Contents
To remove malware from Android, disconnect from the internet, find the app, revoke its device-admin and accessibility access, uninstall it in safe mode if it resists, then scan with Play Protect and a second antivirus. Change passwords and enable two-factor authentication. Reset only if symptoms continue.
By Abdul Emam, APK tester at ApkZena. I removed four malicious samples from test devices in 2026. Two left with a simple uninstall after revoking access. One required safe mode. One needed an ADB uninstall. None needed a factory reset, because I acted within an hour.
You think your phone is infected and you want a clear order of steps. Good. Panic leads to a reset you may not need. I promise a calm sequence with real tools. You will learn the symptoms, seven removal steps, whether malware survives a reset, and how to prevent the next infection.
How to Tell If Your Android Has Malware
Malware shows as behavior more often than as an obvious app. Watch for battery drain, spikes in background data, pop-up ads outside the browser, unfamiliar apps, overlays on banking apps, messages you did not send, heat, and general slowness. Several together point to malware.
Two or three symptoms together justify a cleanup, and one alone can have a benign cause like a failing battery. The malware signs guide separates the before-install red flags from the after-install symptoms and tells you which combinations matter most.
Step 1: Disconnect from the Internet
Disconnect before you do anything else. Turning on airplane mode or turning off Wi-Fi and mobile data stops uploads, remote commands, and SMS fraud while you work. The app is still on the device, but it cannot reach its server.
Why It Matters
Many malware families take commands from a remote server. Cutting the network stops new instructions and blocks data exfiltration. It also stops premium SMS and click fraud, which cost money while you clean up. Reconnect after the device is clean.
Wi-Fi and Mobile Data
Turn on airplane mode to cut both at once, then turn Wi-Fi back on only if you need it for a tool. If you must use Wi-Fi for the scans, keep mobile data off. Re-enable everything after the full removal.
Step 2: Identify the Malicious App
Find the app before you remove it. You need its name and package so you know what to uninstall and what to watch for. Five places reveal it.
Check Recent Installs
Open Settings, Apps, and sort by install date. Malware usually appears near the top, because you installed it recently and did not notice. Look for apps you do not recognize or installed around the time symptoms started.
Check Battery Usage
Open Settings, Battery, Battery usage, and look for an app using far more than its share. A background drain with no matching use is a signal. My miner sample sat at the top of the list every day.
Check Data Usage
Open Settings, Network, Data usage, and sort by usage. Malware uploads data or loads ads, so it often appears high. A wallpaper app near the top of the data list is a mismatch worth investigating.
Check Device Admin Apps
Open Settings, Security, Device admin apps. Any app listed there can lock and wipe the device. Remove the ones you did not deliberately enable. Malware uses device admin to resist uninstall.
Check Accessibility Apps
Open Settings, Accessibility, Downloaded apps. An app bound to accessibility can read your screen. Remove any app you did not enable on purpose. Accessibility is the most dangerous grant malware holds.
Step 3: Uninstall the App
With the app identified, remove it. Start with the normal path and escalate only if it resists.
Normal Uninstall
Open Settings, Apps, tap the app, and tap Uninstall. On most devices this works once you revoked device-admin access. Confirm the app icon is gone from the launcher afterward.
Safe Mode Uninstall
If the app fights the uninstall, reboot into safe mode. Press and hold the power button, then tap and hold Power off until the safe-mode prompt appears. Third-party apps are disabled in safe mode, so you can uninstall without interference. The Google safe-mode help covers the button path by device.
ADB Uninstall
For an app that still resists, connect to a PC with ADB and run adb shell pm uninstall --user 0 com.example.app. That removes the app for your user even when the normal uninstall is blocked. The ADB reference lists the commands and the ADB install guide covers setup.
If the App Will Not Uninstall
Work the access points in order: revoke device admin, revoke accessibility, remove notification access, then retry. If it still will not leave, safe mode and ADB are the reliable paths. A stubborn app is a strong sign it is malicious.
Step 4: Revoke Permissions
Even after uninstall, revoke any lingering access and check for reappearing grants. Malware persists through four channels.
Device Admin
Remove device-admin access under Settings, Security, Device admin apps. An app with admin can lock or wipe the device and can block its own uninstall. This is the first grant to revoke.
Accessibility Service
Turn off accessibility for the app under Settings, Accessibility. An accessibility binding can read the screen, tap through apps, and re-grant itself permissions. Revoke it before and after uninstall.
Notification Access
Check Settings, Notifications, Device and app notifications, or Special access. Notification access lets an app read your notifications, including one-time codes. Revoke it for anything suspicious.
Install Unknown Apps
Check Settings, Apps, Special access, Install unknown apps. Malware that holds this can drop a second payload after you remove the first. Revoke it for every app except a file manager or browser you trust.
Step 5: Run an Antivirus Scan
Now that the device is clean of the known app, scan for anything it left behind. Use two engines, because one can miss what another catches.
Play Protect
Open Play Store, tap your profile, tap Play Protect, and run a scan. Play Protect is built in and free, and it removes some known threats automatically. Keep scanning enabled afterward.
Malwarebytes
Malwarebytes catches adware, PUPs, and repacks well. Install it from Play, run a full scan, and remove anything it flags. It is a strong second opinion for the adware families that often ride with clones.
Bitdefender
Bitdefender has a free Android tier with accurate detection. It is a good alternative second engine if Malwarebytes finds nothing but symptoms persist. Run it, remove flagged items, then re-scan.
