Advice Request Antimalware core service running alongside 3rd party antivirus

Please provide comments and solutions that are helpful to the author of this topic.

Parkinsond

Level 63
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,084
15,370
6,169
I have found Antimalware core service running while checking task manager, inspite of running AVG free antivirus with enabled real-time protection, and disabled MSD periodic scanning and SAC!

Capture.JPG
Capture2.JPG
Capture3.JPG
Capture4.JPG
 
Try reinstalling AVG? I find I always have this weird bug where after I do a clean installation of windows and install a third-party AV, I still receive signature updates for windows defender. Even though periodic scanning is disabled. I find that after I reinstall my antivirus, that fixes the issue and I no longer get updates for defender while using a third party av.

And I just checked I do not have the antimalware service running while I am using McAfee currently.
 
Try reinstalling AVG? I find I always have this weird bug where after I do a clean installation of windows and install a third-party AV, I still receive signature updates for windows defender. Even though periodic scanning is disabled. I find that after I reinstall my antivirus, that fixes the issue and I no longer get updates for defender while using a third party av.

And I just checked I do not have the antimalware service running while I am using McAfee currently.
Thank you for your kind guidance; I will try the reinstall.
 
My antimalware core when running with a main AV is eating 180MB+ of RAM. Yours is only 6MB.
Possibly it could really be off and this is just a bug?
MSD is turned off; its main service is not running (which usually consumes 50-120 MB of RAM); the core service does not use more than 6 MB of RAM even if MSD is the main AV.
I will watch for few days before trying reinstall of AVG.
 
MSD is turned off; its main service is not running (which usually consumes 50-120 MB of RAM); the core service does not use more than 6 MB of RAM even if MSD is the main AV.
I will watch for few days before trying reinstall of AVG.
Instead of uninstalling, try to put avg in passive mode. This will turn on MSD as primary. Then restart. Then undo and restart. See if that works
 
Instead of uninstalling, try to put avg in passive mode. This will turn on MSD as primary. Then restart. Then undo and restart. See if that works
I have put AVG in passive mode days ago as a trial, then disabled the passive mode minutes later.
Could this manuver waked up the core service? 🤔
 
If you put it on passive, then no realtime is running. That will make Defender to take over. Try to play with those settings and ensure you restart. This could be a bug that windows is unsure who's doing the realtime.

I experienced this too from time to time as having multiple AV in my test system. You're not alone.
 
This is one of the reasons I don't use a 3rd-party antivirus, because Microsoft Defender is always running in the background.

This is not the case with W10. It only change on W11 that they made it harder for Defender to be off. I don't blame MS as some Malware abuse the integration with WSC. Malware will emulate a rogue AV, register in the security center to disable Windows Defender and pivot from there.

You can install a 3rd party AV and have smart app control off and see if the defender core services are off.
 
This is not the case with W10. It only change on W11 that they made it harder for Defender to be off. I don't blame MS as some Malware abuse the integration with WSC. Malware will emulate a rogue AV, register in the security center to disable Windows Defender and pivot from there.

You can install a 3rd party AV and have smart app control off and see if the defender core services are off.
In fact, since Microsoft Defender protects so well, is pre-installed, and is lightweight, I no longer find a need to download any 3rd party AV.

I've noticed that Microsoft's pre-installed software are now sufficiently good, which has led me to abandon many of the other software I used to use previously.