A sudden loss of performance, constant pop-up ads and uncontrolled traffic consumption are the first warning signs that your Androidsmartphone is infected with malware. The situation becomes critical when standard antiviruses cannot detect the threat or do not have the rights to remove parasitic system applications. Device owners often encounter the fact that the “Delete” button in the settings is simply inactive or disappears immediately after clicking.

Similar malware are often disguised as harmless utilities: “memory cleaners,” “flashlights,” or battery optimizers. They gain device administrator rights, block uninstallation attempts, and can even take over screen control. There is no need to panic, as there are several proven methods of forced removal that work even in the most advanced cases.

In this material we will analyze the algorithm of actions from soft cleaning to radical measures, such as a complete system reset. You'll learn how to outsmart a virus by taking away its privileges and how to use developer tools for deep cleaning. Remember that ignoring the problem can lead to the leakage of confidential data, including banking details and passwords.

Diagnostics and identification of hidden threats

Before taking active steps, it is necessary to accurately identify the source of the problem. Often the virus does not have an icon in the application menu or is hidden under a system name to avoid detection by the user. The first sign of infection is abnormal behavior of the interface: spontaneous opening of browser tabs, the appearance of notifications from unknown services, or heating of the case during idle mode.

For initial analysis, go to section Settings → Applications → All applications. Carefully scroll through the list, paying attention to apps without a name or with a transparent icon. Sometimes malicious code is injected into legitimate applications, changing their behavior. If you notice an application that you did not install, or a system process with a suspicious name, write down its name.

Use the built-in service Google Play Protection to scan. While it doesn't always catch new strains of viruses, it can identify known threats. Go to the store Play Market, click on the profile icon and select “Protection”. Run the scan and wait for the results. If the system reports a danger, follow its recommendations, but do not rely solely on this tool.

⚠️ Attention: If a virus blocks access to settings or the application store, do not try to download new antiviruses directly on the infected device. This can make the situation worse, as malware often intercepts installations of new apps.

Analysis of traffic consumption can also reveal the attacker. Go to Settings → Network and Internet → Data usage. An app that you barely use, but that consumes gigabytes of traffic in the background, is highly likely to be a miner or a bot. Such an anomaly requires immediate intervention.

📊 How did the virus appear on your device?
Constant advertising
Brakes and heating
Spontaneous calls
Screen lock
I don’t know, it’s just slow

Disabling device administrator rights

The most common reason why a virus is not removed by standard methods is because it has rights device administrator. Malware requests these rights when first installed, often disguising the request as a need to “optimize performance” or “protect data.” While these privileges are active, the system prohibits uninstallation of the application.

To regain control of the smartphone, you must forcibly revoke these rights. Go to menu Settings → Security → Device administrators (the path may vary slightly depending on the model, for example, in Xiaomi or Samsung). In the list that opens, you will see checkboxes next to active applications with access rights.

Find the suspicious application and uncheck it. The system will ask you to confirm the action. If the virus has blocked this function and the “Disable” button cannot be pressed, try the following trick: put your phone in airplane mode, turn off Wi-Fi and mobile data, and then quickly try again. Sometimes this breaks the connection between the malicious script and the management server.

💡

If the “Device Administrators” field is gray and inactive, the virus may be exploiting a system vulnerability. In this case, try starting the device in Safe Mode before performing this procedure.

After successfully revoking rights, immediately return to the application management menu and try to uninstall the app. The “Delete” button should now become active. If the application again asks for administrator rights when trying to uninstall, categorically refuse and proceed to the next cleaning step.

Using Safe Mode to Uninstall

Safe Mode (Safe Mode) is a diagnostic Android that loads only system applications and services. All third-party apps, including viruses, do not run in this mode, which makes it easy to remove them without the resistance of malicious code. This is one of the most effective ways to deal with persistent threats.

To enter safe mode, you usually just need to hold down the power button on the screen until the reboot menu appears. Then press and hold Power Off or Restart on the touchscreen. A pop-up window will appear asking you to enter Safe Mode. Confirm the action, and the phone will reboot.

On some models, for example, older versions Samsung or LG, entry is made through physical buttons: when you turn on the device, you need to hold down the volume down button and hold it until the system is fully loaded. “Safe Mode” should appear in the lower left corner of the screen.

Action Standard mode Safe Mode
Launch third-party applications Active Blocked
Working of virus scripts Running Suspended
Access to removal settings May be blocked Full access
System speed Depends on load Maximum

While in safe mode, go to application settings and remove all suspicious apps. It is also recommended to clear your browser cache and remove recently installed utilities, even if they seem harmless. After cleaning, simply reboot your phone in the usual way to exit diagnostic mode.

