If you are unable to access your Android phone or tablet and are seeing a lock screen message stating that your device has been blocked, it is likely that your device has been infected with a malicious app.
These types of apps can be downloaded from malicious websites or legitimate websites that have been hacked and offer a “video player” or other seemingly useful app for download. The infection may also be downloaded manually if the user is tricked into believing they are installing a genuine update for software such as Adobe Flash Player.
![Android FBI lock screen virus [Image: Android FBI virus]](https://malwaretips.com/blogs/wp-content/uploads/2014/05/android-fbi-virus1.jpg)
What is the Android lock screen Ransomware?
Ransomware has evolved in recent years and the Windows operating system is not the only one who can get infected with this type of malware. With Android overwhelmingly the most common operating system for mobile devices, ransomware specially made for phones, tablets, and more is also on the rise.
The malicious ransomware apps will lock you out of your Android device and applications, so whenever you try to unlock or use your smartphone, it will display instead a lock screen asking you to pay a ransom in vouchers or cryptocurrency (Bitcoin, Monero, Dash). The malware’s authors prefer these payment services because transactions made through them cannot be reversed and are hard to trace.
Unlike Windows devices, the good news is that the infection doesn’t encrypt any of your data on your Android, and it merely locks your device with a popover browser window that quickly reappears if you try to get clear of it. The bad news is that the continually reappearing pop-over window makes it as good as impossible to get into the Settings menu to remove the malware.
Even rebooting won’t help as the malware kicks back in early in the process of restarting. A factory reset will get rid of it, but that also removes all your other installed apps and stored data.
The messages on this Android lock screen Ransomware are for the most part a scam, and you should ignore any alerts that this malicious app might generate.
Under no circumstance should you send any vouchers or cryptocurrency to these cyber criminals, and if you have, you can request a refund, stating that you are the victim of the malware.
Remove Android Lock Screen Ransomware
This page is a comprehensive guide that will remove the malicious app from your Android phone. Please perform all the steps in the correct order. If you have any questions or doubt at any point, STOP and ask for our assistance.
- STEP 1: Start Android in Safe Mode
- STEP 2: Remove malicious device admin apps
- STEP 3: Uninstall malicious apps
- STEP 4: Reset browsers back to default settings
- STEP 5: Use Malwarebytes for Android to remove malicious apps
STEP 1: Start Android in Safe Mode
In this first step, we will start your phone in Safe Mode to prevent malicious apps from interfering with the next steps. We’re using Safe mode because it starts Android in a basic state, with only the factory apps and settings.
-
Long press the power button.
Long press the hardware power button (located on the side of your phone) until the power off menu appears.
-
Tap and hold on “Power off”.
When the power off menu appears, tap and hold on the “Power off” button on your screen until you get the “Safe mode” option.

-
Tap on “Safe Mode”.
When the “Safe mode” option appears on your screen, tap on it to enter safe mode.

-
Your phone is in Safe Mode.
Your Android phone will now restart and enter into safe mode. When your phone is in safe mode, you’ll see the “Safe Mode” text at the bottom left corner of your phone. You can now continue with the next step.

If you can’t find a safe mode on your phone, activate Airplane mode instead, to cut your device off from any networks.
STEP 2: Remove malicious device admin
In this second step, we will check the phone to see if there are any malicious apps with administrator privileges installed on your phone.
The administrator privileges are used by apps to perform legitimate tasks such as device management or for antivirus apps to do a remote wipe. Unfortunately, these elevated privileges are also being used by malicious apps to prevent victims from removing the malicious app from their phone.
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 1 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Go to “Device admin apps”.
When the “Settings” menu opens, if you’re using a newer version of Android or a Samsung phone, tap on “Biometrics and Security“, then tap on “Other Security Settings” and then on “Device admin apps“.
![Remove Android Lock Screen Ransomware [Virus Removal] 2 Device admin apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Go-to-Device-Admin-Apps.jpg)
However, because there are phones with different versions of Android the “Device admins apps” settings may be in a different menu, so below we’ve listed other common ways to reach the “Device admin apps” options:
- Security > Device admin apps
- Security & privacy > Device admin apps
- Security > Device Administrators
- Lock Screen and Security > Other Security Settings > Phone Administrators.
If you’re having trouble finding the “Device admin apps” settings, you can use your phone’s built-in search function to search through the Settings.
-
Disable administrator privileges for the malicious app.
Once you’ve accessed the list of device admin apps, disable admin rights by tapping the option to the right of the app. This will remove the checkmark or toggle the button to the off position. Now you can delete the app normally as seen in the below step. On some phones, you can tap the app right there in the admin apps list and then use the Uninstall app link to remove it immediately.

