Has your smartphone started to slow down for no reason? Does the battery run out in a few hours, although it used to last a day? Do strange advertising banners appear on the screen that were not there before? These symptoms may indicate a malware infection. Viruses on Android started slowing down for no reason? Does the battery run out in a few hours, although it used to last a day? Do strange advertising banners appear on the screen that were not there before? These symptoms may indicate a malware infection. Viruses on Android devices occur less frequently than on PCs, but their consequences are no less dangerous: from theft of personal data to blocking the phone with a ransom demand.
Unlike iOSwhere installing applications outside App Store almost impossible, Android gives users more freedom - and at the same time risks. According to Kaspersky, in 2023, every fifth mobile virus was aimed at stealing banking data, and 38% of infections occurred through fake applications from third-party sources. At the same time, 62% of users do not even suspect the presence of a threat, attributing symptoms to โsystem glitches.โ
In this article you will find practical guide how to identify viruses on Android โfrom obvious signs to hidden threats that masquerade as system processes. We'll look at how to scan your phone manually (without an antivirus), what tools to use for deep diagnostics, and what to do if malware has already penetrated the system. We will pay special attention new types of threats in 2026โ2026that bypass standard protection methods.
1. Top 12 signs of a virus on Android: from obvious to hidden However, even the most sophisticated threats leave traces. Below -
Malware on Android rarely announces itself openly - modern viruses are designed to remain undetected for as long as possible. However, even the most sophisticated threats leave traces. Below - checklist of symptoms, divided into three categories according to the degree of visibility.
- ๐ฅ Obvious signs (visible to the naked eye):
- ๐ฑ Constantly appearing pop-up windows with advertising, even when all applications are closed.
- ๐ฐ Money is debited from your mobile account or bank card without your knowledge (especially small amounts - 1-10 rubles).
- ๐ฒ Applications that you did not install appear in the menu or on the main screen.
- ๐ Hidden symptoms (require careful monitoring):
- ๐ The battery drains 20-30% faster than usual with the same usage.
- ๐ถ Mobile traffic or Wi-Fi data are consumed in the background (check in
Settings โ Network and Internet โ Data usage). - ๐ The phone spontaneously reboots or turns off, especially when connected to the Internet.
- ๐ต๏ธ System anomalies (indicate deep infection):
- ๐ซ Antivirus or
Google Play Protectionare disabled without your participation. - ๐ Account passwords (for example, Google or social networks) stop working, although you did not change them.
- ๐ Files and photos disappear or are encrypted (ransom demands are a sign ransomware).
- ๐ ๏ธ In
Settings โ Applicationsprocesses with suspicious names appear (for example,com.system.updateorandroid.security.patch).
If you notice at least 2-3 items from the list, the probability of infection is 70โ80%Combinations of symptoms from different categories are especially dangerous - for example, rapid battery drain + background traffic + strange applications. In this case, the virus could have already acquired administrator rights and is masquerading as system ones. services.
2 How. check Android for viruses without an antivirus: manual diagnostics
Antivirus apps do not always detect new threats, especially if the virus is written for a specific phone model (for example, Samsung Galaxy or Xiaomi RedmiIn addition, some malware blocks the installation of security software. In such cases, it will help. it will take 10-15 minutes, but will allow you to identify even hidden threats. manual scan โ it will take 10โ15 minutes, but will allow you to identify even hidden threats.
2.1. Checking the list of installed applications
Open Settings โ Applications โ All applications and sort the list by installation date (โฎ โ Sort by: Installation date). to: Settings โ Applications โ All applications data-i="98">unclear names
- ๐ฆ Applications with strange names (For example,
com.android.update.serviceorsystem.security.patch). - ๐ apps that you did not install, but they are in the list.
- ๐ Applications installed on the day you noticed problems with the phone.
If you find suspicious software, try to remove it If. button Delete is inactive or requires administrator rights - this is a sure sign of a virus.
