Antimalware Service Executable Using High CPU
Short answer
MsMpEng.exe is Microsoft Defender scanning your files. Open taskschd.msc,
find Windows Defender Scheduled Scan, untick Start the task only if the
computer is idle for, and set a weekly off-hours trigger. Add narrow process
exclusions for heavy workloads. Do not disable Defender — the problem is timing.
On this page
You open Task Manager because the fans are loud, and the top entry is Antimalware Service Executable at 40% CPU. Nothing is obviously running. It has apparently been doing this for an hour.
That process is MsMpEng.exe, the scanning engine behind Microsoft Defender. It
is not malware pretending to be a security tool — it is the security tool, doing
the single most CPU-intensive thing it does, which is reading and analysing every
file on your drive.
The useful question is not how to stop it, but whether what you are seeing is a scheduled scan that should have run while you were away, or something stuck in a loop. The answers are different.
What the process actually does
Defender works in two modes, and both show up under the same process name.
Real-time protection inspects files as they are created, modified or opened. This is cheap per file but it scales with activity — extracting a large archive, compiling code or downloading a game produces a burst of CPU that is entirely proportionate to what you asked for.
Scheduled scanning reads everything on the drive. A quick scan covers the usual hiding places in a few minutes. A full scan reads every file you own and is heavy by nature.
Windows schedules full scans during “idle time”, using a definition of idle that often means ten minutes after you stopped typing. On a laptop you picked back up, this looks exactly like an unexplained CPU spike.
| Pattern | Likely cause | Action |
|---|---|---|
| Heavy for 20–60 min, then stops | Scheduled full scan | Reschedule it |
| Spikes during downloads or builds | Real-time protection | Targeted exclusion |
| Burst right after a Windows update | Post-update rescan | Expected, let it run |
| Constant, for days, never finishes | Stuck scan or a loop | Reset the scan history |
| High CPU plus 100% disk on an HDD | Normal — hard drive bottleneck | See the disk guide |
That last row is worth noting: on a mechanical hard drive, Defender’s scan will also pin the disk, which makes the whole machine feel worse than the CPU figure suggests. The disk side of this is covered in 100% disk usage in Task Manager.
Reschedule the scan properly
The Settings app has no control over scan timing. Task Scheduler does.
- Press Win+R, type
taskschd.msc, press Enter. - In the left pane, expand Task Scheduler Library → Microsoft → Windows → Windows Defender.
- Double-click Windows Defender Scheduled Scan.
- On the Conditions tab, untick Start the task only if the computer is idle for — this is the setting that causes scans to begin the moment you step away and then fight you when you come back.
- Tick Start the task only if the computer is on AC power if this is a laptop.
- On the Triggers tab, click New, choose Weekly, and pick a day and time when the machine is on but you are not using it.
- Click OK.
Weekly is a sensible cadence for a full scan given that real-time protection is inspecting everything as it happens anyway. Do not delete the trigger entirely — a periodic full scan catches things that were dormant when they arrived.
You can also reduce the CPU ceiling Defender is permitted to use. From Terminal (Admin):
Set-MpPreference -ScanAvgCPULoadFactor 25
The default is 50, meaning Defender targets an average of 50% of one core during scheduled scans. Dropping it to 25 makes scans gentler and correspondingly longer. This affects scheduled scans only, not real-time protection.
To check the current settings:
Get-MpPreference | Select-Object ScanAvgCPULoadFactor, ScanScheduleDay, DisableRealtimeMonitoring
Exclusions — useful, and a genuine tradeoff
An exclusion tells Defender not to scan a path, a file type or a process. It is the most effective fix for real-time protection overhead, and it is also the one place in this guide where you can meaningfully reduce your own security.
An excluded folder is not inspected. Malware written there runs without being examined. This is a well-known technique, which is why exclusions should be narrow, specific and deliberate.
Reasonable candidates:
- A development build output folder that regenerates thousands of files.
- A virtual machine disk (
.vhdx,.vmdk) — large, constantly written, and scanned by the guest OS’s own protection anyway. - A database data directory for a local server such as PostgreSQL or SQL Server, where vendors publish specific exclusion guidance.
- A video editing scratch or render output folder.
Unreasonable candidates, which people do anyway:
- The whole C drive, or an entire user profile.