If there is no malicious app with administrator privileges on your phone, then you can continue with the next step from this guide.
STEP 3: Uninstall the malicious apps
In this third step, while the phone is still in Safe Mode, we will check if any malicious apps are installed on your device. Sometimes browser hijackers or adware apps can have usable Uninstall entries that can be used to remove these apps.
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 1 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 4 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find the malicious app.
The “Apps” screen will be displayed with a list of all the applications that are installed on your phone. Scroll through the list until you find the malicious app.
Look out for any suspicious app that could be behind all the drama – anything you don’t remember downloading or that doesn’t sound like a genuine program. Most often, cyber criminals hide malware inside video or photo editing apps, weather apps, and camera apps.Here are some known malicious apps: ES File Explorer, Xender, Amber Weather Widget, GO Weather Forecast & Widgets, Kitty Play, Touchpal, Z Camera.
The malicious program will most likely have a different name on your phone. If you cannot find any malicious app on your device, you can exit “Safe mode” (as seen below) and continue with the next step from this guide.

-
Uninstall the malicious app
When you find a suspicious or malicious app, tap on it to uninstall it. This won’t start the app but will open up the app details screen. If the app is currently running press the “Force stop” button, then tap on “Uninstall”.

A confirmation dialog should be displayed to confirm you want to uninstall the app, tap on “OK” to remove the malicious app from your phone.

-
Exit “Safe mode”.
Now that we’ve removed the malicious apps from your phone, we can exit “Safe mode”. To do this, hold the power button on your device until you get the power off menu, then select the restart option from the menu.

Your phone will now be rebooted and exit from the safe mode and boot into the normal mode.
STEP 4: Reset browsers back to default settings
In this next step, we will remove spam notifications, redirects, and change to default any settings that might have been changed by malware.
Resetting the browser settings to their default it’s an easy task on Windows or Mac computers; however, when it comes to Android, this can’t be done directly because it’s not an option built-in into the browser settings. Restoring the browser settings on Android can be done by clearing the application data. This will remove all the cookies, cache, and other site settings that may have been saved. So let’s see how we can restore your browser to its factory settings.
Remove malware from Chrome for Android
To reset Chrome for Android to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Chrome.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Chrome app, then tap on it to open the app’s details.

-
Tap “Storage”.
When Chrome’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Chrome’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
![Remove Android Lock Screen Ransomware [Virus Removal] 7 Tap Ok to restore default settings](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Chrome-Android-Confirm-Clean-Data-1.jpg)
Remove malware from Firefox for Android
To reset Firefox for Android to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Firefox.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Firefox app, then tap on it to open the app’s details.

-
Tap “Storage”.
When Firefox’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Firefox data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
Remove malware from the Opera browser
To reset the Opera browser to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Opera.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Opera app, then tap on it to open the app’s details.

-
Tap “Storage”.
When Opera’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Opera’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
Remove malware from Samsung Internet Browser
To reset the Samsung Internet Browser to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Samsung Internet Browser.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Samsung Internet Browser app, then tap on it to open the app’s details.

-
Tap “Storage”.
When the Samsung Internet Browser’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Samsung Internet Browser’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
Remove malware from Microsoft Edge for Android
To reset the Microsoft Edge for Android to its default settings, follow the below steps:
-
Open the “Settings” menu.
Tap on the “Settings” app from your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 5 Settings app in Android](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Menu-Settings.jpg)
-
Tap on “Apps”.
When the “Settings” menu opens, tap on “Apps” (or “App Manager”) to see all the installed applications on your phone.
![Remove Android Lock Screen Ransomware [Virus Removal] 6 Tap on Apps](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Android-Open-Settings.jpg)
-
Find and tap on Microsoft Edge.
The “Apps” screen will be displayed with a list of all the apps installed on your phone. Scroll through the list until you find the Microsoft Edge app, then tap on it to open the app’s details.

-
Tap “Storage”.
When the Microsoft Edge’s app info menu is displayed, tap on “Storage“.

-
Tap “Manage Space”.
Under the storage settings, you will get two options — Manage Space and Clear Cache. Tap on “Manage Space“.

-
Tap “Clear all data”.
Tap “Clear all data” to delete all Microsoft Edge’s data including accounts, bookmarks, and your settings to reset the default settings.

-
Confirm by tapping “Ok”.
A confirmation dialog should now be displayed, detailing the components that will be restored to their default state should you continue with the reset process. To complete the restoration process, tap “Ok“.
STEP 5: Use Malwarebytes for Android to remove malicious apps
In this final step, we will download, install and run a scan with Malwarebytes for Android to remove adware, browser hijackers, and other malware from your phone.
Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.
-
Download Malwarebytes for Android.
You can download Malwarebytes for Android by clicking the link below.
MALWAREBYTES FOR ANDROID DOWNLOAD LINK
(The above link will open a new page from where you can download Malwarebytes for Android) -
Install Malwarebytes for Android on your phone.
In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
![Remove Android Lock Screen Ransomware [Virus Removal] 16 Malwarebytes for Android - Open App](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Malwarebytes-for-Android-Open-App.jpg)
-
Follow the on-screen prompts to complete the setup process
When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
Tap on “Got it” to proceed to the next step.
Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
Tap on “Allow” to permit Malwarebytes to access the files on your phone.
-
Update database and run a scan with Malwarebytes for Android
You will now be prompted to update the Malwarebytes database and run a full system scan.
![Remove Android Lock Screen Ransomware [Virus Removal] 17 Malwarebytes fix issue](https://malwaretips.com/blogs/wp-content/uploads/2020/05/Malwarebytes-for-Android-Fix-Issues.jpg)
Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

-
Wait for the Malwarebytes scan to complete.
Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.

