Defender Remover: what the ionuttbara script actually deletes on Windows 10 and 11
A tool which is uses to remove Windows Defender in Windows 8.x, Windows 10 (every version) and Windows 11.
At a glance
- What is it?
- A Batchfile tool that removes or disables Windows Defender, the Windows Security app, SmartScreen and VBS. It is aimed at technicians who need Defender gone permanently, and it is not reversible by design.
- Who is it for?
- Use it only on machines you own or administer, where you have already decided that Defender, SmartScreen and the Security app should not exist: offline test rigs, kiosks, benchmark machines, or systems where a third-party antivirus is the intended replacement. Do not run it on a machine you cannot reimage, and do not run it on Windows 11 22H2 or later expecting Tamper Protection to be handled, because the README scopes that component to Windows 11 21H2 or earlier.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 37 days ago.
- What is it written in?
- Mainly Batchfile, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Defender Remover removes, and who needs that
The repository describes itself as a tool that removes or disables Windows Defender on Windows 8.x, Windows 10 and Windows 11. The scope is wider than the name. According to the README, the script also takes out the Windows Security app, Virtualization-Based Security, SmartScreen, the Windows Security services, the Web-Threat Service, User Account Control file virtualization, Defender Application Guard, the Microsoft Driver Block List, System Mitigations, and the Windows Defender page inside the Settings app.
The audience is narrow and practical. Someone maintaining a lab machine that keeps flagging a payload they are studying, a technician who has already licensed a third-party antivirus and wants the built-in one out of the way, or an administrator building a fixed-purpose image. For those people, the interesting part is not that Defender can be turned off. It is that a single script reaches the UWP Security app, the kernel drivers and the policy layer at once, which is more than the Settings toggle does.
Anyone who just wants fewer notifications should stop reading here. This is a removal tool with a one-way bias.
How the removal works: scripts, services and drivers
The README splits the work into named modules under script/. Remove Defender handles the antivirus core, Remove SecurityComp handles the Security UI, and ISO_Maker builds an image with Defender already disabled. The top-level entry point is script/Script_Run.cmd, a Batchfile that drives the rest.
On the antivirus side the README lists specific targets: the Defender definition update list, SpyNet telemetry, the antivirus service, the antivirus filter driver and the rootkit scanner driver, scanning tasks, shell associations for the context menu, and the Antivirus Protection section of the Security app. On the security-component side it names Windows Security Center Service (wscsvc) and the SgrmBroker service and drivers, which the README says are needed to run the Windows Security app.
The VBS block is the most consequential. The README states that hypervisor startup gets disabled, which it says fixes the disabling of Virtualization-Based Security, and that this will auto-enable again if Hyper-V, WSL or WSA is used. The same block turns off file virtualization and UAC, so applications run with administrator privileges. That is a deliberate trade: fewer compatibility errors from legacy apps, and no UAC prompt standing between a user and a system-wide change.
Installing Defender Remover and running a first removal
The README recommends creating a system restore point before running the script, and says so explicitly for people who are unsure what they are doing. There are three routes in: the packaged executable from Releases, a git clone, or the source zip from Releases.
The packaged route is the one most people will take. Download the .exe from the Releases page, right-click it and run as administrator, then follow the prompts shown in the console. The README does not document a silent or unattended mode beyond the argument below.
Defender.Remover.exe /rThe README documents /r (or /R) as the removal argument for the executable. Anything beyond that is not described in the README, so treat the interactive prompts as the supported path.
If you prefer to work from source, clone the repository and run the Batchfile directly. The README gives this as the alternative:
git clone https://github.com/ionuttbara/windows-defender-remover.git
script/Script_Run.cmdRunning Script_Run.cmd launches the same prompt-driven flow. Expect a console window with numbered choices, and expect the machine to need a reboot before the service and driver changes settle. The README does not describe the reboot behaviour, so verify it yourself on a disposable VM.
The ISO path: baking a Defender-free Windows image
ISO_Maker exists so that Defender never runs on the target machine at all, rather than being removed after first boot. The README describes the layout rather than the automation. You mount the ISO, extract it, open the sources folder and create a $OEM$ folder there, then inside it a folder named $$, and inside that a folder named Panther. The resulting path is %location of extracted ISO%\sources\$OEM$\$$\Panther\.
Into Panther you drop the unattended.xml file that ships in the ISO_Maker folder of the repository. The README states that this file is what runs the Defender Remover portion during OOBE. It also states plainly that the script cannot yet save the result as a bootable ISO automatically, and that this is planned for a later version. So the last step, repacking the image, is on you.
This is the more defensible deployment route for a fleet, because it avoids the state where Defender has already run, updated its definitions and registered its drivers before you remove them.
Application Guard policy files and the PowerShell fallback
The README documents one failure mode directly. If an application refuses to open with a message about Device Guard or Windows Defender Application Guard blocking it, the README says four files named WiSiPolicy.p7b in different locations have to be deleted. It gives the PowerShell for each, including the EFI partition path, the CodeIntegrity folder, the Boot\EFI folder and a WinSxS search. This is presented as an advanced fix for an extremely rare problem, and the commands touch the EFI partition, so a mistake there affects boot.
