A factory reset removes most malware, but not all of it, and timing matters
A factory reset wipes your device's storage and reinstalls the operating system from scratch. For the vast majority of malware — viruses, spyware, ransomware, trojans — this works. The malicious code lives in files and memory on your device, and a factory reset deletes those files and clears that memory.
But a factory reset does not protect you if malware is hiding in your firmware, the low-level software that runs before your operating system even loads. Firmware attacks are rare and usually target specific people or organisations, not random users. They also require the attacker to have physical access to your device or very sophisticated tools. For a typical person dealing with typical malware, a factory reset is effective.
The real risk is what happens after the reset. If you restore from a backup that was infected, you bring the malware back. If you log into the same accounts without changing your passwords, an attacker who stole them can get back in. If you reinstall the app or visit the website that infected you the first time, you get infected again.
Key Takeaways
- A factory reset removes nearly all malware because it deletes the files and code the malware uses to run.
- Do not restore from a backup made while your device was infected, because the backup contains the malware too.
- Change your passwords for email and banking before you factory reset, because malware may have stolen them.
- Firmware-based malware is extremely rare and usually requires the attacker to have physical access to your device.
- After you reset, use the same security practices that should have prevented the infection in the first place — careful downloads, updated software, strong passwords.
Why a factory reset kills most malware
Malware is a program or a piece of code. Like any program, it needs files on your device to exist — executable files, libraries, configuration files, data files. When you factory reset, the device erases the entire storage drive and reinstalls a clean copy of the operating system. The malware's files are gone.
Even malware that tries to hide is vulnerable to this. Some malware disguises itself as a system file or hides in a folder you do not normally see. Some malware runs in the background without an icon in your app list. A factory reset does not care what the malware calls itself or where it hides — it wipes everything and starts over.
The one exception is malware in your firmware, the permanent software that controls your device at the hardware level. Firmware lives in a separate storage chip, not in the main drive that gets wiped during a factory reset. A firmware infection would survive the reset. But firmware malware is extraordinarily rare. It requires either physical access to your device or an exploit so advanced that it is usually reserved for targeting specific high-value targets — journalists, activists, government officials — not for mass infection campaigns.
The backup problem: how to avoid reinfecting yourself
The biggest mistake people make after a factory reset is restoring from an old backup. If that backup was made while your device was infected, the backup contains the malware too. You wipe the device clean, then when ready put the malware back in.
Before you factory reset, check when your backups were made. On iPhone, go to Settings > [Your Name] > iCloud > Manage Storage > Backups and look at the date. On Android, go to Settings > Google > Manage Your Google Account > Data & Privacy > Data from Apps and Services. If your most recent backup is from before you noticed the infection, you can restore from it. If it is from after the infection started, do not restore from it.
The safest approach is to not restore from backup at all. Set up your device fresh, then reinstall only the apps you actually use. This takes longer, but it guarantees you are not bringing anything infected back.
Passwords: change them before you reset
Malware often steals passwords. If you factory reset without changing your passwords first, the attacker still has them. They can log into your email, your bank, your social media, your cloud storage — and they can do it from any device, not just yours.
Before you factory reset, change your passwords on a different device. Start with email and banking, because those are the accounts an attacker can use to access everything else. Use a password manager like Bitwarden, 1Password, or KeePass to generate new passwords that are long and random — at least 16 characters, with uppercase, lowercase, numbers, and symbols.
If you do not have access to another device, you can change passwords on your infected device too. Malware may log your new passwords as you type them, but at least you will have changed them. After the factory reset, log in with the new passwords on your clean device.
What to do when ready after the reset
Once your device is reset and set up again, your first step is to update the operating system. Go to Settings > System > System Update on Android, or Settings > General > Software Update on iPhone. Install any available updates when ready. These updates patch security holes that malware might have used to infect you in the first place.
Next, install a reputable antivirus or security app if you want one. On Android, Malwarebytes and Kaspersky are widely used. On iPhone, built-in protections are strong enough that most people do not need a separate app. But if you want extra monitoring, Lookout and Norton are options.
Then reinstall your apps one at a time, downloading only from the official app store — Google Play on Android, the App Store on iPhone. Do not sideload apps from third-party websites. Avoid apps with very few downloads or reviews that look fake.
How you likely got infected in the first place
Most malware spreads through one of a few predictable routes. Understanding how you got infected helps you avoid it again.
Phishing emails and texts: A message that looks like it is from your bank, PayPal, Apple, or another trusted company, asking you to click a link or open an attachment. The link goes to a fake website that steals your login, or the attachment contains malware.
Unsafe downloads: A file you downloaded from a website that was not the official source — a cracked version of software, a game from a sketchy site, a PDF that turned out to be an executable.
Compromised websites: A legitimate website that was hacked and now serves malware to visitors. This is less common but does happen.
Outdated software: Malware exploits security holes in old versions of your operating system, browser, or apps. If you do not update, you stay vulnerable.
Weak passwords: An attacker guesses or cracks your password and logs in directly, installing malware themselves.
After your reset, the best protection is the same one that should have prevented the infection: do not click links in unexpected emails, do not read from untrusted sources, keep your software updated, and use strong unique passwords.
When a factory reset is not enough
In rare cases, a factory reset alone is not enough. If your email account was compromised, an attacker might have set up forwarding rules or recovery options that let them get back in even after you change your password. If your cloud storage was accessed, files might be encrypted or deleted. If your bank account was used fraudulently, you may need to dispute charges.
After you reset your device, log into your email account from a different device and check the Security section. On Gmail, go to myaccount.google.com > Security > Your Devices and look for unrecognized logins. Check connected apps and remove anything you do not recognise. On Outlook, go to account.microsoft.com > Security > Recent Activity.
If your bank or credit card was used without permission, contact the bank directly by phone using the number on the back of your card. Do not call a number from an email or text, because that might be fake. Report the fraudulent charges and ask the bank to cancel your card and issue a new one.
Frequently Asked Questions
Does a factory reset remove ransomware?
Yes, a factory reset removes the ransomware program itself. But it does not decrypt your files — the encryption key is usually stored on the attacker's server, not on your device. If you have backups of your files from before the infection, restore from those. If you do not, the files are likely gone.
What if I factory reset but the malware comes back?
This usually means you restored from an infected backup, reinstalled an infected app, or the malware is in your firmware. If it happens when ready after the reset, check your backup. If it happens days or weeks later, look at what apps you installed or what emails you opened. Firmware malware is possible but extremely unlikely unless you have reason to believe you are being specifically targeted.
Can malware survive a factory reset on a Mac or Windows computer?
The same principles explore. A factory reset on Windows (Settings > System > Recovery > Reset This PC) or Mac (System Settings > General > Transfer or Reset > Erase All Content and Settings) removes nearly all malware. The risk of firmware malware is the same — extremely rare. The backup problem is the same — do not restore from an infected backup.
Should I factory reset if I think I have malware but I am not sure?
A factory reset is safe and will not hurt your device. But before you reset, try these steps: update your operating system and all apps, change your passwords, run a malware scan with Malwarebytes or Windows Defender, and check your browser extensions for anything unfamiliar. If those steps do not help and your device is still slow or behaving strangely, a factory reset is reasonable.
Do I need to factory reset my router if my device had malware?
Probably not. Most malware targets individual devices, not routers. But if you are concerned, you can reset your router to factory settings — look for a small reset button on the back, hold it for 10 seconds, and the router will restart with default settings. You will need to set up your Wi-Fi password again. This is optional unless you have reason to believe your router itself was compromised.