How to remove “Your device has been blocked” ransomware virus from Android tablet or phone?

User Rating: / 94
PoorBest 

“Your device has been blocked” - how to remove ransomware infections from an Android devices?

Cyber criminals have been spreading ransomware viruses on Windows-based computers for some time. These types of infections became popular in mid-2006 and continue to infect personal computers and extort money from their victims. Recently, security research began showing a rise in Android-based mobile ransomware infections. Commonly, ransomware viruses exploit the names of authorities including the FBI, USA Cyber Crime Investigations, and The ICE Cyber Crime Center - making fake claims that users must pay an amount of money (for supposed law violations such as watching pornography, using copyrighted files, etc.) in order to unblock their devices.

In most cases, cyber criminals employ the Green Dot MoneyPak, Ukash, or PaySafeCard pre-paid card services to collect fake fines from unsuspecting mobile device users. Tablet and mobile phone users should be aware that paying these fines as ordered by these messages is equivalent to sending their money to cyber criminals. Note that neither the FBI, nor any other authority, use screen lockers to collect any fines.

android ransomware

Cyber criminals have localized ransomware viruses that target mobile devices. Therefore, users from different countries see fake screen-locking messages displayed in their local language and exploiting names of authorities from their countries. Ransomware infections have become a profitable business for cyber criminals who continue to search for various ways of infecting mobile devices across the world. At time of writing, some ransomware viruses were targeting Android devices - all using rogue applications to lock tablet or phone screens.

Koler Android ransomware:

Distributed using fake applications (for example, “BaDoink” and "PhotoViewer").

android koler ransomware spread using badoink fake app

Other known variants of this ransomware are proliferated using text message spam. An infected mobile device sends an SMS message to all contacts in the address book ("Someone made a profile named ‘contact's name’ and he uploaded some of your photos! is that you?”) followed by a link leading to a Dropbox page. Android device users who follow this link will inadvertently download a “PhotoViewer” application, which launches the screen-locking message.

android koler ransomware spread using photoviewer fake app

Screenshots of mobile devices locked by the Koler ransomware virus targeting different counties (Koler Android ransomware Trojan - demanding a payment of $300 using MoneyPak, PaySafeCard, or Ukash):

Norway: KRIMINALPOLITISENTRALEN - OBS! Nelefonen din har blitt blokkert av sikkerhetsmessige grunner nevnt nedenfor.
Finland: POLIISIHALLITUKSEN - HOUMIO! Puhelin on lukittu turvallisuuden vuoksi allamainittujen syiden takia.
Australia: AFP. Crime Commision (ACC) - ATTENTION! Your phone has been blocked up for safety reasons listed below.

android ransomware targeting Finland Norway and Australia

USA: Mandiant U.S.A. Cyber Security FBI. Department of Defense - Your Phone has been blocked up for safety reasons listed below.
Spain: GRUPO DE DELITOS TELEMATICOS - Atención! Su teléfono ha sido bloqueado por razones de seguridad vistos los motivos abajo detallados.
Germany: - BUNDESPOLIZEI, GVU - WARNUNG! Zugang von Ihrem Telefon wurde vorläufig aus den unten aufgelisteten Gründen gesperrt.

android ransomware targeting USA Germany and Spain

Ireland: GARDA, The Guardians of the Peace of Ireland - Your Phone has been blocked up for safety reasons listed below.
Mexico: SSP - Atención! Su teléfono ha sido bloqueado por razones de seguridad vistos los motivos abajo detallados.
Netherlands: - ATTENTE! Uw telefoon wordt geblokkeerd om veiligheidsoverwegingen wegens de hieronder aangegeven redenen.

android ransomware targeting Mexico Ireland and Netherlands

Switzerland: FEDPOL. BundesKriminalPolizei - WARNUNG! Zugang von Ihrem Telefon wurde vorläufig aus den unten aufgelisteten Gründen gesperrt.
United Kingdom: PCeU, Metropolitan British Police - ATTENTION! Your phone has been blocked up for safety reasons listed below.
Poland: Polizja Biuro Służby Kryminalnej - Panska telefon zostal zablokowany ze wzgledow bezpieczenstwa z wskazanych nizej przyczyn.

 android ransomware targeting Switzerland United Kingdom and Poland

France: POLICE NATIONALE - ATTENTION! Votre telephone est bloque des raisons de sécurité suivantes.
New Zealand: New Zealand E-crime Lab - ATTENTION! Your phone has been blocked up for safety reasons listed below.
Portugal: POLICIA JUDICIARIA DE PORTUGAL - ATENÇÃO! O seu telefone esta bloqueado por razoes de segurança, pelas seguintes razoes.

android ransomware targeting France Portugal and New Zeland

Slovakia: Policajnehi Zboru - VAROVANIE! Vas telefon je uzamknuty z bezpecnostnych dovodov by z nasledujucich dovodov.
Slovenia: NACIONALNI PREISKOVALNI URAD - POZOR! Vas spletni telefon je blokiran iz varnostnih razlogov nizje.
Turkey: JANDARMA GENEL KOMUTANLIGI - DIKKAT! Telefon guvenlik hususunda asagidaki nedenlerle bloke edilmis.

android ransomware targeting Slovenia Slovakia and Turkey

Text presented in Koler Android ransomware virus:

Mandiant U.S.A. Cyber Security
FBI Department Defense
U.S.A Cyber Crime Center

ATTENTION! Your phone has been blocked up for safety reasons listed below. All the actions performed on this phone are fixed. All your files are encrypted. CONDUCTED AUDIO AND VIDEO. You are accused of viewing/storage and/or dissemination of banned pornography (child pornography/zoophilia/rape etc.) You have violated World Declaration on non-proliferation of child pornography. You are accused of committing the crime envisaged by Article 161 of United States of America criminal law. The penalty set must be paid in course of 48 hours as of the breach. On expiration of the term, 48 hours that follow will be used for automatic collection of data on yourself and your misconduct, and criminal case will be opened against you. Amount of fine is 300$. You can settle the fine with MoneyPak xress Packet vouchers. As soon as the money arrives to the Treasury account, your phone will be unblocked and all information will be decrypted in course of 24 hours.

FBI Android ransomware virus:

Distributed using a fake Android application named “Porndroid”.

android porndroid app used for spreading FBI ransomware

Users who install this fake app are presented with a ransom-demanding notification (false accusations of viewing child pornography).

Screenshot of a mobile device locked by FBI Android ransomware virus (demanding a payment of $500 using MoneyPak):

android fbi ransomware

Text presented in FBI Android ransomware virus:

DEPARTMENT OF JUSTICE
FEDERAL BUREAU OF INVESTIGATION
FBI HEADQUARTERS
WASHINGTON DC DEPARTMENT, USA

As a result of full scanning of your device, some suspicious files have been found and your attendance of the forbidden pornographic sites has been fixed. For this reason your device has been locked. Information on your location and snapshots containing your face have been uploaded on the FBI Cyber Crime Department’s data center. First of all, familiarize with the positions stated in the section “The Legal Basis of Violations”. According to these positions your actions bear criminal character, and you are a criminal subject. The penalty as a base measure of punishment on you which you are obliged to pay in a current of three calendar days is opposed. The size of the penalty is $500

Attention! Disconnection of disposal of the device or your attempts to unlock the device independently will be apprehended as unapproved actions interfering the execution of the law of the United States of America (read section 1509 - obstruction of court orders and section 1510 - obstruction of criminal investigations). In this case and in case of penalty non-payment in a current of tree calendar days from the date of this notification, the total amount of penalty will be tripled and the respective fines will be charged to the outstanding penalty. In case of dissent with the indicted prosecution, you have the right to challenge it in court. To make a penalty payment, go to section “Payment Penalties”.

Update - 14 September, 2015 - Another variant of this ransomware is capable of changing victims PIN for the lock screen. The malware itself is spread through fake adult videos which install a rogue application called "Porn Droid" on the victims device. After successful infiltration this malicious app gains Device Administrator privileges by tricking users into installing a fake update patch. After gaining the administrator privileges this ransomware presents it's victims with a fake message which supposedly was sent by FBI demanding to pay a fine of $500 for watching forbidden pornographic sites, moreover it changes the PIN lock of the compromised device. To remove the PIN lock users should reset their devices to factory defaults.

android pinlock changing ransomware

Update 13 April 2016 - A new ransomware called Sonorousness started attacking Android users. Cyber criminals are using a name Cyber.Police to trick mobile users into paying a fake fine for supposedly watching illegal pornography. This ransomware installs on victim’s device by impersonating an application that supposedly delivers porn media.

Screenshot of Sonorousness ransomware:

sonorousness android ransomware

Text presented in this ransomware:

CYBER.POLICE American national security agency

ATTENTION! YOUR DEVICE HAS BEEN LOCKED REASONS INDICATED BELOW. Remaining time to pay a fine. Otherwise the case file will be transferred to the court. All actions are illegal, are fixed. History query stored in the database of the U.S. Department of Homeland Security. To unblock your device and close your case you should pay a $200 file to Treasury account. Pay to unblock device with iTunes Gift Card. Your case will be closed immediately after the transaction processing! Avoid becoming a fraud’s victim! Evade the scams, that ask you to afford you iTunes Gift Card. Please, observe following rules for your safety: You mustn’t give your prepaid card number or your bank account details, till you are absolutely sure, that the person is conscientious. Remember, if somebody asks you to buy a iTunes Gift Card, it is a scam. Don;t show or report your iTunes Gift Card Code to anyone. Use only approved Apple partners.

Update 25 April 2016 - A new ransomware was discovered targeting Android usurer who file in Russia. This ransomware is being distributed using fake Android applications named “Домашний Порно Изврат”, “RootChecker” and “Porn Video HUB+”.

Here are some screenshots of Android ransomware targeted at users from Russia:

android russian ransomware sample 1 android russian ransomware sample 2 android russian ransomware sample 3

Fake applications (“Домашний Порно Изврат”, “RootChecker” and “Porn Video HUB+”) used in distribution of these ransomware infections:

android russian ransomware “Домашний Порно Изврат” android russian ransomware “RootChecker” android russian ransomware “Porn Video HUB+”

Ransom demanding message presented in this scam (accusing Android users of viewing child pornography, etc):

ВАШЕ УСТРОЙСТВО ЗАБЛОКИРОВАНО!За Просмотр запретного контента с элементами ПЕДОФИЛИИ, НАСИЛИЯ, ИНЦЕСТА, ЗООФИЛИИ и ГЕЙ-ПОРНО который строго запрещён Законом РФ загружены на сервер МВД,будет передано е прокуратору РФ в случае не оплаты штрафа,даже если вы разблокируете телефон самостоятельно! Причина блокировки обслуживания - посещение и просмотр запрещенных интернет ресурсов содержащие элементы порнографии с участием несовершеннолетних, элементы ПЕДОФИЛИИ, НАСИЛИЯ, ИНЦЕСТА, ЗООФИЛИИ и ГЕЙ-ПОРНО.  Для предотвращения открытия уголовного дела и возобновления доступа к устройству,удалению всех Ваших данных с сервера, Вам необходимо оплатить штраф в размере 1000 Рублей в течении 15 часов. Следуйте инструкциям для оплаты:
1. Найдите терминал сотовой связи для оплаты VISA QIW1 WА1[Е7. 2. Введите номер телефона + 79688220910 З. В поле коментарий введите код -В1)95284680 4. Оплатите 1000 рублей 5. После поступления оплаты Ваше устройство будет автоматически разблокировано и все данные удалены с сервера в течении 3 часов. Если оплата не поступит в течении 15ч, ВСЕМ контактам Вашего телефона, а так же ВСