If you are unable to access your Android phone or tablet and are seeing a lock screen message stating that your device has been blocked, it is likely that your device has been infected with a malicious app.
These types of apps can be downloaded from malicious websites or legitimate websites that have been hacked and offer a “video player” or other seemingly useful app for download. The infection may also be downloaded manually if the user is tricked into believing they are installing a genuine update for software such as Adobe Flash Player.
![Android FBI lock screen virus [Image: Android FBI virus]](https://malwaretips.com/blogs/wp-content/uploads/2014/05/android-fbi-virus1.jpg)
What is the Android lock screen Ransomware?
Ransomware has evolved in recent years and the Windows operating system is not the only one who can get infected with this type of malware. With Android overwhelmingly the most common operating system for mobile devices, ransomware specially made for phones, tablets, and more is also on the rise.
The malicious ransomware apps will lock you out of your Android device and applications, so whenever you try to unlock or use your smartphone, it will display instead a lock screen asking you to pay a ransom in vouchers or cryptocurrency (Bitcoin, Monero, Dash). The malware’s authors prefer these payment services because transactions made through them cannot be reversed and are hard to trace.
Unlike Windows devices, the good news is that the infection doesn’t encrypt any of your data on your Android, and it merely locks your device with a popover browser window that quickly reappears if you try to get clear of it. The bad news is that the continually reappearing pop-over window makes it as good as impossible to get into the Settings menu to remove the malware.
Even rebooting won’t help as the malware kicks back in early in the process of restarting. A factory reset will get rid of it, but that also removes all your other installed apps and stored data.
The messages on this Android lock screen Ransomware are for the most part a scam, and you should ignore any alerts that this malicious app might generate.
Under no circumstance should you send any vouchers or cryptocurrency to these cyber criminals, and if you have, you can request a refund, stating that you are the victim of the malware.
Remove Android Lock Screen Ransomware
This page is a comprehensive guide that will remove the malicious app from your Android phone. Please perform all the steps in the correct order. If you have any questions or doubt at any point, STOP and ask for our assistance.
- STEP 1: Start Android in Safe Mode
- STEP 2: Remove malicious device admin apps
- STEP 3: Uninstall malicious apps
- STEP 4: Reset browsers back to default settings
- STEP 5: Use Malwarebytes for Android to remove malicious apps
STEP 1: Start Android in Safe Mode
In this first step, we will start your phone in Safe Mode to prevent malicious apps from interfering with the next steps. We’re using Safe mode because it starts Android in a basic state, with only the factory apps and settings.
-
Long press the power button.
Long press the hardware power button (located on the side of your phone) until the power off menu appears.
-
Tap and hold on “Power off”.
When the power off menu appears, tap and hold on the “Power off” button on your screen until you get the “Safe mode” option.

-
Tap on “Safe Mode”.
When the “Safe mode” option appears on your screen, tap on it to enter safe mode.

-
Your phone is in Safe Mode.
Your Android phone will now restart and enter into safe mode. When your phone is in safe mode, you’ll see the “Safe Mode” text at the bottom left corner of your phone. You can now continue with the next step.

If you can’t find a safe mode on your phone, activate Airplane mode instead, to cut your device off from any networks.
STEP 2: Remove malicious device admin
In this second step, we will check the phone to see if there are any malicious apps with administrator privileges installed on your phone.
The administrator privileges are used by apps to perform legitimate tasks such as device management or for antivirus apps to do a remote wipe. Unfortunately, these elevated privileges are also being used by malicious apps to prevent victims from removing the malicious app from their phone.
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 1 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Go to “Device admin apps”.
When the “Settings” menu opens, if you’re using a newer version of Android or a Samsung phone, tap on “Biometrics and Security“, then tap on “Other Security Settings” and then on “Device admin apps“.
![Remove Android Lock Screen Ransomware [Virus Removal] 2 Device admin apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Go-to-Device-Admin-Apps.jpg)
However, because there are phones with different versions of Android the “Device admins apps” settings may be in a different menu, so below we’ve listed other common ways to reach the “Device admin apps” options:
- Security > Device admin apps
- Security & privacy > Device admin apps
- Security > Device Administrators
- Lock Screen and Security > Other Security Settings > Phone Administrators.
If you’re having trouble finding the “Device admin apps” settings, you can use your phone’s built-in search function to search through the Settings.
-
Disable administrator privileges for the malicious app.
Once you’ve accessed the list of device admin apps, disable admin rights by tapping the option to the right of the app. This will remove the checkmark or toggle the button to the off position. Now you can delete the app normally as seen in the below step. On some phones, you can tap the app right there in the admin apps list and then use the Uninstall app link to remove it immediately.

