How to kill Trojan in Android 4. How to remove viruses from android? Smartphone scan through computer

Recently, the question of how to remove the virus from the Android phone becomes relevant.

This article provides examples of the most common malicious programs and methods for their rapid and safe neutralization.

Each type of malicious software has its own characteristics and properties ,.

Consider the main types of pest programs faced by users and effective ways to remove them.

Tip! Regularly check the device for malicious utilities and spyware using such programs as 360 Security. Dr. Web, Kaspersky, Lookout. They have the most extensive database of malware for the Android system.

Removal of Trojan

This type of malicious in the most popular. You can find Troyan in almost any device, the amount is so great.

It can encrypt his actions under the guise of another program and at the same time send in the invisible mode paid SMS on third-party numbers.

The Troyan can also steal the numbers of your credit cards and passwords recorded anywhere on the device: in SMS messages, notes, special storage programs.

To get rid of Troyan, follow these actions:

  1. Scan the device for spyware and malicious software, for example, using the Lookout program, as shown in the figure.
  1. Delete suspicious programs found. Such two simple actions are enough to neutralize and remove the Trojan with Android.

Removal of advertising virus

This type of malicious software is also very common, however, in contrast to Trojan, it is not aimed at harming the device and extortion of funds, but on earnings with the help of advertising.

It is not necessary to delete the application due to which advertising appears.

Several ways to solve the problem:

  1. Turning on the regime "on the plane". In this mode, the Internet and other types of compound are disabled, so advertising does not load and is not displayed. Such an option The problem is suitable for games and applications, to work with which the Internet does not need.
    To enable the mode, hold the power button and in the window that appears, select the desired type of action, as shown in the figure;

  1. Delete with scanning. Scan the phone for threats, advertising is defined almost always, so it will not be difficult to remove them.

Removing malicious banner

This type of malicious software blocks all the functions of the phone and extorts the payment of money for the shutdown of the blocker banner.

Often this type of malicious software is found on all phones.

Tip! If your phone or tablet has been infected with this type of malicious software, immediately get the SIM card, until your account has been removed a large amount.

The infected program can be easily eliminated in a few steps:

  1. Turn off the device and fully charge it;
  2. Turn on the device. All subsequent actions need to be made as quickly as possible until the banner-extortionist appeared;
  3. Go to the settings (section for developers);

  1. Turn on the debug mode using USB;

If malicious code has been discovered on your smartphone, then you need to get rid of it urgently. After all, Trojans received their name for the principle of operation - they are introduced into the system, and then act as a transmitter, transmitting the owner of the virus information about your actions in the smartphone and confidential information. Therefore, tell me how to remove the Trojan from the phone android.

We remove the Trojan with the help of special antivirus programs

For the phone, many applications are released to combat viral attacks. Manufacturers recommend that you have to install the antivirus so that you have protection from the introduction of malicious code. If you are looking for an answer to the question, how to remove the Trojan virus from the phone, then most likely you have not previously stood a protective utility or you chose poor-quality software. We give examples of tested time and users and tell about working with them.

Anti-Malware.

This utility is well known to users of computers, for smartphones an analog appeared relatively recently. You can download it from the Application Store or the developer's official website. After the first launch, do the following:

  • agree with the terms of use of the utility;
  • enter the scan menu;
  • run the check;
  • wait for results.

The utility finds all malicious codes on your phone, as well as traces of their activities (damaged files and other). Automatically you will be prompted to clean your smartphone. After solving the problem, how to remove Trojan from android without root, the program will remain useful for you. It in real time will protect the phone from threats from outside, including from careless actions of the user (the transition is blocked by dubious links).

Trojan Killer.

A simple program is not to resolve the question how to remove Trojan from Android. Geoluxis (Virus introduced into the geolocation system), for example, it is almost impossible to remove antiviruses, except those that are narrowly directed. In this case, try apply Trojan Killer. It is necessary to use it according to the instructions:

  • find this utility at Play Market and install it on your smartphone;
  • in the Application menu, locate the program icon and click on it;
  • run the scan from the main screen;
  • remove each detected Trojan with a green button to the right of its name.

