Know your enemy: the four kinds of Android ad plague
Unwanted ads on Android come from four distinct sources, and each dies differently, which is why random flailing fails. Source one: adware apps, an installed app showing full-screen ads outside itself, on the home screen, over other apps, on unlock. Source two: browser notification spam, websites you once clicked Allow on, now pushing 'virus' alerts and prize scams through Chrome notifications. Source three: in-browser popups and redirects from aggressive sites. Source four: legitimate apps with obnoxious but technically legal ad loads, free games above all.
Telling them apart takes one observation each. Ads that appear with no app open, or over every app, are source one, adware, and the hunt below finds it. Alerts that look like notifications (they sit in the shade, mention Chrome or a site name in small print) are source two, killed in browser settings in one minute. Popups only while browsing certain sites are source three, settings plus site hygiene. And ads only inside one specific free app are source four, where your options are paying for the app, replacing it, or tolerating it, but nothing is infected.
One reassurance and one warning up front. Reassurance: the fake 'Your phone has 13 viruses!' popup is itself the scam, Android is not diagnosing anything through a browser ad, and tapping its Clean Now button installs exactly the kind of app this article removes. Warning: the 'cleaner' and 'antivirus booster' apps advertised by those popups are the single largest source of the adware they claim to cure; the fix for ads is removal and settings, never another cleaner app.
The adware hunt: identifying the app showing ads
Modern Android hands you the culprit's name if you know where to look. Method one, the recents trick: the moment a rogue ad appears, press the Recents (square or swipe-up-hold) navigation. The ad appears as a card in the app switcher, and the card's header names the app that drew it. Method two, on Android 12 and later: Settings, Apps, and check 'recently opened' or the digital wellbeing dashboard for what ran at the ad's timestamp; an app you never opened, running constantly, is your suspect.
Method three is the notification long-press: if the ad arrived as a notification, long-press it and Android names the posting app and offers to silence it on the spot. Method four, the population screen: Settings, Apps, See all, sorted or scanned for the classic adware profile, flashlights, QR scanners you did not install our tools exist to replace, wallpaper packs, 'RAM boosters', video downloaders, and anything installed right before the ads began. Your install timeline lives in the Play Store, profile, Manage apps and device, and correlating 'ads started' with 'installed that week' closes most cases.
Method five for the stubborn: Safe Mode (hold the on-screen Power off until Safe mode offers, reboot). Safe Mode disables all third-party apps; if the ads stop, the adware conviction is confirmed, and you uninstall suspects in normal mode one at a time, retesting. If an app's Uninstall button is grayed out, it grabbed Device Admin rights: Settings, Security, Device admin apps, revoke it there, then uninstall. That grayed-button trick is the signature of genuinely malicious adware, and finding it means also doing the account hygiene in the final section.
Killing browser notification spam and popups
The fake-virus notifications and prize alerts that plague millions come through one door: the website notification permission, granted with one misplaced tap on a 'Allow notifications to continue' prompt months ago. Close the door: Chrome, three-dot menu, Settings, Site settings, Notifications. The list under Allowed is your rogues' gallery, news-looking domains, video sites, anything you do not recognize. Remove or block each, or flip the master toggle so sites must ask, and set 'Use quieter messaging' so future asks are a silent chip instead of a popup.
While in Site settings, lock the other two doors: Pop-ups and redirects, blocked; and Intrusive ads, blocked (Chrome's built-in filter for the worst offenders). Samsung Internet and other browsers have identical menus, check whichever browsers live on the phone, because spam arrives through whichever one holds the permission. Then clear the browser's residue: Chrome, Settings, Privacy, Clear browsing data, cached images and cookies, which evicts the session junk aggressive sites use to re-trigger prompts and redirects.
Adopt the two browsing habits that keep this section permanent. Never tap Allow on a notification prompt from a site you would not want texting you, the legitimate need is rare (your email, maybe a news site you love), and everything else is future spam. And treat 'you must click allow / install to view this content' as the site telling you to leave. For families, do this settings pass on relatives' phones too; the notification-spam plague disproportionately harvests people who do not know the Allowed list exists, and the cleanup is ninety seconds per phone.
Deep cleaning: Play Protect, permissions, and the reset threshold
After removing suspects, run the system's own sweep: Play Store, profile, Play Protect, Scan. Play Protect checks installed apps, including sideloaded ones, against Google's malware intelligence and flags or removes known bad actors. Follow with a permission audit focused on the two superpowers adware abuses: Display over other apps (Settings, Apps, Special app access, Display over other apps), where nothing should be enabled that you cannot justify, and Accessibility services, which grant screen-reading powers and should list only tools you deliberately configured. Revoke anything questionable; legitimate apps survive losing overlay rights.
Check the silent settings adware sometimes plants: Chrome's homepage and default search (Settings inside Chrome), the device's default browser and launcher (Settings, Apps, Default apps), and installed keyboards you did not add. Restore each to your choice. If ads began after installing something from outside the Play Store, assume siblings arrived together: review everything installed that day, and prefer reinstalling wanted apps fresh from the Store over trusting the sideloaded copies.
The factory reset is the correct final threshold when: ads persist through Safe Mode testing and full audits, Device Admin tricks recur, or you simply no longer trust the device (it handled banking, it belongs to a family member who taps everything). Our factory reset guide covers the clean procedure; do the backup first, and afterward restore apps selectively from the Play Store rather than wholesale, which resurrects a clean phone instead of restoring the infection. Then change your Google password if anything with Accessibility powers was found, on the reasonable assumption it could read what you typed.
Prevention: an ad-quiet phone by construction
Ad plagues are almost entirely install-time choices, which makes prevention a checklist rather than vigilance. Install from the Play Store; when you must sideload, treat the APK's source with browser-history-level scrutiny. Before installing anything, read the permission requests against the app's job: a wallpaper app wanting Accessibility, a game wanting Display-over-apps, a flashlight wanting anything at all, are declines. Check the developer name and reviews sorted by recent, adware waves show up in last-month reviews long before ratings decay.
Replace the risky app categories with built-ins and trustworthy tools: Android's own flashlight tile, Files by Google for cleaning, and our free browser tools for QR scanning, device info and diagnostics, no install, no permissions harvested, nothing resident. The 'utility app you install for one feature' is the primary adware vector, and the browser-tool alternative removes the vector entirely for a whole class of needs.
Finally, the notification-permission hygiene as a standing rule (site prompts default to no), a quarterly two-minute audit (Play Protect scan, overlay and accessibility lists, Chrome's Allowed notifications), and the family dimension: set Play Store parental controls or purchase PINs on kids' devices, where free games install by the dozen and each carries its ad framework. A phone run this way simply does not develop the plague, and if one slips through, the recents trick plus this article's hunt removes it in ten minutes, which is the entire lifecycle of the problem when you know where the doors are.