Microsoft Defender for Endpoint
Endpoint protection

Rootkits Malware

In brief

The page now uses WDSI threat-description URLs for five malware entries and updates the Microsoft Defender Offline support link.

What Defender admins need to know

Administrators can use the updated links to access threat details and Defender Offline guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Many modern malware families use rootkits to try to avoid detection and removal, including:

How to protect against rootkits

Microsoft security software includes many technologies designed specifically to remove rootkits. If you think you have a rootkit, you might need an extra tool that helps you boot to a known trusted environment.

Microsoft Defender OfflineMicrosoft Defender Offline can be launched from the Windows Security app and has the latest antimalware updates from Microsoft. It's designed to be used on devices that aren't working correctly because of a possible malware infection.

System Guard in Windows 10 protects against rootkits and threats that affect system integrity.