[DISCUSSION] Disabling Microsoft Defender Antivirus (formerly Windows Defender)

Discussion in 'Windows 11' started by Espionage724, Oct 29, 2021.

  1. Espionage724

    Espionage724 MDL Expert

    Nov 7, 2009
    1,066
    394
    60
    I like this option the most and will give it a try later today. I wonder if you could just outright delete the service though instead of disabling it?
     
  2. Krakatoa

    Krakatoa MDL Addicted

    Feb 22, 2011
    667
    1,085
    30
  3. freddie-o

    freddie-o MDL Expert

    Jul 29, 2009
    1,375
    2,277
    60
    #23 freddie-o, Nov 6, 2021
    Last edited: Nov 6, 2021
    Up to you. No turning back unless you back up the Registry keys
     
  4. Espionage724

    Espionage724 MDL Expert

    Nov 7, 2009
    1,066
    394
    60
  5. Very Nice you can "Where Theres a Will theres a Way" :)
     
  6. ABM

    ABM MDL Junior Member

    Mar 16, 2010
    96
    28
    0
    #26 ABM, Feb 7, 2022
    Last edited: Apr 17, 2022
    Using RegEdit to disable Windows Defender in Windows 11
    An alternative way to disable Windows Defender in Windows 10 or 11 is to use the registry. For this, you will also need to boot into safe mode. Follow step 1 from the previous chapter to boot into safe mode.

    Once booted in Safe Mode: (Win key + R,,select Boot tab and then select safe boot)

    1. Press Windows key + R
    2. Type regedit <enter> to open the registry
    3. Use the "Find" feature and locate each folder below and click to change "start" from "3" to "4"
      • Sense
      • WdBoot
      • WdFilter
      • WdNisDrv
      • WdNisSvc
      • WinDefend
    4. Exit out of Safe Mode

    Revert the change
    If you no longer want to disable Windows Defender you can easily revert the change. You will need to restart into safe mode again and give System and Trusted Installer full access permission on the Platform folder.

    When you used the registry method, then restore the values to:

    HKLM\SYSTEM\CurrentControlSet\Services\Sense\Start 3
    HKLM\SYSTEM\CurrentControlSet\Services\WdBoot\Start 0
    HKLM\SYSTEM\CurrentControlSet\Services\WdFilter\Start 0
    HKLM\SYSTEM\CurrentControlSet\Services\WdNisDrv\Start 3
    HKLM\SYSTEM\CurrentControlSet\Services\WdNisSvc\Start 3
    HKLM\SYSTEM\CurrentControlSet\Services\WinDefend\Start 2
     
  7. Dark Dinosaur

    Dark Dinosaur X Æ A-12

    Feb 2, 2011
    3,759
    5,223
    120
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. MrChris

    MrChris MDL Addicted

    Jun 23, 2007
    532
    127
    30
    With Defender being so backed into the core os I found that automating the adding of all my files/folder etc.. to the exclusions list gave better outcome overall and a tad less crippled os! A bit aof a resource hog though! Any Realtime Scanner is likely to be a resource hog imho.

    But still good to know.

    Thanks!
     
  9. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,693
    60
    #31 AveYo, Feb 14, 2022
    Last edited: Feb 14, 2022
    3 years latter, it finally happened!
    Tamper protection is now more than just a buzz word - it actually works, Defender gained resilience that all other AVs have been featuring for years, if not decades!
    Praise the Lord of Incompetent Developers!
    We had to wait for so long until a f**ktard at microsoft hq got ransomware'd via a silly script to notice the elephant-sized holes in their "security" offering.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. fxrtoy

    fxrtoy MDL Novice

    Jan 4, 2009
    3
    1
    0
  11. TairikuOkami

    TairikuOkami MDL Expert

    Mar 15, 2014
    1,172
    1,055
    60
    Defender can still be too easily disabled, when 3rd party AV is installed, I guess it is only a matter of time before hackers create a script pretending to be running 3rd party AV. MS should demand user's input to allow AV change.
     
  12. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,693
    60
    You can't actually do that. To be eligible as a compatible AV you need to obtain a special certificate from microsoft that will allow your elam (early-launch-anti-malware) kernel driver and your binaries to run as PsProtectedSignerAntimalware-Light.
    A more obscure way so far has been to hijack process explorer's signed driver to kill handles of protected processes and hence the process itself. But it looks that it's being addressed in the last few days as well.
    This is also where SecureBoot comes into play, as the Tamper Protection status is saved in the uefi firmware environment. And from what I poked at, Microsoft is toying with getting the TPM device into play as well.
    So we can say that most methods to disable defender without reboot no longer work.
    That's great news honestly, it finally looks like a reliable AV at least when it comes to protecting itself ;)
    Except you can still completely uninstall it on reboot :( Microsoft and their half-efforts when it comes to everything..
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  13. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,693
    60
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. ceo54

    ceo54 MDL Addicted

    Aug 13, 2015
    867
    361
    30
    Usual Microsoft way of doing things. It's almost like ignoring important issues has become a culture at Microsoft compensating productivity with a product that looks more like Android.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  15. exslim

    exslim MDL Novice

    Mar 10, 2022
    6
    5
    0
    #38 exslim, Mar 11, 2022
    Last edited: Mar 11, 2022
  16. Stimpy88

    Stimpy88 MDL Senior Member

    Mar 24, 2011
    353
    188
    10
    Yeah, I have the same question. What IS the best way to do it then, the best tool for the job?
     
  17. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    47,274
    94,765
    450