A delivery notification asks you to install a tracking app. A browser warning insists your phone is infected. An unfamiliar app requests permission to read your screen. These situations can look unrelated, but each deserves the same response: stop, verify, and investigate through settings you control—not through instructions supplied by the warning itself.
Android malware can threaten your device, your accounts, and your money. Effective cleanup means addressing all three. Start with built-in protections, investigate suspicious apps, and secure affected accounts separately. A clean scan does not undo stolen credentials or unauthorized transactions.
Safety exception: If you suspect an abusive partner or another person is monitoring your phone, do not immediately uninstall apps or reset it. Changes could alert that person. Use a device they cannot monitor to seek help and plan your next steps. The FTC’s stalkerware guidance explains safety planning and evidence preservation.
What Is Android Malware?
Android malware is harmful software or code that compromises a device, personal information, or accounts. “Virus” is often used as a catchall, but Android threats include several different categories. Google’s harmful-app classifications include:
- Credential theft and phishing: Apps that capture passwords, banking credentials, or payment information.
- Spyware and stalkerware: Software that collects private information or monitors activity without appropriate consent.
- Billing fraud: Hidden or deceptive activity that generates unwanted charges.
- Trojans and hostile downloaders: Apparently useful apps that perform harmful actions or install additional threats.
- Ransomware and backdoors: Software that restricts access or enables unwanted remote control.
These categories overlap. One malicious app may steal credentials, monitor messages, and download additional software.
How Harmful Apps Get Installed
Attackers often disguise installation requests as ordinary tasks: tracking a parcel, listening to voicemail, claiming a refund, or updating an essential service. Instead of using an unexpected message’s link, find the organization’s app independently through its official website or a trusted app store.
Be especially cautious when an installation requires disabling protection or granting powerful access. Accessibility permissions, for example, support legitimate assistive tools but may also allow an app to read screen content and interact with other apps.
Android’s restricted-settings guidance advises against allowing restricted settings unless you trust the developer. A request to bypass a security warning is a reason to investigate—not a routine setup step.
Warning Signs: What Deserves Investigation?
Persistent pop-ups, unexpected storage loss, poor performance, messages sent without your knowledge, unusual data use, and unexplained battery drain can warrant investigation. However, symptoms alone do not establish infection. An aging battery, a demanding app, or a software problem can produce similar behavior.
Separate three situations:
- An app-security warning: Open Play Protect directly rather than following an advertisement’s link.
- A browser alert: Check website notification permissions. A site displaying “Your Android is infected” has not demonstrated that it scanned your phone.
- An account alert or unauthorized payment: Investigate the account and contact its provider, even if a device scan finds nothing.
For example, notifications that started after you tapped “Allow” on a website may be unwanted browser permissions—not evidence of an installed malicious app.
How to Check and Remove Android Malware
Menu names vary by manufacturer and Android version. Use Settings search or your manufacturer’s instructions when the paths below differ. Consider the stalkerware safety exception before making changes.
1. Run Google Play Protect
On phones with the Google Play Store, open Play Store → profile picture → Play Protect, then select Scan where displayed. In Play Protect settings, keep Scan apps with Play Protect enabled.
Google explains that Play Protect checks apps from Google Play and other sources and may warn about, disable, or remove harmful apps. The optional Improve harmful app detection setting allows unknown apps to be sent to Google for analysis—a protection benefit with a data-sharing tradeoff.
2. Install Available Updates
Check Android software updates, security updates, and Google Play system updates. Typical locations include Settings → System → Software updates and Settings → Security & privacy → System & updates.
Update availability depends on the model, manufacturer, and carrier. If your phone no longer receives security updates, plan to replace it. Scanning software cannot compensate for every unpatched vulnerability. Google’s Android update guidance explains how to check your version and update status.
3. Review Apps and Sensitive Permissions
Open Settings → Apps and inspect the complete app list. Focus on apps you do not trust, no longer need, or installed shortly before the problem began. Open each questionable app’s information page, review its permissions, and uninstall it if you cannot establish that it is trustworthy.
