Skip to content
How‑To Guides

How to Remove Spyware From Windows, Android, and iOS

How to remove spyware requires multiple tools and credential rotation after cleanup. Here is the complete step-by-step guide for Windows, Android, and iOS devices.

How to Remove Spyware From Windows, Android, and iOS

Spyware operates silently — monitoring keystrokes, capturing screenshots, recording calls, harvesting credentials, and transmitting everything to an attacker without any visible indication that something is wrong. By the time most users suspect a problem, sensitive information has already been exfiltrated. For the bigger picture, our Complete Guide to Online Security and Privacy pulls everything together.

This guide covers how to remove spyware from Windows, Android, and iOS, how to verify the removal was complete, and how to address the credential damage that spyware typically leaves behind. The method depends partly on which type is present — some variants are straightforward to remove through antimalware scanning, while others embed deeply in the OS and require more aggressive intervention.

Identifying the infection first

Spyware is designed to be invisible, but several indicators warrant investigation:

  • Unexpected battery drain on mobile devices — background processes continuously transmitting data
  • Elevated data usage without corresponding browsing activity — data being exfiltrated
  • Device performance degradation — background scanning or recording consuming resources
  • Unfamiliar processes in Task Manager (Windows) or Settings → Apps (Android)
  • Browser behaviour changes — new homepage, unexplained redirects, added extensions

On Windows: Task Manager (Ctrl+Shift+Esc) → Details tab shows all running processes. Search the exact name of any unfamiliar process online — this reveals whether it’s legitimate system software or a known malicious process. The Startup tab in Task Manager shows programs that run at boot; spyware frequently adds itself here. For the most comprehensive startup persistence review: Autoruns from Microsoft Sysinternals shows everything that executes at startup or login, categorised by registry key, scheduled task, service, and browser extension.

On Android: Settings → Apps → see all apps → review for unfamiliar applications with disproportionate permissions (microphone, camera, location, contacts for no obvious function). Settings → Battery → Battery usage shows which apps consumed significant power in background — unexpected background usage from an unfamiliar app is a strong indicator.

On iOS: Settings → General → VPN & Device Management shows installed profiles that might be used for monitoring. The iOS attack surface is significantly smaller due to App Store controls and sandboxing, but stalkerware that requires device physical access can install monitoring profiles that don’t appear as normal apps.

How to remove spyware from Windows — step by step

  1. Disconnect from the internet. Severing the network connection stops active data exfiltration while the removal process runs. Disable WiFi and disconnect any ethernet cable before proceeding.
  2. Restart in Safe Mode. Safe Mode loads only essential system components, preventing most spyware from loading alongside the OS. Hold Shift → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press 4 for Safe Mode. Spyware that loads as a startup service cannot run in Safe Mode, making scanning and removal significantly more effective.
  3. Run Malwarebytes Free scan. Download from malwarebytes.com (use a clean device to download and transfer via USB if the infected device is disconnected). Run a full scan. Malwarebytes focuses specifically on adware, spyware, PUPs, and rootkits alongside general malware. Quarantine all findings.
  4. Run Windows Defender Offline Scan. Windows Security → Virus & threat protection → Scan options → Microsoft Defender Antivirus (offline scan) → Scan now. This runs before Windows loads, from a protected environment, catching rootkit-level spyware that hides from on-system scanners.
  5. Run ESET Online Scanner. A second-opinion scanner from a different engine catches variants that Malwarebytes or Defender may classify differently. Download from eset.com, run a full scan, quarantine findings.
  6. Review and remove startup persistence (Autoruns). After scanning: open Autoruns (Sysinternals) → review each tab (Logon, Scheduled Tasks, Services, Browser Extensions) → research any unfamiliar entries → right-click → Delete for confirmed malicious entries. This removes the persistence mechanism that would reinstall spyware on next boot even after main files are quarantined.
  7. Change all credentials after removal. Once the device is confirmed clean, change every password — especially for accounts accessed during the infection period. Use a device confirmed clean to change credentials; changing passwords on the infected device while spyware is potentially still present serves no protective purpose. Enable 2FA on every account that supports it.

