registry location · risk: danger
Microsoft Defender policy settings
What lives here
Group-policy overrides for Windows' built-in antivirus — including switches that disable real-time protection entirely.
What changing it does
Files that set DisableAntiSpyware or similar values are turning your antivirus off at the policy level, where the Settings app can't turn it back on. A hallmark of malware droppers — and of a few overzealous 'tweak' scripts.
Risk level: danger. A .reg file from an unknown source touching this location deserves real scrutiny before you merge it.
Deciding whether to trust a file at all? Read the guide: Is this file safe to open?
Check a .reg file against this (and every other) risky location
Drop the file into the viewer — decoded and risk-flagged in your browser.
Open the .reg file viewer →