A slow phone, warm battery, or unexpected advertisement can have ordinary causes. None proves malware on its own. Identifying a harmful Android app is an evidence problem: find what changed, connect the symptom to a specific app or setting, and use more than one independent signal before making a serious claim.
Build a timeline before installing a cleaner
Write down when the problem began and what happened immediately before it. Include apps installed or updated, APK files opened, links tapped, accessibility prompts accepted, and accounts added. Check Settings for recently installed apps and Google Play’s app-management list. A timeline often narrows twenty suspects to two without granting another “security” app broad access.
Look for behavior outside an app’s normal space
Warning signs include ads appearing over the home screen, browser tabs opening by themselves, a launcher icon disappearing, settings repeatedly turning back on, unexplained device-admin or accessibility activation, and prompts asking you to disable Play Protect. Also investigate large background data use, persistent wake activity, or microphone and camera access that appears in Privacy Dashboard when the app’s feature was not in use.
Context matters. A navigation app using location in the background during a trip is expected. A simple flashlight doing the same overnight is not. A single crash or battery spike is weak evidence; repeated behavior tied to one package is stronger.
Check Play Protect and the installation source
Open Google Play, tap your profile, select Play Protect, and run a scan. Keep scanning enabled. Play Protect can examine Play Store apps and apps installed from elsewhere, warn about harmful behavior, and sometimes disable or remove a detected app. A clean result lowers concern but does not prove that an app has good privacy practices.
Identify where every suspect app came from. An APK received through a message, pop-up, unofficial mod site, or shortened link carries more uncertainty than an app obtained from the publisher’s documented store listing. Do not reinstall the same package merely to “test” it.
Audit high-impact access
Review normal permissions and then the less obvious controls: Accessibility, Device admin apps, Notification access, Display over other apps, VPN, Usage access, All files access, and Install unknown apps. Malware commonly seeks powers that help it read screens, intercept alerts, imitate login pages, resist removal, or install additional packages.
Powerful access is not automatic proof. Screen readers, password managers, corporate management tools, and reputable VPNs may need it. The deciding questions are whether you enabled it intentionally, whether it matches the product’s core function, and whether the developer explains it clearly.
Inspect battery, data, and privacy history carefully
Android’s Battery and Mobile data pages can show unusual background activity. Privacy Dashboard records recent use of location, camera, and microphone on supported versions. These tools help correlate time and app name. They cannot tell you what encrypted network traffic contained, and system services may appear under unfamiliar names. Search the exact package or system component before removing anything essential.
Remove a suspected app in the right order
- Disconnect from sensitive sessions if a fake login or financial theft is possible.
- Record the app name, package, source, permissions, and any warning.
- Disable its accessibility service, device-admin role, VPN, overlay, and notification access.
- Uninstall it through Settings.
- Run Play Protect again and restart the phone.
- Review other apps installed on the same date.
If uninstall is blocked, confirm that the phone is not legitimately managed by an employer, school, or parental-control system. Safe Mode can help diagnose third-party interference on many devices, but the key sequence varies by manufacturer. Use the manufacturer’s support instructions rather than guessing.
Protect accounts after removal
If you typed a password, card number, recovery code, or seed phrase into a suspicious screen, cleaning the phone is only half the response. From another trusted device, change affected passwords, revoke sessions, review forwarding rules and recovery details, and contact the financial provider when necessary. Do not reuse a password changed on a device you still believe is being controlled.
When a factory reset is justified
Consider a reset when harmful behavior persists, administrator control cannot be explained, multiple unknown packages return, or high-value accounts were exposed. Back up documents and photos, not questionable APKs or a full set of unknown apps. After the reset, update Android first and reinstall only what you recognize from trusted sources. A reset does not fix an already compromised online account.
Avoid common diagnostic mistakes
- Do not assume every pop-up is a system malware warning; browser notifications often imitate them.
- Do not trust a scanner solely because it reports a dramatic number.
- Do not delete system components based on an unfamiliar name.
- Do not accuse a developer publicly without reproducible evidence.
- Do not grant accessibility, VPN, or all-files access to an unknown “cleaner.”
The most reliable conclusion comes from a chain: suspicious source, inappropriate privilege, repeatable behavior, and corroboration from Android or Play Protect. Treat uncertainty honestly. Removing an unnecessary high-access app is still a reasonable precaution even when you cannot prove malicious code.
Official references
Google describes Play Protect checks and warnings and provides steps for reviewing app permissions.