How to remove malware from your Android phone without a PC

Smartphones have quietly become the centre of daily life across Australia, from paying for a flat white in Surry Hills with Afterpay to checking CBA balances on the train from Penrith. That dependence also makes Android devices an attractive target for scammers who know that one infected app can expose banking credentials, personal photos, and private messages, so understanding how to clean a handset without a computer is now a practical skill rather than a technical curiosity.

This guide walks through the practical steps for stripping malicious software from an Android phone using only the handset itself, the apps already installed, and a handful of trusted downloads. The approach is built around three phases: detection, isolation, and removal, with a fallback to a factory reset for situations where nothing else works. Australians who rely on services from Telstra, Optus, or Vodafone for everyday tasks will find the routine familiar, and the same habits protect users of budget devices sold through JB Hi-Fi and Officeworks just as effectively as flagship Galaxy handsets.

Recognising the warning signs of a compromised device

Malicious software usually betrays itself through small changes that show up the moment a user picks up the phone. The most common giveaway is sudden battery drain on a handset that previously lasted a full workday in Brisbane or a complete commute on the Sydney rail network. Equally telling is a spike in mobile data usage that cannot be explained by streaming or downloads, since many infections quietly relay information back to remote servers through the Telstra, Optus, and Vodafone networks that carry Australian mobile traffic.

Other red flags include unfamiliar apps appearing in the app drawer, aggressive pop-up advertisements that surface even when no browser is open, and a noticeable slowdown when opening a banking app. Australian users of CommBank, ANZ, and Westpac have reported strange authorisation requests originating from handsets that had never previously triggered them, which is a strong indicator that something is running in the background. Strange SMS messages containing symbols or premium-rate numbers, as well as friends receiving odd links supposedly sent from the user's account, also point to a compromised device that should be cleaned as soon as possible.

Putting the phone into safe mode

Safe mode is the single most useful tool for cleaning an Android phone without a computer, because it temporarily disables every third-party app while leaving the core operating system intact. Once the handset is in safe mode, the offending software cannot launch, which makes it far easier to identify and uninstall without it fighting back. The exact steps vary slightly between manufacturers, but the general routine is similar across Samsung, Google Pixel, OPPO, and Xiaomi devices sold through Australian retailers.

On most modern Android handsets, holding down the power button brings up the shutdown menu. From there, long-pressing the "Power off" option triggers a prompt asking whether the device should reboot into safe mode. Confirming this option restarts the phone with a small "Safe mode" label in the corner of the screen. Once in this state, the user can navigate to Settings, open Apps, and review what is installed without the malicious program restarting itself after removal. Rebooting the handset normally exits safe mode once the cleanup is complete, returning the device to its usual behaviour.

Scanning with built-in and trusted mobile security apps

Google Play Protect is built into every Android phone that ships with the Play Store and runs a baseline scan of installed applications on a regular schedule. While it is not a substitute for a dedicated scanner, it provides a useful starting point and is worth running manually before adding any extra tool. The option is found under Settings, then Security, and choosing Google Play Protect to force an immediate scan of every app currently installed on the device.

For a deeper sweep, a handful of trusted mobile security suites are available directly through the Play Store, including Malwarebytes, Bitdefender Mobile Security, and Norton Mobile Security. These applications specialise in identifying adware, spyware, banking trojans, and other threats that often slip past basic checks, and they update their definition databases daily. Users who prefer not to clutter their device with extra software can still browse curated security utilities through files, where vetted downloads are sorted for Android handsets. Running a full scan with any of these tools typically takes only a few minutes and produces a clear list of items that need attention before the user moves on to manual removal.

Removing suspicious apps and tightening permissions

After the scan has flagged potential threats, the next step is to uninstall each suspicious application directly from the phone. Returning to Settings, then Apps, and sorting the list by "Last used" or "Installed" often reveals programs the user does not recognise. Tapping the entry, selecting Uninstall, and confirming the removal is usually enough, although some malicious apps request device administrator privileges that block uninstallation entirely. In that case, the privilege must be revoked first through Settings, Security, Device admin apps, before the offending program can be removed properly.

Tightening permissions is just as important as deleting the offending software. Many infections rely on broad access to SMS, contacts, accessibility services, and overlay functions to harvest data or trick the user into approving further installs. Walking through Settings, then Privacy or Permissions manager, and revoking access for any app that does not genuinely need it reduces the attack surface considerably. The Australian Cyber Security Centre regularly reminds users that banking apps in particular should never share accessibility permissions with third-party tools, since that level of access can be used to overlay convincing fake login screens.

Clearing browser hijackers and refreshing the cache

Not every threat lives inside a standalone app, and a surprising amount of malware hides inside the browser itself. Hijacked homepages, unwanted search engines, and persistent pop-ups often come from a small helper program or from cached files left behind after visiting a compromised website. Clearing the browser cache, cookies, and site data is a quick way to remove many of these traces without affecting saved passwords or sign-in sessions.

For users on Chrome, the routine is found under Settings, Privacy and security, Clear browsing data, with a tick beside Cached images, Files, and Cookies before confirming. Samsung Internet users can follow a similar route through Settings, then Privacy, choosing Delete personal data and selecting all available categories. If the homepage has been changed, it should be reset to a trusted option such as google.com.au rather than an unfamiliar search engine. Many Australian ISPs, including Telstra and TPG, publish lists of flagged phishing domains, and avoiding those addresses in the future prevents a repeat of the same infection.

Knowing when a factory reset becomes necessary

Some infections dig so deeply into the operating system that ordinary cleanup simply cannot reach them. A factory reset, which restores the handset to the state it was in when it left the box, is the strongest option available without connecting to a computer. Before triggering this step, it is worth backing up photographs, contacts, and important documents through Google Drive or another trusted cloud service, since the reset erases everything stored locally on the device.

The reset itself is performed through Settings, System, Reset options, and Erase all data (factory reset), and the process usually takes between ten and thirty minutes depending on the amount of stored data. Once complete, the handset restarts into the original setup screen and the malicious software is gone. Restoring apps should be done selectively from the Play Store rather than from an older full backup, since any infection hiding inside that backup would simply return to the device. Severe cases involving stolen financial credentials should also be reported through the Notifiable Data Breaches scheme administered by the Office of the Australian Information Commissioner, particularly where identity theft is suspected. Readers who want a reliable starting point for further reading and curated downloads can always return to the Nairatweaks Media homepage for updated guides.