Home › Knowledgebase › KB-289

How to recognise and remove a rootkit or persistent malware from your Windows PC

Summary

This guide helps you troubleshoot and resolve: How to recognise and remove a rootkit or persistent malware from your Windows PC. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Rootkits and persistent malware are among the most difficult threats to detect and remove from a Windows PC. Unlike standard viruses, they are designed to hide deep within your operating system, often surviving regular antivirus scans and even reinstalling themselves after removal. This guide walks you through recognising the signs of a deep infection, removing it using trusted tools, and securing your system afterwards. If at any point you feel unsure or the infection appears to be spreading, stop and open a ticket with our support team for assistance.

Signs Your PC May Be Infected

Persistent malware and rootkits often produce subtle symptoms that can be mistaken for hardware issues or software conflicts. Watch for any combination of the following:

If you suspect a rootkit, avoid logging into banking, email, or any account containing sensitive information until the system is cleaned. Consider using a separate, known-clean device for important transactions in the meantime.

Before You Begin

Preparation helps prevent data loss and ensures you can recover if something goes wrong during the cleanup process.

  1. Back up critical files. Copy important documents, photos, and data to an external drive or a reputable cloud service. Do not back up executable files (such as .exe or .dll) as these may carry the infection.
  2. Disconnect from the network. Unplug the Ethernet cable or turn off Wi-Fi to stop the malware communicating with remote servers.
  3. Note your passwords. Have a list of your important account credentials ready, as you will need to change them from a clean device after cleanup.
  4. Gather your tools. You will need a second device with internet access to download the removal tools below onto a USB drive.

Step-by-Step Removal Process

Step 1: Boot Into Safe Mode with Networking

Safe Mode loads Windows with only essential drivers and services, which prevents most malware from starting.

  1. Press Win + I to open Settings.
  2. Navigate to System > Recovery (Windows 11) or Update & Security > Recovery (Windows 10).
  3. Under Advanced Startup, click Restart now.
  4. After restart, choose Troubleshoot > Advanced options > Startup Settings > Restart.
  5. Press 5 or F5 for Safe Mode with Networking.

Step 2: Run a Full Scan with Microsoft Defender Offline

Microsoft Defender Offline runs outside the normal Windows environment, which makes it far more effective against rootkits.

  1. In Safe Mode, press Win + S and type Windows Security, then press Enter.
  2. Click Virus & threat protection.
  3. Under Current threats, click Scan options.
  4. Select Microsoft Defender Offline scan and click Scan now.
  5. Your PC will restart and perform the scan before Windows loads. Allow the process to complete.

Step 3: Use a Second-Opinion Malware Scanner

No single antivirus engine catches everything. Running a reputable second scanner helps identify threats Defender may have missed.

Only download these tools from their official websites. Never install "free antivirus" software advertised through pop-ups or unknown links, as many are themselves malware.

Step 4: Run a Dedicated Rootkit Scanner

Rootkits hide at a deeper level than standard malware, so specialised tools are often required.

  1. Download Kaspersky TDSSKiller or Malwarebytes Premium onto a USB drive from a clean device.
  2. Transfer and run the tool on the infected PC in Safe Mode.
  3. Follow the prompts to perform a full scan.
  4. Allow the tool to remove or quarantine any rootkits detected.
  5. Restart the PC when prompted.

Step 5: Check Startup Items and Scheduled Tasks

Persistent malware often reinstalls itself through scheduled tasks or startup entries. Removing the infection is only half the battle — you must also remove its persistence mechanisms.

  1. Press Ctrl + Shift + Esc to open Task Manager.
  2. Go to the Startup tab and disable any unfamiliar entries. Note the file path before disabling.
  3. Press Win + R, type taskschd.msc, and press Enter.
  4. Review the Task Scheduler Library for any tasks you did not create. Pay particular attention to tasks that run at logon or with elevated privileges.
  5. Delete any suspicious tasks by right-clicking and selecting Delete.

Step 6: Inspect Registry Run Keys

Malware frequently adds itself to registry locations that launch automatically.

  1. Press Win + R, type regedit, and press Enter.
  2. Navigate to each of the following keys and review the entries on the right-hand pane:
  1. Research any unfamiliar values using their file paths before deleting them. If unsure, export the key first as a backup.
Editing the registry incorrectly can cause Windows to fail to start. Always export a backup of any key before making changes, and only delete entries you can confidently identify as malicious.

Step 7: Reset or Reinstall Windows if Needed

If the infection persists after all the above steps, or if you cannot be certain the system is clean, a clean reinstallation is the most reliable option.

Option A: Reset This PC (Keeps Some Files)

  1. Go to Settings > System > Recovery.
  2. Click Reset PC next to Reset this PC.
  3. Choose Remove everything for the deepest clean, or Keep my files if you want to preserve personal data (note this is less thorough).
  4. Select Cloud download or Local reinstall when prompted. Cloud download fetches a fresh copy of Windows from Microsoft.
  5. Click Next, then Reset, and wait for the process to complete.

Option B: Clean Install from USB

A clean installation from a bootable USB is the most thorough option and guarantees removal of any rootkit, but it requires more preparation.

  1. On a clean PC, download the Media Creation Tool from the official Microsoft website.
  2. Use it to create a bootable Windows USB drive (at least 8 GB).
  3. Back up any files you wish to keep to an external drive.
  4. Boot the infected PC from the USB (you may need to change the boot order in BIOS/UEFI).
  5. Follow the on-screen prompts, choosing Custom install and formatting the system drive before installing Windows.
  6. After installation, install your applications and restore your backed-up files.

After Cleanup: Securing Your System

Once your PC is clean, take these steps to reduce the risk of reinfection.

  1. Change your passwords. From a clean device, change passwords for any accounts you accessed on the infected PC, starting with email, banking, and social media. Enable two-factor authentication where possible.
  2. Update Windows. Go to Settings > Windows Update and install all available updates, including optional ones.
  3. Update your software. Ensure browsers, plugins, and other applications are running the latest versions.
  4. Re-enable Defender. Confirm that Microsoft Defender is active and performing real-time protection.
  5. Monitor for symptoms. Over the following weeks, watch for any of the signs listed earlier in this guide.
If you are unsure whether your PC is truly clean, or if symptoms return after cleanup, open a support ticket and our team can guide you through further diagnostics or arrange a professional reinstall.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket