Updated for 2026

Updated August 2026 · Every step is now quoted from Google's or Samsung's own documentation, read on 19 August 2026 · two claims corrected, and Google's sideloaded-malware figure updated to the current one
Boot to Safe Mode first, because that stops the app running while you work. Then revoke its device admin and accessibility access, because those are what grey out the Uninstall button. Then uninstall it and run a Play Protect scan. Keep a factory reset as a last resort, because it erases your own files too. You almost certainly do not need to pay for anything. Data checked: 19 August 2026.
Most of the time a phone acting strangely is a tired battery or an app that wants updating. Occasionally it is something worse: a hidden app showing ads, reading your screen, or angling for your banking login. The reassuring part is that you almost never need a repair shop or paid software. Android ships with everything needed to find the bad app and pull it out, and this page walks that sequence in the order that works, with the exact steps each vendor publishes for Pixel and for Samsung's One UI. Take it slowly. None of it will damage your phone.
One piece of context worth having before you start: a self-spreading Android virus is not really the thing to worry about. What people call a virus is almost always an app that somebody installed, which is good news, because the fix is to find that one app and remove it.
Confirm the problem first
Before changing anything, make sure there is a real problem. Any one of these has innocent explanations; two or three together is a much stronger signal.
The one symptom that is almost never real: a pop-up telling you that you are infected. A page or notification that shouts about a virus and offers to clean it is itself the scam. Real malware stays quiet, because staying installed is the entire point. Close the tab and never tap the button inside the alert.
Loads only preinstalled apps, so the bad one cannot run or block its own removal
Safe Mode is the most useful trick here. Android loads only the apps that shipped with the phone and leaves everything you installed switched off, so the malicious app cannot run, draw overlays, or interfere with its own removal. Nothing is deleted; you are booting with third-party software paused.
On a Pixel, Google's own help page splits by model. "For Pixel 5a and earlier: Press and hold the Power button for a few seconds. On your screen, tap Power off." For newer hardware: "For Pixel 6 and later, including Fold: Press and hold the Power and Volume Up buttons for a few seconds. On your screen, tap and hold either the Power off or Restart buttons. Tap OK." You will see "Safe mode" at the bottom of the screen. If the phone is already off, Google gives a different route: "Press your phone's power button. When the animation starts, press and hold your phone's volume down button."
On a Samsung Galaxy, Samsung's own support page documents two ways, and most guides only mention the harder one. From powered off: "Turn on the device and when the Samsung logo appears, press and hold the Volume down button," after which "Safe mode" appears in the bottom-left corner. But there is an easier route from a running phone: "press and hold the Side button and the Volume down button at the same time," then "Touch and hold the Power off icon. Tap the Safe mode icon." If your phone is on, use that one.
Two vendor warnings worth reading before you do this, because neither is obvious. Google notes that "Safe mode removes some Home screen widgets. If you use widgets, take a screenshot to help you put them back." Samsung warns that "when you exit Safe mode, some of your customization options (wallpapers, themes, etc.) may be reset to defaults." Neither is damage, but both are annoying to discover afterwards.
Useful detail that saves you a step: Google says "airplane mode is automatically turned on when you enter safe mode." Cutting the phone off from the network while you work is genuinely sensible, since it stops a misbehaving app sending data out or fetching instructions, and Safe Mode does it for you. If you want that isolation before you reboot, swipe down and tap airplane mode yourself. To leave Safe Mode later, restart normally.
Removes the powers that grey out the Uninstall button and let an app read your screen
Here is the step most guides skip, and the reason some apps appear impossible to uninstall. Malware commonly holds two powerful permissions. Device admin can block its own deletion. Accessibility, a feature built for people with disabilities, is misused to read the screen, capture what you type, and draw fake login boxes over real apps. If the Uninstall button is greyed out, one of these is why. Strip them in Safe Mode, where the app cannot fight back.
The security vendor Pradeo, in its analysis of accessibility abuse, puts the mechanism plainly: the permission "gives applications full access to the user's device," which is why it is so heavily targeted. Treat that as a vendor with a product to sell describing a real technique, not as an independent audit.
