Malware

What Is a Rootkit? How It Hides and What to Do

A rootkit can hide malicious activity on a device. Learn how it differs from a Trojan or virus, which signs need checking, and when to scan or seek a trusted rebuild.

Conceptual blue system layers revealing a small hidden red component under a cyan scanning beam

A rootkit is a collection of malicious components designed to hide unauthorized activity on a computer, often by changing what its operating system reports. It may help an attacker retain access or conceal another threat. A strange setting or slow device isn't proof of one. If you have credible evidence, preserve it and use a trusted security or recovery path.

What is a rootkit in cybersecurity?

You open a list of running programs. It looks ordinary. That doesn't tell you everything the computer is doing: a rootkit can interfere with the information the operating system shows you. NIST describes rootkits both as tools for concealing an attacker's access and as malicious files that stealthily alter a host's normal behavior. Microsoft's explanation puts the useful reader-facing point simply: when a rootkit changes standard operating-system processes, a compromised device may give you an incomplete picture of itself. [Evidence: NIST CSRC rootkit glossary; Microsoft Defender for Endpoint, Rootkits.]

The word combines root, a high-privilege account on Unix-like systems, with kit, a set of tools. It doesn't mean every case gives an attacker identical privileges or that every infected device contains one. Some rootkits conceal an unwanted process; others help hide activity closer to the boot or system layer. The particular change needs evidence, not a guess from the name.

If you arrived here because your computer is slow, take a breath. Slowness has many mundane causes. This guide helps you separate a symptom from a credible detection and decide who should handle the next step—especially before you erase a machine that contains work or family files.

How does a rootkit hide activity?

The easiest mental model is a changed answer, not an invisible computer. A healthy operating system tells a tool what programs, files and drivers it can see. A malicious component with enough access may filter or change that answer. It can make a process or file look absent even when another source of evidence suggests it exists. Microsoft gives a concrete example: a rootkit might remove a program from the displayed list of running programs. [Evidence: Microsoft Defender for Endpoint, Rootkits.]

A real investigation asks four separate questions. What entered? Another piece of malware, an unauthorized installation or an abused weakness may be the entry point. What changed? A file, driver, boot component or other system behavior may be altered. What is being hidden? The component may conceal itself, another payload or activity. What was actually done? A hidden process is not automatically proof of stolen passwords, an active botnet or a ransom demand. Each outcome needs its own evidence.

Hiding and persistence are related but different. A rootkit may try to survive restarts, but whether it does depends on where it runs and how it was installed. A restart, a clean-looking process list, or a single scan is not a universal clearance certificate. Equally, a mysterious process isn't proof that it is a rootkit.

Are there different types of rootkits?

People often classify rootkits by where they interfere with normal behavior. These are explanatory categories, not a way to diagnose your machine from one symptom:

The categories don't imply that one is always present whenever another is found. An article about a boot-level threat should not be turned into universal instructions to change firmware settings. [Evidence: Microsoft Defender Offline; NIST glossary.]

  • User/application level: may interfere with what an application or operating-system tool displays. Don't assume an odd browser setting alone is evidence of this type.
  • Kernel or driver level: can affect system functions more deeply, such as how certain files or processes are reported. Investigators need trusted evidence to distinguish this from a malfunctioning driver.
  • Boot-level: acts during the system's start-up path. Microsoft's Offline Scan documentation specifically discusses threats that affect boot records.
  • Firmware level: would involve code below the installed operating system. This is a specialist investigation, not something to conclude because a scan found no threat.

Rootkit vs Trojan, spyware and botnet: what changes?

These labels describe different parts of an incident. A Trojan focuses on disguise: something that appears useful while carrying an unwanted action. A rootkit focuses on concealment or retained control. One malicious package could involve both, but the terms don't mean the same thing. Our Trojan malware explainer owns the disguise and installation question; this article owns the hidden-system-behavior question.

Spyware refers to monitoring or collecting a person's information. A rootkit could hide spyware, yet finding a rootkit does not prove surveillance happened. See the spyware warning-sign guide for that separate question. A botnet is a coordinated group of compromised devices; one infected computer can participate in one without a rootkit, and a rootkit need not be part of a botnet. The botnet guide explains the network distinction.

A virus is a more specific kind of self-replicating malicious code. A rootkit's defining characteristic is concealment, not replication. Malware is the broader umbrella. If a warning names several families, don't collapse them into a dramatic headline; ask which component and behavior the alert actually identified.

What are the warning signs—and which ones prove nothing?

An unexpected administrator-level change, security tool that repeatedly shuts off, suspicious driver alert, or device that keeps showing the same unwanted behavior after a trusted recovery attempt can justify investigation. So can a credible endpoint-security finding or evidence from a managed organization's security team. But a slow startup, high fan speed, a changed homepage or an unfamiliar file name can have less serious causes. None, on its own, proves a rootkit. [Evidence: Microsoft rootkit guidance; CrowdStrike's dated case illustrates one specific browser-hijacking scenario.]

