Factory reset removes most viruses, but not all of them

A factory reset wipes your device back to the state it left the manufacturer, which removes the vast majority of viruses and malware. When you restore factory settings, the operating system and pre-installed apps are rewritten from scratch, and any malicious code that was living in your files, downloads, or user accounts gets deleted along with everything else.

However, a factory reset is not a may provide cure. Some types of malware — particularly firmware-level infections — live in the device's hardware instructions rather than in the software you can see. These are rare, but they survive a factory reset because they exist below the level that gets wiped. A device infected at the firmware level needs specialized tools or professional repair to clean.

For the vast majority of people dealing with a slow, sluggish, or visibly infected device, a factory reset will solve the problem. The catch is that you lose everything on the device in the process, so you need to back up what matters first.

Key Takeaways

  • Factory reset removes nearly all viruses because it rewrites your operating system and deletes all your files, where malware typically hides.
  • Firmware-level infections (extremely rare) survive a factory reset because they live in the device's hardware instructions, not in the software layer.
  • You must back up your important files before resetting, because the process deletes everything on the device.
  • After a factory reset, reinstalling apps from untrusted sources or visiting the same unsafe websites can reinfect your device when ready.

What a factory reset actually does to your device

When you restore factory settings, the device erases the entire storage drive and reinstalls the original operating system from a clean copy stored in the manufacturer's files. On Windows computers, this means Windows itself gets rewritten. On iPhones and Android phones, iOS or Android gets rewritten. All your personal files, photos, documents, and installed apps vanish.

Malware lives in that personal layer — in your files, your browser cache, your downloads folder, or in apps you installed. When all of that gets deleted and replaced with a fresh operating system, the malware goes with it. This is why a factory reset is so effective for the kinds of viruses most people encounter: ransomware, spyware, adware, and trojans all depend on files and code that exist in the user-accessible part of the device.

The process takes 30 minutes to a few hours depending on the device and how much data it has to erase. During that time, do not turn off the device or unplug it — interrupting a factory reset can leave your device in an unusable state.

Why some malware survives a factory reset

Firmware is the permanent software that tells your device's hardware how to work. It lives in a special chip on the motherboard, separate from the storage drive where your files and operating system sit. A factory reset only touches the storage drive, so firmware-level malware stays put.

Firmware infections are extremely uncommon in consumer devices. They require either sophisticated attackers with access to your device's physical hardware, or a compromised firmware update from the manufacturer itself. Most people will never encounter one. But they do exist, and they are nearly impossible to remove without specialized equipment or sending the device to a repair facility that can reprogram the firmware chip.

If you suspect a firmware infection — for instance, if your device is still behaving strangely after a factory reset, or if you know you were targeted by a state-level attacker — contact the device manufacturer's support line or a professional repair service. Do not attempt to fix it yourself.

How to back up your files before resetting

Before you factory reset, move anything you want to keep to an external drive or cloud storage. On Windows, use an external USB drive or cloud services like OneDrive, Google Drive, or Dropbox. On Mac, use an external drive or iCloud. On iPhone, use iCloud or a computer backup. On Android, use Google Drive or Samsung Cloud depending on your phone brand.

Back up only your files and photos, not your apps — apps can be reinstalled fresh from the official app store after the reset. If you back up an infected app, you risk reinfecting the device when you restore it.

Once your files are safely copied elsewhere, you can proceed with the factory reset. The exact steps vary by device: on Windows, go to Settings > System > Recovery > Reset this PC. On Mac, restart and hold Command-R to enter Recovery Mode, then choose Erase Mac. On iPhone, go to Settings > General > Transfer or Reset > Erase All Content and Settings. On Android, go to Settings > System > Reset Options > Erase All Data.

What to do after the reset to stay protected

A factory reset is only as good as your behavior after it. If you reinstall the same apps from untrusted sources, or visit the same websites that infected you the first time, you can reinfect the device within hours.

After resetting, install apps only from official sources: the Microsoft Store on Windows, the App Store on Mac and iPhone, or Google Play on Android. These stores have security screening, though they are not perfect. Avoid downloading apps from random websites or third-party app stores.

Update your operating system and all apps as soon as you finish the reset. Manufacturers release updates to patch security holes, and malware often exploits unpatched devices. Turn on automatic updates so you do not fall behind.

Consider using antivirus software on Windows — it is less critical on Mac, iPhone, or Android because those systems have stronger built-in protections, but it does not hurt. Windows Defender (built into Windows) is free and adequate for most people. Avoid paid antivirus software unless you have a specific reason; the free options are usually sufficient.

When a factory reset is not the right solution

If your device is still under warranty and you suspect a serious infection, contact the manufacturer before resetting. Some warranties cover malware removal, and resetting might void coverage if the infection is caused by a hardware defect rather than user behavior.

If you are not comfortable doing a factory reset yourself, or if you are worried about losing files, take the device to a professional repair shop. They can back up your data, perform the reset, and restore your files afterward. This costs money — typically $50 to $150 — but it removes the risk of losing something important.

If the device is very old and slow even after a factory reset, the problem may not be malware at all. Old hardware straightforward runs slower. In that case, a reset will not help, and you may need to replace the device or upgrade the storage drive.

Frequently Asked Questions

Will factory reset remove ransomware?

Yes. Ransomware encrypts your files and demands payment to decrypt them, but the malware itself lives in files and processes that get deleted during a factory reset. After resetting, the ransomware is gone — though your encrypted files remain encrypted unless you have a backup from before the infection.

Can I factory reset a device that will not turn on?

Yes, but the method depends on the device. On Windows, you can restart into Recovery Mode by holding Shift while clicking Restart, or by using a Windows installation USB drive. On iPhone, you can use recovery mode by connecting to a computer and using iTunes or Finder. On Android, you can usually access recovery mode by holding specific button combinations during startup. Look up the exact steps for your specific device model.

Does factory reset remove spyware that monitors my location?

Yes, location-tracking spyware gets removed because it runs as an app or background process that depends on files stored on your device. After the reset, the spyware is gone. However, if someone has physical access to your device or knows your passwords, they can reinstall spyware after the reset, so change your passwords when ready after resetting.

Will I lose my passwords if I factory reset?

Yes, unless you have saved them to a password manager like Bitwarden, 1Password, or your browser's built-in password storage synced to the cloud. If your passwords are only stored locally on the device, they will be deleted. This is why using a cloud-based password manager is safer — your passwords survive a reset and you can log back in when ready.

How do I know if my device is actually infected?

Signs include: the device is much slower than usual, apps crash frequently, you see pop-up ads you did not click on, your battery drains unusually fast, or you notice unfamiliar apps installed. However, these symptoms can also mean the device is just old or full of files. Run a scan with Windows Defender (Windows) or Malwarebytes (any device) to check before resetting. If the scan finds nothing but the device is still slow, the problem is probably not malware.