How to remove malware from an Android phone without a factory reset
An Android phone that suddenly shows intrusive ads, drains its battery quickly, overheats, or opens unfamiliar websites may have a malicious app or unwanted software. These symptoms can also result from a faulty update, a crowded storage drive, or an aging battery, so avoid deleting important files before checking the cause.
Most Android malware can be removed without erasing the entire device. The safest approach is to identify recently installed apps, block suspicious permissions, scan the phone, and update the operating system. A factory reset should remain a last resort, especially when the problem comes from one unwanted application.
Before making changes, save essential photos, contacts, and documents to a trusted cloud service or computer. Do not back up unknown APK files or suspicious apps, because restoring them could bring the problem back.
Check the symptoms and recent changes
Start by reviewing what changed shortly before the phone began behaving strangely. Think about newly installed apps, APK files downloaded outside Google Play, browser notifications, game mods, or links opened from messages and social media. Malware often arrives disguised as a cleaner, keyboard, wallpaper tool, video player, or unofficial game.
Open Settings and check battery usage, mobile data usage, and storage activity. An unfamiliar app using an unusually large amount of battery or data deserves attention. Persistent pop-ups on the home screen, even when no browser is open, are another strong sign of adware.
Do not tap suspicious pop-ups claiming that your phone has dozens of viruses. These warnings are often designed to make users install another harmful app or submit payment details. Close the page, then use Android’s built-in security features instead.
Remove suspicious apps in safe mode
Try uninstalling the questionable app through Settings > Apps. Sort the list by recently installed or recently used applications, then inspect anything you do not recognize. Remove apps that appeared around the time the symptoms started, especially those installed from unknown sources.
If an app blocks removal, keeps reopening, or covers the screen with advertisements, restart the phone in Safe Mode. The exact method differs by manufacturer, but many Android devices display the power menu when the power button is held; touching and holding “Power off” may then reveal the Safe Mode option. Search your manufacturer’s support page if that option does not appear.
Safe Mode loads Android with most third-party apps disabled. If the phone works normally there, a downloaded application is probably responsible. Uninstall recently added apps one at a time, restarting normally after each removal. Avoid deleting system apps unless you are certain they are unwanted, as this can cause other functions to fail.
Revoke dangerous permissions
Some harmful apps remain active because they receive powerful permissions. In Settings, review Special app access and inspect Device admin apps, Accessibility, Display over other apps, Install unknown apps, and Notification access. An unfamiliar app enabled in one of these areas should be treated carefully.
Disable its special access before uninstalling it. Accessibility access is especially sensitive because it can allow an app to read screen content, press buttons, and control other applications. Device administrator access may also prevent removal until it has been revoked.
Review ordinary permissions as well, including SMS, contacts, microphone, camera, location, and files. A flashlight or wallpaper app should not need access to text messages or accessibility controls. After cleanup, set permissions to “Ask every time” or “Don’t allow” when the app does not require them.
Scan the phone and clean the browser
Open the Google Play Store, tap your profile image, select Play Protect, and run a scan. Keep Play Protect enabled so installed applications are checked for known threats. Also update Android and Google Play system components, since security patches can close weaknesses used by malicious software.
A reputable mobile security app from a well-known provider can provide a second opinion, but install only one scanner at a time. Download it from Google Play, avoid “premium cracked” security tools, and uninstall the scanner afterward if you do not need its ongoing features.
If the problem appears only while browsing, clear the browser’s site data and notification permissions. In Chrome, review Settings > Site settings > Notifications and remove unfamiliar websites. Clear cached files and browsing data, then check the default search engine and home page for unauthorized changes.
For safe app choices after cleanup, review productivity app picks and install tools from trustworthy publishers. The same caution applies to games: unofficial modified versions and cheat tools can conceal spyware, especially when downloaded from random websites. Kepotek’s games coverage can help you find more reliable gaming information.
Compare cleanup methods before acting
Different symptoms call for different responses. Begin with the least disruptive method and escalate only when the evidence points to a deeper problem. Removing an app is usually safer than clearing all device data, while changing passwords is essential if you suspect account access.
| Cleanup method |
Best use case |
Data risk |
Key caution |
| Uninstall a suspicious app |
Problems began after a recent installation |
Low |
Revoke special access first |
| Safe Mode removal |
App blocks normal operation |
Low |
Device steps vary by brand |
| Play Protect scan |
Known malicious or unwanted apps |
Low |
Keep the service enabled |
| Browser reset |
Redirects, pop-ups, or fake alerts |
Low to medium |
Saved site data may be removed |
| Security app scan |
A second opinion after manual checks |
Low |
Use one reputable scanner |
| Factory reset |
Malware persists after thorough cleanup |
High |
Back up personal files first |
If suspicious activity affected banking, email, social media, or payment applications, change passwords from a different trusted device. Enable two-factor authentication and contact your bank promptly if unauthorized transactions or messages appear.
Prevent another infection
Keep Android, Google Play system updates, and frequently used apps current. Security updates reduce the chance that known vulnerabilities will be exploited. Use a screen lock with a strong PIN or password, and avoid granting broad permissions simply to make an app work.
Turn off installation from unknown sources unless you have a specific, trusted reason to use it. Never install an APK because a pop-up says it is required to watch a video, claim a prize, or remove a virus. Check the developer name, reviews, download count, and requested permissions before installing from Google Play.
Use these habits as a practical maintenance routine:
- Install apps only from Google Play or a verified manufacturer store.
- Review installed apps and permissions once each month.
- Keep Play Protect and automatic security updates enabled.
- Avoid cracked games, unofficial streaming tools, and modified APK files.
- Back up photos and documents regularly, but do not back up suspicious applications.
If malware symptoms continue after removing third-party apps, revoking access, scanning the device, and updating Android, contact the phone manufacturer or a qualified technician. A factory reset may eventually be necessary, but it should follow a verified backup and a password change rather than being the first response.
Clean the device carefully, monitor battery and data usage for several days, and reinstall only essential apps from trusted sources. This method preserves your personal data in most cases while addressing the settings and applications that commonly allow Android malware to survive.