2.2. Analysis of battery and traffic consumption
Viruses are often disguised as system processes, but they are revealed by abnormal resource consumption. check:
- Go to
Settings โ Battery โ Battery usage. - See which applications consume the most energy.Norma: screens, instant messengers, games. Suspiciousif unknown processes are in the top (for example
Android System WebViewwith a consumption of 15โ20%). - Check the traffic in
Settings โ Network and Internet โ Data usage โ Mobile data. Viruses often โleakโ data in the background.
โ๏ธ Checklist for manual virus scanning
2.3. Checking administrator rights
Many viruses request rights. administrator to block your deletion. To check:
- Open
Settings โ Security โ Device administrators(on some firmware the path may differ:Settings โ Lock screen and security โ Other security settings โ Device administrators). - There should be no unknown applications in the list. If you see something like
Device AdminorSystem Securityit is almost certainly a virus. - Try to revoke rights by unchecking the box. If the system displays an error, the threat is deeply embedded. in the OS.
If you cannot revoke administrator rights, try rebooting the phone in safe mode). mode (press the power button โ hold "Shutdown" โ click "OK" when prompted to switch to safe mode). In this mode, viruses do not run, and you can remove them.
3. What viruses are most common on Android in 2026? came out:
Every year mobile viruses become more sophisticated. If previously the main threat was adware (adware) and spyware (spies), now the following have come to the fore:
| Type of virus | How it manifests itself | What it does | How it gets to the phone |
|---|---|---|---|
| Banking Trojans (Anubis, Cerberus) | Intercepts SMS, imitates banking applications | Steals card data, passwords from banks | Fake applications (for example, "Sberbank Online" from third-party sources) |
| Ransomware (LeakerLocker, Simplocker) | Locks the screen or encrypts files | Demands a ransom for unlocking | Attachments in letters, malicious APK |
| Hidden mining apps (HiddenMiner) | The phone gets hot, the battery runs out in 2-3 hours | Uses phone resources for mining cryptocurrency | Games and utilities from unverified sources |
| Spyware (Pegasus, XAgent) | No obvious symptoms, but traffic is growing | Monitors location, records calls, steals photos | Vulnerabilities in instant messengers (WhatsApp, Telegram) |
| Adware with root access (Shuanet, LeifAccess) | Advertising on top of all windows, even when blocked | Shows advertising, steals behavior data | Applications from Google Play with deceptive reviews |
Especially dangerous is a virus FluBotthat is distributed via SMS with a link to a โvoice message.โ After clicking on the link, the user is prompted to install an APK file, which steals bank card data and sends itself further to contacts. In 2026 FluBot mutated and learned to bypass two-factor authentication in some banks.
How to recognize a phishing SMS from FluBot
The text of the message usually contains the phrase โNew voice message: [link].โ The link leads to a fake site that imitates a player download page (for example, "Voicemail Player"). The APK file has a name like VoiceMessage.apk or PlayVoice.apk.
4. The best ways to check your phone for viruses: from built-in tools to professional scanners
If a manual check does not produce results, but symptoms of infection remain, itโs time to use specialized tools. Below - method rating from the simplest to the most reliable.
4.1. Built-in Google Play protection
Google Play Protection (previously Verify Apps) is a basic scanner that checks applications for malicious code. To run the scan:
- Open Google Play Store.
- Click on the profile icon โ
Play ProtectionโScan your device for threats. - If suspicious apps are found, the system will prompt you to remove them.
Limitation: Google Play Protection does not find viruses that:
- ๐น Installed from third-party sources (not through Play Market).
- ๐น Masked as system processes.
- ๐น Use kernel vulnerabilities Android (root viruses).
4.2. Antiviruses with deep scanning
For a full scan, you will need a third-party antivirus. The best options for Android in 2026:
- ๐ก๏ธ Bitdefender Mobile Security - detects even new threats thanks to cloud analysis.
- ๐ Kaspersky Internet Security - effective against banking Trojans and spyware.
- ๐ฑ Malwarebytes - specializes in adware and ransomware.
- ๐ Norton 360 - includes VPN and phishing protection.
Before installing an antivirus:
- Download only from official Google Play (not from sites!).
- Check the application permissions - the antivirus should not request access to SMS or calls.
- Update the databases before scanning.
