Spyware operates silently — monitoring keystrokes, capturing screenshots, recording calls, harvesting credentials, and transmitting everything to an attacker without any visible indication that something is wrong. By the time most users suspect a problem, sensitive information has already been exfiltrated. For the bigger picture, our Complete Guide to Online Security and Privacy pulls everything together.
This guide covers how to remove spyware from Windows, Android, and iOS, how to verify the removal was complete, and how to address the credential damage that spyware typically leaves behind. The method depends partly on which type is present — some variants are straightforward to remove through antimalware scanning, while others embed deeply in the OS and require more aggressive intervention.
Identifying the infection first
Spyware is designed to be invisible, but several indicators warrant investigation:
- Unexpected battery drain on mobile devices — background processes continuously transmitting data
- Elevated data usage without corresponding browsing activity — data being exfiltrated
- Device performance degradation — background scanning or recording consuming resources
- Unfamiliar processes in Task Manager (Windows) or Settings → Apps (Android)
- Browser behaviour changes — new homepage, unexplained redirects, added extensions
On Windows: Task Manager (Ctrl+Shift+Esc) → Details tab shows all running processes. Search the exact name of any unfamiliar process online — this reveals whether it’s legitimate system software or a known malicious process. The Startup tab in Task Manager shows programs that run at boot; spyware frequently adds itself here. For the most comprehensive startup persistence review: Autoruns from Microsoft Sysinternals shows everything that executes at startup or login, categorised by registry key, scheduled task, service, and browser extension.
On Android: Settings → Apps → see all apps → review for unfamiliar applications with disproportionate permissions (microphone, camera, location, contacts for no obvious function). Settings → Battery → Battery usage shows which apps consumed significant power in background — unexpected background usage from an unfamiliar app is a strong indicator.
On iOS: Settings → General → VPN & Device Management shows installed profiles that might be used for monitoring. The iOS attack surface is significantly smaller due to App Store controls and sandboxing, but stalkerware that requires device physical access can install monitoring profiles that don’t appear as normal apps.
How to remove spyware from Windows — step by step
- Disconnect from the internet. Severing the network connection stops active data exfiltration while the removal process runs. Disable WiFi and disconnect any ethernet cable before proceeding.
- Restart in Safe Mode. Safe Mode loads only essential system components, preventing most spyware from loading alongside the OS. Hold Shift → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press 4 for Safe Mode. Spyware that loads as a startup service cannot run in Safe Mode, making scanning and removal significantly more effective.
- Run Malwarebytes Free scan. Download from malwarebytes.com (use a clean device to download and transfer via USB if the infected device is disconnected). Run a full scan. Malwarebytes focuses specifically on adware, spyware, PUPs, and rootkits alongside general malware. Quarantine all findings.
- Run Windows Defender Offline Scan. Windows Security → Virus & threat protection → Scan options → Microsoft Defender Antivirus (offline scan) → Scan now. This runs before Windows loads, from a protected environment, catching rootkit-level spyware that hides from on-system scanners.
- Run ESET Online Scanner. A second-opinion scanner from a different engine catches variants that Malwarebytes or Defender may classify differently. Download from eset.com, run a full scan, quarantine findings.
- Review and remove startup persistence (Autoruns). After scanning: open Autoruns (Sysinternals) → review each tab (Logon, Scheduled Tasks, Services, Browser Extensions) → research any unfamiliar entries → right-click → Delete for confirmed malicious entries. This removes the persistence mechanism that would reinstall spyware on next boot even after main files are quarantined.
- Change all credentials after removal. Once the device is confirmed clean, change every password — especially for accounts accessed during the infection period. Use a device confirmed clean to change credentials; changing passwords on the infected device while spyware is potentially still present serves no protective purpose. Enable 2FA on every account that supports it.
