7 ms·
Firefox engineers discover a Windows Defender bug that causes high CPU usage
- Osiris 3y agoIt used to be possible to disable real-time protection but know it’s not. The UI toggle is only for a limited time and the Group Policy option doesn’t work anymore.
- ComputerGuru 3y agoThe gpedit option to disable the real time component continues to work. The toggle for disabling all of it doesn’t.
- odysseus 3y agoTry `Set-MpPreference -DisableRealtimeMonitoring $true` from admin powershell.
- bob1029 3y agoIt appears you would like to take a trip into the windows dark forest. Complete removal of windows defender on retail OS is feasible if you can figure out how to elevate a prompt to trusted installer. Alternatively, if you run Windows Server, you can use Remove-WindowsFeature to get it gone for good. I have a script that accomplishes this, but I hesitate to share it because I don't want some asshole at Microsoft to patch it.
- bdcp 3y ago[flagged]
- boredumb 3y agoFirefox engineers discovered a Windows Defender bug that causes high CPU usage.
- nier 3y agoFirefox engineers discovered a bug in Windows Defender that causes high CPU usage.
- ape4 3y ago"This problem has two sides: Microsoft was doing a lot of useless computations upon each event; and we are generating a lot of events. The combination is explosive. Now that Microsoft has done their part of the job (comment 82), we need to reduce our dependency to VirtualProtect. Bug 1822650 in particular will help with that."
- dakial1 3y ago[flagged]
- nvrspyx 3y agoIt was also fixed with a definition update in Windows Defender some time last month, so you probably have the update since these happen in the background and don't require any restart. You can check by going to: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BUNCH-OF-NUMBERS} Right click `mpengine.dll`, choose Properties, click Details tab, and check to see if Product Version is >= 1.1.20200.3. Mine is 1.1.20200.4 and was updated in mid/late March. If the version is less than 1.1.20200.3, you can manually trigger a definitions update in Windows Defender under Virus & Threat Protection.
- mconley 3y agoTL;DR: Windows Defender had a bug that made certain system calls expensive on CPU cycles when Defender's Real-time Protection feature is enabled. After discovery, Mozilla reported this issue to Microsoft. Microsoft is releasing a patch that should result in lower CPU usage when using Firefox on sites like YouTube (a ~75% CPU usage reduction was noted when browsing YouTube in Firefox with the fixed version of Defender). It seems like the HN submission form truncated the # from the end of the URL I linked to, which linked to the relevant comment. I'll try that here: https://bugzilla.mozilla.org/show_bug.cgi?id=1441918#c82 https://bugzilla.mozilla.org/show_bug.cgi?id=1441918#c82 and https://bugzilla.mozilla.org/show_bug.cgi?id=1441918#c91 https://bugzilla.mozilla.org/show_bug.cgi?id=1441918#c91
- dang 3y agoOk, I've put that back in the URL above. Thanks.
- IronWolve 3y agoIt's not just mozilla, been working defender issues for the last few years on thousands of windows vm's. Mostly due to the enabling the more intensive heuristic real time engine and they have different code bases depending on versions installed on different windows builds, and patching does seem to trigger it. For months we had issues where we couldnt log into some vm's due to high cpu for defender, and had to bounce the vm and apply a temp defender fix. I think its a growing issue, as they mature/migrate their older code base, issues become less frequent.
- psychphysic 3y agoI have malwarebytes premium and defender CPU usage is nearly 100% at times bringin Firefox to a halt. Chrome works fine..I've been blaming Firefox so far.
- rejectfinite 3y agoI am on Windows 10, Malwarebytes premium and using Firefox Nightly on Youtube right now and it is using miniscule CPU and has so for a long time. On a i7 4790k desktop machine. Firefox itself is at 4-5% and the whole machine is at 14% Normal Firefox was also fine last I used it.
- consumer451 3y agoRandom thought: I am not sure what the at-scale energy use reduction of this bug fix will be, but... If I had a pile of money I would consider creating a special bug bounty style program for energy use reduction. This might be a very efficient way to reduce carbon output from personal and data center computing.
