GUIDES

Antimalware Service Executable using CPU while gaming

Antimalware Service Executable is Microsoft Defender Antivirus at work. What wakes it while you play, how to record what it scanned, and how to give its scheduled scan a time you are not playing.

The game hitches, you open Task Manager, and near the top of the CPU column sits Antimalware Service Executable. The name sounds alarming, but it is Microsoft Defender Antivirus itself: Microsoft's troubleshooting page for Defender performance opens by naming it "Anti-malware Service Executable, MsMpEng.exe, Microsoft Defender Antivirus". Its CPU time comes from specific jobs, and which job it was decides what you can do about it.

Three jobs that wake it

  1. Real-time protection. It "reviews files when they're opened and closed, and whenever a user navigates to a folder", per Microsoft's page on scheduled scans. Installing a game or a patch, and a game writing its shader cache to disk, all open and close files. The troubleshooting page adds that launching a program file that is not digitally signed starts a real-time protection scan.
  2. Scheduled scans. They run "in addition to always-on, real-time protection". A daily scheduled scan can only be a quick scan; a weekly one can be quick or full, and a full scan "can take a few hours or days to complete".
  3. The scan after an update. "By default, Microsoft Defender Antivirus scans after a security intelligence update", and the troubleshooting page warns that this can look like scans "run outside of the schedule".

Scheduled scans wait for idle by default: the PowerShell reference says they run "when the computer is on, but not in use". Microsoft's pages put different numbers on idle: overall CPU usage "lower than 80%" on the troubleshooting page, "less than 90% CPU utilization" in the PowerShell reference. Once a scheduled scan runs on an idle machine, the default settings leave it unthrottled: the 50% average CPU guidance, which Microsoft says "isn't a hard limit", is ignored for those scans.

Record what it scans first

The performance analyzer records Defender's scans and reports which files, file extensions and processes cost the most scan time. It needs Windows 10 or 11, Defender platform version 4.18.2108.7 or later, and PowerShell opened as administrator. Start the recording (-RecordTo takes a full path):

New-MpPerformanceRecording -RecordTo "$env:USERPROFILE\Defender-scans.etl"

Leave the window open and play until the hitch comes back; Microsoft's instruction is to reproduce the situation while recording. Then press Enter in the window to stop and save, and read the report:

Get-MpPerformanceReport -Path "$env:USERPROFILE\Defender-scans.etl" -TopFiles 10 -TopExtensions 10 -TopProcesses 10 -TopScans 10

It lists scan counts and durations, the path, the process and the reason for each scan: a file, a process and a cause instead of "Defender is using CPU". The reference adds a caveat: the tool "isn't intended to provide suggestions on exclusions. Exclusions can reduce the level of protection on your endpoints."

Give the scheduled scan a time you are not playing

If the timing or the report points at a scheduled scan, set when it runs. The PowerShell reference gives this example for a daily quick scan at lunchtime, when "the device is likely on, but activity on the device is likely minimal". In an administrator PowerShell window:

Set-MpPreference -ScanScheduleQuickScanTime 12:30:00 -ScanScheduleOffset 0 -RandomizeScheduleTaskTimes $false -ScanOnlyIfIdleEnabled $false

What each part does, per that page:

You can also ask for low CPU priority for scheduled scans. The troubleshooting page says this lowers the scan's thread priority from 9 to 8, "which enables other application threads to run with a higher priority":

Set-MpPreference -EnableLowCpuPriority $true

None of this touches real-time protection; it only decides when and how scheduled scans run.

Exclusions, with Microsoft's warnings attached

Windows Security can exclude a file, a folder, a file type or a process: Windows Security > Virus & threat protection > Manage settings, then under Exclusions select Add or remove exclusions. Microsoft's help page for Windows Security states the cost: Defender "will no longer check those types of files for threats, which could leave your device and data vulnerable." It adds two details that matter for games: a process exclusion means "any file opened by that process will be excluded from real-time scanning", and "Exclusions only apply to real-time scanning", so a scheduled scan may still scan the same files.

Microsoft's list of exclusions to avoid names "Program folders for installed apps", C:\Users\, the Temp folders and the .exe, .dll and .zip file types, "even if you trust that the items aren't malicious". A game's install folder is a program folder for an installed app. Microsoft's overview of exclusions says each one "creates a protection gap" and belongs "only after you determine the root cause".

The pages disagree on how far to go: the performance mode page says to use the analyzer "to narrow down to the hot processes/paths and add them to the exclusions", while the analyzer's reference says it "isn't intended to provide suggestions on exclusions". If a recording shows one file scanned again and again and you decide to exclude it anyway, File is the narrowest of the four types, and Microsoft's advice is to give the full path "so that you exclude only the file you intend".

Dev Drive and performance mode are not for this

Windows 11 has a Defender performance mode that scans a file after it opens rather than while it opens ("Open now, scan later"). It runs only on a Dev Drive, which Microsoft says "is intended only for key developer scenarios", and the Dev Drive page adds: "We do not recommend installing applications on a Dev Drive." The performance mode page itself says it "doesn't apply to high cpu or high memory usage scenarios" with Antimalware Service Executable.

If another antivirus is installed

On a home PC, Defender steps aside on its own once another antivirus product is installed and working, and comes back if that product is "out-of-date, expired, or not working". On Windows 11 with Smart App Control on, Microsoft notes that Defender may go into a passive mode instead. To see which product is active: Windows Security > Virus & threat protection, then under Who's protecting me? select Manage providers.

Two situations keep Defender scanning next to another product:

What does not help

Related

Did this page help?

What was missing, or what did not work? We read every one of these.

If this page did not solve it, write to us — say which article you read, and we will fix the article.