Imagine a laptop with an unfamiliar background process. A novice might delete it and hope for the best. A better first question is whether the process is from a signed, expected application, whether a trusted security tool identified malicious behavior, and whether the device is managed by an employer. If it belongs to work, notify the security team through its established channel. Don't erase logs or try to reproduce suspicious behavior; a responder may need the alert time and device identifier.

A negative scan is useful information but has limits, too. Microsoft's rootkit guidance notes that a compromised system's own reports can be unreliable. That is why running an appropriate tool outside the ordinary Windows session can be a sensible next check where supported. No scanner can retrospectively tell you that credentials were never exposed.

An older case shows what “hidden” can mean

In a 2020 first-party investigation, CrowdStrike described the Spicy Hot Pot browser-hijacking rootkit. Its researchers observed two malicious kernel-mode drivers used to interfere with security checks and obscure files, alongside a changed homepage and other behavior. The lesson is the difference between a visible symptom and the hidden mechanism: the homepage change was a clue, not a stand-alone rootkit diagnosis. This was a dated case, not a report of a new 2026 outbreak or of infections in India. [Evidence: CrowdStrike, Leftover Lunch: Finding, Hunting and Eradicating Spicy Hot Pot, 22 December 2020.]

The case also shows why a do-it-yourself recipe copied from one sample is a poor universal fix. Its exact files and response path belonged to that investigation. Your device may have a different issue—or no infection at all.

I think I have a rootkit. What should I do first?

First, protect the decision-making process. If this is a company, school or shared work device, follow the organization's incident route. Give the responder the date and time, warning details, recent unusual changes, and any actions you've already taken. Don't wipe it, upload suspicious files to a random site or remove software on your own. If a trusted responder advises isolation, disconnect it as directed while preserving evidence.

For a personally owned Windows computer, save the details of a credible warning, back up important personal files with care, and use the operating system's trusted security path. Avoid running a “rootkit remover” from an unexpected pop-up. If sensitive accounts might have been accessed, use another known-clean device for urgent account checks. Once the compromised machine has been dealt with, change affected passwords and review sign-in/session settings. Microsoft's account-recovery guidance advises clearing malware before relying on a password change; a new password typed on an untrusted computer may be captured again. [Evidence: Microsoft rootkit and compromised-account guidance.]

If you only have a general symptom, investigate it without calling it a breach. A recent software update, full disk, or legitimate backup can change performance. A proper support conversation can often narrow the problem before any destructive recovery decision.

How do you run Microsoft Defender Offline safely?

On an eligible x64 Windows 11 or x86/x64 Windows 10 device, Microsoft Defender Offline runs a scan after reboot from outside the normal Windows kernel. Microsoft's current guidance excludes Windows on ARM and Windows Server, and it lists prerequisites such as local administrator rights, enabled Windows Recovery Environment and Defender Antivirus in an appropriate active configuration for updates. Check the support details and operating-system support lifecycle for the actual device before using this route. This is a Windows-specific option, not advice for Mac, Linux, a router or every phone. [Evidence: Microsoft Learn, Run and review the results of a Microsoft Defender Offline scan, updated 3 July 2026.]

The scan restarts the device and is not a license to ignore a recurring warning. If it fails to launch, stops with an error or the device has unsupported hardware, get qualified support instead of improvising invasive command-line changes.

  • Prepare for a restart. Save open work. On a work-managed device, ask your security administrator rather than overriding organization policy.
  • Check disk-encryption recovery readiness. Microsoft warns that if BitLocker is protecting the system drive, a reboot into the offline environment may request the recovery key. Follow the organization's or Microsoft device-specific guidance before starting; don't disable protection casually or share recovery keys with a website.
  • Use the normal Windows Security path: Virus & threat protection → Scan options → Microsoft Defender Offline scan → Scan now. Confirm the restart prompt only when ready.
  • Review the result in Windows Security's protection history afterward. Record what was found or not found. A clean result does not certify that no compromise occurred, and a detection requires you to follow its actual name and remediation guidance.

When is a trusted reinstall the safer choice?

Microsoft's rootkit guidance recommends reinstalling the operating system and security software when the problem persists. Its Windows installation-media guidance distinguishes an in-place reinstall that keeps some content from a clean installation that removes personal files, applications and settings. Those are not equivalent decisions. If there is credible evidence of a persistent compromise, an expert may recommend a clean rebuild from media prepared on a trusted computer, followed by carefully selected clean backups. Back up what you need before any destructive step. [Evidence: Microsoft Defender for Endpoint rootkits; Microsoft Support, Reinstall Windows with the installation media.]

