If your Android phone has suddenly started throwing pop-ups, draining battery overnight, or sending messages you never wrote, something unwanted is probably running on it. The good news: you can almost always remove a virus from Android yourself in under 30 minutes, without paying anyone and usually without wiping your phone. The bad news: most guides ranking today give the steps in the wrong order, recycle malware examples from years ago, and skip the one thing Bangladeshi users need most, which is protecting bKash, Nagad and bank accounts while the cleanup happens.
This guide fixes that. It is built on 2026 threat data, the latest Android security changes, and a removal sequence designed so the malware cannot capture your new passwords or reinstall itself while you work.
Key takeaways
- It is rarely a true "virus": in 2026 the real threats are banking Trojans, droppers, adware and pre-installed backdoors. The removal method is the same: find the app, strip its permissions, delete it.
- Order matters: cut the connection, boot into Safe Mode, remove the app, then scan and update. Change passwords last, from a different device.
- Five hidden permissions (Device admin, Accessibility, Notification access, Install unknown apps, default SMS app) are where modern malware hides. Check all five.
- Most "virus" pop-ups are not malware at all: they are website notifications you allowed in Chrome, and you can turn them off in one minute.
- A factory reset is not a guaranteed cure: backdoors built into a phone's firmware survive it.
- Bangladesh-specific risk is real: BGD e-GOV CIRT rated a 2026 Android banking Trojan campaign a high threat to the country.
Technically, almost never. A classic virus copies itself into other files, and Android's app sandbox makes that very hard. What people call an "Android virus" is almost always malware delivered as an app: something you installed, something bundled inside another app, or something the manufacturer or reseller left inside the firmware. That distinction matters because it tells you where to look. You are not hunting infected files. You are hunting an app and the permissions it has grabbed.
Also rule out the boring explanations first. An old battery, a buggy system update, or a full storage drive can mimic infection. If the problem started right after an Android update and nothing else changed, it is more likely a bug than malware. If it started right after you installed an app, downloaded an APK, or tapped a link, treat it as malware.
Match your symptom to the right fix
Different symptoms point to different culprits. Use this table to jump to the step that will most likely solve your problem, then work through the full sequence to be sure nothing is left behind.
| What you are seeing | Most likely cause | Go to |
|---|---|---|
| "Your phone is infected" warnings or ads popping up on the lock screen / notification shade | Website notifications allowed in Chrome (not true malware) | Step 6 |
| Full-screen ads while using other apps, even the home screen | Adware app using "display over other apps" | Steps 3 and 4 |
| OTPs arriving but not appearing, or unknown bKash/Nagad transactions | Banking Trojan with SMS or Accessibility access | Before you start, then Step 4 |
| An app you cannot uninstall (button greyed out) | App holding Device admin rights | Step 4 |
| Battery drain, heat and high data use while idle | Background malware, proxy or ad-fraud app | Step 3 |
| Problems returned after a factory reset, on a brand-new cheap phone | Pre-installed malware inside the firmware | Step 9 |
| Friends receive links or messages you did not send | Compromised account or messaging malware | Step 8 |
What Android malware looks like in 2026
The threat picture has shifted, and several top-ranking guides still describe it with examples from 2019 to 2023. Here is what the most recent quarterly data actually shows.
304,128
malicious Android installation packages found in Q2 2026 (Kaspersky)
93,574
of those packages were mobile banking Trojans
180
vulnerabilities fixed in the September 2026 Android security update
According to Kaspersky's Q2 2026 mobile threat report, published in August 2026, banking Trojans remained the largest malware category at 30.77% of detected apps, and the Mamont banking family dominated attacks on users. The single most detected threat was Triada, a backdoor family known for being pre-installed in device firmware. The same report describes a trojanized PDF reader on Google Play that showed a fake "update" prompt to install the Anatsa banking Trojan, and a loader that only activated its malicious code for victims arriving from specific install sources, which helped it slip past store review.
Three lessons follow for anyone trying to clean a phone:
- Google Play is safer, not perfect. Malicious loaders still reach the store, usually disguised as utility apps like PDF readers, cleaners and file managers.
- A fake "update" screen inside an app is a red flag. Legitimate apps update through the Play Store, not through pop-ups asking you to allow installs.
- Some malware ships with the phone. That changes what a factory reset can and cannot fix.
What Google changed on Android in 2026
Android 17 reached Pixel phones as a stable release on June 16, 2026, with other brands rolling it out through the year. At its May 2026 Android Show, Google announced that Live Threat Detection, the on-device system that watches app behaviour, would gain warnings for apps that forward your SMS messages and apps that abuse the Accessibility permission to draw invisible overlays. Google also said Chrome on Android would check downloaded APK files for known malware when Safe Browsing is on. Separately, Android developer verification starts on September 30, 2026 in Brazil, Indonesia, Singapore and Thailand, with global expansion planned for 2027. Bangladesh is not in the first wave, so for now, APKs from unknown developers still install here with the usual warnings.
