A factory reset will remove most viruses, but not all of them
A factory reset — also called a hard reset or restore to factory settings — wipes your device back to the state it left the manufacturer. For the vast majority of viruses and malware, this works. The reset erases your files, apps, and settings, which means it erases the malicious code living in those places too.
But a factory reset is not a may provide cure. A small category of malware called firmware-level threats can survive a factory reset because they live in the device's core instructions, not in the files you see. These are rare and usually only affect devices that have been physically compromised or targeted by sophisticated attackers. For everyday users dealing with ordinary viruses, spyware, or ransomware, a factory reset is effective.
The catch is that a factory reset only works if you do it correctly and if you do not reinfect the device afterward. A reset that goes wrong, or a device that gets infected again immediately after, will leave you right back where you started.
Key Takeaways
- A factory reset removes the vast majority of viruses because it deletes all files and apps where malware typically hides.
- Firmware-level malware can survive a factory reset, but this is extremely rare and usually only happens on devices that have been physically compromised.
- Before you reset, back up any files you want to keep to an external drive or cloud storage that you trust — the reset will delete everything on the device.
- After a factory reset, avoid reinstalling apps from untrusted sources or visiting the same websites that infected you in the first place.
What a factory reset actually deletes
When you factory reset a device, the operating system erases the partition where your files, apps, and settings live. This includes any virus or malware code that has been installed there. Most malware — including viruses, trojans, spyware, and ransomware — lives in this same space because it needs to run as a program or hide among your files to do its job.
The reset does not touch the firmware, which is the permanent code that tells your device's hardware how to start up and run. For a malware infection to survive a factory reset, it would have to be written into the firmware itself, which requires either physical access to the device's internal components or an extremely sophisticated attack. This is not what happens in typical malware infections.
Think of it this way: a factory reset is like emptying an entire house and refilling it with new furniture. Any pests living in the furniture or the walls get removed. But if the pests are living inside the foundation itself, they might survive.
When a factory reset might not work
A factory reset fails to remove a virus in a few specific situations. The first is if the malware has infected the device's bootloader or BIOS (on Windows) or the equivalent firmware on other devices. This requires the attacker to have had physical access to the device or to have used an extremely targeted exploit. It is not common.
The second situation is if you do not actually complete the reset properly. Some malware tries to prevent you from resetting the device or interferes with the reset process itself. If the reset appears to finish but something goes wrong partway through, malware could remain. Always follow your device manufacturer's official reset instructions, not workarounds you find online.
The third situation is reinfection. If you reset the device and then immediately download the same infected file, visit the same malicious website, or reinstall the same compromised app, you will get infected again. A factory reset is a fresh start, but only if you change the behavior that caused the infection in the first place.
How to back up before you reset
A factory reset deletes everything on your device, so you need to save anything you want to keep before you start. The safest approach is to back up to an external drive or a cloud service that is separate from the infected device.
For an external drive: connect a USB drive or external hard drive to your device, copy the files you want to keep to that drive, then disconnect it. Do not leave it connected during the reset. After the reset is complete, you can reconnect the drive and copy files back if you want them.
For cloud storage: if you use Google Drive, OneDrive, iCloud, or a similar service, you can upload files there before the reset. These services are generally safe because the files are stored on a separate company's servers, not on your infected device. After the reset, you can download them back.
Do not back up to the same cloud account that might be compromised, and do not back up files that you suspect are infected. If you are not sure which files are safe, back up only documents, photos, and videos — not programs or executable files.
Steps to factory reset your device safely
The exact steps depend on whether you have a Windows computer, Mac, iPhone, iPad, or Android device. Each manufacturer provides official instructions, and you should follow those rather than shortcuts you find elsewhere.
For Windows: go to Settings, then System, then Recovery. Look for "Reset this PC" and choose "Remove everything." Windows will ask whether you want to remove files only or also clean the drive. Choose "Remove files and clean the drive" if you have time — it takes longer but is more thorough.
For Mac: restart your device and hold Command + R to enter Recovery Mode. Go to Utilities, then Disk Utility, select your main drive, and click Erase. Then reinstall macOS from the Recovery Mode menu.
For iPhone or iPad: go to Settings, then General, then Transfer or Reset. Choose "Erase All Content and Settings." You will need your Apple ID password.
For Android: go to Settings, then System, then Reset Options. Choose "Erase all data" or "Factory reset." You may need your Google account password to complete this.
After the reset completes, your device will restart and ask you to set it up as if it were brand new. Do not restore from a backup of the infected device — set it up fresh and reinstall only the apps and files you actually need.
What to do after the reset to stay safe
A factory reset removes the current infection, but it does not change the conditions that allowed you to get infected in the first place. After you reset, take steps to avoid the same problem.
Install antivirus or anti-malware software appropriate to your device. Windows users can use Windows Defender, which is built in. Mac users have built-in protections but can add third-party tools if they want. Android users should install a reputable antivirus app from the Google Play Store. iPhone users have strong built-in protections and rarely need additional software.
Keep your operating system and all apps updated. Malware often exploits known security holes that have already been patched. Turn on automatic updates so you do not have to remember to do this manually.
Be cautious about what you download and where you download it from. Stick to official app stores — the Google Play Store for Android, the App Store for iPhone, the Microsoft Store for Windows. Avoid downloading files from unfamiliar websites or clicking links in emails or messages from people you do not know.
Frequently Asked Questions
Will a factory reset remove ransomware?
Yes, a factory reset will remove the ransomware program itself from your device. However, if your files were encrypted and stored on your device, the reset will delete them permanently. If your files are backed up elsewhere, restore them after the reset. If they are not backed up, the reset will not recover them — it will only remove the malware.
Can I factory reset a device that will not turn on?
Yes. Most devices have a way to force a reset even if the operating system will not start. For Windows, restart and hold F8 or Shift + F8 to enter recovery mode. For Mac, restart and hold Command + R. For Android, hold Power and Volume Down together. For iPhone, the process varies by model — check Apple's support page for your specific device.
Do I need to factory reset if I just have a virus warning pop-up?
Not necessarily. Many virus warning pop-ups are scareware — fake warnings designed to trick you into downloading something. Close the pop-up, do not click on it, and run a scan with legitimate antivirus software like Windows Defender. If the scan finds nothing, the pop-up was fake. A factory reset is more useful when you have confirmed malware or when your device is behaving strangely.
What if I factory reset but the virus comes back?
If you get infected again right after a reset, you are likely reinfecting yourself by downloading the same malicious file or visiting the same compromised website. Review what you downloaded or where you went before the first infection, and avoid that source. If you cannot identify the source, consider whether you need to change your browsing habits or be more selective about what you download.
Is a factory reset better than using antivirus software?
A factory reset is more thorough than antivirus software because it removes everything and starts fresh. But antivirus software is faster and does not require you to lose your files and settings. Use antivirus software first. If the infection is severe or the software cannot remove it, then consider a factory reset.