Ask for help before a wipe if you need forensic evidence, are handling a business or school device, use disk encryption, or suspect firmware rather than the operating system. A normal reset cannot be promised to repair every firmware case. Nor should you restore unknown executables from a suspect backup and call the system clean. Reinstalling is a deliberate recovery choice after evidence and backup planning, not the first action for a warm laptop.

What can readers in India use for general malware help?

CERT-In operates the Cyber Swachhta Kendra, a public botnet-cleaning and malware-analysis initiative. Its FAQ discusses identifying suspected bot infections, using reputable and updated scanning tools, and seeking expert help if a problem continues. That is useful general Indian device-hygiene context. It is not a diagnosis of your device, a rootkit-specific guarantee or a reason to download software from a message you didn't verify. [Evidence: CERT-In Cyber Swachhta Kendra FAQ.]

The safest channel for a work device remains your organization's designated team. For a personal computer, use the known official operating-system and device-support routes. Our site does not accept samples, offer live malware removal or require a paid security product to read this guide.

How can you reduce the chance of a hidden infection?

Keep the operating system, browser and installed software updated through their normal channels. Install applications from sources you trust, treat unsolicited attachments and “urgent scanner” ads with skepticism, maintain updated security protection, and keep recoverable backups. Microsoft specifically recommends software updates and regular backups in its rootkit guidance. No checklist can eliminate risk entirely, but those habits make it easier to avoid an infection and recover without gambling on an untrusted download. [Evidence: Microsoft Defender for Endpoint, Rootkits.]

For a small organization, also keep a device inventory and a simple reporting route. A user who knows where to send a suspicious driver alert can preserve better evidence than one who tries five removal apps and wipes the device before reporting it.

Common questions about rootkits

Does a rootkit always steal passwords? No. It can conceal activity and may accompany credential theft, but that specific outcome needs evidence. If you suspect account access, review sessions and reset relevant credentials using a trusted device as part of response. [Evidence: NIST glossary; Microsoft account recovery.]

Can antivirus detect a rootkit? Some tools can detect and remove known rootkits; a running compromised system may also give incomplete information. Microsoft's Offline Scan is one Windows-specific way to check from outside the normal kernel on supported devices. A negative result isn't a guarantee. [Evidence: Microsoft rootkit and Offline Scan guidance.]

Does a restart or factory reset remove every rootkit? No universal answer. Some threats may not survive a restart; others can persist. A reset and a clean installation are different processes, and firmware concerns need qualified, device-specific investigation. [Evidence: Microsoft rootkit and Windows reinstallation guidance.]

Is every Trojan a rootkit? No. Trojan describes a disguised harmful program; rootkit describes stealthy manipulation or concealment. One incident can involve both, but neither term proves the other is present. [Evidence: NIST glossary; Microsoft rootkit guidance.]

Should I run Windows Defender Offline on my work laptop? Ask your IT/security team first. The scan restarts the machine, and encryption and evidence needs may affect the sequence. Windows on ARM and Windows Server are excluded from that documented tool path. [Evidence: Microsoft Learn Offline Scan.]

Decision checklist

  • Write down what you observed and distinguish a symptom from a named security detection.
  • Verify the warning through the operating system, security team or established support route—never a surprise pop-up.
  • If this is a managed device, contact the responsible team before scanning, wiping or changing system settings.
  • Avoid typing sensitive new passwords on a machine you believe is still compromised.
  • On supported personal Windows hardware, consider the official Offline Scan path after saving work and checking BitLocker recovery readiness.
  • Record any actual detection and follow its specific supported response, not an unrelated rootkit article's sample filenames.
  • If a credible problem persists, plan a trusted rebuild with qualified help and a clean, selective backup.
  • After recovery, review affected accounts and update software and security controls.

Limitations

  • A symptom, unusual file or slow computer is not proof of a rootkit or stolen information.
  • Microsoft Defender Offline steps apply only to eligible Windows configurations and a negative scan is not a universal clearance certificate.
  • India's Cyber Swachhta Kendra offers general malware/botnet context, not rootkit-specific guaranteed cleanup.
  • CrowdStrike's Spicy Hot Pot investigation is a dated 2020 example, not a newly discovered 2026 campaign.
  • A Windows reset or reinstall cannot be promised as a firmware repair; managed devices and persistent incidents need qualified, device-specific help.

Evidence sources

  1. NIST Computer Security Resource Center — Rootkit — glossary entry
  2. Microsoft Defender for Endpoint — Rootkits
  3. Microsoft Learn — Run and review the results of a Microsoft Defender Offline scan
  4. Microsoft Support — Reinstall Windows with the installation media
  5. Microsoft Support — How to recover a hacked or compromised Microsoft account
  6. Indian Computer Emergency Response Team (CERT-In) — Cyber Swachhta Kendra — Frequently Asked Questions
  7. CrowdStrike Research — Leftover Lunch: Finding, Hunting and Eradicating Spicy Hot Pot, a Persistent Browser Hijacking Rootkit