-
Click on “Remove Selected”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.

-
Restart your phone.
Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.
Your phone should now be free of browser hijackers, adware, and other malicious apps.
If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:
- Restore your phone to factory settings by going to Settings > General management > Reset > Factory data reset.
- Ask for help in our Mobile Malware Removal Help & Support forum.
This has happened to my partners fond, he has the Galaxy s5 we have tried all the above tips but will not do anything the fond functions are not working at all, is there anything else we can try
Hello Mo,
You could use the Android Debug Bridge, however this would mean that your phone had the USB debug option enabled.
Some info here: http://www.howtogeek.com/125769/how-to-install-and-use-abd-the-android-debug-bridge-utility/
Here is how to install ADB on Windows – https://www.youtube.com/watch?v=zXd7UC2Xm9U
If you manage to install ADB, then use this command:
adb uninstall com.MALICIOUS APP.apppackage
If you cannot do this, then I would try again the Safe mode, then I would go for a factory reset.
Holy crap. I was scammed. :(
The criminal app is called BrowserUpdate! get rid of it…
It’s not working, everytime I deactivate it, it pops up and reactivated.
yea this worked for me! Luke you saved me
thank you so much you are a life saver!!!!!!!
THANKYOUUUUU…!!!! for one moment i thought i was screwed. this article saved me :’)
Can I just say, this virus is sloppy in its execution? The typos everywhere tipped me off that this was some sort of virus. Thank you for helping me with this problem!!
Hi
I Was hoing you could give me some clarity.
If police came to your home under a warrant and accessed your computer is it true they can upload or download a file to monitor all your movements via that computer for life? By movements I mean the stuff your browsing,downloading,creating etc
I have found random files which look as if they are from when they came but my friend said that they are left the to surveillance me…..
I find this difficult to believe.
Hope you can shed some info
Thanks
Tania :)
I just helped my nephew move it from his. We were Both soo worried because my sister was going to KILL him because he just got the phone yesterday and it’s the second phone this year alone. the one that was on his phone was call XXTRAPlay or something like that. Beware everyone!!!!
Thanks a billion. Or, i guess more like $500. Last time i check out shady russian websites.
THANK YOU SO MUCH!!
ok so i thought my mom was going to kill me and and also the FBI. for the whole day i was shaking with fear thinking “HOW THE FUCK AM I GONNA GET $500 IN 3 DAYS?!!!” so then i started to think after like 5 hours “is that really how the FBI works? no i dont think so” so i try to look up what it was then i saw this and i felt so much better but before i was like about to cry because i didnt have that money nor did i want to go to court like it said.
THANK YOU!!! I ALMOST DIED!!
The latest version of the app is named BrowserUpdate…… dont let its name fool you! Thanks for the help.
@ Charlie: This was it! Thanks allot. This is the second day trying to get the hang of it. Once in safe mode I start checking each app in part as I did not have any Adobe Player or anything else obvious, and for some reason I made few exceptions. Among them BrowserUpdate… Yoy’re the MAN!!!
Wow fucking thank u bro im sorry fucken happy u are here didn’t even know that would be the name u The Real mvp
Thank you so much! I was terrified when i couldnt find any suspicious app. Deleted SystemUpdate and my phone works fine now. Thank you Sir!
woww dude i owe big time for this next pay check ill donate cus you are a hero !!! thanks A LOT man .
Thank you so much! My daughter is ever so thankful that we didn’t have to do a hard reset. However, the first time we got into safe mode and attempted to uninstall the obviously named app (PORNDROID) it would not work, sent us to some other scary screen that wanted to “open a package”. We decided to start over, took the battery out, put it back and went back into safe mode. Had her go into play store first and make sure the Avast Free Mobile Security was downloaded after that I tried to uninstall again and it worked this time, YAY! Had to also delete a bunch of downloaded crap but everything seems fine now. Thank you so much, my daughter thinks you saved her life, LOL.
Thank you.
That is £100 I can keep in my pocket
Thank you so much you literately saved my life Sir!!!Thanks so much your the best and as luis said i would also pay you 500 dollars thank you again!!
U have no idea how much of a superhero u are to me right now!!!! When it popped up on my S3 i was possitive it was some sort of scam. And i wasn’t going to pay anybody $500 ! But my phone was locked none the less. Thanks to u, it no longer is. If i had the $500 i would send it to u my friend. Thanks again. Great work!
You sir are a hero! I totally thought my life was going to be ruined because i was being framed by some virus. But this showed me that it was just a scam *wipes sweat off forhead. Thank you thank you thank you!
Can someone please help me!?
I’ve gone into ‘Safe mode’ on my S4 mini but I cannot see BaDoink or Adobe. Is there anything else it might be called?
Thanks