Norton
Norton 360 bundles antivirus with other tools and has high detection rates at a subscription price. It suits users who want one app for several security jobs. Use any one second engine and re-scan until clean.
Step 6: Change Passwords
Assume anything you typed into the infected device is exposed, especially if accessibility was granted. Change passwords from a different device when you can.
Google Account
Change your Google password, then review recent security activity and sign out sessions you do not recognize. Enable two-factor authentication if it is not already on. Google’s account security page lists active sessions.
Banking Apps
Change banking passwords and app passcodes, and call your bank if you see unfamiliar transactions. If the malware held accessibility or overlay access, treat the credentials as compromised and act quickly.
Social Media
Change passwords for social accounts, and check for unfamiliar logins or posts. Enable two-factor authentication on each account. Recovering a hijacked social account takes far longer than changing the password.
Enable 2FA
Turn on two-factor authentication everywhere it is offered. It is the single best defense after a compromise, because a stolen password alone no longer grants access. Use an authenticator app over SMS where you can.
Step 7: Factory Reset If Needed
A factory reset is the fallback, not the first move. Use it when the app resists removal, when symptoms continue after cleanup, or when the device behaved abnormally for long enough that you cannot trust it.
When to Reset
Reset if malware reappears after uninstall, if new unknown apps keep appearing, or if ads and drain continue after a clean scan. A reset removes user-space malware in nearly every case, so it ends the uncertainty.
How to Backup First
Back up photos, messages, and documents to a service you trust, and export app data for anything you need. Do not back up the malicious app or a full system image, because that can carry the problem forward. Check the backup for unknown apps before you restore.
How to Reset
Open Settings, System, Reset options, Erase all data (factory reset). The path varies slightly by brand. After the reset, sign in and restore only your personal files, not a full app backup.
Post-Reset Checks
After the reset, update Android and Play services, enable Play Protect, and install apps only from trusted sources. If symptoms return on a clean install, the issue may be system-level, and a firmware reinstall is the next step.
Can Malware Survive a Factory Reset?
User-space malware does not survive a factory reset, because the reset wipes the data and app partitions. The rare exceptions involve the system partition or a modified boot image.
Rare Cases
Preinstalled malware in the system partition can survive a reset on some low-cost devices. A rooted device with a modified boot image can also keep a payload. These are uncommon, and they show symptoms on a clean install.
System-Level Malware
If symptoms continue after a reset, reinstall the stock firmware from the manufacturer using the official tool. That replaces the system partition. After that, avoid rooting and sideloading from untrusted sources to keep the device clean.
How to Prevent Future Infections
Prevention comes down to four habits: trusted sources, scanning before install, Play Protect enabled, and avoiding mods. Keep your Android and Play services updated, and review your installed apps periodically. The safety pillar covers the full prevention checklist.
Next, run steps 1 through 5 on the device now, change your passwords from another device, and then scan every remaining app’s permissions for anything that does not fit.
Key Takeaways
- Disconnect first, then revoke access, then uninstall.
- Device-admin and accessibility grants are how malware persists.
- Verify with two scanners, then change passwords and enable 2FA.
- A factory reset clears user-space malware when removal fails.
Frequently Asked Questions
How do I remove malware from Android?
Disconnect from the internet, find the app under recent installs and battery usage, revoke device-admin and accessibility access, uninstall it in safe mode if needed, then scan with Play Protect and a second antivirus. Change passwords and enable 2FA.
Can I remove malware without a factory reset?
Yes in most cases. A factory reset is the fallback when removal fails or symptoms continue. Most user-installed malware leaves with the offending app once you revoke its admin and accessibility access and uninstall it. Reset only when the app resists or the device stays abnormal.
Does a factory reset remove all malware?
A factory reset removes user-installed malware in nearly every case, because it wipes the data and app partitions. Rare system-level threats that persist across resets can exist on rooted or compromised devices, and a full firmware reinstall covers those cases.
Can malware survive a factory reset?
User-space malware does not survive a reset. The rare exception is preinstalled malware in the system partition or a rooted device with a modified boot image. If symptoms continue after a reset, reinstall the stock firmware from the manufacturer.
How do I know if my phone has malware?
Watch for battery drain, background data spikes, pop-up ads outside the browser, unfamiliar apps, overlays on banking apps, messages you did not send, heat, and slowness. Several together suggest malware. The malware signs guide lists the full set.
What apps remove malware from Android?
Play Protect is built in and free. Malwarebytes, Bitdefender, and Norton add a second engine. Run Play Protect first, then one second-opinion scan. Multiple scanners can find what a single engine misses, and re-scanning confirms the device is clean.
Can Android malware steal passwords?
Yes. Malware can capture passwords through fake login screens, keylogging via accessibility, or by reading stored data and messages. This is why you change passwords after removal and enable two-factor authentication, especially for banking and email.
How do I remove a malicious app that won't uninstall?
Revoke device-admin and accessibility access first, then try again. If it still resists, reboot into safe mode and uninstall there, or remove it with ADB using pm uninstall --user 0. Safe mode disables third-party apps while leaving the system running.
Is safe mode enough to remove malware?
Safe mode helps you uninstall a resistant app by disabling third-party apps at boot, but it does not remove malware by itself. Use safe mode to reach the uninstall screen, then follow the full removal and scan steps.
How long does Android malware stay?
Malware stays until you remove it or reset the device. Some families persist by reinstalling themselves through device-admin or accessibility access, which is why revoking those grants first is essential. Without removal or a reset, it does not leave on its own.