Step 7 — changing all credentials — is the most important recovery action after removing spyware, because the primary damage of most spyware is credential theft. The removal stops future data collection; credential rotation limits damage from what was already collected. Credentials harvested during the infection period are potentially in attacker hands regardless of when the spyware is removed — changing them neutralises the stolen data’s value. Our guide on preventing account takeover covers the comprehensive credential remediation that follows an infection.

Tool comparison — why multiple scanners are not redundant

ToolBest forScan depthCost
Malwarebytes FreeAdware, stalkerware, PUPs, infostealersDeep — dedicated spyware detectionFree
Windows Defender Offline ScanRootkits, persistent kernel-level spywareMaximum — pre-OS boot scanFree (built-in)
ESET Online ScannerSecond opinion — catches Defender missesDeep — full disk scanFree
Kaspersky TDSSKillerRootkit-specific spywareDeep — rootkit-focusedFree
Autoruns (Sysinternals)Persistence mechanisms of any spyware typeComprehensive startup auditFree
HitmanProPersistent infections — cloud-based multi-engine scanningDeep — multi-engine cloud scanFree trial / ~$25/year

Different scanners use different signature databases and heuristic engines. A piece of spyware that evades Malwarebytes may be caught by ESET, and a rootkit that hides from on-system scanners is found by the Offline Scan that runs before Windows loads. Running the free three (Malwarebytes, Defender Offline, ESET Online Scanner) sequentially provides overlapping coverage that catches the variants each individual scanner misses.

How to remove spyware from Android

  1. Boot in Safe Mode. On most Android devices: hold the power button → press and hold “Power off” → tap “OK” when prompted for Safe Mode. This disables third-party apps, preventing spyware from running. The exact method varies by manufacturer — search for “[Your phone model] Safe Mode” for the specific steps.
  2. Review installed apps. Settings → Apps → see all apps. Tap each unfamiliar app and note its permissions. Uninstall any app you don’t recognise or that has permissions disproportionate to any obvious function.
  3. Revoke suspicious permissions. Settings → Privacy → Permission manager → work through Microphone, Camera, Location, and Contacts. Remove access from any app that doesn’t have a clear functional need.
  4. Check Device Administrator access. Settings → Security → Device admin apps. Spyware that has been granted Device Administrator status cannot be uninstalled through normal means — revoke the admin status here first, then uninstall.
  5. Factory reset if removal is incomplete. If spyware persists after the steps above: back up important data to a cloud service or clean external device, then Settings → General management → Reset → Factory Data Reset. This is the definitive removal for deeply embedded Android spyware.

How to remove spyware from iOS

iOS spyware is far less common due to App Store controls and sandboxing. When it does exist:

  • Remove suspicious configuration profiles: Settings → General → VPN & Device Management → review all listed profiles → remove any not installed by a known organisation (your employer’s MDM, your school’s WiFi profile). Malicious profiles are the most common iOS spyware installation mechanism.
  • Update iOS immediately: some spyware exploits iOS vulnerabilities patched in updates. Settings → General → Software Update. Update to the latest version.
  • Sign out and back into Apple ID if account compromise is suspected.
  • Factory reset as definitive removal: Settings → General → Transfer or Reset iPhone → Erase All Content and Settings. Set up as a new phone rather than restoring from backup to prevent reinstalling spyware hidden in backup data.

Stalkerware — the safety-critical removal scenario

Commercial stalkerware apps marketed as parental controls or employee monitoring tools — mSpy, FlexiSPY, Hoverwatch, and similar — are sold legally but frequently installed on adult partners’ devices without consent. They function identically to criminal spyware: recording calls, capturing messages, tracking location, logging keystrokes. The technical removal process follows the same Safe Mode uninstall steps above, but with a critical additional consideration.

Some stalkerware products send removal alerts to the monitoring party. If the monitoring situation involves a safety risk, removing the app visibly may escalate the situation before the person is in a safe position to do so. The Coalition Against Stalkerware (stopstalkerware.org) and domestic violence organisations provide specific guidance on how to remove stalkerware safely in these circumstances — including whether the risk of removal notification outweighs the benefit of continued monitoring awareness.

Technical remediation must be weighed against personal safety in this specific scenario. Our guide on avoiding phishing scams covers the delivery-layer prevention for the most common spyware distribution method, and our guide on removing malware from Windows covers the general malware removal process that this guide’s spyware-specific steps complement. For the NCSC’s guidance on identifying and addressing stalkerware, the NCSC’s stalkerware guidance covers both the technical and personal safety dimensions in detail.

