Clean up or reset Windows after malware: how to decide
A careful clean-up is enough for adware, browser hijackers, unwanted programs and most malware that was caught quickly. Reset Windows with Remove everything and Cloud download when an attacker had remote control, security tools were disabled, or detections keep coming back; and remember that no reset changes passwords or brings back data that was already stolen.
The short answer
The question to ask is not how dangerous the malware sounds, but whether you can trust the PC after cleaning it. If you know what was installed, where it lived and how it started, and a full scan plus an offline scan come back clean, cleaning is enough. If you cannot be sure what an attacker did, a reset is faster and more reliable than hunting for every change.
Cleaning is usually enough when
- the problem is adware, a browser hijacker, push notifications or a potentially unwanted program;
- the antivirus blocked a file when it was downloaded or extracted, before it ran;
- a single trojan was detected and removed, an offline scan finds nothing else, and nothing returns after a few days;
- a fake antivirus or scareware program was installed but you never gave it remote access.
Reset Windows when
- a remote access trojan, backdoor or abused remote support tool gave someone control of the PC;
- a rootkit or bootkit was reported, or a scanner finds an item it cannot delete;
- real-time protection was turned off, exclusions were added, or security tools cannot start or update;
- the same or new detections return after each clean-up;
- ransomware ran, after you have saved the ransom note and encrypted samples and tried the recovery options;
- unknown administrator accounts, services or drivers appeared;
- you ran a loader or a pasted command and do not know what it downloaded.
Why cleaning sometimes fails
Removing malware is easy when it is one program. It gets hard when the malware was a door for something else. A loader may have downloaded several payloads, of which the antivirus detects only some. A remote attacker may have added a second remote tool, a new account or a scheduled task that looks like a Windows component. A rootkit may hide files from the very tools that are looking for them.
Each of these leaves something behind that a scan can miss, and every missed piece can reinstall the rest. That is the typical pattern of a detection that returns a day after every clean-up. See trojans and loaders for how one download turns into several infections.
A reset sidesteps the problem. Instead of finding every change, it replaces Windows and removes every installed program, so anything the malware added goes with it.
If you clean up: what a thorough clean-up includes
A scan alone is not a clean-up. Work through these steps, each of which has its own procedure:
- Disconnect from the internet while you work, so nothing new is downloaded.
- Uninstall unknown programs, especially those installed on the day the problems began: Uninstall a program or app in Windows On uGetFix.
- Remove unknown startup entries and check Task Scheduler: Stop apps from opening at startup On uGetFix.
- Remove unknown browser extensions and reset each browser: Remove a browser extension, Reset a browser and fix a hijacked search engine. If Chrome or Edge says Managed by your organization on a home PC, policies were added and need removing too.
- Stop notification spam from websites: Stop website notifications and pop-ups.
- Check that the hosts file was not changed: Restore the hosts file.
- Run a full scan, then a Microsoft Defender offline scan, which runs before Windows starts: Run a Microsoft Defender Offline scan.
- In Windows Security > Virus & threat protection > Manage settings, check that real-time protection is on and remove exclusions you did not add.
- From a clean device, secure your accounts: securing your accounts after malware.
Then watch the PC for a week. If a detection returns, or settings change again, stop cleaning and reset. If malware blocks scanners from starting, Start Windows or a Mac in Safe Mode On uGetFix can help you run the tools.
Reset this PC: which options to choose
Windows 11 and Windows 10 can reinstall themselves without a USB stick. In Windows 11, open Settings > System > Recovery and select Reset PC next to Reset this PC. In Windows 10, the same option is under Settings > Update & Security > Recovery, with a Get started button. If Windows does not start, the same reset is available from the Windows Recovery Environment under Troubleshoot > Reset this PC.
You then make two choices. Microsoft's descriptions, in short:
- Keep my files reinstalls Windows and removes apps and settings, but keeps your personal files.
