Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

High CPU usage by Antimalware Service Executable often means Microsoft Defender Antivirus is scanning files, either during a scheduled scan or as an app opens or changes them. A brief spike can be normal; sustained use when the PC is idle deserves investigation. Check what is being scanned before changing Defender settings, and use an exclusion only for a trusted, identified workload.

What is Antimalware Service Executable?

Antimalware Service Executable is the Task Manager name commonly associated with MsMpEng.exe, a Microsoft Defender Antivirus process. Defender uses it for real-time protection, scheduled scans, and scans you start yourself. Real-time protection checks files and programs as they are accessed or run, so an application that creates or changes many files can trigger repeated scanning.

The process name alone does not show whether the activity is harmless or a problem. A scan can account for temporary CPU use, but persistent unexplained activity should be investigated. Microsoft’s Defender performance troubleshooting guide recommends identifying what is being scanned rather than beginning with broad exclusions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not end, delete, rename, or exclude MsMpEng.exe just because it appears in Task Manager. Those actions do not identify the workload causing the activity and can weaken protection.

#1 Best Overall
Kaisi Professional Electronics Opening Pry Tool Repair Kit Metal Spudger
  • Kaisi 20 pcs opening pry tools kit for smart phone,laptop,computer tablet,electronics, apple watch, iPad, iPod, Macbook, computer, LCD screen, battery and more disassembly and repair
  • Professional grade stainless steel construction spudger tool kit ensures repeated use
  • Includes 7 plastic nylon pry tools and 2 steel pry tools, two ESD tweezers
  • Includes 1 protective film tools and three screwdriver, 1 magic cloth,cleaning cloths are great for cleaning the screen of mobile phone and laptop after replacement.
  • Easy to replacement the screen cover, fit for any plastic cover case such as smartphone / tablets etc

How much CPU use is normal?

There is no single CPU percentage that separates a normal scan from a fault. Consider how long the load lasts, whether it recurs, whether the PC remains responsive, and whether battery drain or heat is unusual. A short-lived spike during a scan is not necessarily a problem. Sustained high use while the machine is idle and no scan or file-heavy activity is apparent is a reason to check further. The same scan may feel more disruptive on an older or low-power PC than on a modern desktop.

Microsoft documents a default scan average CPU load factor of 50 when the relevant setting is not configured, but this is a guidance value, not a guaranteed hard cap. Actual behavior depends on scan type and policy. See Microsoft’s Set-MpPreference documentation and scan best practices.

Check whether a scan is running

  1. Press Ctrl + Shift + Esc to open Task Manager. In Processes, check which items are using CPU.
  2. Open the Details tab and look for MsMpEng.exe to confirm the process associated with the load.
  3. Open Windows Security → Virus & threat protection and check the scan or protection status and recent scan information.
  4. If the CPU spike coincides with a scheduled, custom, or on-demand scan, let it finish before changing settings. Microsoft also recommends checking Task Manager’s Details tab and whether a scheduled scan is underway in its Defender troubleshooting guidance.

A scan may also be triggered by real-time file activity, so the absence of an obvious scheduled scan does not by itself identify the cause.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Try low-risk fixes first

Restart and update Windows and Defender

  1. Restart Windows.
  2. Install pending Windows updates.
  3. In Windows Security, check for available Protection updates or security-intelligence updates. Labels can vary by Windows version, language, and organization policy.
  4. Restart again if Windows or Defender requests it, then check CPU use while idle and during the activity that previously caused the spike.

These steps are low risk, but they are not a guaranteed cure.

Run a security scan if the activity is persistent or suspicious

Unexpected CPU use alone does not prove malware. If it continues or occurs alongside pop-ups, browser redirects, unfamiliar processes, or unusual network activity, run a Quick scan from Windows Security. If symptoms remain, consider a Full scan; a more comprehensive scan can take substantially longer and use more resources. Consider Microsoft Defender Offline scan if you suspect a persistent threat or normal scanning cannot resolve it.