The gut check that does most of the work here. A wallpaper, a flashlight or a simple game has no honest reason to want device admin or accessibility. Reading the screen is exactly what a banking trojan needs. If the request does not match what the app is for, that mismatch is the finding.
Menu labels really do move, which is why the search box beats a memorised path. This one changed in the current release: Google's own Settings source for Android 16 defines the entry as "Device admin," where the Android 15 source called it "Device admin apps." The route through Security and privacy is unchanged, but the wording at the end of it is not, and guides that quote only one label will be wrong for half their readers. If a path does not match your phone, search Settings for "device admin" or "accessibility" instead.
Once you are clean, our guide to app lock tools is a sensible follow-up.
The actual fix in most cases, once the powers above are gone
With the special powers gone, the app should remove cleanly. Still in Safe Mode: open Settings, then Apps, and find the suspect in the list. Tap it to open App info. Tap Force stop first, which kills any lingering process, then Uninstall and confirm. Samsung's own page frames Safe Mode as exactly this opportunity: "Once you're in Safe mode, you can remove the third-party app that is causing issues."
Not sure which app is the culprit? Sort the app list by install date if your phone offers it and look at whatever arrived just before the trouble started. Open a suspect's Permissions and ask whether they make sense: a small utility wanting SMS, call logs and accessibility is a red flag. When genuinely unsure, an app you do not remember installing and do not use is safe to remove, because anything legitimate can be reinstalled. A file manager also helps you spot stray APK files sitting in Downloads.
The thing that does not work, and the usual reason people give up and assume the phone is broken: trying to uninstall while the app is running normally. Safe Mode is what makes the Uninstall button cooperate.
Sweeps for what you missed, against malware Google already knows about
With the obvious app gone, let Google's built-in scanner sweep the rest. Play Protect is free and already on every certified Android device. Restart normally to leave Safe Mode, since Play Protect needs the Play Store running, then open the Play Store, tap your profile picture, tap Play Protect, then Scan.
Google's own help page describes the coverage: it "runs a safety check on apps from the Google Play Store before you download them," and, importantly for this page, "it checks your device for potentially harmful apps from other sources. These harmful apps are sometimes called malware." It also "checks apps when you install them" and "periodically scans your device."
What happens when it finds something depends on how bad the thing is, and Google's developer documentation spells the rule out: "Some PHAs are more harmful than others and we treat them differently depending on the PHA classification. The most harmful PHAs are automatically removed from the device, while less severe PHAs are disabled." PHA is Google's term for a potentially harmful app.
The detail worth knowing is what "disabled" means, because it is not deletion. Google: "A disabled app is unusable but remains on the device, and any data associated with the app is recoverable. When an app is automatically disabled, users are notified and can make the decision to remove the app or re-enable it to make it usable again. If no action is taken, the app remains disabled." So a disabled app still needs you to finish the job, and if Play Protect got it wrong you can put it back. On the consumer-facing help page Google phrases the same behaviour more loosely, saying it "might" notify you, "disable the app until you uninstall it," or "remove the app automatically," and that "in most cases, if a harmful app has been detected, you will get a notification saying the app was removed."
Do not treat a clean scan as an all-clear, because Google's technical documentation is narrower than the help page's summary. Google's developer documentation says the install-time check "conducts a real-time check of the app against known harmful or malicious samples." Against known samples: something newly built or freshly repackaged is exactly what can slip past. And for an app it has never seen, Google's Play help page says you "may get a recommendation to scan an app from outside of Google Play that has never been scanned by Google Play Protect before," and that "scanning the app will send app details to Google for a code-level evaluation." That deeper look is an offer you accept, not something automatic.
So if symptoms persist after a clean scan, a second opinion is reasonable. Choose a scanner from a known security company rather than the top search result; our roundup of Android antivirus apps lists names worth trusting, and most offer a free on-demand scan, which is plenty for a one-off cleanup. You can uninstall it afterwards.
Finishing touches
Removing the app is most of the battle. A few finishing touches stop it coming back.
Then watch battery and data for a day. If both look normal, you are done. You do not need a dedicated cleaner app for any of this. A reputable cleaner can help with routine tidying, but treat the flashy "boost your phone" ones with suspicion, since that category is where a fair amount of adware lives. A trustworthy VPN is worth having on public Wi-Fi, but it is a privacy tool and does not remove malware.