- Remove everything reinstalls Windows and removes personal files, apps and settings. Under additional settings, the clean data option also wipes the drive so that removed files are harder to recover; it takes longer and is meant for giving the PC away.
- Cloud download downloads a fresh copy of Windows from Microsoft, with recent updates.
- Local reinstall rebuilds Windows from files already on the PC.
What to choose after malware
Choose Remove everything with Cloud download. Remove everything guarantees that malware hidden in your user folders, such as a loader in AppData, does not survive. Cloud download avoids rebuilding Windows from local files that the malware may have touched, and it needs an internet connection only during the reset.
Keep my files is acceptable after adware or a single trojan that was caught early, because programs and their startup entries are removed either way. It is a weaker choice after a remote access trojan, because the user profile folders where malware often sits are kept.
Windows 11 also has Fix problems using Windows Update with a Reinstall now button on the same Recovery page. Microsoft describes it as reinstalling the current version of Windows while preserving apps, files and settings. That repairs system files, but it keeps the programs, so it is not a malware removal method.
Before you reset: what to save and check
- Copy documents, photos and other personal files to an external drive or cloud storage. Copy data only, never programs, installers, scripts or archives from the infected PC.
- Note the programs you need to reinstall and find their licence keys or account details.
- Make sure you know your Microsoft account password and, if the drive is encrypted with BitLocker or device encryption, that you can find the recovery key, which is usually saved in your Microsoft account.
- For ransomware, keep a copy of the ransom note and a few encrypted files. They identify the family if a free decryptor appears later; see free ransomware decryptors.
- Disconnect USB drives and backup disks you do not need, so they are not touched by the reset or reinfected afterwards.
If you have a recent backup made before the infection, it is the best source for restoring files. If you are unsure, follow the 3-2-1 backup rule next time, and see Back up your files (Windows Backup, File History, Time Machine) On uGetFix for making a copy now.
What a reset does not fix
A reset cleans one Windows installation on one drive. Several things are outside its reach, and each can undo the work if ignored.
- Stolen data and accounts. Passwords, cookies and wallet data that were sent out stay with the attacker. Secure the accounts from a clean device: securing your accounts after malware.
- Browser sync. If you sign in to Chrome or Edge on the fresh system, sync can bring back extensions, including a malicious one. Review extensions in the browser's sync settings or on another device, and remove bad ones before syncing.
- Cloud files and backups. Files in OneDrive or another cloud service come back as they are. A malicious file in a synced folder, or a backup made while the PC was infected, can reinfect the clean system. Scan restored files before opening them.
- Other drives and devices. USB sticks, external disks, other PCs on the network and phones are not touched. Scan other Windows PCs and do not run programs copied from the old system.
- Your router. If the router's admin or Wi-Fi password was saved on the PC, or its DNS settings were changed, fix them on the router and update its firmware.
- Firmware. Rare bootkits live in the PC's firmware or boot process, which a reset does not rewrite. Keep Secure Boot on and the firmware updated; if a bootkit is suspected after a reset, ask the PC maker or a professional for help.
- The original mistake. If you reinstall the same crack, fake installer or browser extension, the infection returns.
After the reset
- Run Windows Update until no more updates are offered, and check that Microsoft Defender is on.
- Install programs only from their official sites or the Microsoft Store.
- Restore files from your backup or from the copies you made, and scan them with Microsoft Defender before opening them.
- Turn on Potentially unwanted app blocking in Windows Security > App & browser control > Reputation-based protection.
- Consider using a standard user account for daily work.
- Finish any account steps you have not done yet, and turn on two-step verification: Turn on two-step verification / secure a hacked account.
If the reset fails or Windows will not start, a clean installation from installation media, created with Microsoft's media creation tool on another PC, does the same job more thoroughly. If you lost money or data to the attack, report it: where to report cybercrime.