Before you start: 3 things to do in the first five minutes
Do these before touching any settings
- Turn on Airplane mode. This stops the malware sending data out and blocks SMS forwarding while you find and remove it. Safe Mode and uninstalling both work offline. You will reconnect later for scanning and updates.
- If money apps are on the phone, call from a different phone. Contact bKash (16247), Nagad (16167) or your bank's helpline and ask them to check recent activity or temporarily lock the account. Do not open the finance app on the infected phone.
- Do not change passwords on the infected phone yet. Malware with Accessibility or keylogging access can read what you type. Change them in Step 8, from a clean device.
How to remove a virus from Android: 9 steps that work in 2026
Menu names differ between Samsung One UI, Xiaomi HyperOS, Realme and Oppo ColorOS, Vivo and stock Android. Wherever a path varies, use the search bar at the top of the Settings app and type the setting name shown in quotes. Samsung's own support documentation recommends this for finding "Device admin apps".
1Restart in Safe Mode
Safe Mode starts Android with every third-party app disabled, so the malware cannot run, show pop-ups or block you from uninstalling it. It does not delete anything on its own.
- Open the power menu (hold the Power button; on newer Samsung and Pixel phones, hold Power + Volume Down or tap the power icon in Quick Settings).
- Touch and hold Power off until the Safe Mode prompt appears.
- Tap Safe mode or OK. When the phone restarts, "Safe mode" appears in the bottom-left corner.
If the prompt never appears, switch the phone off, turn it on, and hold Volume Down as soon as the logo shows. This is Samsung's documented fallback and works on many other brands, but some models differ, so check your manufacturer's support page if neither method works. If your symptoms vanish in Safe Mode, you have confirmed a third-party app is the cause.
2Note when the problem started
Think back to what you installed or downloaded in the day or two before the symptoms began: an APK from a Facebook group, a "modded" game, a free VPN, a cleaner or battery booster, or an app a caller asked you to install. Malware nearly always arrives just before trouble starts, and that timeline narrows your search from a hundred apps to three or four.
3Find the suspicious app
Go to Settings > Apps (called "See all apps" on some phones) and scroll the full list. The list shows apps even when their home-screen icon is hidden. Look for:
- Apps you do not remember installing, or installed around the time problems began
- Generic or blank names such as "System Update", "Service", "Security", or a second "Settings" or "Google" app
- Utility apps you rarely open: PDF readers, file managers, cleaners, flashlight or QR apps
- Apps using unusual battery or mobile data (check Settings > Battery and "Data usage")
Then check the five places malware hides its power. An app that appears in any of these and is not something you trust is your prime suspect.
| Hidden permission | Search Settings for | Why malware wants it |
|---|---|---|
| Device admin | "Device admin apps" | Blocks you from uninstalling it; can lock or wipe the screen |
| Accessibility | "Accessibility", then Installed / Downloaded apps | Reads your screen, taps buttons for you, captures PINs and OTPs |
| Notification access | "Notification access" or "Device & app notifications" | Reads every notification, including OTP codes and chats |
| Install unknown apps | "Install unknown apps" | Lets a dropper download and install more malware |
| Default SMS / overlay | "Default apps" and "Display over other apps" (Samsung: "Appear on top") | Intercepts texts and draws fake login screens over real apps |
4Strip its permissions, then uninstall it
Removal order matters when an app is holding admin rights, because Android will not let you uninstall it until those rights are gone.
- In Device admin apps, turn off the suspicious app and confirm Deactivate.
- Turn off its Accessibility, Notification access and Install unknown apps permissions.
- Go back to Settings > Apps, tap the app, then tap Force stop and Uninstall.
- If you are unsure between two apps, remove both. You can reinstall a genuine app from the Play Store afterwards.
- Restart normally and see whether the symptoms have stopped.
If the Uninstall button stays greyed out even after deactivating admin rights, the app is likely a system-level or pre-installed component. Skip ahead to Step 9.
5Delete the installer files
Removing the app does not remove the APK file you downloaded. Open your Files app, go to Downloads, and delete any .apk files, plus files shared through WhatsApp, Telegram or Messenger that you do not recognise. Otherwise you, or someone else using the phone, may reinstall it by accident. Ignore advice about hunting ".exe" files: those are Windows programs and cannot run on Android.
6Clean up Chrome and browser notifications
If your main symptom is "virus alert" notifications or ads that open random sites, this step alone often fixes everything. These come from websites you once allowed to send notifications, not from an installed app.
