Disconnect the device from Wi‑Fi and mobile data
Boot into Safe Mode
Uninstall recently installed or suspicious apps
Remove Device Admin access from suspicious apps
Disable Accessibility services for unfamiliar apps
Turn off Unknown sources
Review and remove suspicious app permissions
Clear browser and app data for the affected browser (and any suspicious apps)
Remove malicious browser extensions or site notifications (Chrome: Site settings → Notifications)
Run a full scan with a reputable antivirus/anti-malware app
Update Android OS to the latest available version
Update Google Play services and Google Play Store
Change passwords from a trusted device (email, banking, social accounts)
Check account activity/sign-in sessions and revoke unknown sessions
Enable two-factor authentication
Back up important data you trust
Factory reset the phone (then reinstall only trusted apps)
After reset, reinstall apps one at a time and avoid restoring from untrusted backups
If the device won’t stay clean, stop using it and contact your carrier or a professional service
