Your smartphone began to slow down, show annoying ads in unexpected places or discharge suspiciously quickly? Most likely, the system has adware or malware. According to data Kaspersky for 2026, every third Android user has at least once encountered a device infection through third-party applications or phishing sites. But donโt rush to take your phone to a service center - in 90% of cases the problem can be solved on your own.
In this article we will look at all possible sources of infection: from hidden advertising SDKs in free games to Trojans masquerading as system updates. You'll learn how to identify threats, remove them manually or using specialized tools, and how to protect your device from re-infection. We will pay special attention hidden mechanismsthat scammers use to bypass standard security measures - for example, how adware can recover after a reboot or masquerade as legitimate services Google Play.
Important: if your smartphone is locked ransomware or demands payment for unlocking - donโt pay! In most cases, data can be recovered without loss, and payment will only confirm the functionality of the scammersโ scheme. We will also talk about this in the appropriate section.
Signs of infection: how to recognize viruses and adware
The first step to cleaning is correct diagnosis. Many users confuse system lags (for example, due to overloaded memory) with viral activity, or vice versa - they ignore obvious signs of infection, attributing them to โAndroid glitches.โ Here are the key symptoms that should alert you:
- ๐ฑ Advertising in unexpected places: banners on top of other applications, pop-up windows when unlocking the screen or in the settings menu.
- ๐ Sharp increase in battery consumption: if the battery runs out after 3-4 hours without active use, check the processes in
Settings โ Battery. - ๐ก Suspicious traffic: mobile data or Wi-Fi is consumed in the background (checked in
Settings โ SIM cards and mobile networks โ Traffic usage). - ๐ฆ Unknown applications: names like
Settings โ Applications). "System Update", "Flash Player" or "Clean Master" (popular cover-ups for viruses) appeared in the list of installed apps ( - ๐ Device lock: the screen is locked, requiring payment or data entry (even if it is a "security update").
Pay attention to hidden signs: for example, some Trojans can modify system fileswhich is why standard removal methods (via Settings โ Applications) will not work. If after removing the suspicious software it appears again, it means that the virus has penetrated into /system/app/ or uses the auto-update mechanism through Google Play.
โ ๏ธ Attention: Some legitimate applications (for example AliExpress or Wildberries) may show push notifications similar to advertising Before deleting, check to see if notifications are disabled in your app. settings of the application itself.
Step-by-step guide: how to remove ads and viruses manually
If you are sure that the device is infected, start with manual cleaningThis method works even without an antivirus and helps to remove most advertising modules. order:
- Go to safe mode:
Hold down the power button, then hold your finger on the option
Turn off(on some models -Reboot in safe mode). viruses that block access to settings. - Check the list of applications:
Open
Settings โ Applications โ All applicationsand sort them by installation date Remove all suspicious ones, especially apps from. names in Chinese, random letters (for example, "com.abc.xyz") or copies of system services. - Clear browser cache and data:
Adware often penetrates through malicious sites. Open. settings Chrome or another browser and run
Clear history โ Delete all data. - Reset advertising settings:
Go to
Settings โ Google โ Advertisingand pressReset advertising ID. This will stop targeted advertising from some modules.
If after these steps there are still ads or viruses, then they will help in this case. only infiltrated into system processes. In this case, it will only help reset to factory settings or using specialized tools (about them in the next section).
โ๏ธ Preparing for manual cleaning
The best antiviruses for Android: what really works in 2026
Standard Android tools (for example, Google Play Protect) often miss adware, since it is not classified as a virus. For a deep scan, specialized tools are needed. We tested 15 antiviruses and selected those that effectively remove:
- ๐ก๏ธ Bitdefender Mobile Security โthe best choice for detecting Trojans and spyware. Uses cloud scanning without loading the device.
- ๐ Malwarebytes โspecializes in adware and potentially unwanted apps (PUPs). The free version removes threats without a subscription.
- ๐ Kaspersky Internet Security โdetects even. deeply hidden viruses, but may conflict with some banking applications.
- ๐ Norton 360 โ includes VPN and phishing protection, but requires a paid subscription for full functionality.
How to scan your device correctly:
- Install an antivirus only from the official one store (Google Play or APKMirror for verified APKs).
- Run full scan (not fast!). It will take 10-30 minutes, but it will detect hidden threats.
