Back to Blog

Your Windows PC Could Lose Its Antivirus Before It Starts – What Every Small Business Must Do

Your Windows PC Could Lose Its Antivirus Before It Starts – What Every Small Business Must Do
August 22, 2026|David Velarde RoblesDavid Velarde Robles

Your Windows PC Could Lose Its Antivirus Before It Starts – What Every Small Business Must Do

Imagine turning on your computer in the morning, only to discover that the antivirus that usually protects you is gone before Windows even finishes loading. It sounds like a plot twist, but a recent discovery shows that a built‑in Windows driver can be weaponised to delete security software during the boot process. For a small business that relies on Windows machines, this is a real outage‑type risk that can leave your data exposed in minutes.

What the Windows boot‑time driver vulnerability means for your business

Microsoft Defender includes a component called BTR.sys (Boot Time Removal Tool). Its job is simple: after a reboot, it finishes removing malware that was locked while the system was running. Because it runs before most user‑mode services start, it has the power to delete files and registry entries that are otherwise protected.

Researchers at Check Point Research showed that, if an attacker already has an administrator account with the right to load low‑level system components (a permission that lets a user install drivers) (SeLoadDriverPrivilege), they can use a small utility to install BTR.sys as a service without the usual Windows logging. Once loaded, the driver can:

  • Delete the Defender binaries (e.g., MsMpEng.exe and WdFilter.sys) while the system is still starting up.
  • Remove registry keys that keep security software active.
  • Write new registry values that could keep the system in a vulnerable state.

The attack does not exploit a coding error in the driver; it exploits the trust Windows places in its own components. In other words, the driver is legitimate, but it can be misused by anyone who already has high‑level admin rights.

Why this matters to small‑business owners

  1. Loss of protection before the OS is ready – If the Defender stack is erased during boot, the machine runs without any real‑time protection until someone manually reinstalls it. Malware can then install itself silently.
  2. Fast, silent impact – The “golden window” described by the researchers is only a few seconds, making it hard to detect with ordinary monitoring tools.
  3. Administrative access is the real gatekeeper – Most small businesses already grant admin rights to a handful of staff (e.g., IT helpers, accountants). If those credentials are compromised, the attacker can launch the BTR.sys technique without needing any additional vulnerability.
  4. Microsoft has not yet released a specific fix, so you need to rely on controls now. – The risk stays until you change how those privileges are managed.

In short, the danger isn’t a new virus; it’s the possibility that an attacker who already has admin rights can wipe your antivirus before it even starts.

Practical steps you can take right now

1. Enforce least‑privilege admin policies

  • Limit admin accounts – Only give admin rights to people who truly need them (e.g., a trusted IT contractor). Everyone else should work with standard user accounts.
  • Separate duties – Keep the accounts that manage backups, finance, or point‑of‑sale systems separate from those that can install software or change system settings.

2. Enable multi‑factor authentication (MFA) for admin accounts

Even if a password is stolen, MFA adds a second verification step (a code on a phone, a hardware token, etc.). This dramatically reduces the chance that an attacker can obtain the admin credentials needed to load BTR.sys.

3. Keep Windows updated

Microsoft regularly releases cumulative updates that tighten the security around driver loading and privilege escalation. Enable automatic updates on all business PCs, and verify that the latest patches are applied within a week of release.

4. Maintain offline backups

If a machine is compromised before the OS boots, you may need to reinstall Windows and restore data. Having recent, offline backups (e.g., on an external drive that isn’t constantly connected) ensures you can recover without relying on a potentially infected system.

5. Use a managed service for privileged‑access management and 24/7 monitoring – it stores admin passwords safely, enforces MFA, and alerts you to unusual driver activity.

FAQ

Q: How can I stop a Windows boot‑time driver from deleting my antivirus?
A: Restrict admin rights to the few people who truly need them, protect those accounts with MFA, and let a managed security service monitor for suspicious driver installations and alert you instantly.

Q: How can I tell if my PC has been tampered with at boot?
A: Look for missing Defender files (MsMpEng.exe, WdFilter.sys) in the C:\Program Files\Windows Defender folder, or check the Windows Event Viewer for unusual driver load events. A managed security service can automate this detection.

Q: Are offline backups enough if my PC is compromised?
A: They are a critical part of the recovery plan, but they work best when combined with strong admin controls and regular patching. Backups alone won’t stop the attack; they only help you recover afterward.

How IT Move NL can help

Dealing with admin privileges, patch management, and boot‑time threats can feel overwhelming, especially when you have a bakery, a dental clinic, or a small logistics fleet to run. Our Security & Protection service takes the burden off your shoulders:

  • 24/7 monitoring – We watch for suspicious driver activity and unauthorized admin actions, alerting you before damage occurs.
  • Privileged‑access management – We set up a secure vault for admin credentials, enforce MFA, and provide detailed logs of every privileged operation.
  • Rapid response – If a boot‑time tampering attempt is detected, our team isolates the affected machine, restores the Defender stack, and helps you rebuild from a clean backup.
  • Patch & update stewardship – We ensure all Windows machines stay up‑to‑date, handling the testing and rollout so you never miss a critical security update.

You don’t have to become a security expert yourself. Let us handle the technical safeguards while you focus on growing your business. Contact IT Move NL today for a free security health check and see how we can keep your Windows PCs safe from boot‑time attacks.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch