A factory reset often removes malware from a computer, but it is not an absolute guarantee. The result depends on the type of infection, the reset method, the storage being erased, and whether the malware also affected your accounts, backups, browser profiles, or other devices.
For an ordinary Windows computer, a properly performed reset that removes personal files and reinstalls the operating system will eliminate most malware living in Windows. However, “most” is not the same as “all,” and a reset can create serious data-loss problems if you begin without a plan.
What a factory reset actually does
A factory reset returns a computer to a defined software state. Depending on the manufacturer and operating system, it may restore the original factory image or reinstall a current operating system using recovery files or downloaded installation media.
On Windows, the reset process may offer choices such as Keep my files or Remove everything. It may also offer a local reinstall or a cloud download. These choices matter:
- Keep my files removes applications and many settings but preserves user files. It is not the strongest option when malware is suspected because files, scripts, shortcuts, or browser data may still contain harmful content.
- Remove everything deletes the Windows user environment and is generally the safer reset choice for a confirmed infection, provided important data has been backed up safely first.
- Local reinstall uses recovery files already stored on the computer. If those files are damaged or compromised, the result may be unreliable.
- Cloud download obtains Windows installation files from Microsoft during the reset. It can be useful when local recovery files are corrupt, but it still requires a trustworthy internet connection and does not address account compromise.
Manufacturer recovery tools can be helpful, but they may reinstall older drivers, trial software, or outdated applications. A clean installation from official installation media can sometimes provide a more controlled starting point, although it requires careful preparation.
When a reset will usually remove the infection
Most consumer malware runs from the operating system, installed applications, startup entries, scheduled tasks, browser extensions, or user folders. Removing the Windows installation and formatting the operating system partition normally removes those components.
A full reset is more likely to be effective when:
- The reset uses Remove everything rather than preserving user files.
- The operating system is reinstalled from a trusted local recovery source or official installation media.
- Suspicious programs, cracked software, unknown browser extensions, and unauthorized remote-access tools are not restored afterward.
- Backups are checked before being copied back to the reset computer.
- The computer’s firmware and storage are functioning normally and have not been deliberately tampered with.
This is why a reset is often recommended for persistent infections, especially when the original cause is unclear or the operating system has been heavily modified. It can be more dependable than trying to identify and remove every malicious component manually.
Why a factory reset is not a complete security guarantee
A reset changes the computer’s software installation. It does not automatically repair every other part of the security problem.
Malware may be stored outside the operating system
Some threats can affect boot records, recovery partitions, device firmware, or other low-level components. These cases are uncommon on typical home computers, but they are more serious than ordinary adware or a malicious browser extension. A standard Windows reset may not remove them.
Unexpected behavior that returns immediately after a carefully performed reinstall—such as unexplained pre-boot screens, unauthorized boot changes, or a security tool detecting a threat before normal applications are installed—should be treated as a reason to stop and investigate. Do not repeatedly reset the computer while assuming the problem is solved.
Backups can reintroduce the problem
Personal documents such as photographs and ordinary office files are not automatically safe simply because they are personal. Malicious macros, executable files, scripts, altered shortcuts, and infected installers can be restored along with legitimate data.
Before copying files back, scan the backup with current security software. Be especially cautious with files ending in .exe, .msi, .bat, .cmd, .vbs, .js, or macro-enabled Office extensions. If a backup contains business-critical or unusual file types, preserve it separately and have it assessed before opening files.
Accounts may remain compromised
A factory reset does not undo a stolen password, an active email session, a hijacked social-media account, a fraudulent browser session, or an unauthorized cloud token. If an attacker obtained credentials before the reset, the computer may be clean while the account remains under someone else’s control.
Use a different, trusted device to change important passwords. Start with email, banking, Microsoft or Apple accounts, password managers, and business systems. Turn on multifactor authentication where available, review recent sign-ins, remove unfamiliar devices or sessions, and contact financial institutions directly if financial information may have been exposed.
Important: If the computer uses BitLocker, FileVault, another encryption system, or a business-managed security policy, do not reset it until you have confirmed that you have the recovery key and understand the data implications. A reset can make existing files inaccessible, and a repair shop cannot bypass encryption legitimately without the proper recovery information.
What to do before resetting an infected computer
- Stop using the computer for sensitive activity. Do not sign in to banking, email, payroll, or other important services from a suspected infected machine.
- Record the symptoms. Note suspicious pop-ups, detection names, unusual account activity, remote-control software, and when the problem began. Screenshots can help, but do not interact with suspicious alerts.
- Protect important data. Copy only necessary files to a separate drive or approved business backup. Do not assume every file is safe, and do not overwrite the only copy.
- Confirm encryption and recovery information. Locate BitLocker or FileVault recovery details, Microsoft or Apple account information, software licenses, and any business-management credentials.
- Disconnect when appropriate. Disconnecting from Wi-Fi or Ethernet can limit ongoing communication with an attacker, although it does not remove malware.
- Decide whether evidence matters. A business may need logs or forensic information before erasing the computer. Resetting first can destroy useful evidence.
How to reset more safely
For Windows, use the built-in recovery settings only after confirming the backup and recovery-key issues above. When malware removal is the primary goal, Remove everything is generally more appropriate than preserving files. If local recovery is suspect or damaged, an official cloud reinstall or clean installation may be preferable.
Do not download “one-click malware removal” tools from pop-ups, unknown websites, or search advertisements. If installation media is needed, obtain it from the official operating-system or computer-manufacturer website using a trusted computer. After installation, apply operating-system updates before restoring applications and data.
On a Mac, erasing the startup disk and reinstalling macOS can remove ordinary malware from the operating system. The exact steps vary by Apple silicon and Intel models, and Activation Lock or FileVault can affect the process. An Apple Account password, FileVault recovery key, or proof of ownership may be required. Do not attempt to defeat Activation Lock or another ownership control.
What to check after the reset
A freshly reset computer should be rebuilt gradually rather than restored all at once. Install operating-system updates, drivers from trusted sources, and reputable security software. Then add only the applications you recognize and still need.
Before restoring data, scan the backup. Open documents cautiously, leave macros disabled unless they are required and verified, and avoid reinstalling pirated software or utilities from unofficial download sites. Check browser extensions, startup applications, remote-access tools, and default search settings.
Continue monitoring the computer. If the same detection returns after a clean reinstall and before questionable software or backups are restored, stop using the system and seek a deeper assessment. The cause could be a compromised account, an unsafe network device, a malicious backup, a firmware issue, or a false positive—not necessarily a failed reset.
When professional help is the safer choice
Consider professional assistance before resetting when the computer contains irreplaceable data, uses business encryption or management, shows signs of unauthorized access, or is connected to other company systems. A reset may be technically simple but still be the wrong first action.
AME Computers can help home users and small businesses in Bellevue, Omaha, Papillion, La Vista, Plattsmouth, Ralston, Council Bluffs, and nearby areas evaluate the infection, protect data, plan a reset, and rebuild the computer without bypassing passwords or security controls. The goal is not to promise that a reset solved everything; it is to identify what was changed, what remains at risk, and what should be verified next.
Bottom line
A properly performed factory reset removes most malware that lives in Windows or macOS, but it cannot guarantee that every part of a security incident is resolved. Backups, passwords, cloud accounts, firmware, encryption, and other devices may still need attention. Treat the reset as one step in a recovery plan—not as proof that the entire incident is over.
When to call a professional
If the problem continues, the data is important, or the repair requires work beyond your comfort level, AME Computers can provide professional diagnosis and repair or call 402-505-6600.
Free repair guidance
Get New Computer Repair Guides by Email
Practical PC and Mac help from AME Computers. Confirm your email once and unsubscribe anytime.