This program will not protect you in real time, but it will not take much space on the smartphone and masterfully copes with the most dangerous forks of malicious codes.

Manual removal of Trojan

If when you re-scan after cleaning the phone, you again found a Trojan, then it is necessary to remember its location to remove manually. In this case, the operation, how to remove the Trojan from the phone, can be performed in two ways.

Use the file manager

In this case, you will need to download, which displays hidden files. After installing it, you must select the instruction in accordance with the location of Trojan:

  1. The virus is among the stored information in the memory of the smartphone. In this case, it is enough to find and remove the malicious code. The user will not even need root.
  2. Troyan is located in the folders associated with the operation of the system. Deleted only if the superuser's rights are available.
  3. An ordinary application is infected. Delete it through the settings menu.
  4. The malicious code damaged the system utility - stop it in the Task Manager, and then erase using the root ticket.

After manually deletion, check the status of the phone with an anti-virus utility. This will allow you to get rid of additional vulnerabilities.

How to remove a trojan from the phone using a computer

Remove the Trojan from the phone through the computer in two ways. Before each you need to connect the smartphone to the device in the USB process. Then act in one way:

  1. Check the device using a computer antivirus. As a rule, this software more perfectly and has extensive bases in which there are records of the newest and most complex variants of malicious code.
  2. Manually locate the folder with the virus and delete it. Often, trojans are stored hidden and protected from removal. To find a malicious code, use the Total Commander's computer program, and switch from removal using Unlocker.

After completing the work, restart the smartphone and check it again by the anti-virus utility. In most cases, you get rid of the virus.

What if the Trojan is not deleted?

If all your efforts have not led to success, then solve the problem, how to remove the Trojan from the Android phone, you can use extreme measures. Important photos and videos Save on the cloud disk (if the virus is not hidden among them), and then use sequentially - resetting the settings and flashing if the first method did not help.

Reset

Hard reset can be done through the usual or system menu.

  1. In the first case, you will need to find in the settings "Restore and Reset". Click on it and agree with the conditions. The phone after the reboot will return to its original state, even the device and operating system updates are deleted. After loading the phone, it will be necessary to wait for the time that the device automatically downloads the necessary files and configured. Do not hurry to set your applications, first download the antivirus and check the condition of the device.
  2. The second version of the discharge is carried out during the reboot of the smartphone. As soon as the start screen appears, press the power keys simultaneously and reduce the volume. If everything is done correctly, you will fall into recovery mode. Using the power and volume keys, find the Hard Reset in this menu, confirm your choice.

After resetting the settings, you will have to re-enter your Google account, but all applications you need will be restored automatically.

Refracting

If all the methods described above did not help, only devices can help you. People who are not familiar with this procedure are best to apply to change the firmware in service centers or more experienced users. If in the process of shifting something will go wrong, your smartphone turn into a useless piece of plastic.

These are all ways to remove Trojan from Android. If you know other methods of solving this problem, share with us in the comments. This article may be useful to your friends, share it with them.


Sometimes, with the usual use of programs, the user faces unexpected difficulties. In some cases, these are pop-ups about a possible threat from third-party files. This material will talk about the dangerous family of viruses "HEUR: Trojan", which often signals Sberbank online. We will show how to remove malware androidos.agent.eb, androidos.dropper, downloader.script.generic, win32.generic, win32.banker and other similar.

What are these viruses?

The HEUR: Trojan family is the most dangerous of modern viruses on Android, iOS and Windows, which is characterized by an extended functionality, deep penetration, and hence the increased level of threat to the user.

These malware are made through the smartphone or PC system files, cloning with an unprecedented speed, can also be masked for ordinary files, processes and innocuous applications.

Unfortunately, due to the evolution of malicious software, antiviruses can not always warn the owner of the threat of the downloaded file or the page being visited, which causes the distribution of such an infection. Modern systems are protected by administrator rights, however, and this moment viruses are able to bypass.