- Open Chrome, tap the three-dot menu > Settings > Site settings > Notifications.
- Block every site you do not recognise, or turn notifications off entirely.
- Back in the three-dot menu, tap Delete browsing data, choose All time, tick cookies and cached files, and delete.
- Repeat in any other browser you use, such as Samsung Internet or Opera.
Clearing cache helps with redirects and leftover site data, but it will not remove a malicious app. That is why it sits here, after the app is gone, and not at the top of the list where some guides put it.
7Reconnect, scan with Play Protect and a second scanner
Now turn Airplane mode off. Scanners need the internet to check the latest threat signatures.
- Open the Play Store, tap your profile picture, then Play Protect.
- Tap the settings gear and make sure Scan apps with Play Protect is on. Turn on Improve harmful app detection if you have ever installed apps from outside the Play Store.
- Go back and tap Scan. Remove anything it flags.
For a second opinion, install one security app from the Play Store only and run a full scan. The independent lab AV-Comparatives' Mobile Security Review 2026, tested on Android 16 with over 3,000 recent malware samples, covered Avast, AVG, Bitdefender, G DATA, Kaspersky, Norton, Securion, Tencent and Google Play Protect. Free tiers are enough for a one-off cleanup scan. Never install a "cleaner" or "antivirus" because a pop-up told you to: that is one of the most common ways malware gets on phones in the first place.
8Update Android, then secure your accounts from a clean device
Search Settings for "Software update" and "Security update" and install everything available, including the Google Play system update. Then check your security patch level under Settings > About phone. Google's September 2026 Android Security Bulletin fixed critical flaws, the worst of which could allow remote code execution with no user interaction; a patch level of 2026-09-05 or later covers all of them, if your manufacturer has released it.
Now, using a different phone or a computer you trust:
- Run the Google Security Checkup at myaccount.google.com/security-checkup, remove unknown devices, and change your Google password.
- Turn on 2-Step Verification for Google, Facebook and your email.
- Change your bKash, Nagad and banking app PINs once the phone is clean.
- On WhatsApp, open Linked devices and log out any session you do not recognise. On Facebook, check Accounts Center > Password and security > Where you're logged in.
For full walkthroughs, see our guides on recovering a hacked Gmail account, the 10-minute Google account security checkup and securing your Facebook account.
9Factory reset, and know when a reset will not help
If symptoms persist after Steps 1 to 8, a factory reset is the next move. It erases apps, accounts and files, so first back up photos, contacts and documents, but not apps or APK files, since restoring those can bring the malware straight back. Our guides on backing up your Android phone and factory resetting Android the right way cover each brand's menus. After the reset, reinstall apps one at a time from the Play Store rather than restoring everything at once.
When a factory reset will not work
A factory reset wipes the user data area of your phone. It does not rewrite the firmware. Backdoors like Triada that were planted in firmware at the factory or by a reseller come back the moment the phone restarts. If a brand-new or very cheap phone shows adware or unknown apps straight out of the box, or problems return immediately after a reset, install every available system update and take the phone to the brand's authorised service centre to have official firmware reinstalled. If the phone is a clone or grey-market unit with no official support, replacing it is the only reliable fix.
"Your phone has 13 viruses": how to tell fake alerts from real ones
Scareware is designed to panic you into installing a "cleaner" that is itself malware, or into calling a fake support number. Here is how to tell the difference.
| Fake alert (scareware) | Real warning | |
|---|---|---|
| Where it appears | Inside a browser tab or as a website notification | A system notification from Google Play Protect or your installed security app |
| What it asks | Download an app, tap "Clean now", call a number, or pay | Uninstall or disable a specific named app |
| Tone | Countdown timers, flashing text, exact virus counts | Plain, calm wording with no deadline |
| What to do | Close the tab and block that site's notifications (Step 6) | Follow it, then check the app it names in Step 3 |
Common advice that is wrong or outdated
We reviewed the guides currently ranking for this topic. Several give advice that is outdated, in the wrong order, or simply does not apply to Android. Here is what to ignore.
