Removing a rootkit that disrupts network drivers
A rootkit that interferes with network driver communication can be difficult to recognise because its symptoms resemble ordinary hardware or Windows faults. Internet access may fail intermittently, Wi-Fi may disappear, Ethernet adapters can show errors, or security software may stop updating. In some cases, the malware hides processes and files while manipulating low-level system components.
This type of infection deserves a careful response. A rootkit may load before standard security tools, modify driver behaviour, or install a malicious kernel component that survives routine scans. Avoid repeatedly resetting the network or downloading random “driver fix” utilities, as these actions can conceal evidence or introduce additional unwanted software.
The safest approach is to isolate the computer, preserve important data, inspect the system from a trusted environment, and reinstall damaged drivers only after malware checks are complete. The steps below are aimed at Windows users, with notes that are also relevant to Australian home offices and small businesses.
Signs of a hidden driver-level infection
Common warning signs include a network adapter that repeatedly disconnects, unexplained DNS changes, blocked security websites, and Windows updates that fail without a clear reason. A rootkit may also cause unusual outbound traffic, high system activity while the computer is idle, or a security application that suddenly loses its services.
Look for several symptoms occurring together rather than treating one error as proof of infection. Check Device Manager for warning icons, unfamiliar virtual adapters, or a driver with a recent installation date. Event Viewer may show repeated network service, NDIS, or driver-loading errors, although a clean log does not rule out a stealthy threat.
Isolate the affected computer
Disconnect the Ethernet cable and turn off Wi-Fi from the router or computer. Do not log in to banking, email, myGov, cryptocurrency, or work accounts from the affected machine. If it is used in a Sydney office, a Melbourne apartment, or a home connected through an NBN modem, disconnecting the device is more useful than switching off the entire household router.
Use a separate, trusted device to change important passwords and enable multifactor authentication. If the infected computer contains business records, notify the relevant administrator and preserve unusual alerts or timestamps. Australian organisations may also need to consider Privacy Act obligations if personal information has been accessed, while serious cyber incidents can be reported to the Australian Cyber Security Centre.
Back up files without carrying the infection
Prioritise personal documents, photographs, project files, browser bookmarks, and other irreplaceable data. Copy selected files to a clean external drive rather than cloning the entire system. Avoid transferring executable files, cracked software, scripts, unknown installers, and suspicious browser extensions.
If ransomware or secondary malware has affected the computer, file recovery should happen after the machine is contained. This recover files safely guidance explains how recovery software may be used without casually overwriting deleted data. Keep the backup disconnected when it is not being scanned or used.
Scan from outside the normal Windows session
A standard antivirus scan may miss a rootkit that starts before Windows or hides its components from ordinary processes. Run Microsoft Defender Offline from Windows Security, allowing the computer to restart into a trusted scanning environment. A reputable rescue disk created on a clean computer can provide a second opinion.
Download rescue media only from the security vendor’s official website, and never use a tool advertised through a pop-up or an unsolicited support call. If the scan identifies a bootkit, kernel driver, or hidden service, record the detection name and quarantine result. Do not manually delete system files based only on a filename, because a legitimate storage or network driver may be removed accidentally.
Repair network drivers carefully
After malware scans, open Device Manager and inspect Network adapters. Uninstall a corrupted adapter only when you have access to the correct driver from the computer manufacturer, motherboard vendor, or official adapter provider. For laptops, the manufacturer’s support page is generally safer than a third-party driver catalogue.
Resetting TCP/IP and Winsock can repair legitimate configuration damage, but it will not remove a rootkit. Commands such as netsh winsock reset and netsh int ip reset should be used after containment and scanning, followed by a restart. Check proxy settings, DNS entries, and the hosts file for unauthorised changes before reconnecting to the internet.
Decide when a clean reinstall is safer
A clean installation is often the most reliable response when a rootkit has modified kernel components, boot records, security services, or multiple drivers. Save essential files first, then create installation media on a trusted computer. Delete existing system partitions during setup only after confirming that important data is stored elsewhere.
Download firmware and drivers from official sources after Windows is installed. Apply security updates before restoring applications, and reinstall software from legitimate vendors rather than old installers of uncertain origin. Australian consumers should be cautious with cheap “lifetime” software keys and grey-market downloads, which are common sources of bundled malware in the local online market.
Reduce the chance of reinfection
Once connectivity is restored, review every browser extension, startup item, scheduled task, and installed application. Remove tools you do not recognise, especially pirated utilities, fake driver updaters, and programs that appeared after a bundled installation. Adware can accompany a deeper compromise, so this adware cleanup guide is useful when shopping pages display injected coupons or unexpected adverts.
Keep Windows, browsers, routers, and endpoint protection updated. Use a standard account for daily activity, maintain offline or versioned backups, and avoid approving administrator prompts without checking the publisher. On shared Australian household connections, secure the NBN router with a unique password and current firmware, especially when smart TVs, cameras, and home-office devices are connected.
Practical checks before reconnecting
Use these checks after cleanup or reinstallation:
- Confirm the network driver is digitally signed and sourced from the device manufacturer.
- Run a full security scan and an offline scan, then review the detection history.
- Check DNS, proxy, firewall, and hosts-file settings for unexplained changes.
- Restore files selectively from a scanned backup, keeping the backup disconnected afterward.
- Monitor network activity and account alerts for several days after recovery.