▣ Tue, Jul 28, 2026 - 11:57:36 AM ⌁ Contact our editorial team and share your feedback.
Daily News
Removing spyware from an Android phone

How to Remove Spyware from Android: A Safe Step-by-Step Guide

Spyware is software that secretly collects information or gives another party access to a device. It may arrive through a malicious APK, abusive monitoring app, compromised account or app that misuses powerful permissions.

Personal-safety warning: if you suspect a partner, family member or another person with physical access installed monitoring software, removing it may alert them. Use a different trusted device to seek help, preserve evidence and plan safely. If you face immediate danger, contact local emergency services.

One symptom does not prove infection. Battery drain can come from a worn battery, heat, poor signal or a legitimate app. Treat the following process as a structured investigation.

Possible Signs of Android Spyware

  • An app, VPN or device administrator you do not recognise.
  • Accessibility access granted to an app that should not control the screen.
  • Microphone, camera, location, SMS or notification access that does not match an app’s purpose.
  • Persistent advertisements outside the app that generated them.
  • Unexplained mobile-data use, battery drain or overheating while the phone is idle.
  • Google Account security alerts, unfamiliar devices or changed recovery information.
  • A security setting that changes back after you disable it.

These are clues, not a diagnosis. Record what you observe before removing anything.

Before Cleanup: Protect Evidence and Accounts

  1. Use a clean device for sensitive communication. Do not change an important password on a phone you believe is actively monitored.
  2. Record suspicious details. Photograph app names, permission screens, device-admin entries, dates and account alerts with another device when safe.
  3. Protect financial accounts. If you see unauthorised banking or wallet activity, contact the provider using its official number or app from a trusted device.
  4. Do not upload private APKs casually. Public malware-analysis services may share submitted samples with security partners. Never upload a confidential company app or a file containing personal data without authorisation.

Step 1: Turn On Google Play Protect and Scan

  1. Open the Google Play Store.
  2. Tap your profile icon.
  3. Tap Play Protect, then the settings icon.
  4. Ensure Scan apps with Play Protect is enabled.
  5. If you install outside Google Play, consider enabling Improve harmful app detection.
  6. Return to Play Protect and start a scan.

Google states that Play Protect checks apps during installation, periodically scans the device and can warn, disable or remove potentially harmful apps. It also covers apps obtained from other sources. See the official Play Protect documentation.

Step 2: Review Recently Installed Apps

Open Settings → Apps → See all apps and sort by recently installed or recently updated when the phone offers that option. Look for:

  • Apps installed just before the problem started.
  • Generic names such as “System Service” that are not actual system components.
  • Duplicate icons or apps with a blank icon.
  • Remote-support, parental-control or employee-monitoring tools you did not knowingly configure.

Do not remove a genuine Android system package based only on an unfamiliar name. Search the exact package and phone model using the manufacturer’s support resources first.

Step 3: Audit High-Risk Permissions

In Settings → Privacy → Permission manager, review Camera, Microphone, Location, Contacts, SMS, Phone and Files. Remove any permission that does not match the app’s purpose.

Then inspect Special app access. The most important areas are:

  • Accessibility: can read screen content and interact with apps. Google warns this access can expose sensitive information.
  • Device admin apps: can make an app harder to remove or enforce device policies.
  • Notification access: can expose message previews and one-time codes.
  • Display over other apps: can place deceptive windows over banking or login screens.
  • VPN: can route network traffic through another service.
  • Usage access: reveals which apps are used and when.
  • Install unknown apps: allows a browser, file manager or messenger to request package installation.

Turn off unexplained access. After a legitimate sideload, use our guide to disable Install unknown apps.

Step 4: Remove Device Administration Before Uninstalling

If the Uninstall button is unavailable, the app may hold device-administrator access. Search Settings for Device admin apps, deactivate the suspicious app, then return to its App info page and uninstall it.

On a company-managed phone, do not remove management software without permission. Ask the organisation’s administrator to confirm what belongs on the device.

Step 5: Restart in Safe Mode if Necessary

Safe Mode temporarily prevents most downloaded apps from running, which can make a disruptive app easier to remove. The button sequence differs by manufacturer, so use the official support instructions for your model.

Once in Safe Mode:

  1. Open Settings and the suspicious app’s App info page.
  2. Remove administrator or accessibility access if still present.
  3. Uninstall the app.
  4. Restart normally and repeat a Play Protect scan.

Step 6: Install Security Updates

Open Settings → System → Software updates or your manufacturer’s equivalent. Also search Settings for Google Play system update. Google includes Android, security and Play system updates in its malware-removal guidance.

Step 7: Secure Important Accounts from a Clean Device

If spyware may have captured passwords or notifications, cleaning the phone is only half the job. From a device you trust:

  1. Change the Google Account password and any reused passwords.
  2. Review recent security events and signed-in devices.
  3. Remove unfamiliar third-party access and recovery information.
  4. Enable two-step verification or a passkey.
  5. Review banking, email, social, cloud storage and messaging sessions.

Google’s compromised account guide recommends reviewing security events and devices, changing affected passwords and enabling stronger verification.

Step 8: Factory Reset When Trust Cannot Be Restored

A factory reset is appropriate when suspicious behaviour continues, security settings revert, system software is modified, or you cannot identify what has access. Before resetting:

  • Back up personal photos and documents, not unknown APK files.
  • Make sure you know the Google Account credentials needed after reset.
  • Record authenticator recovery codes and move essential two-factor access safely.
  • After reset, install updates first and restore apps manually from trusted sources instead of restoring every old app automatically.

A reset cannot repair an untrusted custom firmware or unlocked system image by itself. Seek manufacturer support if the phone is rooted, the bootloader was modified without your knowledge, or Play Protect certification fails.

What Not to Do

  • Do not install several unknown “cleaner” APKs; one may create a second problem.
  • Do not disable Play Protect because a questionable app tells you to.
  • Do not pay a pop-up claiming your phone has hundreds of viruses.
  • Do not assume an antivirus result proves a file is safe; scanning is one layer, not a guarantee.
  • Do not confront a suspected abuser using a device they may monitor.

How to Reduce the Risk Next Time

  • Prefer Google Play or the verified official website of the developer.
  • Before sideloading, follow our safe APK installation process.
  • Keep installation permission off except during a specific trusted installation.
  • Reject unexplained requests for accessibility, device admin, SMS or notification access.
  • Keep Android, Google Play system components and apps updated.
  • Use a screen lock and do not share the PIN with people who should not control the device.

Frequently Asked Questions

Can spyware survive a factory reset?

Ordinary downloaded apps are removed by a proper factory reset. Risk can remain if you restore the same harmful app, an account is still compromised, or system firmware was modified. Update first and reinstall apps selectively.

Does battery drain prove spyware?

No. Battery age, heat, weak signal, games, background syncing and updates are more common explanations. Look for permission, app and account evidence.

Can an antivirus app remove every threat?

No single scanner guarantees detection. Combine Play Protect or a reputable security scanner with permission review, account security, updates and reset when needed.

Should I upload a suspicious APK to VirusTotal?

It can provide useful multi-engine results, but do not upload confidential or personal files. VirusTotal identifies a file by its SHA-256 hash and may share samples within its security ecosystem.

Official References

Hakim
Written by

Hakim

OS Tech & App Malaysia editor covering Android guides, device performance, mobile security and gaming. Read our editorial standards.