- howinteresting 3y agoI agree. Windows Defender and Gatekeeper on macOS both have pathological performance characteristics in some cases -- $$$ should act as a good incentive to figure them out.
- JoeAltmaier 3y agoFunny how that sort of thing can work out. I was involved in an industrial optimization company years ago. Microsoft came out with power-save features in their new release. The staff at a metal-recycling company we were installing at, started complaining that the furnace would stop optimizing overnight. We investigated. The controller computer would go into power-save mode, which suspended our control app. So the furnace would just sit there wasting power and burning up electrodes. I calculated that during that week our furnace site wasted more power than all the power saved in America that year with power-save mode. It would literally have been better if they'd never invented power save mode. So be careful how much fiddling around we do. The law of unintended consequences will bite you in the butt every time.
- paulryanrogers 3y agoIsn't this more a failing of the operator: using a consumer grade OS for an industrial case?
- dijit 3y agobe very careful what you define as “consumer grade”, microsoft officially positions variants of windows as professional, industrial and enterprise grade. Linux as she is written comes with no warranty of anything, it is much more “consumer grade” than those variants of windows. I think even enterprise linux does not come with support for industrial applications. (I say this as a huge proponent of Linux supremacy)
- nabakin 3y agoA bug pending for 5 years, wow
- marcodiego 3y ago> a ~75% CPU usage reduction was noted when browsing YouTube in Firefox I wonder how many of the people who say "Firefox is significantly slower than chrome" are using windows... On my computer, Firefox IS slower than chrome but (with ad blockers enabled) by an insignificant amount. By still being "the last remaining mostly independent, maintained and reasonably popular browser" I'd prefer it to use over chrome even if it is a bit slower. Of course, ms is no longer the "old micro$oft" but their history on how they handle competitor browsers makes one think how much interest they could have in investigating and fixing such a bug. My takeaway is: prefer independent software as much as you can.
- nijave 3y agoFirefox seems a little slower than Chrome on Linux but force enabling some of the GPU offload stuff seemed to help.
- boringuser2 3y agoFirefox is significantly slower than chrome. This usually doesn't matter, but you can immediately see it in any page that A) has a massive DOM or B) uses complex regular expressions that eat up the engine
- Cthulhu_ 3y agoBoth of which are more issues with the website than the browser, imo.
- stkdump 3y agoI've read that a number of times now, but I have trouble matching it to my perceptions. Can you point to a specific website where you notice that slowness and then describe what action is slower? (Initial load, clicking stuff, scrolling, etc.) Just as an example, loading jslinux.org for me in Firefox is about twice as fast than in Chrome. That might be a special case of course, because it is a very special type of workload that probably is not common on other websites. But I would love to see concrete examples of the opposite.
- mgaunard 3y ago[flagged]
- pfoof 3y agoAn an experienced one-person IT department "Antimalware Service Executable" turns our laptops into rockets since always
- vezycash 3y agoI suffered because of this problem until I remembered that it's possible to exclude firefox.exe process in defender.
- ivanmontillam 3y agoI've experienced a bug related to the on-disk real-time scanning of Windows Defender, but instead with 100% disk bandwidth usage for unreasonable amounts of time. I purchased a license of a proper antivirus software to avoid that bug and the performance issues gone away. When you install another AV software, Windows Defender steps down and leaves scanning to the 3rd-party security solution. I selected one of the most lightweight ones I could find. It has been a net win for me. One shouldn't need to do this, but it has worked so far, for years now.
- Arrath 3y ago> I've experienced a bug related to the on-disk real-time scanning of Windows Defender, but instead with 100% disk bandwidth usage for unreasonable amounts of time. Sophos does this on my work laptop with depressing regularity. At this point I just go grab coffee when the fans max out, cause I know the disk is similarly pegged and it'll be about as snappy as a bogged down Windows 98 machine until it finishes.
