Skip to content
  • Sign In
Malwarebytes logo
  • Products

    < Products

    Solutions
    • Paid tier, explained plainly
    • Privacy VPN
    • Identity Theft Protection
    • Personal Data Remover
    • Phone security notes for iOS and Android
    • Running a few office PCs? Read our business notes
    Free device cleaners
    • Malware and virus remover
    • AdwCleaner
    • Antivirus trial
    Free ways to check your exposed personal data
    • Digital footprint scanner
    • Personal data scanner
    Free scam and ad blockers
    • Scam Guard
    • Scam number checker
    • Browser Guard
    See all free tools

  • Pricing
  • Partners
  • About
    Company
    • About Malwarebytes
    • Why read us?
    • Jobs
    Newsroom
  • Resources

    < Resources

    Cybersecurity News
    • Malwarebytes Blog
    • Threat Center
    • Lock & Code podcast
    Cybersecurity Basics
    • What is Malware?
    • What is Antivirus?
    • What is Phishing?
    • See all topics
    Research reports
    • Romance scams and dating-app safety
    • Mobile Scam Report
    • How AI tools changed the scams we see
    Small office security basics
    • Small business news
    • Upcoming Webinars
    See all resources
  • Help

    < Help

    Malwarebytes Help Center
    Community Forums
Free Download
Home/Rootkit

Rootkit

Last reviewed 2026-08-30

A rootkit is malware designed around one goal: staying hidden. Rather than simply running as a process you might notice in Task Manager, a rootkit modifies how the operating system reports information about itself, so infected files, processes, or network connections don't show up at all — even to tools that would normally catch them.

Where rootkits sit on a Windows system

  • User-mode rootkits — intercept API calls that applications use to list files and processes
  • Kernel-mode rootkits — operate at the same privilege level as Windows itself, able to alter what the OS reports to every program running above it
  • Bootkits — infect the boot process before Windows even loads, surviving reinstalls that don't touch the boot sector
  • Firmware rootkits — the rarest and most persistent, living in UEFI firmware rather than on the drive

Kernel-mode rootkits are the most common serious variant on consumer Windows machines, usually arriving bundled with a trojan or dropped by a separate exploit.

Why normal scans can miss them

A standard antivirus scan asks Windows for a list of running processes and files, then checks that list against known threats. A kernel-mode rootkit can alter the answer Windows gives back, so the malicious process is simply never listed. This is different from social-engineering-based malware like phishing payloads, which rely on tricking a person rather than tricking the operating system.

Because of this, rootkit detection generally requires either signature-based detection before the rootkit loads, behavior monitoring that catches the initial installation, or an offline scan run from bootable media that never lets the infected Windows kernel load in the first place.

Warning signs, even when hidden

  • Windows Security or third-party antivirus turns itself off and won't stay enabled
  • Network traffic shows outbound connections that Task Manager doesn't account for
  • The system clock, file timestamps, or free disk space don't add up
  • A scan reports the machine clean, but symptoms of infection persist

Removal in practice

For user-mode rootkits, an up-to-date anti-malware scan with real-time protection enabled — such as Malwarebytes Premium — will often catch the dropper before the rootkit component fully installs. For kernel-mode or boot-level infections, many security professionals recommend a full wipe and clean reinstall of Windows from trusted media rather than attempting in-place removal, since there's no fully reliable way to confirm a compromised kernel has been completely cleaned.

Frequently asked questions

Can a rootkit survive a Windows reinstall?

A standard reinstall removes most rootkits, but bootkits and firmware-level rootkits can survive if they live outside the partition being wiped, which is why a full drive wipe is sometimes recommended.

Does Malwarebytes detect rootkits?

Malwarebytes includes rootkit detection as part of its scanning engine, though catching the initial installer before it loads is generally more reliable than removing an already-active kernel-mode rootkit.

Are rootkits still common on home PCs?

They're less common than trojans or adware because they require more sophistication to build and deploy, but they still appear bundled with certain trojan and banking-malware campaigns.

Keep reading

  • the broader malware glossaryThe umbrella term for every kind of malicious software, explained.
  • trojan scanning toolsMalware that looks legitimate until it isn't.
  • real-time protection featuresThe real-time layers and who needs them.

Malware-Bytes.net is an independent information resource about malware protection for Windows. We are not Malwarebytes, and this site is not the official Malwarebytes website or support channel. Malwarebytes is a trademark of Malwarebytes Inc.

Malware-Bytes.net - independent Windows security guides and explainers.

COMPUTER SECURITY

  • Rootkit Scanner
  • Trojan Scanner
  • Free Antivirus
  • Free Virus Scan
  • Premium protection

MOBILE SECURITY

Google Play download badge
  • iOS Security and Spam Blocker
Apple App Store download badge

PRIVACY PROTECTION

  • Digital Footprint Scan
  • Dark Web Monitoring
  • Adware Removal
  • Ad Blocker

IDENTITY PROTECTION

  • Identity Monitoring & Alerts
  • Credit Monitoring & Reporting
  • Identity Recovery & Resolution
  • ID Theft Insurance
  • Personal Data Remover
ThreatDown business product logo
  • Business Endpoint Security Solutions
  • Managed Service Provider (MSP) Program

LEARN ABOUT CYBERSECURITY

  • Blog
  • Social Engineering
  • Phishing
  • Ransomware
  • Malware
  • Antivirus
  • What is a VPN?
  • Doxxing

PARTNER WITH MALWAREBYTES

  • Computer Repair
  • Affiliates
  • Strategic Business Partnerships
  • Resellers

ADDRESS

Editorial contact: see our contact page

Independent publication, United States

ABOUT MALWAREBYTES

  • Careers
  • News and Press
  • Vulnerability Disclosure
  • Report a False Positive
  • Territory Notice
  • Special Offers

WHY US

  • Malwarebytes vs. Bitdefender
  • Malwarebytes vs. McAfee
  • Malwarebytes vs. Norton
  • Malwarebytes vs. Windows Defender

GET HELP

  • Forums
  • Sign in to MyAccount
  • Help Center
  • X social media icon X
  • Facebook social media icon Facebook
  • LinkedIn social media icon LinkedIn
  • YouTube social media icon Youtube
  • Instagram social media icon Instagram
  • Reddit social media icon Reddit

Windows security, explained weekly

New guides on malware scanning, cleanup and Windows hardening land in our updates list. No sales pitches, no vendor sponsorship.

By subscribing you agree that we may email you about new guides, and that we handle your address as described in our Terms of Service and Privacy Policy.

    • Your Privacy ChoicesPrivacy opt-out icon used next to the privacy choices link
    • Legal
    • Privacy
    • Terms of Service
    • Accessibility

    © 2026 Malware-Bytes.net — an independent publication