Wipes everything back to shipped state, including your own files
If you have removed every suspect, run Play Protect, cleared the browser, and the phone still misbehaves, a factory reset is the reliable last resort. It returns the phone to its shipped state, so anything buried goes too. The trade-off is real: it erases your files as well, and only what is tied to your Google account comes back.
Back up first. Settings, Google, Backup, and check it has run recently. Copy photos to Google Photos or a computer. Then reset from Settings, System, Reset options on a Pixel, or Settings, General management, Reset on a Samsung.
Know the account before you wipe, because this is the mistake that turns a fixable phone into a paperweight. Google's device protection page explains: "you can set your device to help prevent others from using it if it gets reset to factory settings without your permission," so that "only someone with your Google Account or screen lock could use it." Google is specific that "to factory reset a protected device, you'll need to either unlock your screen or enter your Google Account password." Note that screen unlock is an accepted alternative to the account password, and note the term: Google calls this device protection, though it is widely known by the older name Factory Reset Protection. Never reset a phone whose Google password you do not know.
One correction to a claim this page used to make. Google's own reset page does not give per-device taps; it says "on most phones, you can reset your phone through the Settings app" and then explicitly defers: "we recommend checking your manufacturer's support site for device-specific instructions." So for the exact prompts, your maker's page is the authority, not Google's. Google's page also flags that "some of these steps only work on Android 14 and up."
When you set the phone up again, restore from backup but reinstall apps deliberately, one at a time, rather than letting everything flood back. If the phone will not start at all, that is a different problem and our guide to a phone that will not turn on is the better starting point.
Where the risk actually lives
It helps to know where Android malware actually comes from, because the answer is narrow enough to act on. The overwhelming majority arrives through sideloading: installing an app from outside the Play Store, whether an APK from a website, a link in a message, or a third-party store. Google's most recent published figure, from a March 2026 post, is that "our recent analysis found over 90 times more malware from sideloaded sources than on Google Play." An earlier announcement from August 2025 gave the number as "over 50 times more malware from internet-sideloaded sources than on apps available through Google Play." Both sentences are still live on Google's site, which is worth knowing if you see the smaller figure quoted elsewhere as current.
Treat either number as a direction rather than a measurement. Google publishes no methodology for the 50 times figure or the 90 times one, does not explain why it nearly doubled in seven months, and quietly broadened the comparison in the process: the 2025 wording was "internet-sideloaded sources" against "apps available through Google Play," while the 2026 wording is "sideloaded sources" against "on Google Play." This is also a company describing the safety of a channel it competes with. The direction is not seriously disputed; the precision is Google's alone.
This is shifting in 2026. Google is rolling out a developer verification requirement that ties apps to an identity-checked developer, with the aim of accountability: if a malicious app is pulled, the same person cannot immediately publish ten more anonymously. Google's rollout update gives the milestone as "September 30, 2026: App registration becomes required for participating stores in Brazil, Indonesia, Singapore, and Thailand," and says it "will begin by verifying app installations from the following stores," naming seven run by Google, Honor, OPlus, Samsung, Transsion, vivo and Xiaomi.
Read the scope carefully, because this page previously overstated it and it is widely overstated elsewhere. The September 2026 milestone covers participating stores in four countries, not every install on every phone, and it does not end sideloading. Google says the design keeps "allowing power users to maintain the ability to sideload apps from unverified developers," and that "unregistered apps can be sideloaded with Android Debug Bridge (adb) or advanced flow." In the earlier announcement Google is blunter still: "developers will have the same freedom to distribute their apps directly to users through sideloading or to use any app store they prefer." What changes is the identity requirement and which stores participate.
Until those protections are widespread, the advice is unchanged and it is short. Install from the Play Store when you can. Treat APK links in texts and ads as guilty until proven innocent. Read permission requests at install time. The moment an app asks for accessibility or device admin without an obvious reason is the moment to back out. Our explainer on the 2026 sideloading changes covers what is shifting in more detail, and if the Play Store itself is misbehaving, that is usually mundane and our guide to Play Store problems covers it.