Rank #2
Webroot Antivirus Software 2026 | 3 Device | 1 Year PC/Mac with Keycard
  • NEVER WORRY about losing important files and photos again! With 25GB of secure online storage, you know your files are safe and sound.
  • KEEP YOUR COMPUTER RUNNING FAST with our system optimizer. By removing unnecessary files, it works like a PC tune-up, so you can keep working smoothly.
  • Our PASSWORD MANAGER by Last Pass creates, encrypts, and saves all your passwords, so you only have to remember one.
  • As the #1 TRUSTED PROVIDER OF THREAT INTELLIGENCE, Webroot protection is quick and easy to download, install, and run, so you don’t have to wait around to be fully protected.
  • STAY PROTECTED EVERYWHERE you go, at home, in a café, at the airport—everywhere—on ALL YOUR DEVICES with cloud-based protection against viruses and other online threats.

Do not turn off real-time protection as a routine fix. Microsoft explains that disabling it leaves newly opened or downloaded files unscanned until protection resumes or another scan occurs; see its Windows Security virus and threat protection guide.

Find what Defender is scanning

Repeated scanning often follows file activity rather than a fault in the Defender process itself. Likely triggers include large source-code trees, build output and dependency caches, virtual-machine disk images, database files, mail stores, archives and ISO files, synchronized folders, network shares, rapidly changing temporary files, and unsigned programs. Microsoft notes that archive and container scanning, mapped network locations, OneDrive-synchronized content, and unsigned binaries can contribute to scan activity in its scan best-practices guidance and performance troubleshooting guide.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with built-in tools

  • Task Manager: correlate CPU use with the application or task you are using.
  • Windows Security: review scan status and protection history for relevant events.
  • Resource Monitor: when useful, correlate disk activity with file-heavy applications. This can help identify when the load occurs, though it may not pinpoint the Defender scan cause.

Use advanced diagnostics when the trigger is unclear

For developers, administrators, or persistent cases, Microsoft’s recommended escalation is to start with the Microsoft Defender Antivirus Performance Analyzer, which can help identify costly paths, processes, extensions, or scans. If that is not enough, capture activity with Process Monitor during the CPU spike, ideally for several minutes. Use Windows Performance Recorder or WPRUI if the earlier tools do not identify the cause. These are diagnostic tools, not beginner fixes. Microsoft documents the workflow in its guides for Process Monitor and Windows Performance Recorder.

Choose a fix that matches the trigger

If CPU rises only during scheduled scans

Let the scan complete, then consider scheduling future scans for idle time or lowering the scheduled-scan CPU guidance if the machine becomes difficult to use. Do not add exclusions unless repeated scans of a known workload are the actual problem.

If a particular application triggers the load

Identify the application’s executable and working directories, and determine whether it repeatedly creates or changes files. Use the diagnostic tools above if needed. If the workload is trusted and the evidence points to a specific location, a dedicated build, cache, or data folder is usually narrower than excluding an entire drive or user profile.

Rank #3
Sale
Webroot Internet Security Plus Antivirus Software 2026 3 Device 1 Year Download for PC/Mac/Chromebook/Android/IOS + Password Manager
  • POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
  • IDENTITY THEFT PROTECTION AND ANTI-PHISHING: Webroot protects your personal information against keyloggers, spyware, and other online threats and warns you of potential danger before you click
  • ALWAYS UP TO DATE: Webroot scours 95% of the internet three times per day including billions of web pages, files and apps to determine what is safe online and enhances the software automatically without time-consuming updates
  • SUPPORTS ALL DEVICES: Compatible with PC, MAC, Chromebook, Mobile Smartphones and Tablets including Windows, macOS, Apple iOS and Android
  • NEW SECURITY DESIGNED FOR CHROMEBOOKS: Chromebooks are susceptible to fake applications, bad browser extensions and malicious web content; close these security gaps with extra protection specifically designed to safeguard your Chromebook

If CPU stays high while idle

Check for a stuck or repeatedly restarting scan, review Windows Security protection history, install updates, and scan for threats if symptoms warrant it. Inspect recent software installations and large synchronized folders. If the cause remains unclear, use Microsoft’s diagnostic tools or contact Microsoft, the PC manufacturer, or your IT administrator.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If another security product is installed

A third-party antivirus can change Defender’s mode depending on the product and system configuration. Multiple real-time products can also add overhead or inspect the same files. Do not install another antivirus as a performance fix. If one is already installed, follow its vendor’s guidance to determine whether its protection or integration is contributing; do not leave the PC without active malware protection while testing.

