Microsoft Defender Antivirus Boot Driver (WdBoot) Service Defaults in Windows 11

Microsoft Defender Antivirus Boot Driver.

Default Settings

Startup type: Boot
Display name:Microsoft Defender Antivirus Boot Driver
Service name:WdBoot
Service type:kernel
Error control:normal
Group:Early-Launch
Path:%SystemRoot%\system32\drivers\WdBoot.sys
Registry key:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdBoot

Default Behavior

Microsoft Defender Antivirus Boot Driver is a kernel driver. In Windows 11 it starts by the operating system Boot Loader before the Kernel initialization, as a part of the driver stack. If Microsoft Defender Antivirus Boot Driver fails to start, the failure details will be recorded into Event Log. Then Windows 11 should boot up and notify the user about the WdBoot service startup failure.

Restore Default Startup Configuration of Microsoft Defender Antivirus Boot Driver

1. Run the Command Prompt as an administrator.

2. Copy the commands below, paste them into the command window and press ENTER:

sc config WdBoot start= boot
sc start WdBoot

3. Close the command window and restart the computer.

The WdBoot service is using the WdBoot.sys file that is located in the C:\Windows\system32\drivers directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.