What Antimalware Service Executable does and why you might want to disable it

Antimalware Service Executable is a Windows process that runs in the background to scan your computer for viruses and malware. It is part of Windows Defender, the built-in security tool that comes with Windows 10 and Windows 11. The process uses your processor and disk space while it works, which can slow down your computer — especially on older machines or when you are doing something that needs a lot of processing power.

You might want to turn it off temporarily if it is making your computer unusable while you work, or if you are using a different antivirus program and do not want two security tools running at the same time. Disabling it is not the same as removing your protection entirely — you can turn it back on whenever you need it, or use a different security tool instead.

Before you disable it, understand the trade-off: your computer will not scan for threats in the background. If you turn it off, you are responsible for making sure another security tool is protecting you, or for running manual scans regularly.

Key Takeaways

  • Antimalware Service Executable is the Windows Defender background scanner, and disabling it stops automatic threat detection but does not delete your protection settings.
  • You should only disable it if you are using a different antivirus program, or if you understand you are temporarily without automatic protection.
  • Temporary disables (for a few hours while you work) are safer than permanent ones, because you can turn it back on when you are done.
  • If you disable Windows Defender entirely, you lose the ability to scan files on demand, so make sure another tool can do that for you.

How to temporarily disable the antimalware service while you work

The fastest way to stop the process from slowing you down right now is to pause Windows Defender for a set amount of time. Open the Windows Security app by typing "Windows Security" into the search box at the bottom left of your screen and pressing Enter. Click "Virus & threat protection" on the left side.

Under "Virus & threat protection settings," click "Manage settings." You will see a toggle for "Real-time protection" — click it to turn it off. Windows will ask you to confirm; click "Yes." The protection will stay off for 15 minutes, then turn back on automatically. If you need more time, you can turn it off again when the 15 minutes are up.

This method is safer than permanently disabling the service because you do not have to remember to turn it back on. When you are done with the task that was slowing down, the protection resumes on its own.

How to permanently disable Windows Defender

If you want to turn off Windows Defender completely — usually because you are installing a different antivirus program — you need to change a Windows setting that prevents the service from running at all. Open the Group Policy Editor by pressing the Windows key and R together, typing "gpedit.msc" into the box that appears, and pressing Enter. (This only works on Windows Pro, Enterprise, or Education editions. If you have Windows Home, skip to the next section.)

Navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Find the policy called "Turn off Microsoft Defender Antivirus" and double-click it. Select "Enabled" and click OK. Windows Defender will stop running when ready and will not restart when you reboot your computer.

To turn it back on later, return to the same location, set the policy back to "Not Configured," and restart your computer.

Disabling Windows Defender on Windows Home edition

Windows Home does not have the Group Policy Editor, so you cannot disable Windows Defender the same way. Your options are more limited: you can pause real-time protection for 15 minutes at a time (as described above), or you can uninstall Windows Defender entirely by installing a different antivirus program.

When you install most third-party antivirus tools — Norton, McAfee, Kaspersky, Bitdefender, and others — they automatically disable Windows Defender to avoid conflicts. The antivirus installer handles this for you, so you do not have to do anything manually. After installation, the new program will protect your computer instead.

If you want to go back to Windows Defender after using a different antivirus, uninstall the third-party program and Windows Defender will turn itself back on.

Why you should not disable antimalware service without a replacement

Running your computer without any active antivirus protection is risky. Malware can install itself silently while you work, and you may not notice until it has already done damage — stolen passwords, encrypted your files for ransom, or used your computer to attack other machines.

If you disable Windows Defender, make sure you have another security tool in place first. That tool should be able to scan files on demand (so you can check something manually if you are suspicious) and ideally should run in the background. Do not disable Windows Defender and then leave your computer unprotected while you shop for a replacement.

If you are disabling it because it is slowing down your computer too much, consider whether the slowdown is worth the protection. On most modern computers, Windows Defender runs quietly in the background. If it is noticeably slowing you down, your computer may have a hardware problem (not enough RAM, a failing hard drive) that disabling antivirus will not fix.

What happens to your computer after you disable the antimalware service

Disabling the service does not delete any files or settings. It straightforward stops the background scanning process from running. Your Windows Security app will still open, but it will show that real-time protection is off. You can still run manual scans by opening Windows Security and clicking "Scan options," then choosing a scan type and clicking "Scan now."

If you have scheduled scans set up, they will not run while the service is disabled. If you turn the service back on, your scans will resume on their original schedule.

Any quarantined files (files Windows Defender suspected were malware) will stay in quarantine. If you want to restore one, you can do that through Windows Security even while the service is disabled.

How to check if antimalware service is using too much CPU or disk

Before you disable the service, confirm that it is actually the cause of your slowdown. Open Task Manager by pressing Ctrl, Shift, and Esc together. Click the "Processes" tab. Look for "Antimalware Service Executable" in the list and click it to highlight it. Look at the CPU and Disk columns — if both are near 0%, the service is not the problem.

If the CPU or Disk column shows a high number (above 50%), the service is using a lot of resources. This usually happens when Windows Defender is running a full scan, or when it is scanning a large folder for the first time. Wait a few minutes — the scan usually finishes on its own. If it stays high for more than an hour, you may have a malware infection that is causing the slowdown, not the antivirus itself.

If you see high CPU or disk use only at certain times of day, Windows Defender is probably running its scheduled scan. You can change when that scan runs by opening Windows Security, clicking "Virus & threat protection," then "Manage settings," and scrolling down to "Scheduled scan."

Frequently Asked Questions

Will disabling antimalware service executable remove my antivirus protection?

Disabling the service stops the background scanning, but your protection settings remain in place. If you turn the service back on, it will resume protecting you when ready. If you install a different antivirus program, that program takes over protection instead. You only lose protection if you disable Windows Defender and do not have another antivirus tool running.

Can I disable it just while I am installing software?

Yes. Use the 15-minute pause method described above — open Windows Security, go to Virus & threat protection settings, and toggle off Real-time protection. It will turn back on automatically. This is safer than permanently disabling it because you do not have to remember to turn it back on.

What if I disable it and then get infected with malware?

If you suspect an infection, turn Windows Defender back on and run a full scan when ready. Open Windows Security, click Virus & threat protection, then Scan options, choose Full scan, and click Scan now. A full scan takes 30 minutes to several hours depending on how much data you have. If Windows Defender finds something, it will quarantine it automatically.

Does disabling antimalware service save battery on a laptop?

It may save a small amount of battery, but the difference is usually not noticeable on modern laptops. If your laptop battery is draining quickly, the problem is more likely your screen brightness, background apps, or an aging battery than the antivirus service. Disabling security to save battery is not a good trade-off.

Can I disable just the scheduled scan without disabling the whole service?

Yes. Open Windows Security, click Virus & threat protection, then Manage settings. Scroll down to Scheduled scan and toggle it off. The background real-time protection will keep running, but Windows will not run automatic scans at the time you have set. You can still run manual scans whenever you want.