https://drive.google.com/file/d/1Z8GIYcaUdXEhadhH30QT9opgK7vz6KVZ/view?usp=sharing (fixlog) https://drive.google.com/file/d/1LQFRCfouQ7yIBnnoH_W4ZiIuSFFIUWm4/view?usp=sharing (boot log zip) also, this time there was no un-grayed setting like last time, no changes
Antimalware service executable eats memory
title. it's always taking 200-300 mb of memory.
I tried:
disable windows security, got hit with this setting is managed by your (non existent) administrator
end task, got access is denies
command prompt things, did nothing
edit group policy, did nothing
enable disableantispyware in regedit, got hit with access is denied
tried to give myself permission to enable disableantispyware, access is denied
in case I missed any, I basically tried everything you can find online. no matter what I do, either nothing happens, access is denied or this setting is managed by your administrator
I'm about to flip this is my computer, I should get to choose what to do. I am the administrator and only user
Windows for home | Windows 10 | Settings
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
61 answers
Sort by: Newest
-
Anonymous
2025-02-06T03:57:18+00:00 -
Ramesh Srinivasan 87,865 Reputation points Independent Advisor
2025-02-06T03:44:09+00:00 //THEN, 2 seconds later, a 'do you want this app to make changes' notif from windows security popped up.//
Just now saw your edited post.
If the UAC dialog appears again, click "Show more details" and note the process name Post the info here.
-
Ramesh Srinivasan 87,865 Reputation points Independent Advisor
2025-02-06T03:42:56+00:00 The policies are readded, maybe during the boot process, although we've reset the group policies file already.
From Command Prompt, run:
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /sPress Enter.
If it shows many registry values, it confirms that the policies were readded.
Re-run the fix in my last reply. But before rebooting the system, enable ProcMon boot logging.
After the reboot, save the boot log.
Zip the boot trace and share it. Also, share the latest fixlog.txt.
-
Anonymous
2025-02-06T03:35:56+00:00 https://drive.google.com/file/d/1WskIRqL6PNodlQrWsQs5VQVZN3kVl1HO/view?usp=sharing
after the fix, 'automatic sample submission' and 1 or 2 others is no longer grayed out but everything else is still grayed and managed by administrator
THEN, 2 seconds later, a 'do you want this app to make changes' notif from windows security popped up. I clicked yes, and now it's grayed out again. it repeatedly pops up, and whenever I click yes, a new setting goes back to being grayed out
-
Ramesh Srinivasan 87,865 Reputation points Independent Advisor
2025-02-06T02:43:37+00:00 Some Defender policies (some, not all) are readded somehow. I'm unsure how they're back when the system is not connected to a domain.
Please copy the following lines to the clipboard, including the Start and End directives:
Start:: Unlock: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sense HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION StartRegedit: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sense] "Start"=dword:00000004 EndRegedit: End::Open the Farbar Scanner and click "Fix".
After the reboot, post fixlog.txt
Note:
The Windows Security app is slightly old. But it's not causing the issue because I tested with an older app build and it still worked fine.