The most reliable way to check for malware on Android
The most reliable way to check for malware on Android is to use Google Play Protect, which scans your phone automatically and is built into every Android device. Open Settings, go to Security and privacy (or Security, depending on your Android version), then tap Google Play Protect. Tap Scan to run a manual scan right now — it takes a few minutes and shows you any detected threats with options to remove them.
Google Play Protect works because it has access to your entire phone and can see what apps actually do, not just what they claim to do. It runs in the background continuously, which means it catches problems even if you never manually scan. If it finds something, the threat name tells you what kind of malware it detected — ransomware, spyware, a fake banking app — so you know what you're dealing with.
Beyond Google Play Protect, a second opinion from a dedicated antivirus app can catch things the built-in scanner misses, though this is rare. Bitdefender Mobile Security and Norton Mobile Security are both legitimate options that don't slow down your phone noticeably. Install one, run a full scan, then uninstall it if nothing turns up — you don't need to keep it running all the time since Google Play Protect already does that job.
Key Takeaways
- Google Play Protect, built into every Android phone, is your first line of defense and can be manually scanned from Settings under Security and privacy.
- If Google Play Protect finds malware, the threat name tells you what type it is, and you can remove it directly from the scan results.
- A second scan with Bitdefender or Norton can catch rare threats that Google Play Protect misses, but is not necessary for most users.
- Malware usually enters through sideloaded apps (apps installed outside Google Play Store) or fake versions of legitimate apps, so checking your installed apps is as important as scanning.
- If your phone is running slowly, draining battery fast, or showing ads you didn't click, malware is one possible cause but not the only one.
Where malware actually comes from on Android
Most Android malware arrives through apps you install yourself, not through some invisible network attack. The malware either hides inside an app that looks legitimate — a fake version of WhatsApp or a banking app — or it's bundled with a real app that has been repackaged by someone else. Google Play Store has automated checks that catch most of these before they go live, but not all.
Sideloading — installing apps from outside Google Play Store — is where the real risk lives. If you download an APK file from a website and install it directly, you're bypassing Google's scanning entirely. This is how most people end up with malware. The app might work fine for weeks, then suddenly start stealing passwords or sending premium text messages without your knowledge.
Less common but still real: malware can hide in apps you've already installed if the developer's account gets hacked. Google Play Protect catches this when it happens and removes the malicious version automatically, but there's a window of time between infection and detection.
What to look for in your installed apps
Open Settings, then Apps (or Application Manager on older phones). Scroll through your installed apps and look for anything you don't remember installing. Malware often disguises itself with a generic name like "System Update" or "Google Services" or hides under an icon that looks like a system app. If you see an app with a name you don't recognize and you definitely didn't install it, that's a red flag.
Check the install date for suspicious apps. Go to Settings, Apps, then tap any app you're unsure about. At the bottom you'll see "Installed on" — if an app was installed months ago and you have no memory of it, that's worth investigating. You can uninstall it directly from this screen by tapping Uninstall.
Pay special attention to apps that ask for unusual permissions. Open Settings, Apps, then tap Permissions. Look for apps that have access to your contacts, messages, location, or camera when they have no reason to need it. A flashlight app should never need access to your contacts. A weather app should never need access to your messages. If the permissions don't match what the app does, uninstall it.
Signs your phone might have malware
A phone running slowly or draining battery fast can mean malware, but it usually means something else — too many apps running at once, a full storage drive, or an old battery. Before you assume malware, check your storage. Go to Settings, Storage, and see how much space is left. If you're below 1 GB free, your phone will slow down noticeably. Delete old photos, videos, or apps you don't use.
Ads appearing on your home screen or in places they shouldn't be — like inside your lock screen or in notifications — are a stronger sign of malware. These are usually from an app you installed that's showing ads without permission. Open Settings, Apps, and look for recently installed apps you don't recognize. Uninstall anything suspicious.
Unexpected charges on your phone bill, especially for premium text messages or subscriptions you didn't sign up for, can mean malware is sending paid messages in the background. Check your phone bill and your app subscriptions (Settings, Google Play, Account, Subscriptions) to see what's active. Cancel anything you didn't authorize, then run a Google Play Protect scan.
