Why did Google suspend my account for malicious or unwanted software?
Direct answerRead the label. Malicious software means Google thinks you intentionally distributed malware. That suspension can happen on detection, with no warning, and Google says you will not be allowed to advertise again unless an appeal shows a mistake. Unwanted software means the download is deceptive, bundled, hard to remove, or missing a clear description of what install does. That one comes with a warning at least 7 days before suspension.
Which label you actually have
| What Google found | Policy | Account effect Google states |
|---|---|---|
| Virus, ransomware, keylogger, rogue antivirus, credential-stealing ad | Malicious software | Egregious. Suspended on detection, without prior warning. |
| Hidden bundle, browser change, no terms, function that does not match the ad | Unwanted software | Warning at least 7 days before suspension. |
| Landing page code changed by someone else | Compromised sites, listed separately under abusing the ad network | The 2023 split said this label gets a 7-day warning. Confirm the live article. |
| Review saw a clean page and people saw another | Circumventing systems | Can suspend with no warning. Not a disclosure rewrite. |
Malicious software
Google’s malicious software policy, under abusing the ad network, defines malware as software that aims to harm or get unapproved access to a computer, device, or network. Intentional distribution is not allowed. Named examples include viruses, ransomware, worms, trojan horses, rootkits, keyloggers, dialers, spyware, rogue security software, forced redirects to an infected site without a click, and HTML5 ads that steal credentials from a publisher’s page.
Google calls a violation egregious. Accounts are suspended upon detection and without prior warning, and the page says you will not be allowed to advertise with Google Ads again. Appeals are for cases where you believe the finding is an error. Google says accounts are only reinstated in compelling circumstances, such as a mistake. Some advertisers must pass advertiser verification to appeal, and three failed identity checks can remove the appeal path. The suspension workflow itself is in why Google Ads accounts get suspended.
Unwanted software
Google’s unwanted software policy describes software that is deceptive, tricks people into installing or piggybacks on another install, hides principal functions, changes the system in unexpected ways, is hard to remove, collects or transmits private information without the user’s knowledge, or is bundled without disclosure.
Disapproval examples include no product type in the ad or on the page, a function description that does not match the software, system or browser changes without consent, a difficult uninstall, missing terms of service or an end-user license, a silent bundle, and transmitting private information without the user’s knowledge.
Policy: the ad should contain a product type and one accurate line about what the software does. The destination should repeat that and explain the full result of installing, including browser or settings changes. Disclosures must be conspicuous, prominent, in reasonably large type, and plain enough for someone who is not technical. A large disclosure does not make a silent bundle allowed. The characteristics above are still violations. This policy warns at least 7 days before suspension.
A picture of a download icon that is not a working control is misleading ad design. Software sold so someone can read another adult’s texts is dishonest behavior, not a missing EULA.
A hacked page is the third label
In May 2023 Google split the old malware policy into malicious software, compromised sites, and unwanted software. The policy update describes a compromised site as one whose code was changed to benefit someone else without the owner’s knowledge, often in a way that harms visitors. Ads may not use that destination. The update said this label gets a warning at least 7 days before suspension, unlike malicious software. Open the live Compromised sites article from the abusing-the-ad-network hub before you rely on that timing. Clean the site. Do not file the appeal as if you meant to distribute the payload.
Setup workflow
- Read the policy name in the notification. Malicious software, unwanted software, compromised site, and circumventing systems are different labels.
- If the label is malicious software, stop spending and appeal from the suspension notice. Google says reinstatement is for compelling cases such as a mistake. Do not open a replacement account.
- If the label is unwanted software, put the product type and one true function line in the ad. On the page, explain install effects, including settings changes, in large plain text, and add terms or an EULA.
- Remove silent bundles, hidden uninstall steps, and private-data collection the user was not told about.
- If the landing page was hacked, treat that as a compromised destination. Clean the site, then appeal. Do not describe a virus you shipped on purpose as a hack.
Frequently asked questions
Will unwanted software suspend the account immediately?
No. Google’s unwanted-software policy says violations will not lead to immediate suspension without warning. A warning is issued at least 7 days before suspension. Malicious software is the opposite: Google calls it egregious and says accounts are suspended on detection, without prior warning.
Does the policy apply if the ad is not for the software?
Yes. Both policies say the rules cover ads and any software the site or app hosts or links to, whether or not that software is what the ad is promoting. A blog that links a bundled installer can still be the destination problem.
What has to be on the page for a normal app?
Google’s unwanted-software fix says the ad needs a product type and one accurate line about what the software does. The destination needs the same, plus a clear explanation of what install does, including browser or system changes. That disclosure has to be conspicuous, in a prominent spot, in reasonably large type, and in plain language. The page also needs terms of service or an end-user license.
Sources
- Google Ads: Malicious software
- Google Ads: Unwanted software
- Google Ads: Abusing the ad network
- Google Ads: Update to Abusing the ad network policy (February 2023)
Enforcement details change. This reading is as of September 23, 2026. It is not a promise that an appeal will be granted.
Check the installer the ad actually opens
LaunchGuarding reads the ad and the destination, including a download path that never says what the file changes.