Common myths
System Restore removes malware
System Restore rolls back system files, drivers and some settings, but it is not designed to remove malware and does not touch personal folders where malware often lives. Use it to undo a bad change, not to clean an infection. See Undo recent changes with System Restore On uGetFix.
Formatting is always necessary
For adware, hijackers and most unwanted programs, a reset is unnecessary. Cleaning these is reliable because they live in a known program, extension or setting.
A reset makes the stolen passwords useless
The reset happens on your PC; the passwords are on the attacker's server. Only changing them and ending sessions protects the accounts.
Keep my files is just as safe as Remove everything
It is close for simple infections, but malware often hides in the user profile, which Keep my files preserves. After a serious infection, choose Remove everything and restore files from a backup or scanned copies.
Frequently asked questions
Does resetting Windows remove all viruses?
A reset with Remove everything removes all installed programs, user accounts and personal files from the Windows drive, so it removes virtually all malware that lives in Windows. The exceptions are rare firmware-level bootkits, malware on other drives, USB sticks or other PCs, and files that come back from cloud sync or a backup made while the PC was infected. Choosing Cloud download also avoids rebuilding Windows from local files. A reset does not affect data that was already stolen, so passwords and sessions still have to be changed and ended from a clean device.
Should I choose Keep my files or Remove everything?
After adware, a hijacker or a single trojan caught early, Keep my files is usually fine, because apps and settings are removed either way. After a remote access trojan, a loader, a rootkit or anything that disabled your security, choose Remove everything, because malware often hides in user folders such as AppData, which Keep my files preserves. Before you choose Remove everything, copy documents and photos to an external drive or the cloud, never programs or installers, and scan the copies before opening them on the clean system.
What is the difference between Cloud download and Local reinstall?
Cloud download downloads a fresh copy of Windows from Microsoft and installs it, which also brings recent updates. Local reinstall rebuilds Windows from files already on the PC, which is faster on a slow connection but may be older and depends on local files being intact. After malware, prefer Cloud download, because it does not rely on files that the malware might have damaged or changed. Both options are offered in Settings > System > Recovery > Reset PC on Windows 11 and in the recovery environment if Windows does not start.
Will a factory reset remove a remote access trojan?
A reset with Remove everything removes the trojan and any remote tools or accounts the attacker added, so it ends their access to that PC. It does not end their access to your online accounts if they copied passwords or session cookies while connected. So before or straight after the reset, change your e-mail and banking passwords from another device, sign out of all sessions, and check recovery options and forwarding rules. Also check other PCs on the same network and the router settings, because an attacker with control of one PC may have looked at others.
Is it safe to restore my files after a reset?
Documents, photos, music and videos are generally safe to restore, especially from a backup made before the infection. Scan them with Microsoft Defender before opening them on the clean system. Do not restore programs, installers, scripts, shortcuts or archives from the infected PC, and be careful with Office files that ask you to enable macros. Files in OneDrive come back automatically when you sign in, so check the OneDrive folder too. If ransomware encrypted the files, restoring the encrypted versions does not help; see the ransomware recovery steps instead.
How long does it take to reset Windows 11?
There is no fixed time. It depends on the speed of the drive and the processor, the internet connection when you choose Cloud download, which has to fetch a full copy of Windows, and the options you pick: the clean data option wipes the whole drive and is by far the slowest. The PC restarts several times during the process. Afterwards, Windows Update, reinstalling programs and restoring files add more time. Start when you will not need the PC for the rest of the day, keep a laptop plugged in, and do not turn the PC off while the reset is running.
Sources
- Microsoft Support: Reset your PC (read 4 October 2026)
- Microsoft Support: Fix issues by reinstalling the current version of Windows (read 4 October 2026)
- Microsoft Support: Virus and threat protection in the Windows Security app (read 4 October 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read 4 October 2026)
- Microsoft Support: Find your BitLocker recovery key (read 4 October 2026)
- Microsoft: Download Windows 11 (installation media) (read 4 October 2026)
Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.