Releases: ionuttbara/windows-defender-remover
Release 12.8.4 (.exe)
Version 12.8.4
- Starting with newer installations of Windows the default configuration of UAC (User Account Control) will NOT be modified by the script. (such disabling UAC and UAC Prompts), removal of Defender works great without this.
no new modifications for powershell version
release 12.8.3 (.exe)/release 13.0 (beta, powershell)
Note from me, the Developer
I wanted to let you know that development is currently progressing at a slower pace due to my ongoing studies, a full-time job, and involvement in another projects. I truly appreciate your patience and continued support during this time.
What's next?
Important Update (v12.8.4), short title Plans for the future of the app:
Starting with version 12.8.4, DefenderRemover no longer modifies the default UAC (User Account Control) settings, unlike some previous versions. This change was made to improve system compatibility and preserve user security preferences.
Also i will post some presets of removing defender via Windows Installation. A .xml file putted in the ISO Disc which removes defender. But it got some chances to be restored by Windows Update.
In v13, it moves away to .ps1 version.
Thank you again for your understanding and support!
Known Issues
I am working to solve some little bugs specified in Issues section.
In rare cases, Windows Update can restore the functionality of Defender.
New changes into the app (12.8.2 -> 12.8.3)
This version of app fixes removing in lastest canary builds.
In lastest canary builds (27858+), it does not disable Tamper Protection, it is fixed.
Powershell version is doing same thing. Is just trusted installer container from PowerRun to RunAsTi. It does not work 100%, and it need future intense modifications.
version 12.8.2
fixed listed issues.
version 12.8.1
fixes some listed issues (unresponse because of jobs and studies)
restructed some informations from pull requests
improved the way of removal of defender without uac disablation.
version 12.8.0
add ability to remove antivirus without disable UAC or another Security mitigations by default
version 12.7.2
Release 12.7
What's new?
Fixed #130 which when you pressing another key than 'Y' and 'y' the script will start. Also added a warning about reboot.
Remover removes Microsoft Pluton services and enforcing the OS to NOT use it. Also if you PC have a Pluton chip, disable it from BIOS (disablation from BIOS is for Lenovo Laptops for now) because after the removal with the script , Windows Update will re download Pluton Service again sometime. also removes the smartscreen classes in build 26052 canary build.
Release 12.6.9
Announcent
The development of project is ended. This seems no more major changes of the script will be added, so i will release versions of the script if this version is not working in a specific Windows Canary Build. The pause was cause by the university exams and patience of releasing of Windows Canary Build. So the development of this project will have same priority like Melody Script and Edge/OneDrive Uninstaller.
What's new?
For people who not create a system restore point, its not a way to solve / revert things due script. If a method is revertible, and MSFT patches that , will be harder for me to found new methods to bypass and remove Defender Antivirus on Windows.
But good news. In some versions of windows it don't need disablation of Tamper Protection!
- removed and deprecated 'safe' method because of microsoft's patchable tamper protection. so now, no more safe methods.
- if your antivirus said the .exe of remover is virus. don't worry. you can download the source code and run the Script_Run.bat file from archive.
- updating the way of disabling VBS
- enforcing removal of files
- AIO exe and package for (x86,x64 and ARM64)
- fixed issues of #128, #127 where firewall shows problems and removal of C:\ProgramData\Microsoft\Windows instead C:\ProgramData\Microsoft\Windows Defender.
- all issues about N , U and more methods will be closed due depreciation and removal from the script.
- re-write the removal of SecHealthUI app.
- updated documentation
Note of testing
These notes are for x64 and ARM64 (Windows 11 only) releases.
✅ Windows 8.1 and ALL version of Windows 10
✅ Windows 11 (21H2, 22H2 and 23H2)
✅ Windows Dev Channel
✅ Windows 11 Canary Channel / Windows 12 Alpha Builds
release 12.6.4
What's new?
this release was removed due a another problem which remover is removing content from c:\programdata and breaks uwp and microsoft store apps , where the script was configure NOT TO DO that.
Known issues
Note of testing
These notes are for x64 and ARM64 (Windows 11 only) releases.
✅ Windows 8.1 and ALL version of Windows 10 (all options)
✅ Windows 11 (all options)
❓ Windows Dev Channel (untested)
✅ Windows 11 Canary Channel / Windows 12 Alpha Build (its OK for Y option)
release 12.6.3
What's new?
fixes when a bounch of cmds are opened
Known issues
'Safe methods' is not working with Windows 11 due a problems with permmissons to disable and restore. This will be fixed and updated in 12.6.4.
Way to force disable VBS.
If VBS (Virtualization Based Security ) is enabled after you applied the script and applied policy, if you use Hyper-V Virtual Machine or WSL , this is forcelly enabled.
If you don't use: disable Secure Boot from BIOS. These will disable VBS if you applied the script, also it disables automatic encryption (so big ATTENTION for BITLOCKER-enabled users). After disablation you'll get this in msinfo32:

Note of testing
These notes are for x64 and ARM64 (Windows 11 only) releases.
✅ Windows 8.1 and ALL version of Windows 10 (all options)
✅ Windows 11 (all options)
✅ Windows 11 Dev Channel (its OK for Y option)
✅ Windows 11 Canary Channel / Windows 12 Alpha Build (its OK for Y option)