Step 7 — changing all credentials — is the most important recovery action after removing spyware, because the primary damage of most spyware is credential theft. The removal stops future data collection; credential rotation limits damage from what was already collected. Credentials harvested during the infection period are potentially in attacker hands regardless of when the spyware is removed — changing them neutralises the stolen data’s value. Our guide on preventing account takeover covers the comprehensive credential remediation that follows an infection.
Tool comparison — why multiple scanners are not redundant
| Tool | Best for | Scan depth | Cost |
| Malwarebytes Free | Adware, stalkerware, PUPs, infostealers | Deep — dedicated spyware detection | Free |
| Windows Defender Offline Scan | Rootkits, persistent kernel-level spyware | Maximum — pre-OS boot scan | Free (built-in) |
| ESET Online Scanner | Second opinion — catches Defender misses | Deep — full disk scan | Free |
| Kaspersky TDSSKiller | Rootkit-specific spyware | Deep — rootkit-focused | Free |
| Autoruns (Sysinternals) | Persistence mechanisms of any spyware type | Comprehensive startup audit | Free |
| HitmanPro | Persistent infections — cloud-based multi-engine scanning | Deep — multi-engine cloud scan | Free trial / ~$25/year |
Different scanners use different signature databases and heuristic engines. A piece of spyware that evades Malwarebytes may be caught by ESET, and a rootkit that hides from on-system scanners is found by the Offline Scan that runs before Windows loads. Running the free three (Malwarebytes, Defender Offline, ESET Online Scanner) sequentially provides overlapping coverage that catches the variants each individual scanner misses.
How to remove spyware from Android
- Boot in Safe Mode. On most Android devices: hold the power button → press and hold “Power off” → tap “OK” when prompted for Safe Mode. This disables third-party apps, preventing spyware from running. The exact method varies by manufacturer — search for “[Your phone model] Safe Mode” for the specific steps.
- Review installed apps. Settings → Apps → see all apps. Tap each unfamiliar app and note its permissions. Uninstall any app you don’t recognise or that has permissions disproportionate to any obvious function.
- Revoke suspicious permissions. Settings → Privacy → Permission manager → work through Microphone, Camera, Location, and Contacts. Remove access from any app that doesn’t have a clear functional need.
- Check Device Administrator access. Settings → Security → Device admin apps. Spyware that has been granted Device Administrator status cannot be uninstalled through normal means — revoke the admin status here first, then uninstall.
- Factory reset if removal is incomplete. If spyware persists after the steps above: back up important data to a cloud service or clean external device, then Settings → General management → Reset → Factory Data Reset. This is the definitive removal for deeply embedded Android spyware.
How to remove spyware from iOS
iOS spyware is far less common due to App Store controls and sandboxing. When it does exist:
- Remove suspicious configuration profiles: Settings → General → VPN & Device Management → review all listed profiles → remove any not installed by a known organisation (your employer’s MDM, your school’s WiFi profile). Malicious profiles are the most common iOS spyware installation mechanism.
- Update iOS immediately: some spyware exploits iOS vulnerabilities patched in updates. Settings → General → Software Update. Update to the latest version.
- Sign out and back into Apple ID if account compromise is suspected.
- Factory reset as definitive removal: Settings → General → Transfer or Reset iPhone → Erase All Content and Settings. Set up as a new phone rather than restoring from backup to prevent reinstalling spyware hidden in backup data.
Stalkerware — the safety-critical removal scenario
Commercial stalkerware apps marketed as parental controls or employee monitoring tools — mSpy, FlexiSPY, Hoverwatch, and similar — are sold legally but frequently installed on adult partners’ devices without consent. They function identically to criminal spyware: recording calls, capturing messages, tracking location, logging keystrokes. The technical removal process follows the same Safe Mode uninstall steps above, but with a critical additional consideration.
Some stalkerware products send removal alerts to the monitoring party. If the monitoring situation involves a safety risk, removing the app visibly may escalate the situation before the person is in a safe position to do so. The Coalition Against Stalkerware (stopstalkerware.org) and domestic violence organisations provide specific guidance on how to remove stalkerware safely in these circumstances — including whether the risk of removal notification outweighs the benefit of continued monitoring awareness.
