Quick Answer: How to Remove Malware From Android
To remove malware from an Android phone, work through the safe-mode → uninstall → scan → reset ladder. Boot into safe mode to disable all third-party apps; if symptoms stop, the cause is a third-party app. Uninstall any apps you do not recognize, starting with the most recent installs. Run Google Play Protect scan. Run a third-party scanner (Malwarebytes, Bitdefender) for deeper cleanup. If the issue persists, back up your files (not apps) and do a factory reset. After cleanup, keep Google Play Protect enabled, avoid sideloading apps, and keep Android updated.
Warning Signs Your Android Has Malware
Several indicators, alone or together, point to malware:
- Battery drain far faster than normal — malware running in the background eats battery.
- Data usage spike even when you are not using the phone — malware phoning home.
- Unfamiliar apps appear in your app drawer or home screen.
- Phone runs hot when idle — same root cause as battery drain.
- Pop-up ads appear outside the browser, even on the home screen.
- Homepage or search engine changes without your action — typical of browser hijackers.
- Unexplained SMS or calls in your logs — premium-SMS dialers and toll-fraud malware.
- Unexplained purchases or password-reset emails you did not request — strong indicator of compromise.
The 8-Step Android Malware Removal
Step 1: Boot Into Safe Mode
Safe mode boots Android with only the system apps loaded — no third-party apps run. This is the most reliable way to confirm that malware is third-party app-caused.
To enter safe mode:
- Press and hold the power button until the power menu appears.
- Long-press Power off on the menu.
- Tap OK when the "Reboot to safe mode" prompt appears.
- The phone restarts with a "Safe mode" watermark in the corner.
Steps vary slightly by manufacturer (Samsung, Pixel, Xiaomi). Search "safe mode + [your model]" if the standard steps do not work.
Step 2: Identify Suspect Apps
While in safe mode, open Settings → Apps and sort by Install Date. Look for any apps installed recently that you do not recognize. Common offenders include:
- Fake cleaner or booster apps ("Phone Cleaner Pro", "Super Booster")
- Battery-saver or RAM-booster apps (usually scams)
- QR-code scanners from unknown developers
- "Adult" content apps
- Free VPN apps from unknown developers
- Custom keyboards that request permission to read keystrokes
Step 3: Uninstall Suspect Apps
Tap the suspect app → Uninstall → OK. If the Uninstall button is greyed out, the app has been granted Device Administrator permission. To remove Device Admin status: Settings → Security → Device Admin Apps → uncheck the suspect app → Deactivate. Then return to Apps and uninstall normally.
Step 4: Restart Out of Safe Mode
Restart normally. Test the symptom you were worried about. If it returns, you have not yet removed the responsible app. Return to safe mode and look for apps you missed.
Step 5: Run Google Play Protect
Settings → Security → Google Play Protect → Scan. Play Protect scans installed apps and any sideloaded apps for known-bad signatures. Enable "Scan apps with Play Protect" and "Improve harmful app detection" for full coverage.
Step 6: Run a Third-Party Scanner
Install Malwarebytes for Android, Bitdefender Mobile Security, or ESET Mobile Security. Run a full scan. These scanners catch malware that Play Protect sometimes misses, including aggressive adware, SMS-fraud apps, and accessibility-abusing trojans.
Step 7: Audit Accessibility and Permission Settings
Settings → Accessibility → Downloaded Services — review any apps with accessibility access. Accessibility is the highest-risk permission on Android: malicious apps use it to read screens, automate actions, and overlay fake login screens. Revoke any accessibility permission you did not explicitly grant.
Then review each app's permissions: Settings → Apps → [app] → Permissions. Revoke any permission that does not match the app's purpose (e.g., a flashlight app does not need location or contacts access).