Prevention — closing the vectors that allowed this infection

Spyware primarily arrives through:

  • Phishing — malicious email attachments or links
  • Drive-by downloads from compromised websites
  • Software bundled with free downloads (unofficial game cracks, free software download sites, torrent files)
  • For mobile devices: apps sideloaded from outside official app stores; or through physical device access by the stalkerware installer

The removal process cleans the current infection. Preventing recurrence requires: download software only from official sources; apply phishing awareness before clicking any unexpected link or opening any attachment; keep OS and application software updated; run Windows Defender’s Tamper Protection (Windows Security → Virus & threat protection settings → Tamper Protection → On) which prevents malware from disabling security software.

After completing the removal steps, the goal is a device both clean and configured to resist the next infection attempt through the same vectors that allowed the current one.

What spyware was actually doing — understanding the damage scope

Different spyware types cause different categories of damage. Understanding which type was present helps prioritise the post-removal response:

Spyware typeWhat it typically collectedPriority post-removal action
KeyloggerEvery keystroke — passwords, messages, credit card numbers typed during infectionChange all passwords; cancel and replace any payment cards used during infection period
Infostealer (Redline, Raccoon, etc.)Browser-saved passwords, session cookies, cryptocurrency wallet files, authentication tokensChange all passwords; log out all active sessions on all accounts; check for fraudulent activity
StalkerwareLocation history, messages, calls, photos, contacts — often over an extended periodSafety planning first; then remove per above process; change account passwords attacker may have seen
Adware/browser hijackerBrowsing history, search queries, form data — lower credential riskBrowser extension audit; clear cookies and cache; check saved passwords for any captured
RAT (Remote Access Trojan with spyware component)Potentially everything — screen recording, file access, camera, microphoneFull credential rotation; check for uploaded files; review cloud storage for unauthorised access

The infostealer category is the one that most frequently produces immediate account takeover in the hours and days following infection — session cookie theft in particular allows attackers to access accounts without needing the password, bypassing 2FA in some cases. For infostealer infections specifically: after changing passwords, actively check active sessions on all accounts (especially Google, Microsoft, financial, and social media) and terminate all sessions except the current trusted device. This closes access that cookie theft may have granted.

When to wipe and reinstall rather than scan and clean

For particularly persistent infections — spyware that reinstalls after removal, rootkits that survive scanning, or infections on a device that handles highly sensitive data — a clean reinstall is more reliable than any cleaning process:

  • Windows: create a fresh Windows installation USB using the Media Creation Tool from Microsoft → boot from USB → wipe the drive during installation setup → reinstall from scratch. Do not restore from a backup made after the infection date — restore only personal files (documents, photos) not system or application data.
  • Android: factory reset followed by setting up as a new phone (not from backup). Restore contacts and files from cloud sync rather than a device backup.
  • iOS: factory reset and set up as new. Restore individual app data from iCloud as needed, but set up the phone fresh rather than restoring from an encrypted iPhone backup which might include malicious profiles.

A clean reinstall takes 1–2 hours longer than the scanning approach but provides certainty rather than confidence. For devices that handled financial data, work credentials, or any other high-value information during the infection period, the certainty is worth the time investment.

Removing spyware is a two-phase process: the technical removal (scanning, quarantining, persistence deletion) and the credential remediation (changing passwords, revoking sessions, monitoring for fraud). Both phases are necessary. The removal stops the bleeding; the credential work addresses the damage already done.

Nikolas Lamprou

Nikolas Lamprou (MSc; GCFR, SC-200, Security+) has been working with computers professionally since 2009 — starting with web development and e-commerce, and moving into cybersecurity over the years. Based in Greece, he brings over 15 years of real-world IT experience to SolveTechToday, where he writes about Windows fixes, software reviews, security tools, and AI applications. His goal is straightforward: cut through the noise and give readers clear, honest guidance on the tech decisions that matter.

Stay Ahead

Fix your next problem before it starts

Get the week's best Windows fixes, software picks, and security guides delivered straight to your inbox. No noise, just solutions.

Press ESC to close · Try "Windows 11" or "Chrome"