From popular "opportunities" HEUR: Trojan allocate:

  1. Mailing messages to paid rooms, confirmation of paid subscriptions to pull funds from the balance of the account.
  2. Theft of personal data, including passwords from financial resources, bank card numbers with all the resulting.
  3. Penetration directly into Internet banking programs, electronic wallets for the unimpeded translation of funds on third-party accounts.

Sounds quite terrifyingly, isn't it? It pleases one thing - this variation of the virus already recognizes most of the Kaspersky, Eset, Dr.Web, NOD, AVAST and others anti-virus programs.

Protection of Sberbank online, for example, at the entrance to the system, Identifies the attempt to penetrate, offering to remove the virus. However, it is not necessary to rejoice ahead of time - such removal will not lead to the complete destruction of the virus.

Trojan.androidos detected by Sberbank Online

What viruses are there

If we talk, about the possible reasons for the appearance of malware, then everything is simple - a banal negligence on the network:

  1. Downloading pirated versions of games, other APK files on a smartphone with third-party resources.
  2. Visit to dubious Web sites with many pictures, gif images and hyperlinks. In this case, the downloading of the virus can be activated by accidentally pressing, in the background.
  3. File sharing with already infected users - via Bluetooth, clouds and similar services.
  4. Go to the links in the sending spam on the mail or in SMS.

From the popular HEUR variations: Trojan allocate:

  • Androidos.Agent.eb or Androidos.boogr.gsh - establishes a special utility that implements advertising into all other applications. Used for monetization due to similar impressions.
  • Downloader.androidos.Agent - SMS virus used for paid subscriptions and sending messages to tariff numbers.
  • Script.generic.miner.gen - the sale of user traffic, download and redirect files (significantly slows down and Internet connection).

There is also a Win32.Genic type - this is a file under suspicion of a viral system. Even official applications may include such a type, in the code of which are detected tracking or intercepting information scripts.

How to remove HEUR: Trojan.androidos and those like him?

The basic proposal to "delete" from the same Sberbank, as already mentioned, is not enough - but it is not necessary to worry about the complexity of the manipulations carried out. To solve the problem, standard scanners from Dr.Web, Avg or Kaspersky will be suitable. The versions of these programs are both for PC and for mobile OS.

Follow the simplest instructions:


Next - just choose "Delete" for all suspicious items. It is more efficient than "treated" files, since the virus may have time to spread to other system compartments. If you are denied access, then:

Conclusion

We recommend you more skeptically refer to "free" versions of original applications. It is better to spend a few dollars and buy a "license" than to spend tens due to the action of malicious utilities, sending paid SMS. Also, after deletion, I recommend updating passwords, turn on double authentication.

If you have difficulty, with threats of type Androidos.Agent.eb and nothing happened in removal - write below in the comments, try to help you.

Delete a malicious code that fell into the gadget with any application or through the browser from the network, it is possible in different ways. Sometimes it is enough to install a simple free mobile antivirus and clean the system to them, sometimes these actions do not lead to the expected result. Let's later tell you how to remove the virus from android in various ways, safe for your device.

Search and remove malware with antivirus

This is the easiest way to clean the phone from a malicious code, but it helps it no more than 40% of cases of infection. Nevertheless, it is necessary to start working to restore the performance of the system. List the most effective:

This simple way does not always allow you to get rid of a malicious utility. Sometimes it is simply not detected by the scanner, sometimes a remote application is already managed to recover spontaneously. In some cases, in the smartphone, individual functions can continue to remain inaccessible after cleaning. If such problems occurs, the transfer of the gadget to the safe mode and the test of its anti-virus utility is often helped.

Removing malicious code in safe mode

Most of the programs in this operation does not interfere with the operation of scanners. Therefore, we describe how to remove the virus or Trojan from the Android in Safe Mode, since going to it to get rid of maliciousness from the Android phone it turns out in a much greater number of cases. But for this you need to know what to do to go to the safe device of the device with version 4.0 and above:

  1. Press and hold the "POWER" button on the device until the shutdown window appears;
  2. Keep your finger on the touch button "Disconnect the device" of this window until the gadget transition appears to the desired mode, click OK.