No. Safe Mode, a manual uninstall and a free Play Protect scan handle the large majority of cases at zero cost. A paid app adds ongoing monitoring and extra detection, which is nice to have but not required to remove an infection you have already found. Most reputable scanners offer a free on-demand check if you want a second opinion.
That usually means the app holds device admin rights, which can block deletion. Revoke device admin for it first, on a Pixel under Settings, Security and privacy, More security and privacy, Device admin apps, and on Samsung under Settings, Security and privacy, More security settings, Device admin apps. Turn off any accessibility access too, and do it in Safe Mode so the app cannot interfere.
For ordinary consumer cases, yes, since a reset wipes installed apps and their data. The bigger risk is to you: it erases your photos and files as well. Back up first, and be certain you can get back in afterwards, because Google requires either your screen unlock or your Google Account password to reset a protected device.
It is Google's mechanism, still widely called Factory Reset Protection, for stopping a thief using a phone they have wiped. Google's wording is that after a reset "only someone with your Google Account or screen lock could use it." It matters because it means you should never factory reset a phone whose Google password you do not know. Checked 19 August 2026.
Almost always no. A page or notification that shouts about a virus and urges you to tap is itself the scam, usually pushing fake software or a payment. Real malware stays quiet, because remaining installed is the point. Close the tab and revoke notification permission for that site in Chrome under Settings, Notifications, Site settings. Never tap the button inside the alert.
No, and Google's own documentation is clear about the limit. The install-time check is "a real-time check of the app against known harmful or malicious samples," so something new or freshly repackaged can pass it, and the deeper code-level evaluation of an app it has never seen is a recommendation you accept rather than an automatic step. Treat it as a backstop against known-bad software.
No. Google's September 2026 milestone requires app registration for participating stores in Brazil, Indonesia, Singapore and Thailand, and Google says the design keeps "allowing power users to maintain the ability to sideload apps from unverified developers." What changes is the developer identity requirement and which stores take part, not the ability to install software yourself.
Stick to the Play Store, and be wary of APK files sent by message or offered by random sites. Read permission requests at install time and refuse anything wanting accessibility or device admin without a genuine reason. Keep the phone updated, since patches close the holes malware uses, and run a Play Protect scan occasionally. Those few habits prevent the large majority of repeat infections.
Checked 19 August 2026: this page gave detailed menu paths for a security cleanup while citing almost nothing, so every step is now quoted from the vendor that publishes it. The core advice held up: Safe Mode first, strip device admin and accessibility, then uninstall, is the right order and the page had it right. Several details did not survive the check. The Safe Mode instructions were incomplete on both platforms: Google splits the steps between Pixel 5a and earlier and Pixel 6 and later, and Samsung documents an easier route from the power menu that this page did not mention at all. Two vendor warnings were missing entirely, Google's that Safe Mode removes some home screen widgets and Samsung's that leaving it can reset wallpapers and themes, as was Google's note that Safe Mode turns on airplane mode by itself, which makes the separate airplane-mode step largely redundant. Two claims were wrong. The page said Google's official reset instructions "cover the exact taps," when that page gives no per-device steps and explicitly refers you to your manufacturer. And it described developer verification as covering "even apps you sideload," which overstates a rule that applies to participating stores in four countries and that Google pairs with an explicit commitment to keep sideloading available. A link to McAfee has been dropped because the page returned an error and could not be checked. Google's sideloaded-malware figure has been updated: this page cited "over 50 times," which was Google's August 2025 number, while Google's March 2026 post gives "over 90 times." Both remain published by Google, so both are shown with their dates, along with the caveat that Google supplies no methodology for either. One correction reversed before publication: a draft of this rewrite removed the claim that Google automatically removes the most harmful apps and disables less severe ones, on the grounds that Google stated no such severity rule. That was wrong. Google's developer documentation states it almost word for word, under the heading "Automatically disable PHAs," and the claim has been restored with its source and with the detail the original lacked, that a disabled app is not deleted and its data stays recoverable. A cleanup table, an "Our answer" capsule, a dated verification box and this changelog are new.