- The Downloads folder — precisely where unknown files arrive.
C:\WindowsorProgram Files..exeas a file type.
To add one: Windows Security → Virus & threat protection → Manage settings → Exclusions → Add or remove exclusions → Add an exclusion. Choose Folder, File, File type or Process, and pick the narrowest option that solves your problem.
A Process exclusion is often the better choice: it excludes files touched by a specific program rather than everything in a location, which is a much smaller hole.
Keep a note of what you excluded and why. Exclusions accumulate and nobody remembers adding them.
If it never stops
A scan that has apparently been running for days is usually stuck on something — a network drive that is slow or gone, a corrupt archive, or a scan history database that has grown unmanageable.
Things to try, in order:
- Check the scan history size. The folder
C:\ProgramData\Microsoft\Windows Defender\Scans\Historycan grow very large. Clearing its contents is safe; Defender rebuilds it. You will lose the record of past detections. - Exclude mapped network drives. Defender scanning a slow or disconnected network location retries indefinitely.
- Update definitions manually.
Windows Security → Virus & threat protection → Protection updates → Check for updates. A failed definition update can leave the engine retrying. - Check for a second antivirus. Two real-time engines inspecting each other’s activity produces exactly this symptom. Uninstall the one you do not want — leftover remnants of an expired trial are a frequent cause.
- Run the offline scan once: Virus & threat protection → Scan options → Microsoft Defender Antivirus (Microsoft Defender Offline scan). The machine reboots into a minimal environment and scans before Windows loads, which catches things that evade a live scan. It takes about 15 minutes and you cannot use the PC during it.
If the behaviour started right after a Windows update and nothing above helps, see Windows 11 slow after an update.
What not to do
- Do not disable Microsoft Defender. Not through Settings, not through Group Policy, not through a registry edit from a forum post, and certainly not by disabling Tamper Protection to make the change stick. You would be trading real protection for CPU that scheduling and exclusions fix properly. Modern Windows is also designed to re-enable it, so the “fix” tends to be temporary and leaves the machine in an inconsistent state.
- Do not exclude your entire drive or user folder. That is functionally the same as disabling it, with the added downside that you will think you are protected.
- Do not kill
MsMpEng.exein Task Manager. It restarts, and you have gained nothing but a restarted scan. - Do not install a registry cleaner or “antivirus optimiser”. There is nothing in the registry to fix here, and tools in that category frequently bundle the exact thing Defender exists to catch.
- Do not run two antivirus products. One real-time engine. A second on-demand scanner used manually is fine; a second resident one is not.
Realistic expectations
Moving the full scan to a weekly off-hours slot and unticking the idle condition resolves the symptom for most people, because the problem was never the scanning — it was the timing.
Real-time CPU during heavy file activity is proportionate and expected. If your workload genuinely creates thousands of files a minute, one or two narrow process exclusions bring it down without meaningfully weakening the machine.
If the CPU is high and Defender is not the top consumer after all, work through find what is using 100% CPU or disk instead — the browser is a common answer, and Chrome using too much CPU covers that case specifically.
Frequently asked questions
Is Antimalware Service Executable a virus?
MsMpEng.exe, the scanning engine behind Microsoft Defender, doing the most CPU-intensive thing it does — reading and analysing files on your drive. The real question is whether it is a scheduled scan or something stuck in a loop.How do I reschedule Defender's full scan?
taskschd.msc, go to Task Scheduler Library → Microsoft → Windows → Windows Defender, open Windows Defender Scheduled Scan, untick the idle condition on the Conditions tab, and add a weekly trigger for a time you are not using the machine.Can I limit how much CPU Defender uses?
Set-MpPreference -ScanAvgCPULoadFactor 25 from Terminal (Admin). The default is 50, so dropping it to 25 makes scheduled scans gentler and correspondingly longer. It affects scheduled scans only, not real-time protection.Which folders are reasonable to exclude?
C:\Windows, or the .exe file type — an excluded folder is not inspected at all.What if the scan never finishes?
C:\ProgramData\Microsoft\Windows Defender\Scans\History, exclude mapped network drives, update definitions manually, and check for a second antivirus — two resident engines produce exactly this symptom. An offline scan takes about 15 minutes and catches what a live scan evades.