MalwareWindows reinstall

Does Reinstalling Windows Remove Malware?

5 min read

The conclusion first, so you are not reading for ten minutes to get it: reinstalling works against the vast majority of ordinary viruses and adware. Format the system drive, install Windows again, and whatever was hiding in there goes with it. The advice online that says reinstalling is useless mostly takes rare cases and presents them as the norm. That said, I have seen machines reinfected shortly after a reinstall, and the reason was almost never the machine itself. These six situations are the ones a reinstall does not solve.

1. You restored an old backup

This is the one I see most, and it is entirely reasonable behaviour: you finish the reinstall, and of course you want your files back. The problem is that the backup was taken after the infection started, or it is a cloud folder that syncs continuously, so the malware rides back in with the data. A whole day of work, and you are where you started.

The safer approach is to restore documents and photos only. Leave programs, installers and whole user profiles behind. Scan what you restored before you start using the machine again. If there is an executable in the backup and you cannot remember what it was for, do not bring it back.

2. The account was already taken over, and the PC was just one way in

A reinstall deals with this machine. It does nothing about anything in the cloud. If somebody has your email password, they can still read your mail after the reinstall. If they set up an auto-forward rule in your mailbox, that rule survives untouched. The same goes for social accounts, your company's collaboration tools, and any sharing links on your cloud drive. None of that is within reach of a format.

3. The way in is still open

If a colleague got hit because they clicked a phishing email, they will receive the next one after the reinstall too. If a machine had remote desktop exposed with a weak password, that service is still exposed afterwards. Reinstalling clears the result and leaves the cause exactly as it was.

That is why "how did it get in" matters more than "what was it". Answer the first and you know what to change. Answer the second thoroughly and all you have learned is which tool the other side happened to use.

4. Someone changed the router settings

There is a class of attack that leaves your computer alone and changes the network kit in your home or office instead, pointing the server that looks up web addresses at the attacker. The result is that you finish the reinstall, open a browser, type the correct address, and still land on a fake site. The problem was never on the computer.

Testing for it is easy: put a device you know is fine on the same network and see whether it behaves the same way. If it does, the thing to fix is the network equipment, not the PC. Change the admin password on that equipment while you are in there. A great many units are still on the factory default.

5. USB sticks, shared drives and the NAS

Offices run into this constantly. One machine gets infected, the malware writes itself to a shared drive, and everyone who opens a file from there picks it up. You reinstall your own machine, a colleague opens that shared folder the next morning, and you have it again. USB sticks behave the same way: plug the same stick back in after the reinstall and you have restarted the whole cycle.

So when one machine in a company is hit, the question to ask is which other machines have touched the same shared folder, rather than treating only the one in front of you.

6. Firmware, though this one really is rare

Some malware writes itself into the boot firmware on the motherboard. That sits below the operating system, so formatting the drive never touches it. In that case a reinstall genuinely does not help.

7. The one thing a reinstall does destroy: evidence

Everything above is about whether a reinstall works. This section is about what it costs. Once the drive is formatted, execution history, scheduled tasks, connection records and account creation times all disappear, and three questions become permanently unanswerable: how long they were in, which files they touched, and whether anything was sent out.

On a personal machine none of that matters. Reinstall whenever you like. But if the machine holds personal data belonging to customers or staff, you may have a duty to report the incident, and a report has to state what happened and how many people it affected. Reinstalling first and investigating afterwards means deleting your own answers. Where personal data is involved, find out what your local rules require before you format anything.

Your situationIs a reinstall enoughWhat else to do
Home PC, nothing important on itYesChange passwords, and do not restore an old backup wholesale
Home PC, but with online banking and work accountsYes, but not on its ownChange passwords from another device, check mailbox forwarding rules
Work PC, no customer personal dataYesFind the way in at the same time, or a colleague is next
Work PC holding customer or staff personal dataDo not reinstall yetPreserve the machine as it is, establish the scope and any duty to report
Cleaned once and the symptoms came backNoThe problem is not this machine. Check shared drives and network kit

8. Before you decide, find out how it got in

All of the above in one line: reinstalling is an effective way to clear a machine, but it is the end of the process rather than the start. Establish where the way in was, whether any accounts fell with it, and which other machines touched the same shared folder. Do that first and the half day you spend formatting is not wasted.

Four things to finish before you start the reinstall

  • Change passwords from a different device, email first, and check whether auto-forwarding has been set up.
  • Establish the way in. A clicked email, software from an unknown source, or a service exposed to the internet with a weak password.
  • List who else touched the same shared folder or USB stick. In an office it is almost never only one machine.
  • If personal data is involved, preserve the machine as it is. Do not format. Establish what you are required to report first.

Whether a reinstall works depends on which question you are asking. To clear what is on this machine, it works and it is decisive. To make sure this does not happen again, it does nothing, because the way in, the accounts and the shared drives all sit outside its reach. The time worth spending is the half hour before you start: how it got in, and what else this touches.

Common questions

Should I replace the drive as well as reinstalling?
No. Fully formatting the system drive and reinstalling is enough, and ordinary malware cannot survive a format. The reason to replace a drive is bad sectors or poor health readings on the drive itself, which is a hardware matter and has nothing to do with the infection.
What should I do first after the reinstall?
Finish the system updates before signing in to the accounts you use daily, so there is no window where a freshly installed and unpatched machine is online. Restore data after that, and only data: documents and photos, not programs and installers. Then confirm antivirus is actually turned on.
How do I know whether I have been reinfected?
Watch for the same symptom returning: the home page changed again, antivirus switched off again, or the program you removed reappearing. Recurrence almost always means the way in was never closed, and reinstalling a second time gives you the same result. What needs checking then is shared drives, network equipment and accounts.

Read next