Can one prevent Antimalware Executable to start hogging CPU for extended periods each time some network adapter gets active?

Anonymous
2013-03-15T20:00:20+00:00

One of the most annoying habits in Windows 8 is, that the built-in "Antimalware Service Executable" (part of "Windows Defender") starts hogging my device's CPU with 60-70% (and 100% disk) for extended periods EACH AND EVERY time after I wake it up.

I wouldn't mind if it starts doing its business IN THE BACKGROUND but when I wake my device up from standby it's usually to get something done NOW and thus I find it increasingly unacceptable, that the system is always taken over by Window's defender exactly then and for up to several minutes! If I don't find a solution soon to throttle this beast, then I will disable Defender altogether!

What I noticed is, that this process seems to be actually triggered not by the system waking up, but by the network adapter becoming active. And actually, this happens each and every time ANY network adapter gets active! E.g. if my system has NO network connection at all and I plugin the network cable the Antimalware Service Executable starts. When - after it has settled again - I additionally enable Bluetooth then the Antimalware Service Executable starts its hogging business again. And if I then additionally enable the WLAN a few minutes later, it will AGAIN start to consume CPU!

So: can one decouple this? Running a scan ONCE after (re-)starting it is definitely enough, especially if Defender hasn't downloaded any new signatures since the last run! And, second, can one make Defender convince to strictly run in the background ONLY?

Michael

[Moved from Windows]

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

146 answers

Sort by: Newest
  1. Anonymous
    2016-05-16T07:23:40+00:00

    I have admin rights on my Win8 pc, and in the Task Scheduler **Library/Microsoft/Windows/Windows defender,**the condition "Power" has a checkmark but it is greyed out so I cannot remove the checkmark. how to "ungrey" this condition ?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-05-16T04:53:16+00:00

    Tadasha Mishra's answer is worthless, and should be redacted.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-05-10T02:12:28+00:00

    a simple solution is to uncheck the "high privileges" option of that specific task.

    cpu usage will go down

    try click to run that task and watch the cpu usage

    the effect is instant

    don't bother with other settings

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-04-21T20:15:31+00:00

    Seriously people, the "answer" here is a prank, and you shouldn’t be wasting your time with it. If this thread would have been moved into the Virus and Malware forum in a timely manner, then we’d be able to concentrate on things that might actually help. This is the kind of “answer” that quite often passes muster in the other Answers forums, and now it looks like we’ll just have to live with it here; because while we once had leadership that set a higher standard for this forum, that’s unfortunately no longer the case.

    The worst part is that this "answer" doesn’t even come close to describing how Task Scheduler actually works, and that should be abundantly clear to anyone who’s at all familiar with this app. Now you’d think that this would include at least one moderator in the Windows forum, since Task Scheduler is an ages-old Windows app. So this is really sad.

    In addition to giving us a fictitious method for “unscheduling” the Windows Defender Scheduled Scan task, this “answer” also falsely attributes the problem to a user-scheduled scan. Now Microsoft actually did later publish a (bogus) method for scheduling a scan in Windows 10 that asks the user to add a trigger to the Windows Defender Scheduled Scan task – but if the source of the OP’s problem was actually a Windows Defender scan, then it would have undoubtedly been the Windows Defender Quick Scan that Automatic Maintenance runs every day. That scan runs for everyone who uses Windows Defender.

    Of course if you read this thread carefully, it should be obvious that the reason that the OP was seeing such a high CPU utilization with the maintenance scan (and also probably with other Windows Defender components; like the Network Inspection Service), was that he still had Security Essentials (or elements thereof) installed after upgrading to Windows 8:

    What I find odd, is that there are TWO different paths to an executable of the same name MpCmdRun.exe, i.e.:

    - c:\Program Files\Microsoft Security Client\MpCmdRun.exe

    - c:\Program Files\Windows Defender\MpCmdRun.exe

    Is this the same program or are these different programs and/or versions?

    And if the original "answer" isn’t bad enough – we’re now being lectured on a “new and improved” Carte Blanche method for modifying the Windows Defender Scheduled Scan task’s Conditions:

    You can uncheck all boxes as Tadasha suggests under Idle, Power, and Network. In my case, I only had the first checkbox under Power checked by default. I decided to instead check all three boxes under Idle and change 10 minutes to 30 minutes. You can do as you like.

    How cool is that?

    GreginMich

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2016-04-21T16:22:01+00:00

    If you want to (if you can), you should be able to get your hands on a Win7 DVD and overwrite the current Win8 installation fully. You most likely already know you can do this, but still... I consider it a must to separate user data and app data (different partitions) because it's the easiest way to be assured of the safety of your data without backing up or using other drives. Just saying, I keep a Win8.1 installation and a Data partition, then the third is system-reserved and the fourth keeps switching between Ubuntu, Win7 and Win10. Easiest for me. When everyone that uses this computer listens to me and stores personal data on Data, there's nothing short of drive failure or a format that could cause them to lose their data.

    Was this answer helpful?

    0 comments No comments