Antimalware service executable eats memory

Anonymous
2025-02-04T08:12:19+00:00

title. it's always taking 200-300 mb of memory.

I tried:

disable windows security, got hit with this setting is managed by your (non existent) administrator

end task, got access is denies

command prompt things, did nothing

edit group policy, did nothing

enable disableantispyware in regedit, got hit with access is denied

tried to give myself permission to enable disableantispyware, access is denied

in case I missed any, I basically tried everything you can find online. no matter what I do, either nothing happens, access is denied or this setting is managed by your administrator

I'm about to flip this is my computer, I should get to choose what to do. I am the administrator and only user

Windows for home | Windows 10 | Settings

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

61 answers

Sort by: Oldest
  1. Anonymous
    2025-02-06T01:12:39+00:00

    Was this answer helpful?

    0 comments No comments
  2. Ramesh Srinivasan 87,865 Reputation points Independent Advisor
    2025-02-06T02:43:37+00:00

    Some Defender policies (some, not all) are readded somehow. I'm unsure how they're back when the system is not connected to a domain.

    Please copy the following lines to the clipboard, including the Start and End directives:

    Start::
    Unlock: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sense
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
    StartRegedit:
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sense]
    "Start"=dword:00000004
    EndRegedit:
    End::
    

    Open the Farbar Scanner and click "Fix".

    After the reboot, post fixlog.txt

    Note:

    The Windows Security app is slightly old. But it's not causing the issue because I tested with an older app build and it still worked fine.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-02-06T03:35:56+00:00

    https://drive.google.com/file/d/1WskIRqL6PNodlQrWsQs5VQVZN3kVl1HO/view?usp=sharing

    after the fix, 'automatic sample submission' and 1 or 2 others is no longer grayed out but everything else is still grayed and managed by administrator

    THEN, 2 seconds later, a 'do you want this app to make changes' notif from windows security popped up. I clicked yes, and now it's grayed out again. it repeatedly pops up, and whenever I click yes, a new setting goes back to being grayed out

    Was this answer helpful?

    0 comments No comments
  4. Ramesh Srinivasan 87,865 Reputation points Independent Advisor
    2025-02-06T03:42:56+00:00

    The policies are readded, maybe during the boot process, although we've reset the group policies file already.

    From Command Prompt, run:

    reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /s
    

    Press Enter.

    If it shows many registry values, it confirms that the policies were readded.

    Re-run the fix in my last reply. But before rebooting the system, enable ProcMon boot logging.

    After the reboot, save the boot log.

    Zip the boot trace and share it. Also, share the latest fixlog.txt.

    Was this answer helpful?

    0 comments No comments
  5. Ramesh Srinivasan 87,865 Reputation points Independent Advisor
    2025-02-06T03:44:09+00:00

    //THEN, 2 seconds later, a 'do you want this app to make changes' notif from windows security popped up.//

    Just now saw your edited post.

    If the UAC dialog appears again, click "Show more details" and note the process name Post the info here.

    Was this answer helpful?

    0 comments No comments