- kleiba 3y agoI experience the same issue on my laptop, and I've come to think it might be everytime the memory got swapped out. Sophos seems to interfere when the memory is read back from disk, which is annoying and frustrating.
- miyuru 3y agoI stopped using windows and moved to Fedora and Mac when I faced the same issue you faced. Cannot trust windows after shipping this perf bug and the modern standby bug.
- Cthulhu_ 3y ago> I purchased a license of a proper antivirus software Which is that? For years (and come to think of it, this goes back to the 2000's or even 90's), AV / antimalware software comes across as scareware, using tricks to ensure you're afraid of not having it. And second, who here has ever had a virus in the past ten years?
- moonchrome 3y agoThis just reminds me of constant "things worked so fast on my Windows 95 machine back in the day with 16MB RAM". Meanwhile any piece of software could crash your PC and it did so regularly (I still keep spamming save in software because of those days) and internet was a pandoras box. I wonder how much overhead in modern OS/PC user experience comes from security/stability abstractions and tools.
- jacobsenscott 3y agoI think it mostly comes from the fact that computers are so fast now people write apps without worrying too much about performance - apps have always grown to use whatever resources are available. But when you app had to run on a pentium with 16MB of memory - you actually had to work hard on performance because you had such limited resources.
- moonchrome 3y agoYes but people have this nostalgic rose tinted glasses of software from that era - it was hot garbage that crashed all the time because they had so many constraints. Yeah GC introduces a bunch of overhead - but it also means you don't get segmentation faults, memory corruption, etc. Modern software is much more reliable than the software from that era, people nowadays complain when a button isn't working - back then a button could randomly freeze my entire PC.
- throitallaway 3y ago> it was hot garbage that crashed all the time because they had so many constraints Correlation != causation. I started using PCs heavily in the mid 90s, and yes "Illegal Operations" were abound. However, the SDLC has also come a long way with testing, automated QA, etc. Back then there was a lot more "wild west" going on for both hardware and software. Generally, practices are much more mature by default nowadays.
- moonchrome 3y ago
- SpaceManNabs 3y agoI knew I wasn't hallucinating about windows defender.
- RcouF1uZ4gsC 3y agoIs Windows Defender even worth enabling? It eats up a lot of CPU. It doesn’t seem like much help in a default update enabled system where you are using a regular user account instead of an administrator account. In addition, anti-virus and real time scanning is itself potential surface area for an exploit (for example a few years back there was an exploit based on Norton antivirus email scanner).
- Dalewyn 3y agoYes. It uses next to no system resources (issues like this aside), it integrates perfectly with Windows (it comes from Microsoft, after all), it's reasonably effective (to the chagrin of AV vendors the world over), and it isn't intrusive.
- lapsis_beeftech 3y agoWindows Defender is worse than nothing but in recent versions of Windows it is enabled by default, very difficult to disable, and may get re-enabled at any future software update.
- bobsmooth 3y agoEnable it on your parents PC but you shouldn't need it.
- Narishma 3y agoI don't think you can disable it anymore in recent versions of Windows unless you install another AV software.
- ravenstine 3y agoWindows Defender is a long standing bug in the Windows operating system. ;) My impression is that its invention was for the sole purpose of eradicating the idea that Windows is insecure and prone to viruses, which explains why it can be overzealous and CPU hungry. I would only enable it for family members who don't know what they are doing. For some reason, I haven't needed any form of active virus scanning in something like 15 years. If it turns out I've been infected this entire time, the criminals sure are taking their time stealing my money, etc.
- thewataccount 3y agoThere's a misconception that you need to do something "stupid" to get a virus which is simply not the case. 0 days exist, and worms are still a thing (looking at you samba). A great example is Pytorch just recently had a supply chain attack, and installing the nightly version between December 25th and December 30th, 2022 - would result in your home directory getting uploaded including ssh keys. Chrome also just had a 0 day 2022 - CVE-2022-3075 Pytorch supply chain attack via Triton 2022/2023 - https://www.bleepingcomputer.com/news/security/pytorch-discloses-malicious-dependency-chain-compromise-over-holidays/ https://www.bleepingcomputer.com/news/security/pytorch-discl... EDIT: Also there's a misconception that linux somehow doesn't get viruses - however the Pytorch attack affected linux users. Making a virus for windows gives you far more targets then linux, which is why they're far more common.
