were still incapable of finding it in just 4 pages of the thread you are already on. So I searched the thread for you, found the answer 3 times in under 2 minutes and copied the it. Now instead of a 'thank you' you start talking back to me?
Who the **** do you think you are, expecting others to search the forums for you to give you the answers you seek on a silver platter? This thread isn't just littered with loads of complaints, but with several people asking the exact question you did, all of which have received the exact same answer. You are part of the very problem that bothers you so much
Finaly, yes, I also know a solution to your other question, because I posted it in this very thread. It's probably not the answer your were looking for, though. You can either search for it yourself or, if you are too lazy, kindly ask me on which page and see if I'll reply. Just don't assume I'll go and fetch it for you again.
I dont want anything from you - its too nasty.