There is also a PowerShell-only route for removing the Windows Security app without downloading the script at all. The README pastes a snippet that deprovisions the SecHealthUI package, writes EndOfLife markers under the AppxAllUserStore registry key, and calls dism with /online /set-nonremovableapppolicy. Note that the snippet in the README is truncated mid-command (it ends at remove-appxpr), so it is a starting point rather than something to paste and run unread. If you only want the Security UI gone and not the antivirus engine, this is the smaller intervention.
Where Defender Remover is the wrong tool
The README scopes Tamper Protection removal to Windows 11 21H2 or earlier. On later Windows 11 builds, Tamper Protection is designed to block exactly this kind of service and driver modification, and the README does not claim to handle it. That is the single biggest practical limitation: on a current Windows 11 install, parts of the script may simply fail, and the README does not document what happens when they do.
Second, the README does not document rollback. It recommends a restore point rather than offering an undo, which tells you the author expects the change to be permanent. On a machine with no restore point and no image, recovery means a repair install or a reimage.
Third, disabling UAC and file virtualization is a system-wide security posture change, not a Defender change. If you wanted Defender gone but still wanted UAC prompts, this tool does more than you asked. There is no documented flag to keep UAC while removing the antivirus components.
Finally, the licence file is present in the repository root but GitHub reports the licence as NOASSERTION, meaning it could not be matched to a known licence. If you plan to redistribute a modified build inside a company image, read LICENSE yourself; the repository does not spell out redistribution terms in the README.
Alternatives and how they differ
The obvious alternative is the built-in path: Group Policy or the registry under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender, plus the Tamper Protection toggle in the Security app. That approach disables Defender without deleting services or drivers, and it is reversible. The difference in kind matters: policy settings can be reverted by another administrator or by Windows Update, while Defender Remover's deletions are not policy and are not restored by flipping a switch.
A second alternative is a third-party antivirus that registers itself with the Security Center and takes over the antivirus role. Windows then stands Defender down on its own. You keep the Security app, SmartScreen and VBS intact, and you keep the ability to uninstall and go back. Defender Remover is for the cases where that handover is not enough, for instance when you need the Security app itself gone or you are building an image where no antivirus should be present.
A third is a custom image built with DISM and an answer file, removing the Defender capability before first boot. That overlaps with ISO_Maker, but ISO_Maker's contribution is the unattended.xml that runs the remover during OOBE; without it you are writing the OOBE step yourself.
Maintenance, releases and what to check before deploying
The repository is not archived and the last push was on 2026-08-24, which is recent. The release history shows release13 in February 2026, followed by release13-rev1 on 2026-08-24, and release_def_12_8_4 from June 2025 before that. That cadence suggests fixes are shipped as revised releases rather than as a stream of small commits, so the release notes matter more than the commit log when you are deciding whether a specific Windows build is covered.
Upgrade cost is mostly re-imaging cost. Because the README documents no uninstall path, moving to a newer release means running the new script over a machine that is already modified, and there is no documented state check that tells you which components are still present. On a fleet, that argues for treating the image as the unit of upgrade: rebuild from ISO_Maker rather than patching a running system.
On licensing, the repository root contains a LICENSE file, but GitHub reports NOASSERTION, so the terms are not a standard template the platform recognises. If your use is internal, that is usually a detail; if you intend to redistribute a modified build, read the file. Nothing here is legal advice.
Editorial conclusion
Use it only on machines you own or administer, where you have already decided that Defender, SmartScreen and the Security app should not exist: offline test rigs, kiosks, benchmark machines, or systems where a third-party antivirus is the intended replacement. Do not run it on a machine you cannot reimage, and do not run it on Windows 11 22H2 or later expecting Tamper Protection to be handled, because the README scopes that component to Windows 11 21H2 or earlier. Before running anything, create the system restore point the README recommends, and check the release notes for the build you are installing, since release13-rev1 is the current packaged build.
Frequently asked questions
Is it okay to remove Windows Defender?
That is a judgement about your machine, not something the repository answers. The README frames the tool as removing Defender along with SmartScreen, VBS, UAC file virtualization and the Security app, and recommends a system restore point before running it, which indicates the author expects the change to be significant and hard to undo.
How do I completely remove Windows Defender with Defender Remover?
Download the packaged executable from Releases, run it as administrator and follow the prompts, or clone the repository and run script/Script_Run.cmd. The README also documents Defender.Remover.exe /r as the removal argument.
How do I stop Windows Defender from constantly running?
Defender Remover takes the heavier route rather than quieting the scanner: the README lists the antivirus service, the antivirus filter driver, the rootkit scanner driver and the scanning tasks as removal targets. Turning Defender off through policy instead is not described in this repository.
Is windows defender remover safe?
The README does not make a safety claim, and it recommends creating a system restore point before running the script if you are unsure what you are doing. It also documents no rollback procedure, so on a machine without a restore point or image the change is effectively permanent.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/ionuttbara-windows-defender-remover)