Review camera, microphone, location, contacts, and SMS access, along with accessibility access and other special permissions. A flashlight app requesting SMS access, for example, deserves scrutiny because the access does not obviously match its purpose.
Follow Google’s permission-review instructions, but do not remove unfamiliar system components solely because their names look technical. Verify them with your manufacturer or IT administrator.
4. Troubleshoot Apps That Will Not Uninstall
An app with device-administrator privileges may resist removal. On Samsung devices, search Settings for Device admin apps; suspicious administrator access may need deactivation before uninstalling. Samsung’s guidance also cautions that employer-managed devices can have legitimate restrictions. Contact IT before disabling management software.
Safe mode can help when a troublesome app interferes with normal operation. It disables third-party apps temporarily, making investigation easier. Follow your manufacturer’s procedure; Samsung provides instructions in its Galaxy malware guidance. Safe mode is a troubleshooting tool, not proof that every threat is gone.
5. Remove Unwanted Browser Notifications
In Chrome, open Settings → Site settings → Notifications and revoke access for untrusted sites. Keep Pop-ups and redirects blocked. Chrome may also offer an Unsubscribe option directly on a notification.
Use Chrome’s notification controls rather than installing a “cleaner” advertised by the alert. Browser cleanup and app removal solve different problems.
6. Secure Accounts Separately
While the phone remains suspect, use another trusted device for sensitive account recovery. For your Google Account and other affected services:
- Review security activity and signed-in devices; sign out unfamiliar sessions.
- Check recovery details and third-party access.
- Change compromised or reused passwords and enable two-step verification.
- Inspect email forwarding rules and filters you did not create.
- Contact your bank promptly about unauthorized transactions or exposed financial information.
Google’s compromised-account guidance provides detailed recovery checks. Removing an app does not invalidate credentials an attacker already obtained.
7. Reset Only After Preparing
If problems persist, Google recommends considering a factory reset or manufacturer assistance. First preserve important files and necessary evidence, confirm your Google Account credentials and screen-lock information, and arrange access to essential accounts.
A reset erases local data and installed apps. Google’s reset instructions advise waiting 24 hours if you recently reset your Google Account password.
Reinstall needed apps individually from trusted sources. For suspected stalkerware, the FTC warns that restoring apps from the old backup could reinstall monitoring software. If suspicious behavior returns after a fresh setup, seek qualified help rather than repeatedly resetting.
Prevent Reinfection Without Adding Unnecessary Complexity
Keep Play Protect enabled, install updates, and limit which apps can install software from unknown sources. Supported Samsung devices also offer Auto Blocker to restrict unauthorized installations.
Installing outside an app store is not automatically malicious, but it transfers more verification responsibility to you. Conversely, an app-store listing is not a guarantee of safety. Check the developer, purpose, and requested permissions.
Start with built-in protections before adding security apps. Samsung specifically discourages third-party anti-malware products in its Galaxy guidance; that is manufacturer-specific advice, not a universal rule. Evaluate any additional product’s permissions, privacy practices, cost, and concrete benefit.
Your Android Malware Checklist
Use this checklist only after considering personal-safety risks:
- Run Play Protect and keep scanning enabled.
- Install Android, security, and Google Play system updates.
- Investigate suspicious apps and sensitive permissions.
- Check administrator access; involve IT for managed devices.
- Revoke unwanted browser notification permissions.
- Secure affected accounts from a trusted device.
- Investigate unauthorized payments with the relevant provider.
- Preserve files and evidence before resetting.
- Reinstall trusted apps carefully; seek help if problems persist.
Take Control, Not the Bait
The strongest response to Android malware is a sequence of verified actions—not a panic-driven download. Check device protections, remove untrusted software, and address account exposure independently.
Start today: open Play Protect, check for updates, and review apps with sensitive access. If the evidence points to financial theft, persistent compromise, or personal danger, escalate to the appropriate provider, manufacturer, or safety advocate.