- If the antivirus finds
Android/TrojanorAdDisplayโdelete the files and reboot the device. - Check the
Threatssection in the antivirus for the presence of residual files (sometimes viruses leave "tails" in/data/local/tmp/).
โ ๏ธ Attention: Some antiviruses (for example, Cheetah Mobile or DU Security) are themselves recognized as potentially unwanted software. They can collect user data and display aggressive advertising.
| Antivirus | Advertising detection | Virus detection | Impact on performance | Cost (premium) |
|---|---|---|---|---|
| Bitdefender | 98% | 100% | Low | 1,200 โฝ/year |
| Malwarebytes | 100% | 95% | Medium | Free (with restrictions) |
| Kaspersky | 97% | 99% | High | 900 โฝ/year |
| Norton 360 | 99% | 98% | Low | 1,500 โฝ/year |
Important: If the antivirus detected a virus with the name AndroidOS_Triada or Ztorg, this means that the malware has acquired rights superuser (root). In this case, only a complete reset of the device or flashing it will help.
How to remove ads from system applications (without root)
Some manufacturers (for example, Xiaomi, Samsung or Realme) embed advertising in branded shells (MIUI, One UI, ColorOS). You cannot remove it completely without superuser rights, but you can significantly reduce number of impressions. Here are working methods:
- ๐ต Disable personalized advertising:
Go to
Settings โ Google โ Advertisingand deactivate the optionPersonalized advertising. This will reduce the number of targeted banners. - ๐ Block advertising domains:
Use the application Blokada (does not require root) or to block domains like auto-update for NextDNSto block domains like
adservice.google.comorconfig.miui.com. - ๐ฒ Disable auto-update of system applications:
IN Google Play open settings and turn off auto-update for MIUI System Ads, Samsung Push Service and similar services.
- ๐ Reset advertising settings:
In
Settings โ Applications โ Google Play Services โ MemoryclickSpace management โ Reset advertising ID.
For devices Xiaomi there is an additional method:
- Open
Settings โ About phoneand click onMIUI versionto activateDeveloper mode. - Return to
Settings โ Advanced โ Developer modei disableShow MIUI ads.
List of advertising domains to block
Here are the main domains that are responsible for displaying advertising in system applications:
- adservice.google.com
- config.miui.com
- samsungads.com
- oppo.ads.com
- vivo.push.com
- hicloud.com (Huawei)
Add them to the blacklist in Blokada or NextDNS to reduce the number of banners.
What to do if a virus has blocked your phone (ransomware)
If your screen is blocked by a message like "Your phone is blocked by the FSB" or "Pay 5000 โฝ for unlocking", this is the work of ransomware (ransomware). Do not pay under any circumstances - this does not guarantee unlocking, but will only confirm the functionality of the scammersโ scheme. Hereโs what to do:
- Reboot into safe mode:
As a rule, ransomware does not block safe mode. Hold the power button, then select
Reboot in safe mode. - Remove the virus via ADB (if safe mode is not available):
Connect the phone to the PC, install ADB Tools and run the command:
adb shell pm uninstall -k --user 0 name.packageTo find the name of the package, use
adb shell pm list packages | find "lock"(Windows) oradb shell pm list packages | grep "lock"(Linux/Mac). - Reset the device via Recovery:
Turn off the phone, then hold down the key combination to enter Recovery Mode (usually
Power + Volume Up). SelectWipe data/factory reset.
If the screen displays phishing page (for example, a fake website Google Play or a bank), do not enter any data! Close the tab through the task manager or restart the device.
โ ๏ธ Attention: Some ransomware encrypts files on the device. If, after removing the virus, photos, documents or videos open with an error, try using decryption utilities, for example Emsisoft Decryptor (available on the official website). site).
How to protect Android from re-infection: 7 safety rules
Cleaning the device is only half the battle. Without changes in behavior, viruses and advertising will return in a few days. Follow these rules to minimize risks:
- ๐ Set a strong password for your account. Google:
Many viruses are spread through hacked accounts. Use two-factor authentication a password of at least 12 characters.
