Windows

Antimalware Service Executable (MsMpEng.exe) High CPU? Fix It Without Disabling Defender

Updated Sources linked 3 min read October 3, 2026 · by Ryan Bennett

Antimalware Service Executable (MsMpEng.exe) — the Microsoft Defender Antivirus engine — is eating CPU (and sometimes RAM), making the PC sluggish, especially during file-heavy work.

Why the popular advice is a terrible idea: the top results tell you to permanently disable Defender, delete MsMpEng.exe, or kill its scan tasks. That leaves the machine unprotected — and on most PCs Defender is the only real-time protection there is. You don’t need to disable it; you need to find what it’s scanning so hard.

The right tool: Defender’s built-in Performance Analyzer. It records scan activity and identifies files, extensions and processes that take the most scan time. Use that evidence to investigate the workload; appearing in the report does not mean an item should be excluded.

Fix 1: Find the real culprit with Performance Analyzer

In admin PowerShell:

New-MpPerformanceRecording -RecordTo .\defender.etl

Reproduce the slowdown (or just let it run a couple of minutes during normal work), press Enter to stop, then read the top offenders:

Get-MpPerformanceReport -Path .\defender.etl -TopFiles 20 -TopExtensions 10 -TopProcesses 10

This names the worst paths/processes — usually a dev folder, a database, a backup target, or a VM disk being scanned repeatedly.

Fix 2: Address the measured workload

Check whether a large download, build, backup or database job is causing repeated scans. Update Windows, Defender security intelligence and the affected app, then repeat the recording to compare results. A new or scheduled scan may simply need time to finish.

If an application vendor documents a necessary exclusion, assess the risk and use the narrowest supported scope. Every exclusion reduces protection. A process exclusion skips files opened by that process; it does not merely skip its executable. Avoid whole drives, broad extensions such as .exe, and security-process exclusions as generic performance fixes. On a managed device, have IT review the evidence and any exception.

Fix 3: Let the initial/scheduled scan finish, and reschedule it

A brand-new PC (or one after a big update) runs a heavy first scan — let it complete once. To stop scans hammering you at the wrong time:

  • Task Scheduler → Microsoft → Windows → Windows Defender → Windows Defender Scheduled Scan → set a convenient time and untick “Wake the computer to run.”

Fix 4: Escalate persistent Defender activity

Do not add MsMpEng.exe as a routine “exclude itself” fix. Seeing Defender busy is not evidence that it is scanning itself in a loop. Keep protection enabled, save the analyzer report, and use Microsoft’s performance troubleshooting guidance or contact support if the cause remains unclear.

FAQ

Isn’t it easier to just turn Defender off? Easier, but it leaves you exposed, and Windows re-enables real-time protection automatically if no other AV is installed — so the “fix” doesn’t even stick. Use measured troubleshooting; exclusions are security exceptions that need a specific justification.

High CPU only at certain times? Check whether a scheduled scan or an app job matches those times. Use the analyzer to gather evidence rather than assuming the schedule or one file is the cause.

Related: 100% disk, not CPU? If it’s disk usage pinned at 100% rather than Defender CPU, see Windows 11 stuck at 100% disk usage.

Sources: Microsoft Learn — Performance analyzer, Microsoft Learn — Antivirus exclusion scope and risks, Microsoft Learn — Exclusions to avoid

↑↓ navigate · ↵ open · Esc close See all results →