If there is no malicious app with administrator privileges on your phone, then you can continue with the next step from this guide.
STEP 3: Uninstall the malicious apps
In this third step, while the phone is still in Safe Mode, we will check if any malicious apps are installed on your device. Sometimes browser hijackers or adware apps can have usable Uninstall entries that can be used to remove these apps.
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 1 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 4 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find the malicious app.
The “Apps” screen will be displayed with a list of all the applications that are installed on your phone. Scroll through the list until you find the malicious app.
Look out for any suspicious app that could be behind all the drama – anything you don’t remember downloading or that doesn’t sound like a genuine program. Most often, cyber criminals hide malware inside video or photo editing apps, weather apps, and camera apps.Here are some known malicious apps: ES File Explorer, Xender, Amber Weather Widget, GO Weather Forecast & Widgets, Kitty Play, Touchpal, Z Camera.
The malicious program will most likely have a different name on your phone. If you cannot find any malicious app on your device, you can exit “Safe mode” (as seen below) and continue with the next step from this guide.

-
Uninstall the malicious app
When you find a suspicious or malicious app, tap on it to uninstall it. This won’t start the app but will open up the app details screen. If the app is currently running press the “Force stop” button, then tap on “Uninstall”.

A confirmation dialog should be displayed to confirm you want to uninstall the app, tap on “OK” to remove the malicious app from your phone.

-
Exit “Safe mode”.
Now that we’ve removed the malicious apps from your phone, we can exit “Safe mode”. To do this, hold the power button on your device until you get the power off menu, then select the restart option from the menu.

Your phone will now be rebooted and exit from the safe mode and boot into the normal mode.
STEP 4: Reset browsers back to default settings
In this next step, we will remove spam notifications, redirects, and change to default any settings that might have been changed by malware.
Resetting the browser settings to their default it’s an easy task on Windows or Mac computers; however, when it comes to Android, this can’t be done directly because it’s not an option built-in into the browser settings. Restoring the browser settings on Android can be done by clearing the application data. This will remove all the cookies, cache, and other site settings that may have been saved. So let’s see how we can restore your browser to its factory settings.
Remove malware from Chrome for Android
To reset Chrome for Android to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Chrome.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Chrome app, then tap on it to open the app’s details.

-
Tap “Storage”.
When Chrome’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Chrome’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
![Remove Android Lock Screen Ransomware [Virus Removal] 7 Tap Ok to restore default settings](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Chrome-Android-Confirm-Clean-Data-1.jpg)
Remove malware from Firefox for Android
To reset Firefox for Android to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Firefox.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Firefox app, then tap on it to open the app’s details.

-
Tap “Storage”.
When Firefox’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Firefox data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
Remove malware from the Opera browser
To reset the Opera browser to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Opera.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Opera app, then tap on it to open the app’s details.

-
Tap “Storage”.
When Opera’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Opera’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
Remove malware from Samsung Internet Browser
To reset the Samsung Internet Browser to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Samsung Internet Browser.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Samsung Internet Browser app, then tap on it to open the app’s details.

-
Tap “Storage”.
When the Samsung Internet Browser’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Samsung Internet Browser’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
Remove malware from Microsoft Edge for Android
To reset the Microsoft Edge for Android to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Microsoft Edge.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Microsoft Edge app, then tap on it to open the app’s details.

-
Tap “Storage”.
When the Microsoft Edge’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Microsoft Edge’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
STEP 5: Use Malwarebytes for Android to remove malicious apps
In this final step, we will download, install and run a scan with Malwarebytes for Android to remove adware, browser hijackers, and other malware from your phone.
Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.
-
Download Malwarebytes for Android.
You can download Malwarebytes for Android by clicking the link below.
MALWAREBYTES FOR ANDROID DOWNLOAD LINK
(The above link will open a new page from where you can download Malwarebytes for Android) -
Install Malwarebytes for Android on your phone.
In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 16 Malwarebytes for Android - Open App](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Malwarebytes-for-Android-Open-App.jpg)
-
Follow the on-screen prompts to complete the setup process
When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
Tap on “Got it” to proceed to the next step.
Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
Tap on “Allow” to permit Malwarebytes to access the files on your phone.
-
Update database and run a scan with Malwarebytes for Android
You will now be prompted to update the Malwarebytes database and run a full system scan.
![Remove Android Lock Screen Ransomware [Virus Removal] 17 Malwarebytes fix issue](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Malwarebytes-for-Android-Fix-Issues.jpg)
Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

-
Wait for the Malwarebytes scan to complete.
Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.

-
Click on “Remove Selected”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.