Use a narrow exclusion only when you understand the risk

Exclusions reduce protection. A folder exclusion can cover every file below that folder; a process exclusion can exclude files opened by that process from real-time scanning; and a file-type exclusion can affect every file of that type. Exclusions may not affect every scan mode. A compromised or replaced application may also exploit a broad exclusion. Microsoft describes these effects and the available exclusion types in its Windows Security guide.

Add an exclusion in Windows Security

  1. Open Windows Security.
  2. Select Virus & threat protection → Manage settings.
  3. Scroll to Exclusions and select Add or remove exclusions.
  4. Select the narrowest applicable type: file, folder, file type, or process.
  5. Add only a trusted path or process shown by your investigation to be responsible, then re-test the workload.
  6. Remove the exclusion if it does not improve the problem or when the workload no longer needs it.

For a process exclusion, use a full path and filename for the specific trusted application; do not exclude Defender itself. Microsoft notes that scheduled and on-demand scans may still scan some excluded processes, so an exclusion is not a universal bypass. If a setting is blocked by Tamper Protection or organizational policy, ask the administrator rather than trying to bypass it.

PowerShell for advanced or managed systems

Use PowerShell only after identifying the cause and with the administrative privileges required by your system. Check Defender’s reported status with:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Anti Static Plastic Spudger Pry Opening Tool for Laptop Mobile Phone Tablet
  • Material: Carbon fiber plastic; Length: approx 150 mm
  • Anti-static, can be used in prying sensitive components.
  • Dual ends spudger tool, thick and durable, not easy to break.
  • Use the flat head to open screen, housing, pry battery.
  • Use the pointed head to dis-connect ribbon flex cables.
Get-MpComputerStatus

For example, a verified trusted build folder or application could be added with:

Set-MpPreference -ExclusionPath "C:PathToTrustedBuildFolder"
Set-MpPreference -ExclusionProcess "C:PathToTrustedApp.exe"
Set-MpPreference -ExclusionExtension ".db"

These are illustrative values, not recommended defaults: replace them with the exact trusted path, application, or verified extension responsible in your environment. Do not exclude a broad drive, profile, or file type for convenience. Microsoft documents exclusion parameters in Set-MpPreference. To check whether a path is excluded, Microsoft documents:

MpCmdRun.exe -CheckExclusion -Path <PathAndFileOrPath>

The location of MpCmdRun.exe varies with the Defender platform installation; run it from the current platform directory or use the documented installation path for the system. See Microsoft’s performance troubleshooting guide.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reduce disruption from scheduled scans

On supported managed Windows editions, administrators can configure the maximum percentage of CPU utilization during a scan, run a scheduled scan only when the computer is on but not in use, or configure low CPU priority for scheduled scans where supported. Availability depends on Windows edition and organizational policy. Microsoft describes these settings in its Group Policy scan scheduling guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The documented scan CPU setting accepts 5–100 percent; 0 means no CPU limit is applied. When the relevant Group Policy setting is not configured, its documented default is 50. These values are guidance, not a guaranteed hard limit. A lower value can reduce interference but makes scans take longer; a higher value can finish scans sooner with more foreground impact. Microsoft warns that disabling throttling can make applications unresponsive or increase heat. Do not set 0 or 100 as a performance fix.

