Reg add "HKLM\System\CurrentControlSet\Services\SecurityHealthService " /v "Start " /t REG_DWORD /d "4 " /f Reg add "HKLM\System\CurrentControlSet\Services\WinDefend " /v "Start " /t REG_DWORD /d "4 " /f Reg add "HKLM\System\CurrentControlSet\Services\WdNisSvc " /v "Start " /t REG_DWORD /d "4 " /f Reg add "HKLM\System\CurrentControlSet\Services\WdNisDrv " /v "Start " /t REG_DWORD /d "4 " /f Reg add "HKLM\System\CurrentControlSet\Services\WdFilter " /v "Start " /t REG_DWORD /d "4 " /f Reg add "HKLM\System\CurrentControlSet\Services\WdBoot " /v "Start " /t REG_DWORD /d "4 " /f Reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP " /f Reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP " /f Reg delete "HKCR\*\shellex\ContextMenuHandlers\EPP " /f Reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run " /v "WindowsDefender " /f Reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run " /v "Windows Defender " /f Reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run " /v "Windows Defender " /f
#Hklm software policies microsoft windows defender verification
Schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification " /Disable Schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan " /Disable Schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup " /Disable Schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance " /Disable Schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh " /Disable Reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger " /v "Start " /t REG_DWORD /d "0 " /f Reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger " /v "Start " /t REG_DWORD /d "0 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet " /v "SubmitSamplesConsent " /t REG_DWORD /d "0 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet " /v "SpynetReporting " /t REG_DWORD /d "0 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet " /v "DisableBlockAtFirstSeen " /t REG_DWORD /d "1 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting " /v "DisableEnhancedNotifications " /t REG_DWORD /d "1 " /f
![hklm software policies microsoft windows defender hklm software policies microsoft windows defender](https://www.intowindows.com/wp-content/uploads/2016/10/disable-Windows-defender-in-Windows-10-via-registry-or-group-policy-step5.png)
Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection " /v "DisableScanOnRealtimeEnable " /t REG_DWORD /d "1 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection " /v "DisableRealtimeMonitoring " /t REG_DWORD /d "1 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection " /v "DisableOnAccessProtection " /t REG_DWORD /d "1 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection " /v "DisableIOAVProtection " /t REG_DWORD /d "1 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection " /v "DisableBehaviorMonitoring " /t REG_DWORD /d "1 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine " /v "MpEnablePus " /t REG_DWORD /d "0 " /f
![hklm software policies microsoft windows defender hklm software policies microsoft windows defender](https://www.windowsphoneinfo.com/proxy.php?image=https%3A%2F%2Fwww.tenforums.com%2Fattachments%2Fsoftware-apps%2F331894d1620488969t-impact-removing-hklm-software-policies-microsoft-windows-appprivacy-capture_05082021_174624.jpg)
Reg add "HKLM\Software\Policies\Microsoft\Windows Defender " /v "DisableAntiVirus " /t REG_DWORD /d "1 " /f Reg add "HKLM\Software\Policies\Microsoft\Windows Defender " /v "DisableAntiSpyware " /t REG_DWORD /d "1 " /f
![hklm software policies microsoft windows defender hklm software policies microsoft windows defender](https://user-images.githubusercontent.com/40590467/71544940-64fe5480-2985-11ea-8e37-d568bb69e403.png)
Reg delete "HKLM\Software\Policies\Microsoft\Windows Defender " /f Rem reg add "HKLM\System\CurrentControlSet\Services\SecurityHealthService" /v "Start" /t REG_DWORD /d "4" /f Rem To also disable Windows Defender Security Center include this Rem USE AT OWN RISK AS IS WITHOUT WARRANTY OF ANY KIND !!!!! Learn more about bidirectional Unicode characters To review, open the file in an editor that reveals hidden Unicode characters. This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below.