If your device is controlled by an Android version below 4.0, then the order of the transition to Safe Mode will be different:

  1. Turn off the device completely and then click again on the power button;
  2. When displaying the company's logo, hold the rocker to zoom in and reducing the volume until the OS is fully loaded.

Going to a secure mode, download one of the above antiviruses above and scan the gadget. After that, to go to the usual operating mode, you reboot the device.

Removing malicious code through a PC or laptop

Catch the Troyan on Android through the browser. We describe how to remove it from the system. Sometimes the installation of a mobile security application and scanning them, even in safe mode, remove malware does not work. In this case, the task can be solved by the desktop utility by scattering it a gadget through a computer. The cleaning system is performed as follows:

It will only remain to run the scanning, after which the powerful desktop application with huge bases is likely to find the trolar on the device and remove the virus from the phone.

Mobile browsers for the most part are not equipped with modules of the blocking of advertising, so when they are used, the probability is randomly pressing on the graphics banner, which is unnoticed for you to load a viral file. After that, during the work of the device, advertising banners may appear at the most unexpected moment.

Remove the virus from a tablet or smartphone in this case manually can be manually via the Android Commander application (http://android-commander.ru.uptodown.com/windows), which shall exchange files between the PC and the gadget.

True, it will require root-rights and enabled debugging by USB (to enable the option, go to the "Parameters" section of your device, hereinafter - "System" and "Developer Settings").

  1. Connect the android device to the computer as a drive.
  2. Run Android Commander on a laptop or PC on behalf of the administrator. Using this application, you can control in all. Mobile OS system files that the usual Windows conductor does not see.
  3. Among the system directories, find the folder with executable files (with the APK extension), remove the infected file or move it to the computer disk, where you can remove the virus from the file by any specialized scanner.

If the virus cannot be deleted

If it is impossible to solve the problem described in the described methods, consider how to remove system flashing viruses. In this case, together with all malware, user data will be deleted, therefore this method is the most radical. We describe the Hard Reset procedure on the example of Samsung devices.

The phone is no less than the computer are subject to attacks. In this regard, we learn how to independently remove the Trojan from the phone on the Android platform if infected occurred.

How to recognize the presence of Trojan

The fact that the malicious program settled on the smartphone indicates the following:

  • advertising banners;
  • independent download and installation of applications;
  • sudden loss of access to internal or external memory;
  • fast discharge and heating of the smartphone;
  • SMS mailing to foreign numbers.

If such problems are observed, measures must be taken.

Removal with utilities

You can use special programs. Here are examples of a suitable software.

Antivirus

Conventional antivirus programs are likely to solve the problem. Download Antivirus from Google Play and scan the device.

Anti-Malware.

You can download here https://play.google.com/store/apps/details?id\u003dorg.malwarebytes.antimalware&hl\u003dru, the program removes the available infection and protects from new ones. Changes with the most difficult situations.

Trojan Killer.

Download from here https://play.google.com/store/apps/details?id\u003dcom.cleanmaster.security.stubborntrjkiller&hl\u003dru. Removes even "stubborn" trojans.

Lookout

Removing the virus manually

You can delete the Trojan program from Android and manually, for this you can use the computer or cope with the forces of the smartphone.

Through the file manager

You must track the malicious product through the file manager and delete it. To do this, go to the gadget settings and open the Application Manager. In the Launched Application tab, find Troyan. Then open the root folder.apk and delete. Restart your smartphone.

Through PC

Antiviruses on the PC are designed to fight stronger threats. Therefore, the computer program will easily cope with malicious programs on the smartphone.

  1. Enable USB debugging on the device and connect it from PC.
  2. Once the PC recognizes the device, scan it using an antivirus.
  3. Correct the threats found.

Despite the difference in the code, the desired result will be obtained.

Reset to factory settings

If you remove the Trojan from the Android described above, you cannot roll back the device to factory settings. In the configuration menu, open the "Restore and Reset" section and select the Data Reset command.