Best Value
Sale
OriGlam 6pcs Dual Ends Metal Spudger Set, Professional Pry Opening Spudger, Prying Opening Repair Tool Kit for iPhone iPad iPod Mobile Phone Tablet Laptop Mp3 Watch
  • √ Premium Quality Material - Made of stainless steel, sturdy yet still flexible. Ergonomic silicone handle, non slip.
  • √ Excellent For Opening - Open Easily, you just need a little power to disassembly, your screen or cover will be opened.
  • √ Great Value - The screen open pry tool kit help to remove the LCD screen from your mobile devices during repairing.
  • √ Easy To Carry - Portable pry tools with light weight and compact design, fit in your pocket.
  • √ Suitable for - Fit for any touch screen or cover case such as Cell phone,Ipad, Ipod,Tablets, Watch, Laptop, MP3 etc

For example, an administrator can set the scan average CPU guidance with:

Set-MpPreference -ScanAvgCPULoadFactor 30

The value 30 is an example, not a universal recommendation. Choose it in light of the device’s workload and scan requirements. Microsoft’s scan best practices explain why this setting is not a hard cap.

Developer, enterprise, and managed-device cases

SQL Server, compilers, package managers, build agents, virtual machines, containers, large test-data directories, network shares, and OneDrive or enterprise synchronization can all create heavy file activity. Identify the particular path, process, or extension before proposing an exclusion. Microsoft’s Defender troubleshooting scenarios and behavior-monitoring guidance provide context for managed environments.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On devices controlled by Group Policy, Intune, or Microsoft Defender for Endpoint, local settings may be restricted or overwritten. Tamper Protection can also prevent changes. Have the administrator or security team review and approve any exclusion, document its purpose, and remove it when it is no longer necessary.

What not to do

  • Do not end the process in Task Manager. It does not address the trigger and may be blocked or only temporarily effective.
  • Do not exclude MsMpEng.exe or Defender’s installation directory. That can create a security blind spot without fixing the workload.
  • Do not permanently disable real-time protection. That reduces protection and does not resolve scheduled or on-demand scan behavior.
  • Do not set the scan CPU value to 0 expecting zero CPU use. In the documented policy, 0 means no CPU limit.
  • Do not delete Defender’s cache or scheduled tasks. This can damage protection, conflict with policy, or leave the underlying issue unresolved.
  • Do not install a second antivirus as a workaround. It can add scanning overhead and configuration complexity.

When to escalate

Contact your IT administrator, Microsoft, or the device manufacturer when high CPU persists at idle after updates and scans, Windows Security reports errors, a suspected threat remains, or diagnostic captures point to a Defender or platform problem. Escalate sooner if the same behavior affects multiple managed devices. Provide the approximate time of the spike, the activity underway, Task Manager observations, scan status, and any Performance Analyzer, Process Monitor, or WPR findings. For business workloads, involve the security team before applying exclusions.

Quick Recap

Bestseller No. 1
Kaisi Professional Electronics Opening Pry Tool Repair Kit Metal Spudger
Kaisi Professional Electronics Opening Pry Tool Repair Kit Metal Spudger
Professional grade stainless steel construction spudger tool kit ensures repeated use; Includes 7 plastic nylon pry tools and 2 steel pry tools, two ESD tweezers
$9.99
Bestseller No. 4
Anti Static Plastic Spudger Pry Opening Tool for Laptop Mobile Phone Tablet
Anti Static Plastic Spudger Pry Opening Tool for Laptop Mobile Phone Tablet
Material: Carbon fiber plastic; Length: approx 150 mm; Anti-static, can be used in prying sensitive components.
$4.99

Quick decision guide

What you observe What to do
CPU rises during a scan and falls afterward Allow it to finish; if disruptive, ask an administrator about idle scheduling or lower scan CPU guidance.
CPU rises whenever one trusted application runs Identify its file activity, diagnose the path, and consider a narrow exclusion only if evidence supports it.
CPU remains high while idle or symptoms look suspicious Check scan and protection history, update Windows and Defender, run an appropriate scan, then diagnose or escalate.
Settings are blocked on a managed PC Ask the administrator or security team to review the policy; do not bypass Tamper Protection.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.