Technical remediation must be weighed against personal safety in this specific scenario. Our guide on avoiding phishing scams covers the delivery-layer prevention for the most common spyware distribution method, and our guide on removing malware from Windows covers the general malware removal process that this guide’s spyware-specific steps complement. For the NCSC’s guidance on identifying and addressing stalkerware, the NCSC’s stalkerware guidance covers both the technical and personal safety dimensions in detail.
Prevention — closing the vectors that allowed this infection
Spyware primarily arrives through:
- Phishing — malicious email attachments or links
- Drive-by downloads from compromised websites
- Software bundled with free downloads (unofficial game cracks, free software download sites, torrent files)
- For mobile devices: apps sideloaded from outside official app stores; or through physical device access by the stalkerware installer
The removal process cleans the current infection. Preventing recurrence requires: download software only from official sources; apply phishing awareness before clicking any unexpected link or opening any attachment; keep OS and application software updated; run Windows Defender’s Tamper Protection (Windows Security → Virus & threat protection settings → Tamper Protection → On) which prevents malware from disabling security software.
After completing the removal steps, the goal is a device both clean and configured to resist the next infection attempt through the same vectors that allowed the current one.
What spyware was actually doing — understanding the damage scope
Different spyware types cause different categories of damage. Understanding which type was present helps prioritise the post-removal response:
| Spyware type | What it typically collected | Priority post-removal action |
| Keylogger | Every keystroke — passwords, messages, credit card numbers typed during infection | Change all passwords; cancel and replace any payment cards used during infection period |
| Infostealer (Redline, Raccoon, etc.) | Browser-saved passwords, session cookies, cryptocurrency wallet files, authentication tokens | Change all passwords; log out all active sessions on all accounts; check for fraudulent activity |
| Stalkerware | Location history, messages, calls, photos, contacts — often over an extended period | Safety planning first; then remove per above process; change account passwords attacker may have seen |
| Adware/browser hijacker | Browsing history, search queries, form data — lower credential risk | Browser extension audit; clear cookies and cache; check saved passwords for any captured |
| RAT (Remote Access Trojan with spyware component) | Potentially everything — screen recording, file access, camera, microphone | Full credential rotation; check for uploaded files; review cloud storage for unauthorised access |
The infostealer category is the one that most frequently produces immediate account takeover in the hours and days following infection — session cookie theft in particular allows attackers to access accounts without needing the password, bypassing 2FA in some cases. For infostealer infections specifically: after changing passwords, actively check active sessions on all accounts (especially Google, Microsoft, financial, and social media) and terminate all sessions except the current trusted device. This closes access that cookie theft may have granted.
When to wipe and reinstall rather than scan and clean
For particularly persistent infections — spyware that reinstalls after removal, rootkits that survive scanning, or infections on a device that handles highly sensitive data — a clean reinstall is more reliable than any cleaning process:
- Windows: create a fresh Windows installation USB using the Media Creation Tool from Microsoft → boot from USB → wipe the drive during installation setup → reinstall from scratch. Do not restore from a backup made after the infection date — restore only personal files (documents, photos) not system or application data.
- Android: factory reset followed by setting up as a new phone (not from backup). Restore contacts and files from cloud sync rather than a device backup.
- iOS: factory reset and set up as new. Restore individual app data from iCloud as needed, but set up the phone fresh rather than restoring from an encrypted iPhone backup which might include malicious profiles.
A clean reinstall takes 1–2 hours longer than the scanning approach but provides certainty rather than confidence. For devices that handled financial data, work credentials, or any other high-value information during the infection period, the certainty is worth the time investment.
Removing spyware is a two-phase process: the technical removal (scanning, quarantining, persistence deletion) and the credential remediation (changing passwords, revoking sessions, monitoring for fraud). Both phases are necessary. The removal stops the bleeding; the credential work addresses the damage already done.







