If viruses are not being deleted even after you format your computer, what could be the reason?
A clean install removes most malware, but bootkits, firmware attacks, infected backups, and USB drives can bring the problem back.
12punto
When a computer is infected with malware, one of the first solutions that comes to mind is formatting. Reinstalling the operating system can clean up many malicious programs, especially those that reside in Windows files. However, formatting is not a definitive solution that automatically eliminates every security issue.
During a clean install, when the disk partition containing the system is deleted and Windows is reinstalled, the majority of threats such as ransomware, trojans, adware, and similar threats are removed from the system. However, "resetting" a computer is not the same as performing a clean install using an official installation file from a USB drive. While the Windows reset option sometimes relies on existing recovery files, a clean install recreates the system partition more comprehensively.
For this reason, the installation source is also of critical importance. Windows should only be installed using Microsoft's official ISO file, and modified or untrusted installation packages should be avoided. Otherwise, the system may encounter a new risk during the very first installation phase.
IN WHICH CASES IS FORMATTING NOT ENOUGH?
Some malware does not only target operating system files. Threats known as bootkits can reside in boot components that run before the operating system starts. Simply reinstalling Windows may not solve the problem in some scenarios if the boot structure is not completely renewed. Although security features such as UEFI, Secure Boot, and TPM 2.0 in modern Windows 11 systems provide additional protection against such attacks, the risk may be higher in older systems.
Rarer firmware-based attacks can also fall outside the scope of a standard format. In such attacks targeting the motherboard's UEFI software or certain hardware components, it may be necessary to apply the BIOS or UEFI update released by the manufacturer. Since these operations require caution, only the manufacturer's official instructions should be followed.
One of the most common reasons for a virus to reappear after a format is the restoration of old files without checking them. When an infected USB drive, external disk, network storage area, or cloud backup is reconnected to the newly installed system, the same malware can run again. Compressed files, installation packages, and downloaded software also pose a risk when opened without being scanned.
In particular, files such as pirated software, cracks, and keygens can quickly render the clean start provided by the format useless. Installing an outdated version of Windows, connecting to the internet before security patches are completed, or disabling antivirus protection can also lead to the system becoming re-infected.
For a secure formatting process, the first step after installation should be to install all security updates via Windows Update. Microsoft Defender's real-time protection should be left on, or a reliable antivirus solution should be used. Hardware drivers should be downloaded from the official pages of the device or component manufacturer instead of third-party sites.
Old backups should be scanned with up-to-date security software before being restored; USB drives and external disks should be checked before being connected to the system. Files synchronized in cloud storage services should also be examined with the same care. This is because the return of an infected file from a backup is one of the most common causes of problems that start again after a format.
In conclusion, formatting is a powerful cleaning step against malware, but it does not provide permanent security on its own. When an up-to-date operating system, official installation files, reliable software, regular backup scanning, and conscious usage habits are combined, the likelihood of the computer becoming re-infected is significantly reduced.