Step-by-step guide to cleaning a rootkit infection on Windows
A rootkit is malware designed to hide inside or beneath normal Windows processes, drivers, boot components, or firmware-related areas. Because it can conceal files and manipulate security tools, a computer may appear clean while an attacker still has access. Unusual crashes, disabled antivirus protection, unexplained administrator activity, and persistent browser or network changes can all justify a deeper investigation.
Cleaning this type of infection requires more care than removing ordinary adware or a potentially unwanted application. Avoid repeatedly deleting suspicious files at random, since removing a critical driver can make Windows unbootable and destroy useful evidence.
This educational guide focuses on Windows 10 and Windows 11. Results vary according to the rootkit family, the system’s boot mode, and whether the infection has reached the bootloader or firmware.
Recognize the Warning Signs
Rootkits often operate without visible windows or obvious pop-ups. Warning signs may include antivirus services that stop unexpectedly, security settings that cannot be changed, unknown users with elevated privileges, or processes that return immediately after termination. Persistent redirects, unexplained outbound connections, and programs launching before Windows fully loads also deserve attention.
A single symptom does not prove a rootkit infection. Hardware failure, damaged system files, unwanted browser extensions, and ordinary malware can produce similar behavior. Review recent installations and run reputable scans before making a final determination. Guidance about suspicious applications and related threats is available in the potentially unwanted programs category.
Isolate the Computer Safely
Disconnect the affected PC from Wi-Fi and wired networks as soon as practical. Unplug external drives that are not needed for backup, and avoid signing in to banking, email, work, or social media accounts from the suspected machine. If the computer belongs to an organization, contact its security team before attempting cleanup because volatile evidence may be important.
From a separate, trusted device, change important passwords and enable multifactor authentication. Do not copy executable files, scripts, or unknown installers from the infected computer. If a backup drive was connected during the suspected infection, treat it as potentially exposed and scan it before opening its contents elsewhere.
Preserve Important Data
Before aggressive remediation, copy irreplaceable documents, photographs, and other personal files to clean storage. Use a separate device or a newly scanned external drive, and avoid copying system folders, browser profiles, cracked software, or unknown file types. If ransomware activity is also present, preserve encrypted files and ransom notes rather than overwriting them.
Record error messages, suspicious filenames, recent security alerts, and the approximate time symptoms began. This information can help determine whether the problem is a bootkit, a kernel-level driver, or a less advanced threat. Technical users may also export relevant event logs, but they should avoid changing timestamps or modifying suspicious files.
Scan Outside the Installed System
A normal antivirus scan can miss a rootkit because the infected operating system controls what the scanner can see. Start with Microsoft Defender Offline, which reboots the computer into a trusted scanning environment. Open Windows Security, select Virus & threat protection, choose Scan options, and run Microsoft Defender Offline scan. Save open work first because Windows will restart.
For a second opinion, create rescue media from a reputable security vendor using a clean computer. Boot the affected PC from that USB device, update its detection database if the environment supports it, and perform a full scan of internal disks. A bootable rescue environment can inspect files and partitions before the installed Windows system loads.
| Cleanup method |
Best use |
Important limitation |
| Microsoft Defender Offline |
First response on supported Windows systems |
May not detect advanced or firmware-level threats |
| Vendor rescue USB |
Independent scan outside Windows |
Requires a clean computer and careful boot-media creation |
| Safe Mode |
Removing ordinary drivers, services, or startup items |
A sophisticated rootkit may remain active or hidden |
| System Restore |
Reversing recent system changes |
Does not reliably remove every malware component |
| Clean Windows installation |
Persistent infection or damaged system |
Erases applications and may erase personal data without backups |
Repair Boot And System Components
If scans identify a bootkit or modified boot files, use Windows recovery tools from installation media or the Advanced Startup environment. Startup Repair may correct damaged boot configuration data, while System File Checker and Deployment Image Servicing and Management can repair altered Windows components. Run these tools only when you understand the commands and have reliable backups.
Safe Mode can help remove a malicious service or driver that loads during a normal startup. However, it should not be treated as proof that the system is clean. Check installed drivers, scheduled tasks, startup entries, and unfamiliar services using trusted Windows utilities. Do not delete a driver solely because its name looks unfamiliar; verify its publisher, location, signature, and role first.
If the infection returns after offline scans and repairs, a clean installation is usually safer than continued manual deletion. Delete existing system partitions during setup only after confirming that personal data has been backed up. Firmware-level infections may require a manufacturer BIOS or UEFI update and, in rare cases, professional incident response.
Verify Recovery And Reduce Risk
After cleanup, reconnect to the internet only when Windows, the browser, and security software are updated. Run another full scan, review firewall prompts, inspect administrator accounts, and check that real-time protection remains enabled. Watch for recurring redirects, disabled security settings, unknown services, or new files appearing in system directories.
Restore personal files selectively from a backup that has been scanned. Reinstall applications from official sources rather than restoring old installers. The site disclaimer explains the informational nature of security guidance and why results can differ between systems.
Safer Cleanup Decisions
Use these precautions to reduce the chance of spreading the infection or damaging Windows:
- Keep the affected computer offline until initial scans and password changes are complete.
- Prefer Microsoft Defender Offline or reputable rescue media over unverified “rootkit remover” tools.
- Back up personal files without copying programs, scripts, or suspicious system components.
- Treat repeated reinfection as a reason to reinstall Windows or seek qualified professional help.
- Update firmware only with files obtained from the computer or motherboard manufacturer.
Rootkit cleanup is complete only when scans remain clear, system protections work normally, and suspicious behavior does not return after several restarts. For continuing malware-removal instructions, security updates, and file-recovery guidance, visit the malware removal guides on Pc Malware Expert.