Fully disabled Defender but "Windows Defender Antivirus Service" runs

Page 2 of 4 FirstFirst 1234 LastLast

  1. Posts : 61
    Windows 10 pro 64 bits 1903 build 18362.836
       #11

    muchomurka said:
    It will block Security options in Settings app. If you really want to have Security Center enabled, remark or delete the line.
    Hi muchomurka,
    Ok

    Another question,
    At the end of the link you suggested, there are two ways to roll back:
    1 - To revert this update to the previous version
    2 - To revert this update to the CAMP version

    What is the difference between them? ... What is the CAMP Version?
    Which one should I use?

    Thank you
    Clamarc
      My Computer


  2. Posts : 913
    CP/M
       #12

    1. there were several antimalware platform updates so this is one step back only
    2. imo CAMP means "right after OS installation, before winupdate", no antimalware platform patch installed
    your choice is 2
      My Computer


  3. Posts : 61
    Windows 10 pro 64 bits 1903 build 18362.836
       #13

    OK muchomurka,

    Very, very thank's
    Clamarc
      My Computer


  4. Posts : 1
    Windows 10 Home
       #14

    TairikuOkami said:
    Make sure, that the tamper protection is disabled, then run this twice as admin, then restart.

    [Batch] Windows Defender Disable - Pastebin.com
    I'm having the same issue now but the pastebin is expired, could you please repost it?
      My Computer

  5.   My Computer


  6. Posts : 3
    Windows 10 Pro
       #16

    TairikuOkami said:
    Make sure, that the tamper protection is disabled, then run this twice as admin, then restart.

    Windows/Microsoft Defender Disable.bat at main . TairikuOokami/Windows . GitHub
    TairikuOkami, you are my HERO.

    I have battled the Defender issue for awhile. Uninstalled Malwarebytes because of it, as it thought that program was the culprit. Up until the last WD update snuck in a few days back it would defer to my antivirus, and not make too much noise, so I didn't have much reason to dig.

    But then, after the last update for it, it no longer would defer to my 3rd party AV, and would swell to 2gigs of RAM within minutes of starting the PC.

    I got "smart" and hopped straight to the policy manager, thinking I was going to teach it a lesson. The joke was on me.

    There are lots of directions floating around the internet, and this is by far the best one I have found, and also the only one that would actually work.

    I did have some problems though. Because of mpcmdrun.exe some of the registry entries didn't take, even in safe mode.

    To those of you that experience this, reboot an extra couple of times after running the bat file twice, then go down each entry in it and check the reg keys manually for yourself, to see which ones did not change the way they should or weren't created.

    I will add--before you run a bat file, or do any changes to the registry at all; do two things. Set a system restore point, then make copy (export) of your registry before you do a thing to it.

    One thing that tripped me up this time, is I didn't have registry editor open as admin. So make sure you run regedit and the task scheduler as administrator.

    After making sure that the tasks were disabled via task scheduler, and removing triggers (the rest of you do this at your own risk!), I was able to get all keys but one via elevated regedit.

    The holdout is
    rem reg add "HKLM\System\CurrentControlSet\Services\SgrmBroker" /v "Start" /t REG_DWORD /d "4" /f
    Also, the antispyware key would not generate from the script, but I was able to create it manually using regedit.

    Where the value will not change to 4, but stays at 3. I am thinking this has something to do with WD Advanced Threat Protection Service, which still is inaccessible to edit from services.

    All services listed in your screenshot from process hacker are disabled. Also thank you for the idea for the nice program.

    I've set the policy editor, on the off-chance it still works now that the AV is disabled, and am looking forward to Let IOBit Defender actually run now.

    Thanks so much again, you are a true life saver! I intend to check back in here w/an update in a couple of days, to report on whether it stuck or not.

    Last but not least, I am in your eternal gratitude for the reversal bat file on Github! Chances are at some time the settings will need to be reversed.

    You just rock and the admin on this forum needs to give you way more stars.
      My Computer


  7. Posts : 5,452
    Windows 11 Home
       #17

    GrumpyOlBumpkin said:
    The holdout is
    rem reg add "HKLM\System\CurrentControlSet\Services\SgrmBroker" /v "Start" /t REG_DWORD /d "4" /f
    I keep this service mentioned for a reference only. It handles boot, so Windows might need it.
    Actually disabling it might result in Critical Process Died BSOD, making Windows unbootable.

    https://docs.microsoft.com/en-us/win...rotect-windows
      My Computer


  8. Posts : 3
    Windows 10 Pro
       #18

    TairikuOkami said:
    Make sure, that the tamper protection is disabled, then run this twice as admin, then restart.

    Windows/Microsoft Defender Disable.bat at main . TairikuOokami/Windows . GitHub
    TairikuOkami said:
    I keep this service mentioned for a reference only. It handles boot, so Windows might need it.
    Actually disabling it might result in Critical Process Died BSOD, making Windows unbootable.

    https://docs.microsoft.com/en-us/win...rotect-windows
    Good to know! I will remove it from the batch file then. If there is one thing I didn't want it is a BSOD.
      My Computer


  9. Posts : 5
    Windows 10 Pro v21H1-‎6/‎6/‎2020 osb19043.1165 exp
       #19

    TairikuOkami said:
    Make sure, that the tamper protection is disabled, then run this twice as admin, then restart.

    Windows/Microsoft Defender Disable.bat at main . TairikuOokami/Windows . GitHub
    Hannele2 said:
    That worked! Thank you! I didn't know about Tamper protection, turns out it was disabled. Apparently Microsoft pushed it quite recently. I can't remember turning it off, but it was off when I looked, after running the script.

    Any idea why this happened? What is Microsoft up to?
    I have the exact same problem. Unfortunately, I possess zero knowledge as to how to fix it. Is there a tutorial or something I can use to learn exactly what it is I'm looking at (git hub link) and how to run it as an admin? Any assistance would be greatly appreciated as I'm just about to toss this laptop into the trash where it currently belongs, thanks to Microsoft. It takes an egregious amount of time to perform the simplest of tasks, such as moving between programs. It's taken me 17 min so far just to quote/comment/reply here (19 min). Thank you!
      My Computer


  10. Posts : 23,271
    Win 10 Home ♦♦♦19045.4355 (x64) [22H2]
       #20

    I still think the easiest way is to just use Autoruns.

    1. Set the options as shown
    2. In the filter (search box) type: windows defender
    3. Uncheck the boxes shown, then reboot

    Then you can just disable the Defender Services.


    Fully disabled Defender but "Windows Defender Antivirus Service" runs-0000-disable-defender.png
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 00:26.
Find Us




Windows 10 Forums