antivirusvergleich.ch
Glossary

Rootkit

Malware that hides deep in the operating system and stays invisible to traditional antivirus scanners.

A rootkit hides deep in the operating system (kernel mode or bootloader) and stays invisible to traditional scanners – other malware can use it as cover. Rootkit removal often requires a boot scan before the OS starts.

Most modern suites (Kaspersky, Bitdefender) offer dedicated rootkit scanning.

Why this matters in 2026

UEFI rootkits like BlackLotus and CosmicStrand are the most dangerous variant in 2026: they nest themselves before the operating system starts and survive reinstalls. Detection requires dedicated UEFI scanners (Kaspersky Rescue, ESET SysRescue). Main distribution path: fake BIOS updates on compromised websites.

How to protect yourself

Enable Secure Boot in UEFI; download BIOS/UEFI updates only directly from the vendor (Asus, MSI, Gigabyte, HP, Dell, etc.) – never from Google results. If you suspect a rootkit: scan via an antivirus rescue medium (Kaspersky Rescue Disk, ESET SysRescue) instead of from the running system.

Related terms

Compare paid antivirus solutions now

From CHF 29 in the first year. With real-time protection, VPN, password manager and real support.