Even the best antiviruses do not provide 100% protection. with root access or those that exploit firmware vulnerabilities (for example, in phones Huawei or Meizu) may go unnoticed. In such cases, only resetting to factory settings will help.
4.3 Checking via ADB (for advanced users)
If a virus blocks the installation of an antivirus or disguises itself as a system application, you can scan your phone through ADB (Android Debug Bridge).
Instructions:
- Enable
USB Debuggingon phone (Settings โ About phone โ Build numberโ press 7 times, then return toSettings โ System โ For Developers โ USB debugging). - Connect your phone to the PC and open the command line.
- Enter the command to list packages:
adb shell pm list packages -f - Look for suspicious packages in the output (for example, with the names
com.android.security.patchorsystem.update.service). - Remove the virus with the command:
adb shell pm uninstall -k --user 0 package name
โ ๏ธ Attention: Removing system packages via ADB can lead to the phone not working. Do not delete anything unless you are 100% sure!
5. What to do if a virus is detected on your phone: step-by-step action plan
If the scan confirms the presence of malware, follow the algorithm:
- Isolate the phone:
- ๐ต Turn off your phone Internet and Wi-Fi.
- ๐ Put your phone in
airplane mode. - ๐ณ Remove linked bank cards from Google Pay, Samsung Pay and other services.
- Try deleting virus:
- ๐๏ธ Remove suspicious applications through
Settings โ Applications. - ๐ง Revoke administrator rights (see section 2.3).
- ๐ก๏ธ Carry out a deep dive antivirus scanning.
- ๐๏ธ Remove suspicious applications through
- If the virus is not removed:
- ๐ Restart the phone in
safe modeand repeat the removal. - ๐ฑ Back up your important data (photos, contacts) to an external drive.
- โ๏ธ Perform
reset to factory settings(Settings โ System โ Reset settings).
- ๐ Restart the phone in
- ๐ Change passwords for all accounts (email, social networks, banks).
- ๐ Check your payment history in mobile banking.
- ๐ก๏ธ Install a reliable antivirus and enable automatic scanning.
โ ๏ธ Attention: If the virus requires ransom for unlocking (ransomware), do not pay! There is no guarantee that you will get access to the files back. Instead:
- ๐ Try to find decryption tools on the Internet (for example, No More Ransom).
- ๐ฑ Take your phone to a service center - sometimes specialists can restore data through a memory chip.
6. How to protect Android from viruses: 100% prevention
The best protection against viruses is their prevention. Follow these rules, and the risk of infection will be reduced to a minimum:
- ๐ฅ Install applications only from Google Play:
APK files are the main source of viruses. Even if an application seems safe (for example, a modified game), it may contain hidden malicious code.
- ๐ Check reviews and ratings:
Viruses are often disguised as popular utilities. (for example, "Cache Cleaner" or "Battery Boost") Read reviews before installing - if there are complaints about advertising or strange behavior, it is better to refuse.
- ๐ Update your OS and applications regularly:
Updates often close vulnerabilities that viruses exploit. data-i="264">Settings โ System โ System update
Settings โ System โ System update. - ๐ Do not give applications unnecessary permissions:
If the flashlight asks for access to your contacts or SMS, this is suspicious. Check the permissions in
Settings โ Applications โ [name. applications] โ Permissions. - ๐ต Use a VPN on public networks:
Viruses can penetrate through vulnerabilities in public Wi-Fi. Set up a VPN (for example, ProtonVPN or NordVPN) to encrypt traffic.
- ๐ก๏ธ Install an antivirus with real-time protection:
Even if you are careful, some threats (for example zero-day) can penetrate your phone. An antivirus with activity monitoring will help detect them.
Pay special attention phishing attacks. In 2026, scammers are actively using:
- ๐ง Fake letters from Google or Sberbank with a request to โconfirm the data.โ
- ๐ฃ SMS with links to โfree giftsโ or โtraffic police fines.โ
- ๐ค Bots in Telegram/WhatsAppthat offer to โearn money quickly.โ
To check the authenticity of a letter from the bank, never follow the links in the message. Instead, open the bankโs official application or enter the website address manually in. browser.
7. Myths about viruses on Android: what you shouldnโt be afraid of
There are many myths around mobile viruses that only scare users. Letโs look at the most common ones:
- ๐ซ Myth 1: โViruses can damage the phoneโs hardware.โ data-i="288">In fact: Viruses cannot physically break the processor or battery. They only
Fact: Viruses cannot physically destroy the processor or battery. They are only overload the system, which is why the phone heats up and discharges faster. After removing the virus, the deviceโs operation returns to normal.
- ๐ซ Myth 2: โIf the phone is slow, it means itโs not working.โ it's a virus"
In fact: Brakes can be caused by full memory, fragmented storage or outdated firmware. Before sinning for viruses, check:
- ๐ Free space in memory (
Settings โ Storage). - ๐ Android version (
Settings โ About phone). - ๐๏ธ Number of background processes (
Settings โ Applications โ Running).
- ๐ Free space in memory (
- ๐ซ Myth 3: โAntiviruses for Android are uselessโ
In fact: Free antiviruses (for example, Avast or AVG) do often show false positives, but paid solutions (like Bitdefender or Kaspersky) are effective against 95% of threats.
- ๐ซ Myth 4: โViruses can penetrate via Bluetooth or NFCโ
In fact: Modern viruses practically do not spread through Bluetooth or NFC. Main infection channels:
- ๐ฅ Installation of APK from unverified sources.
- ๐ Vulnerabilities in the browser (for example, when visiting malicious sites).
- ๐ง Phishing links in SMS/email.
Another common fear is "viruses on a SIM card". In fact, a SIM card cannot be infected in the traditional sense, but scammers can:
- ๐ฑ Replace your SIM card in a communication shop (attack SIM-swap).
- ๐ณ Intercept SMS with confirmation codes (if your phone has spy virus).
To protect yourself, enable banking applications two-factor authentication via push notifications instead of SMS.
FAQ: Frequently asked questions about viruses on Android
โ Can a virus on Android infect a computer when connected via USB?
๐น Yes, but only if:
- The phone has a virus that spreads through
ADBorMTP(for example, Triada or Ztorg). - The antivirus is disabled on the PC or the OS is not updated Windows/macOS.
- You have allowed the transfer of files from the phone to the computer.
๐ก๏ธ How protect yourself: Connect the phone in the "Charge only" mode and use the antivirus on the PC (for example, Kaspersky Total Security).
โ Is it possible to remove the virus without resetting the settings?
๐น In 80% of cases - yes. Try:
- Remove suspicious applications manually.
- Revoke administrator rights.
- Scan the phone with an antivirus (Malwarebytes or Bitdefender).
๐จ Reset is needed if:
- The virus has received
root access. - The antivirus cannot remove threat.
- The phone is blocked (ransomware).
โ Which Android models are most often infected with viruses?
๐น Viruses do not depend on the model, but risk above on phones:
- ๐ฑ With an outdated version of Android (below Android 10).
- ๐ With an unlocked bootloader (bootloader) or
root access. - ๐ Popular in countries with high level of cybercrime (for example, Xiaomi and Samsung in Russia, Huawei in Asia).
- ๐ฅ With pre-installed "extra" applications (for example, some models data-i="358">Before buying a phone, check how long the manufacturer supports updates. For example, Lenovo or ZTE).
๐ก Tip: Before purchasing a phone, check how long the manufacturer supports updates. For example, Google Pixel receives updates for 5+ years, and many budget smartphones only 1-2 years.
โ Can a virus on Android monitor me through a camera or microphone?
๐น Yes, but this requires special conditions:
- ๐ค The virus must obtain permission to access the camera/microphone (you had to confirm it).
- ๐ Most often spyware disguises itself as:
- Applications for video calls (for example, fake Zoom).
- Games with access to the camera (AR games).
- Utilities for "optimizing" the phone.
๐ก๏ธ How to check:
- Close all applications and see if the camera/microphone indicator is on.
- Check permissions in
Settings โ Applications โ [name] โ Permissions. - Use an antivirus with a spyware detection function (for example, Kaspersky).
โ What to do if the antivirus finds a virus, but cannot remove it?
๐น Follow the algorithm:
- ๐