-
Restart your phone.
Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.
Your phone should now be free of browser hijackers, adware, and other malicious apps.
If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:
- Restore your phone to factory settings by going to Settings > General management > Reset > Factory data reset.
- Ask for help in our Mobile Malware Removal Help & Support forum.
Thank you sooooo much! I got it on my htc phone, and this got rid of it! Update the page for htc users, though, that one of the names for the virus is “system update” now. Otherwise, you are the best!!!!
Hi,
Ive got the loadgovstatesecurity version of the police virus on my galaxy tablet. I can activate safe mode and discovered the app ‘softwareupdate’ but its grayed out so I can’t remove it.
Any way I can overide this? I have tried going through security / administrator but the app is not there either. I also downloaded avast ransomware and have done scans with Sophos and 360 but none are identifying it!
Help!!
Thanks your method worked first time and was easy to follow . Nice job !!!!?
Thanks followed your instructions and managed to remove the app. Downloaded the app as I thought that it was an android security update. Phone appears to be working
fine now. Thanks
Instructions to remove the police virus if your phone doesn’t have the “Safe mode” option (no hard reset necessary!):
– Install the utility ADB (Android Debug Bridge) on the computer (https://developer.android.com/sdk/index.html#Other) and the driver for your cell phone (for example http://adbdriver.com/)
– On mobile (currently totally inaccessible) install the utility “ADB Network Enabler” through Google Play Store (to enable ADB over wifi) -> https://play.google.com/store/apps/details?id=com.soynerdito.adbnetworkenabler&hl=en
– Turn off your phone (by removing the battery), then turn it on and quickly press on the “ADB Network” icon, then on the “Start” button (all this before the virus starts)
– Also quickly write down the phone IP (eg. 192.168.x.x)
– From your computer, open a window with “cmd”, navigate to the folder where “adb.exe” is (ie: cd “C:Program Files (x86)Androidandroid-sdkplatform-tools”) and type “adb connect 192.168.x.x” (replace ip with that of your mobile phone) to start the wifi connection
– Type “adb shell” to open a shell on the phone
– In the shell list all the installed packages by typing “pm list packages”, check all packages beginning with “/data/app/…” and find the suspect one (in my case “com.coil.twiddled” was the name of the virus)
– Type “exit” to exit the shell
– Type “adb uninstall com.coil.twiddled”
The virus is uninstalled, also remember to clear the browser cache on the phone.
THANK YOU! This method worked so well! I just open my phone with safe mode and deleted the “malware” app, and then turn on with normal mode. The Virus deleted
Just Happened to me unfortunately was not able to take a screenshot, Malware was self loading rather than you having to install, called System Update disguised as the green android, methods above worked
exactly. Thanks for the guide OP
txs man mine had the same issue.
Many thanks. The ‘System Update’ was the rogue in my den also.
I ended up just resetting my phone. it wasn’t that hard since all my info was already backed up.
My Trojan was asking for $100 in iTunes cards. I tried everything here, and nothing worked. I found the “Internet” app had over 250mb in the cache. I cleared the cache, reset the app, and re-started the phone. (Samsung Galaxy Note 4) This finally got rid of the Malware. Try this as a last resort. Your methods did not work for me, but these scams are always evolving and getting better at hiding. Thank you for this site, Stelian.
Thank U so much I Been trying for days Lol thanks
This helped me out. Many Thanks. To those of you who cannot seem to get the uninstall to work even through the administrator settings u will probably have to do the entire factory reset. Thanks again
thanks a lot. the solution in my table samsung was great only deleting the system update app. Great solution, thanks again from Spain.
THANK YOU! Searched my virus on google, this was 4th site I viewed, & fixed randsomware in under 5 min. Didnt have to dl or pay for anything. Was almost too easy!
Stelian,
Thank you so much for your article! My daughter’s phone picked up that damned Cyber Police crap, and it took a few hours of searching to find this article. Her malware was labelled as System Update. Uninstalled that, installed and ran some scanners, and all is well! I will be sharing this article on my facebook, just in case!
Thanks again!
Eric
My tablet has been locked by this virus. Ive followed all the instructions to get rid of it but i can’t find any of the malicious malware that have been mentioned here on my tablet. No Badoink no systems update version 1:1 … I’ve even downloaded avast.. although I already had AVG. Neither of these will scan as I can’t find them in safe mode. I’m at a loss at what to do. Please help.
i’m in safe mode and when i try to deactivate it as administrator it brings me back to the fbi virus screen
I have a Galaxy Note 10.1 and I have managed to pick up the United Kingdom Police message but I am unable to move from this page. I am unable to get internet connection or move to the settings page. What do you suggest?
Hello John,
Please try again to start into Safe Mode. Turn off the gadget (hold the power button, tap “Power off” and then tap OK). Wait a few seconds and then turn the gadget back on.
When you see the Samsung logo, press and hold the Volume Down button until Safe Mode shows up .
Next go and uninstall any malicious app (recently known malicious app: System Update, System Malware, Security Update or Security Helper.
Thanks a million. Worked on my very first try.
Thank you, thank you so much! I seriously cannot thank you enough. I had inadvertently downloaded this malicious app and I had no idea what was going on. It wouldn’t let me do anything with my phone. After I read your article I removed it so you helped me a lot. If I could thank you personally, I would.
I recently came across this ad on my tablet yesterday and while trying to get rid of it took me to other pages and without knowing this FBI page locked my tablet I freaked out. I started my research and tried many times as it said but I can’t get to safe mode nor turn it off. I have the Galaxy Tab 4 and I don’t know what to do please help..
Hello,
Most likely you have the Cryptowall 4.0 ransomware on your computer… More details here: https://malwaretips.com/blogs/remove-cryptowall-4-0-virus/
On my god I freaked out when this happened, I didn’t sleep at all the whole night worrying about what I would have to do to fix this. Thank you so much like really thank you. My phone is working properly now and hopefully I don’t run into anymore of these problems, but if I do I know I’m coming back to stelian. Again thanks so much..