Hello community, I have an issue removing Windows Defender from Windows 10. Until today I thr used intall_wim_tweak with the following command: install_wim_tweak.exe /o /c Windows-Defender /r Today I updated to build 1809, and it seems that install_wim_tweak.exe dowesn't work anymore. Is there any other method to completely uninstall Windows Defender? Thank you Lucas
Are you sure it doesn't work anymore? I used this on a mounted (LTSC2019) install.wim: Code: install_wim_tweak.exe /p d:\mount /c Windows-Defender /r So you're saying that doesn't work anymore? I also use these reg settings (straight after apply, before first reboot): Spoiler: Disable defender Code: [HKEY_LOCAL_MACHINE\temp\Microsoft\Windows Defender] "DisableAntiSpyware"=dword:00000001 [HKEY_LOCAL_MACHINE\temp\Microsoft\Windows Defender\Real-Time Protection] "DisableRealtimeMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\temp\Policies\Microsoft\Windows Defender] "DisableAntiSpyware"=dword:00000001 This does in fact turn off Defender, but I have to admit I haven't really checked if the Install_wim_tweak commands actually "uninstalled"/ removed Defender from the install.wim.
I use this on a live system, just can't remove Windows Security icon in start menu in 1809 Spoiler Code: reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d "Off" /f reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost" /v "EnableWebContentEvaluation" /t REG_DWORD /d "0" /f reg add "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v "EnabledV9" /t REG_DWORD /d "0" /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v DontReportInfectionInformation /t REG_DWORD /d 1 /f reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Sense" /f reg delete "HKLM\SYSTEM\CurrentControlSet\Services\SecurityHealthService" /f reg add "HKLM\SOFTWARE\Policies\Microsoft\MRT" /v "DontReportInfectionInformation" /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\MRT" /v "DontOfferThroughWUAU" /t REG_DWORD /d 1 /f reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /f reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run" /v "SecurityHealth" /f reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecHealthUI.exe" /v Debugger /t REG_SZ /d "%windir%\System32\taskkill.exe" /f install_wim_tweak /o /c Windows-Defender /r
@Lucas Rey make a small .bat with this content in it: Code: @echo off cd /d "%~dp0" echo Generating Package List... CLS install_wim_tweak.exe /o /l pause Run it as administrator in the same folder where "install_wim_tweak.exe" is. It will create small .txt file with all the current packages.Go trough them and look for windows-deffender...(usually is located on the bottom),this way you'll know if you successfully uninstall it or not. @Trickz do same as above and see if there is a package "Microsoft-Windows-SenseClient...." .If there is i think that is what you need to remove to get rid of the Windows Security icon.This is just a guess cause i'm still on LTSB 2016 and haven't mess with the LTSC 2019's packages yet.
Just install using the MRP files, you can almost do all what the choppers want to achieve, only now windows will run stable
Maybe try this or this. P.S. This is not a recommendation. Just helping you find what you may be looking for.
Disabling Windows Defender is one thing. Removing such a component and the associated reg entries that is soo backed into the windows os.....not sure thats a good idea. your asking for trouble at some point (windows upgrades, windows updates etc..). just my .02 cents ~MC
It takes a simple registry key to disable Windows Defender. Hardly worth uninstalling, in my opinion.
DONE! Something went wront on the first attempt, so I used the reg tweak there: https://forums.mydigitallife.net/th...tion-from-enabling-itself.77298/#post-1446078 And now the Windows Defender has gone! Thank you all!
,,.and thank you! Like you, I have always removed Defender this way (in my case: on offline wim), so to me this does not feel like "chopping", Microsoft could have made this a bit easier to do in the first place. I also noticed the icon in the bottom right, removing the "Microsoft-Windows-SenseClient....", as mentioned post #4 of this thread, did not help either. But I'm sure the reg tweaks mentioned in your last post will do the trick, I will test as soon as possible. Thanks again for bringing this up, nice to have all the info here in case others need it. EDIT: Ahh, the icon was actually easy to get rid of, just a single entry in HKLM\S\M\W\Curr\Run
i use this for defender Code: Windows Registry Editor Version 5.00 [-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\EPP] [-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\EPP] [-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\EPP] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender] "DisableAntiSpyware"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=- and for command prompt: Code: reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d "Off" /f reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost" /v "EnableWebContentEvaluation" /t "REG_DWORD" /d "0" /f reg add "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v "EnabledV9" /t REG_DWORD /d "0" /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f reg add "HKLM\SOFTWARE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f reg add "HKLM\SOFTWARE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v DontReportInfectionInformation /t REG_DWORD /d 1 /f reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Sense" /f reg delete "HKLM\SYSTEM\CurrentControlSet\Services\SecurityHealthService" /f for icon in tray go to task manager -start up- defender -disable
@Atari800XL "Microsoft-Windows-SenseClient...." is part of the Defender anyway,so,if you already removed the main Defender's packages removing the "SenseClient" will just get rid of a leftover that might cause some feature Cumulative Update to reinstall the Defender.
I have a question regarding this method. Is it possible to reinstall Windows Defender later? Or is it one-way ticket ? I tried to search but it's always uninstall procedure described without mention about reinstalling possibility. TIA.
Definitely not. As far I know, there is no way to reinstall Defender on a live Windows after removing it. Unless you'll use the upgrade functionality of your Windows 10 untouched DVD.
Do i have to run both the 1st one (reg file) and the 2nd one (batch file ) to completely get rid of this s**tty windows defender ?. Thanks