☑️ Algorithm of actions in Safe Mode

Done: 0 / 6

Forced removal via computer and ADB

If the virus is so deeply embedded in the system, which blocks even safe mode, you will need the help of a computer. Using the debug bridge Android Debug Bridge (ADB) allows you to control the device at the command line level, ignoring the graphical interface, which may be blocked by malware.

First, you need to enable USB debugging. If a virus blocks access to the developer menu, try calling it by dialing: enter the code ##4636## in the dialer. If this does not work, connect your phone to the PC and try sending the activation command via ADB, if debugging was previously enabled.

adb devices

adb shell pm list packages

adb shell pm uninstall --user 0 virus.package.name

The command pm list packages will display a complete list of installed packages. Find the package name of the infected application (it usually does not match the name on the screen). Then use the delete command, substituting the found name. Please note that some system viruses may require a command with a flag --user 0, which removes the application for the current user, without directly affecting the system partition, but making it non-working.

⚠️ Warning: Be extremely careful when entering ADB commands. Removing critical system packages (for example com.android.systemui) may cause the phone to become unbootable or lose connectivity. Please check the package name three times before uninstalling.

This method requires ADB drivers to be installed on your computer. If the phone is detected as “Unknown device”, install universal drivers Google USB Driver. After successfully completing the uninstall command, reboot your smartphone. The virus should disappear as its executable file will be removed from user space.

Factory reset as a last resort

When none of the soft methods help, the only guaranteed way to get rid of the threat remains - a complete data reset (Factory Reset). This procedure removes all user data, apps, and settings, returning the phone to its out-of-the-box state. The virus located in the user partition will be destroyed.

It is important to understand the difference between resetting through the settings menu and resetting via Recovery Mode. If a virus blocks entry to settings, use hardware buttons. Turn off your phone completely. Then hold down the key combination specific to your model (most often it is Volume up + Power or Volume down + Power).

In the_recovery_ menu, select item Wipe data/factory reset, moving with the volume buttons and confirming the selection with the power button. The process may take several minutes. After completion, select Reboot system now. The phone will turn on like new, without any traces of malware.

What to do with the data before resetting?

If possible, copy important photos and contacts to computer or to the cloud before resetting. However, if a virus encrypts files or blocks data transfer, the priority is to save the device rather than the information. Ransomware viruses may infect the backup, so check the files before restoring.

After the reset, do not restore the data from the old backup first, install an antivirus and check the system if you restore it. installation file of the virus, the problem will return. Download applications only from official sources.

Preventing re-infection of the system

Removing the virus is only half of the solution. To prevent re-infection, you need to change your smartphone usage habits. The main vector of attacks is installing applications from unverified sources. Never download files from. forums, file sharing sites or dubious sites. APK-files from forums, file hosting services or dubious sites.

Regularly update your operating system and applications. Developers Google and device manufacturers are constantly patching security vulnerabilities. An outdated version is an open door for hackers. Enable automatic updates in the settings. store Android is an open door for hackers. Enable automatic updates in your store settings Play Market.

Install a reliable antivirus from a well-known vendor, such as Kaspersky, Dr.Web or ESET. Modern antiviruses are able to monitor application behavior in real time and block suspicious activity before it causes harm.

💡

The main principle of security: 90% of viruses get on the phone due to the user’s desire to save money on paid content or install a hacked game. Free cheese is only in the mousetrap.

Also pay attention to the permissions that applications give. If a simple flashlight requests access to contacts, microphone and location, this is a clear sign of fraud. Reject redundant requests and. remove such applications immediately. Control over access rights is in your hands in the menu Settings → Privacy → Permission Manager.

Is it possible to remove a virus without losing data?

In most cases, yes, if the virus has not encrypted the files and has not received full superuser rights. (Root), then deleting through safe mode or revoking administrator rights will save your photos and contacts. However, if the malware is deeply embedded in the system, a complete reset may be the only option, which will result in data loss.

Why does the antivirus not detect the virus on the phone?

Modern viruses use polymorphism techniques, changing their code every time they run to bypass signature analysis. Moreover, some Trojans disguise themselves as system processes. In such cases, behavioral analysis or manual removal via ADB is more effective than standard scanning.

Is it dangerous to unlock the bootloader for treatment?

Unlocking the bootloader itself does not cure the virus, but it allows you to install clean firmware. However, this procedure erases everything. data and can disrupt the operation of banking applications (Google Pay/Samsung Pay). Use this method only if other methods have not helped.

What is an advertising virus and how does it work?

An advertising virus (Adware) does not steal data, but displays intrusive advertising on top of all windows. It often works as a background service. Removal of such viruses is usually successful after revoking administrator rights. how they do not encrypt the system.

Do you need to change passwords after removing the virus?

Yes, definitely. If there was a Trojan on the phone that intercepted keystrokes or took screenshots, your passwords for social networks, mail and banks could have been compromised. Change all critical passwords from another, clean one. device.