Microsoft Defender Antivirus Mini-Filter Driver (WdFilter) Service Defaults in Windows 11
Microsoft Defender Antivirus On-Access Malware Protection Mini-Filter Driver.
Default Settings
| Startup type: | Boot |
| Display name: | Microsoft Defender Antivirus Mini-Filter Driver |
| Service name: | WdFilter |
| Service type: | filesys |
| Error control: | normal |
| Group: | FSFilter Anti-Virus |
| Path: | %SystemRoot%\system32\drivers\WdFilter.sys |
| Registry key: | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdFilter |
Default Behavior
Microsoft Defender Antivirus Mini-Filter Driver is a file system driver. In Windows 11 it starts by the operating system Boot Loader before the Kernel initialization, as a part of the driver stack. If Microsoft Defender Antivirus Mini-Filter Driver fails to start, the failure details will be recorded into Event Log. Then Windows 11 should boot up and notify the user about the WdFilter service startup failure.
Dependencies
Microsoft Defender Antivirus Mini-Filter Driver cannot be started, if the FltMgr service won't start.
Restore Default Startup Configuration of Microsoft Defender Antivirus Mini-Filter Driver
Before you begin doing this, make sure that all the services on which Microsoft Defender Antivirus Mini-Filter Driver depends are configured by default and function properly. See the list of dependencies above.1. Run the Command Prompt as an administrator.
2. Copy the commands below, paste them into the command window and press ENTER:
sc config WdFilter start= boot
sc start WdFilter
3. Close the command window and restart the computer.
The WdFilter service is using the WdFilter.sys file that is located in the C:\Windows\system32\drivers directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.