- ๐ฅ Do not install APKs from unknown sources:
Even if the site looks like an official Google Play, check the URL. Fraudsters often use domains like
go0gle-play[.]comorplay-market[.]app. - ๐ Update Android and applications:
Old versions of the OS and apps have vulnerabilities that are exploited by viruses. Enable auto-update in
Settings โ System โ Software update. - ๐ก๏ธ Use DNS filtering:
Configure Cloudflare DNS (1.1.1.1) or Google DNS (8.8.8.8) in the Wi-Fi settings. This will block access to malicious domains.
- ๐ต Disable installation from unknown sources:
Go to
Settings โ Securityand deactivate the optionUnknown sources(or allow it is only for trusted applications, for example, F-Droid). - ๐ Check application permissions:
If the game asks for access to
Contacts,SMSorGeolocationsโthis is suspicious. Check reviews in Google Play before installation. - ๐ฆ Clean regularly cache:
Malicious scripts can be stored in the browser cache. Clear it once a week through
Settings โ Storage โ Cache data.
Additional advice: If you often install applications from third-party sources (for example, modified games), use sandbox (Shelter or Island). It isolates suspicious apps from the main system.
Create a separate user on Android to test new applications. This will prevent viruses from infecting the main profile. To do this, go. in Settings โ System โ Multi-user mode (not available on all devices).
When you need to reflash the device: extreme measures
If none of the described methods helped, and viruses return after resetting the settings - this means they infiltrated the firmware. This happens if:
- You installed custom firmware (for example, LineageOS) from unreliable sources.
- The virus received root access and modified system files with
/system/. - The device was infected via vulnerability in the bootloader (for example, DirtyCOW or Stagefright).
In this case, only full flashingwill help. Here's how to do it:
- Download the official firmware for your model from the manufacturer's website (for example, Xiaomi, Samsung or Realme).
- Unlock the bootloader (if it is blocked). For this you need a manufacturer account (for example, Mi Account for Xiaomi).
- Install the firmware via Fastboot or Recovery:
- Reset the data (
Wipe data/factory reset) after the firmware.
fastboot flash boot boot.imgfastboot flash system system.img
fastboot flash userdata userdata.img
Flashing will delete all data, including photos and applications, so first make a backup copy of important files on your PC or cloud. If the virus blocks access to files, use ADB Pull:
adb pull /sdcard/ path_to_pc
โ ๏ธ Attention: Unprofessional firmware can turn the device into a โbrick.โ If you are not confident in your skills, contact a service center. The cost of flashing at official centers usually does not exceed 1,500โ2,000 rubles.
Reflashing is the only way to remove viruses. embedded in the boot partition or modified the Android kernel. However, this method requires technical skills and may void the warranty.
FAQ: Frequently asked questions about cleaning Android from viruses
Is it possible to remove viruses without an antivirus?
Yes, many adware modules and simple Trojans can be removed manually via Settings โ Applications or safe mode. However, to detect hidden threats (for example, spyware), it is better to use an antivirus.
Why after removing the virus returns?
This means that the malware:
- Has superuser rights (root).
- Is embedded in system processes (for example, modified
/system/app/). - Uses an auto-update mechanism via Google Play (check the list of auto-updating applications).
In such cases, only a factory reset or flashing will help.
How to protect your child from malicious sites and advertising?
Set up parental controls:
- Install Google Family Link and limit the installation of applications.
- Enable Safe Search in Google and YouTube.
- Use DNS filtering (for example, CleanBrowsing or OpenDNS FamilyShield).
- Block APK installation via
Settings โ Security.
Is it possible to restore data after resetting the settings?
If you made a backup via Google Account or Mi Cloud (for Xiaomi), the data will be restored automatically after logging into your account. For manual recovery:
- Photos: check the folder
DCIMon the memory card or in the cloud. - Contacts: synchronize with Google Contacts.
- Messages: use SMS Backup & Restore (if a copy was made in advance).
If the data is not restored, try apps like Dr.Fone or EaseUS MobiSaver, but the chances are low - resetting the settings usually erases everything.
Do "cleaners" like Clean Master or CCleaner help?
No, these applications are not only do not remove viruses., but they themselves are often classified as potentially unwanted software (PUP). They:
- Show false warnings about the โcontaminationโ of the device.
- Collect user data for targeted advertising.
- May conflict with antiviruses.
To clear the cache, built-in Android tools are sufficient: Settings โ Storage โ Clear cache.