A factory reset removes most malware, but not all of it

A factory reset wipes your device back to its original state, which deletes the files and programs where most malware lives. For the majority of infections — viruses, spyware, ransomware that encrypts your files — a factory reset will remove them. But some types of malware can survive a reset, and a few can even prevent you from resetting at all. Understanding which threats a reset will actually stop helps you decide whether it's the right move for your situation.

The reason a reset works for most malware is straightforward: the malware exists as files on your device, and a reset deletes those files. When you factory reset a phone or computer, the operating system erases everything on the main storage drive and reinstalls a clean copy of itself. Any program that was running in that storage — whether it's legitimate software or malware — gets deleted in the process.

Key Takeaways

  • A factory reset removes the vast majority of malware because it deletes the files where malware lives and reinstalls a clean operating system.
  • Firmware-level malware and bootkit infections can survive a factory reset because they live in a part of your device that the reset does not touch.
  • Some malware can lock you out of the reset process itself, so you may need to use recovery mode or a different device to regain control.
  • After a factory reset, avoid restoring from a backup that was made while your device was infected, as this can reintroduce the malware.
  • A factory reset is not a substitute for antivirus software going forward — you still need protection to prevent reinfection.

What a factory reset actually deletes

When you perform a factory reset, the device erases the main storage partition — the section of the hard drive or solid-state drive where your files, programs, and operating system live. This includes any malware that installed itself there. Viruses that hide in program folders, spyware that runs in the background, ransomware that encrypted your files, and trojans that opened a back door for attackers — all of these are stored as files that get deleted.

The reset also reinstalls a fresh copy of the operating system. On Windows, this means a clean installation of Windows 10 or Windows 11. On Mac, it installs a fresh copy of macOS. On Android or iPhone, it installs the original version of the operating system that shipped with your device. This clean operating system has no malware baked into it, so you start from a known-safe state.

The key word is "most" malware. Some infections live in places a standard factory reset does not reach, and those can persist even after you wipe everything else.

Malware that can survive a factory reset

Firmware-level malware is the main exception. Firmware is the low-level software that runs before the operating system even loads — it's the code that tells your device how to be a device at all. On a computer, this is called the BIOS or UEFI. On a phone, it's called the bootloader. A factory reset only touches the operating system and storage, not the firmware. If malware has infected the firmware itself, it survives the reset and can reinfect your operating system as soon as it boots up.

Firmware infections are rare in consumer devices. They require either a sophisticated attacker with deep technical knowledge or a device that was compromised before you bought it. They're more common in targeted attacks against specific people or organizations than in mass malware campaigns. If you suspect a firmware infection — for instance, if malware keeps coming back even after multiple factory resets — you may need to contact the device manufacturer or a professional repair service.

Bootkit malware operates in a similar way. A bootkit infects the boot process itself, the sequence of code that runs when you turn on your device. Some bootkits can survive a factory reset because they're stored in a location the reset process doesn't overwrite. Like firmware infections, bootkits are uncommon in typical consumer malware.

Malware that locks the reset process is more common. Some malware can prevent you from accessing the factory reset option at all, or it can block the reset from completing. In these cases, the malware itself isn't surviving the reset — it's just stopping you from doing the reset in the first place. You can usually work around this by booting into recovery mode (on Mac or iPhone) or safe mode (on Windows and Android), which bypasses the normal startup process and lets you reset without the malware interfering.

How to factory reset safely if your device is infected

If malware is preventing you from resetting normally, try booting into recovery or safe mode first. On Windows, restart your computer and press F8 or Shift+F8 repeatedly as it boots to enter safe mode. On Mac, restart and hold Command+R to enter recovery mode. On iPhone, connect to a computer with iTunes or Finder and choose "Restore." On Android, the process varies by manufacturer, but usually involves holding Power and Volume Down during startup to reach recovery mode.

Once you're in recovery or safe mode, the malware's ability to interfere is limited, and you can proceed with the factory reset. Follow your device's standard reset instructions from that point.

After the reset completes, do not restore from a backup that was made while your device was infected. If you restore from a backup, you risk bringing the malware back. Instead, set up your device fresh and reinstall only the programs you actually use. If you need files from the old backup, restore them selectively rather than restoring the entire backup at once.

Why you still need antivirus after a factory reset

A factory reset cleans your device, but it doesn't change the behavior that got you infected in the first place. If you downloaded malware because you clicked a suspicious link, or because you installed a program from an untrusted source, those same behaviors can lead to reinfection. A factory reset is a one-time cleanup, not ongoing protection.

After you reset, install antivirus software and keep it running. On Windows, Windows Defender (built into Windows) provides baseline protection at no cost. On Mac, the built-in XProtect offers similar coverage. On Android, Google Play Protect scans apps in the Google Play Store. On iPhone, the operating system itself is designed to prevent malware installation, though you should still avoid sideloading apps from outside the App Store.

Beyond antivirus, the most effective protection is behavioral: avoid clicking links in unexpected emails or texts, download programs only from official sources (the Microsoft Store, Apple App Store, Google Play Store), and keep your operating system and programs updated. Malware often exploits known security holes that patches have already fixed.

When a factory reset is not the right answer

A factory reset is a drastic step that erases everything on your device. Before you do it, consider whether the malware actually requires it. If antivirus software has already detected and removed the threat, you may not need to reset at all. Run a full scan with your antivirus program first and see whether it can clean the infection without erasing your data.

A factory reset also makes sense only if you're confident the malware is actually on that device. If you're seeing suspicious activity on your email account or bank account, the problem might be a compromised password rather than malware on your computer. In that case, resetting the device won't help — you need to change your passwords and check your accounts for unauthorized access.

If you're unsure whether a reset will solve your problem, or if you suspect a firmware-level infection, consider having a professional look at the device before you erase everything. A technician can run diagnostics and sometimes remove malware without requiring a full reset.

Frequently Asked Questions

Can malware survive a factory reset on my phone?

Almost never on iPhone. iOS is designed so that a factory reset removes all malware. On Android, the same is true for standard malware — a reset removes it. Firmware-level infections are theoretically possible but extremely rare on consumer phones. If malware keeps returning after multiple resets, contact the manufacturer.

Will I lose my files if I factory reset?

Yes. A factory reset erases everything on your device — all files, photos, messages, and installed programs. This is why you should back up important files before resetting. After the reset, you can restore files selectively from your backup, but avoid restoring the entire backup if the device was infected when the backup was made.

What's the difference between a factory reset and a hard reset?

These terms are often used interchangeably and mean the same thing: erasing your device and reinstalling the operating system. Some people use "hard reset" to mean a forced restart (holding the power button until the device shuts down), but in the context of malware removal, both terms refer to the full wipe-and-reinstall process.

Do I need to reset if antivirus already removed the malware?

Not necessarily. If your antivirus program detected the malware, quarantined it, and reported that it was removed, the threat is gone. A reset is more thorough and guarantees removal, but it's not always required. Run a full scan after the antivirus removal to confirm the infection is gone before deciding whether to reset.

Can I reset my device if I don't remember my password?

Yes, but the process depends on your device. On Windows, you can reset without a password by using another computer to create a password reset disk. On Mac, you can use recovery mode. On iPhone, you can reset through recovery mode without knowing the password. On Android, the process varies, but you can usually reset through recovery mode. If you're locked out, contact the device manufacturer for help.