Menu

Antivirus and Windows Defender

Why loaders get quarantined, and how to stop it happening.

Why this happens

Loaders inject code into a running game. That is, structurally, exactly what malware does, so heuristic scanners flag it whether or not it is doing anything harmful. A detection here is not evidence that something is wrong with the file, and a clean scan would not be evidence that it is safe either.

It also means the failure is silent. Defender quarantines the file, the download folder looks empty, and it reads as "the download did not work".

Which do I need, an exclusion or a removal?

Two different jobs, and most products need the second one.

Exclusion Full removal
What it does Stops the scanner touching one folder Stops the scanner running at all
Good enough for Keeping the loader file from vanishing Loaders that are actively blocked while running
Risk Low, one folder is unscanned Real, the machine is unprotected until you undo it

Check your product's setup page. Most products in this catalogue need real time protection off and third party antivirus uninstalled, not excluded, because the scanner blocks the loader at the point it tries to work rather than at download. Where a product only needs an exclusion, its guide says so.

If you are not sure, start with the exclusion. If the loader then reports missing dependencies, closes instantly, or opens empty, that is the scanner and you need the removal path.

Path one: add an exclusion

Windows Defender

  1. Open Windows Security.
  2. Virus and threat protection.
  3. Under Virus and threat protection settings, Manage settings.
  4. Scroll to Exclusions, Add or remove exclusions.
  5. Add an exclusion, choose Folder, and pick the folder you keep the loader in.

Use a dedicated folder rather than excluding all of Downloads. Excluding Downloads means every future download is unscanned, which is a genuinely bad trade.

Restoring a quarantined file

  1. Windows Security, Virus and threat protection.
  2. Protection history.
  3. Find the quarantined item, expand it, choose Actions, then Restore.

Third party antivirus

Kaspersky, Bitdefender, Avast, Norton, ESET and Malwarebytes all do the same thing under different menu names. Look for Exclusions, Exceptions, or Allowlist in their settings and add the loader's folder.

Some of them also need the file added to a separate ransomware protection or controlled folder access allowlist, which is a different list from the scan exclusions and is easy to miss.

Controlled folder access

If Windows blocks the loader from writing anywhere, check Controlled folder access under Virus and threat protection, Ransomware protection. Either allow the loader through it or turn it off while you use the product.

Path two: turn protection off

Windows Defender real time protection

  1. Open Windows Security.
  2. Virus and threat protection, then Manage settings.
  3. Turn off Real-time protection.
  4. Turn off Tamper Protection first if the switch will not stay off. It is on the same screen, and it exists to stop exactly this.

Windows turns real time protection back on by itself after a while, and always after a restart. That is expected. Turn it off again before each session rather than hunting for a way to make it permanent.

Third party antivirus

Uninstalling through Add or remove programs frequently leaves the driver behind, and the driver is the part that blocks the loader.

  1. Uninstall it from Settings, Apps, Installed apps.
  2. Restart.
  3. Run the vendor's own removal tool. Every major vendor publishes one, named something like "Removal Tool" or "Clean Uninstall", and it clears what the uninstaller leaves.
  4. Restart again.

Check Windows Security afterwards. If it now shows Microsoft Defender as your provider, the old product is properly gone.

Anti-cheat services

Riot Vanguard, FACEIT and ESEA each load a kernel driver at boot. Closing them does nothing, and several loaders refuse to run with any of them installed.

  • Riot Vanguard: uninstall Riot Vanguard from Installed apps, then restart. Uninstalling Valorant alone does not remove it.
  • FACEIT and ESEA: uninstall the anti-cheat client, not just the desktop app, then restart.

They reinstall themselves the next time you launch the game they belong to, so this is something you redo if you play Valorant between sessions.

Windows PIN and password

Some products, the Exodus range in particular, cannot complete their setup while a Windows PIN or password is set, and will restart the machine repeatedly until it is removed.

Remove it under Settings, Accounts, Sign-in options. Put it back afterwards.

When you finish playing

Turn real time protection back on, reinstall your antivirus if you removed one, and put your PIN back.

Stuck on something this does not cover? Open a ticket inDiscord.

Cart

Loading your cart.

Create order

Total due 

This step does not collect payment. Most products are delivered by our staff in a Discord ticket after payment is confirmed.