A factory reset removes most malware, but not all of it
A factory reset wipes your device back to the state it left the factory, erasing your files, apps, and settings. For most malware — the kind that lives in your apps and files — this works. The malicious code gets deleted along with everything else.
But some malware can survive a factory reset. The most dangerous type, called bootkit or rootkit malware, hides in the firmware or bootloader — the deepest layer of your device that runs before the operating system even loads. A factory reset only touches the operating system and your files, not that layer. So the malware stays put and reinfects your device as soon as it starts up again.
This is rare on phones and tablets. It is more common on computers, especially if the malware was installed by someone with physical access to your device or through a targeted attack. For most people dealing with a virus or spyware they picked up normally, a factory reset will solve the problem.
Key Takeaways
- A factory reset removes the vast majority of malware because it deletes the files and apps where malware lives.
- Deep malware that hides in firmware or the bootloader can survive a factory reset and reinfect your device when ready after.
- Bootkit and rootkit malware are uncommon on phones but more common on Windows computers, especially after targeted attacks.
- If your device acts infected again within hours of a factory reset, the malware may be in the firmware, and you may need professional help or a replacement device.
Why a factory reset usually works against malware
When you do a factory reset, the device erases the entire operating system and reinstalls a clean copy from the manufacturer. All your apps, photos, documents, and settings vanish. Malware that lives in those apps and files — which is the vast majority of malware — gets erased too.
Think of it like burning down a house to get rid of termites in the walls. The termites in the wood are gone, but if they also nested in the foundation, they survive. For malware, the "house" is your operating system and files, and the "foundation" is the firmware.
This is why a factory reset is often the fastest way to clean a device that has picked up a virus, spyware, or adware through normal use — downloading a suspicious file, visiting a malicious website, or installing a fake app.
The malware that survives a factory reset
Firmware-level malware is installed below the operating system, in code that runs before Windows, iOS, or Android even loads. When you factory reset, you are only replacing the operating system. The firmware stays untouched, so the malware stays with it.
This type of malware is extremely difficult to install. It usually requires either physical access to your device (opening it up and modifying hardware) or a zero-day exploit — a security flaw that the manufacturer does not yet know about. Hackers do not waste zero-day exploits on random people; they use them against specific targets like journalists, activists, or corporate employees.
On phones, firmware malware is so rare that most people will never encounter it. On Windows computers, it is more common but still uncommon. If you picked up malware the normal way — through a read or a website — a factory reset will remove it.
How to know if malware survived the reset
If your device starts acting infected again within a few hours of a factory reset, the malware may be in the firmware. Signs include unexpected pop-ups, the device running slowly, apps crashing, or strange network activity even though you have not installed anything yet.
Before you assume firmware malware, check whether you are syncing data from a backup. If you restored your files and apps from a cloud backup after the reset, you may have restored the malware along with them. In that case, set up the device as new without restoring anything, and see if the problem goes away.
If the device still acts infected after a clean setup with no backup restored, and it happens within hours of the reset, firmware malware is possible. At that point, contact the device manufacturer or a professional repair service. Some devices can have their firmware updated or reflashed to remove the malware, but this requires specialized tools.
Factory reset versus antivirus software
A factory reset is more thorough than running antivirus software. Antivirus programs scan for known malware signatures and remove what they find, but they can miss new or hidden malware. A factory reset erases everything and starts fresh, so there is nowhere for malware to hide — except in the firmware.
If your device is running slowly or acting strange, and you suspect malware, a factory reset is usually faster and more reliable than trying to clean it with antivirus software. The downside is that you lose all your files and settings unless you backed them up first.
If you want to try antivirus first, that is reasonable. But if the problem persists after running a scan, a factory reset is the next step.
Steps to factory reset safely
Before you reset, back up anything you want to keep. On most devices, you can back up to cloud storage (Google Drive, iCloud, OneDrive) or to a computer. Make sure the backup is complete before you start the reset.
On Windows, go to Settings > System > Recovery and choose Reset this PC. On Mac, restart and hold Command + R to enter Recovery Mode, then choose Reinstall macOS. On iPhone, go to Settings > General > Transfer or Reset > Erase All Content and Settings. On Android, go to Settings > System > Reset Options > Erase All Data.
The reset takes 15 minutes to an hour depending on the device. Do not turn off the device or unplug it during the reset. When it finishes, set it up as new without restoring a backup, at least for the first day. Use the device normally and watch for signs of malware. If everything seems clean, you can restore your backup.
When to get professional help
If a factory reset does not solve the problem, or if the device acts infected again when ready after the reset, the malware may be in the firmware. This is beyond what most people can fix on their own. Contact the device manufacturer's support line or take the device to an authorized repair center.
If the device is old or the manufacturer no longer supports it, you may not be able to fix firmware malware. In that case, the safest option is to replace the device. Continuing to use a device with firmware malware puts your data and accounts at risk.
Frequently Asked Questions
Does a factory reset remove all viruses?
A factory reset removes most viruses because they live in files and apps that get erased. But viruses that hide in firmware or the bootloader can survive. This is rare on phones and uncommon on computers unless the malware was installed by someone with physical access or through a targeted attack.
Can I get malware back after a factory reset if I restore my backup?
Yes. If the malware was in your files or apps, restoring a backup from before the reset can restore the malware too. After a factory reset, set up your device as new without restoring anything for at least a day. If it stays clean, the malware was in your backup, and you should restore selectively — only the files and apps you trust.
How long does a factory reset take?
Most factory resets take 15 minutes to an hour, depending on the device and how much data it has. Do not turn off the device during the reset. If it takes longer than two hours, something may have gone wrong — restart and try again.
Will a factory reset delete my photos and documents?
Yes. A factory reset erases everything on the device. Back up your photos, documents, and any files you want to keep before you start. You can back up to cloud storage like Google Drive or iCloud, or to a computer.
What if my device is locked and I cannot factory reset it?
On most devices, you can force a factory reset even if the device is locked. On iPhone, use Find My iPhone from another device or a computer. On Android, restart into Recovery Mode (usually by holding Power and Volume Down) and choose Factory Reset from the menu. On Windows, restart into Safe Mode and use Settings to reset. If you are locked out of your account, you may need to verify your identity to the manufacturer first.