What to do if Google Play Protect finds malware
When Google Play Protect detects malware, it shows you the threat name and the app it came from. Tap Remove to delete the app immediately. Google Play Protect will uninstall it completely, and the malware goes with it. This is the safest option and works for almost every threat it finds.
If you need the app for something important — like a banking app that got flagged as a fake — don't reinstall it from the same source. Instead, go to Google Play Store, search for the official version, and install that. The official version will have a blue checkmark next to the developer name and will show the real company's name (like "JPMorgan Chase Bank" not "JPMorgan Services").
After removing malware, change your passwords for any accounts the malware might have touched — email, banking, social media. Do this from a computer if possible, not from your phone, in case the malware is still partially active. If the malware was on your phone for weeks before you caught it, consider monitoring your accounts for unauthorized activity for the next month.
How to avoid malware in the first place
Install apps only from Google Play Store. This is the single most effective rule. Google Play Store has automated scanning and human review, which catches most malware before it reaches you. Third-party app stores and direct APK downloads have much less oversight.
Check app reviews and the developer's history before installing anything. If an app has 50 reviews and a 4.8 rating, that's more trustworthy than an app with 3 reviews and a 5.0 rating. Look at the negative reviews specifically — if people are complaining about unexpected charges or ads, that's a warning sign. Check the developer's other apps too. If they have a history of legitimate apps, the new one is probably safe. If this is their only app or their other apps have bad reviews, skip it.
Keep your phone updated. Android updates include security patches that close holes malware uses to get in. Go to Settings, About phone, and tap System update to check for updates. Install them as soon as they're available, even if it means restarting your phone.
Turn off installation from unknown sources. Go to Settings, Apps, then tap the three-dot menu and select Special app access, then Install unknown apps. Make sure every app shows "Don't allow" except Google Play Store. This prevents you from accidentally sideloading malware.
When to use a second antivirus app
You don't need a second antivirus app running all the time — Google Play Protect is enough for most people. But if you've had malware before, or if you download a lot of apps from less-trusted sources, running a second scan occasionally can catch things Google Play Protect misses.
If you decide to use a second app, install Bitdefender Mobile Security or Norton Mobile Security, run a full scan, then uninstall it. Don't leave it running in the background. Two antivirus apps running simultaneously will slow your phone down and drain your battery faster because they're both scanning everything. One scan from each is useful; constant scanning from both is overkill.
Avoid free antivirus apps with names you've never heard of. Many of them are malware themselves, designed to look like security tools while stealing your data. Stick with names you recognize — Bitdefender, Norton, Kaspersky, Avast — or just rely on Google Play Protect alone.
Frequently Asked Questions
Can malware hide from Google Play Protect?
Rarely. Google Play Protect scans apps before they're installed and monitors them afterward. Some very new malware might slip through for a few days before Google's systems catch it, but Google usually detects and removes it within 24 to 48 hours. If you install an app and it gets flagged later, Google Play Protect will notify you and offer to remove it.
Is it safe to use free antivirus apps?
Most free antivirus apps from well-known companies like Avast or Kaspersky are safe, but many unknown free apps are malware themselves. Stick with brands you recognize or skip the second antivirus entirely and rely on Google Play Protect. If you do use a free app, uninstall it after scanning rather than leaving it running.
What does it mean if Google Play Protect says "device not certified"?
This usually means your phone is running a modified version of Android or you've sideloaded apps. It doesn't mean your phone has malware. Google Play Protect will still scan your phone, but some apps from Google Play Store may refuse to install. If you see this message and you haven't modified your phone, restart it and check again.
If I factory reset my phone, will it remove malware?
Yes, a factory reset will remove almost all malware because it deletes everything and reinstalls Android fresh. But it also deletes all your photos, messages, and app data, so it's a last resort. Try Google Play Protect and a second antivirus scan first. Only factory reset if malware keeps coming back after you've removed it multiple times.
Can malware spread from my Android phone to my computer?
Android malware is designed to run on Android and usually can't run on Windows or Mac. However, if malware steals your passwords on your phone, someone could use those passwords to log into your computer accounts. Change your passwords on a computer after removing malware from your phone, especially for email and banking.