- lionkor 3y agowindows users will also happily "run as administrator", while a lot of linux users know not to do that in my experience
- qup 3y agoYes, I have an absolutely pristine record and I have never, ever copy-pasted a script from the internet with sudo, or piped curl into bash because I'm lazy and I trust most github READMEs. Never.
- pwarner 3y agoEvery security app seems to have problems like this all the time, and they never seem to be able to detect them themselves. Security software that didn't suck would be a huge opportunity, and yeah as others have alluded too, a huge carbon emission reduction! I had two different IT mandated apps taking up a total of 3.5 complete CPU cores for a week before I undocked and noticed the fast battery drain. On an M1 no fan blast to alert me. It's a terrible terrible state of affairs.
- avtar 3y agoDoes anyone know if MS have released any further information besides what's mentioned in the bug report? Specifically any patch information.
- LeoNatan25 3y agoWindows Defender itself is a bug that causes high CPU usage, by design. ;-)
- Sunspark 3y agoDefender's Real-Time feature also creates 100% CPU usage when burning a Windows To Go ISO using Rufus. Need to turn it off or things will go slowly.
- prepend 3y agoI’ve found many of these bugs and defender would frequently peg cpu and I’d have to disable it.
- initplus 3y agoBiggest headache with Windows Defender is it's abysmal single threaded IO bottlenecking. Writing large number of files to disk? Windows defender will be busy slowing down every single one of those writes as it scans... wouldn't be so bad if it didn't do so on a single thread. I have 10 cores, use them!
- StillBored 3y agoWell, windows defender is the single largest CPU hog Ive found on these low end cherry trail/silvermont/goldmont/etc tablets. Particularly when windows update kicks on the CPU's go to 100%, the thing overheats, and generally is absolutely unusable as it downloads and scans/etc the update its preparing. The devices go from usable but slow, to put it down for a couple hours cause you won't get anything done levels of usability. Disabling windows defender for the 24 hours (or whatever it takes) before windows decides to turn it back on, is the single largest performance hack I've found to make those devices run reasonably. Guess this "bug" just reinforces that fact. Maybe someone should donate a few to MS's windows engineering teams so they can enjoy the monster they have created running on the low end hardware that is still being sold.
- LtdJorge 3y agoRe:24h If you disable it and leave the security window, it automatically turns on again. It's bullshit.
- deleted 3y ago[deleted]
- AraceliHarker 3y agoI remember some people reporting that their old PCs with unsupported CPUs got a high CPU usage after installing Windows 11, and I remember some people saying that it was because they lacked TPM, which increased the CPU load. But it turned out to be just a bug, didn’t it? After all, features like memory randomization that require TPM couldn’t be enabled on Windows 11 anyway, and similar CPU usage spikes were seen on Windows 10 as well.
- ComputerGuru 3y agoMemory randomization shouldn’t require a TPM.
- deleted 3y ago[deleted]
- 29athrowaway 3y agoWindows itself causes high CPU usage. If you don't believe me, try XFCE on Linux. You will see how fast your computer truly is.
- hoseja 3y agoI think I have been experiencing that! I just turned off realtime protection, it's useless anyway and I think it cripples filecopy performance too.
- fulafel 3y agoOrders of magnitude slowdown of mmap() on ix platforms would never be accepted by users or developers on ix. Seems the expectations are quite far gone in the malware-ridden win* world.
- butz 3y agoIf Firefox engineers spent more time on Firefox bugs, maybe we would be able to fully use MS Teams and other important for work video conferencing apps on Firefox. (Hey, don't take me too seriously.)
- floatboth 3y agoWait so they… they have a hook in the mmap() equivalent that allows AV software to scan new pages mapped as executable? I see the reasoning but damn does that feel cursed.