| What some guides say | Why it is a problem | What to do instead |
|---|---|---|
| Clear your Chrome cache as step one to remove the virus | Cache clearing never removes an installed malicious app | Remove the app first, clean the browser after (Step 6) |
| Change all your passwords immediately on the phone | Malware with Accessibility or keylogging access can capture new passwords as you type | Change passwords from a clean device after removal (Step 8) |
| Turn off Wi-Fi and data, then run an antivirus scan | Cloud scanners and Play Protect need a connection to check current threats | Stay offline while removing apps, reconnect only to scan and update |
| Long-press the app until it starts jiggling, then uninstall | That is iPhone behaviour; Android shows a menu with Uninstall or App info | Uninstall from Settings > Apps, after revoking admin rights |
| Search for .exe files on your phone | .exe files are Windows programs and cannot run on Android | Delete unknown .apk files from Downloads (Step 5) |
| A factory reset is almost guaranteed to remove malware | Firmware-level backdoors such as Triada survive a reset | Update firmware or visit an authorised service centre (Step 9) |
If you use bKash, Nagad or mobile banking in Bangladesh
Bangladesh's heavy reliance on mobile financial services, NID-based e-KYC and SMS one-time PINs makes Android banking malware especially damaging here. In July 2026, the national computer incident response team, BGD e-GOV CIRT, issued an advisory on the GoldPickaxe banking Trojan. Its current Android variant spreads through a fake video-streaming website that persuades people to install an APK manually. It can steal face videos and identity documents to defeat facial-recognition checks, and researchers found one variant configured to target 118 banking apps. CIRT assessed the threat to Bangladesh as high.
Warning signs specific to Bangladeshi users
- An APK shared as a "scholarship", "government aid", "free internet" or "bKash cashback" app
- Any app, other than bKash or Nagad themselves, asking for Accessibility, SMS or "Appear on top" access
- An unexpected request to record a selfie video or upload your NID from an app you did not get from the Play Store
- A caller who walks you through installing an app or changing security settings
- bKash or Nagad verification codes arriving when you did not request one
If money has already left your account, call bKash on 16247 or Nagad on 16167 immediately with the time and transaction details, file a General Diary (GD) at your local police station, and call 999 in an emergency. bKash and Nagad staff will never ask for your PIN or OTP.
Not sure whether someone is monitoring you rather than stealing money? Our guides on signs your phone is hacked and how to check for stalkerware go deeper. And if the infection has already spread to your social accounts, start with our complete Facebook account recovery guide for Bangladesh.
How to keep your Android phone clean after removal
- Install apps only from the Play Store or your phone brand's official store, and turn Install unknown apps off for every app once you are done
- Never grant Accessibility access to anything that is not a genuine accessibility tool
- Keep Play Protect on and install security updates the day they arrive
- Skip "modded", "premium unlocked" and cracked APKs: they are the most common malware carriers
- Be suspicious of any app that asks you to install an "update" from inside itself
- Buy phones from official channels that still receive security patches
- Check your hidden-permission list (Step 3 table) once a month; it takes two minutes
Frequently asked questions about removing viruses from Android
How do I remove a virus from my Android phone for free?
Turn on Airplane mode, restart in Safe Mode, check Device admin, Accessibility, Notification access and Install unknown apps for anything suspicious, revoke those permissions, and uninstall the app. Then reconnect and run a Google Play Protect scan. Every step uses built-in Android tools and costs nothing.
Can I remove a virus from Android without a factory reset?
Yes, in most cases. The majority of Android malware lives inside an installed app, so removing that app in Safe Mode solves the problem. A factory reset is only needed when you cannot identify or uninstall the culprit.
Will a factory reset remove all viruses?
It removes anything you installed, but not malware built into the phone's firmware. Pre-installed backdoors return after a reset and need a firmware update or a visit to an authorised service centre.
How do I know if the virus is really gone?
Your original symptoms stop, Play Protect and a second scanner find nothing, battery and data use return to normal, and no unknown apps reappear in Device admin or Accessibility over the next few days. If anything returns, repeat Step 3 or move to Step 9.
Is Google Play Protect enough to protect my phone?
It is a solid free baseline and catches most known threats, especially if you only install from the Play Store. If you often install APKs or use mobile banking heavily, a reputable second security app adds another layer.
Why do I keep getting virus warning pop-ups in Chrome?
Almost always because a website was allowed to send notifications. Open Chrome Settings, go to Site settings, then Notifications, and block the sites responsible. These pop-ups are fake, so do not download anything they recommend.
Can someone install a virus on my phone through a call or SMS?
A call or text on its own rarely installs anything. The danger is being talked into installing an app, opening a link, or granting permissions. That is also why keeping Android updated matters: some patched flaws, such as those fixed in September 2026, could be exploited without user interaction.
Should I use a phone cleaner app to remove viruses?
No. Cleaner and booster apps are one of the most common disguises for malware, including loaders found on Google Play in 2026. Use Play Protect and a well-tested security app from an established vendor instead.
Final thoughts
To remove a virus from Android, you rarely need special tools. What you need is the right order: isolate the phone, find the app in Safe Mode, strip the permissions it is hiding behind, remove it, then scan, update and secure your accounts from somewhere safe. Work through the nine steps once, check the hidden-permission table every month, and treat any APK or in-app "update" with suspicion. That habit protects your phone, your photos and, for millions of people in Bangladesh, the money in their mobile wallet.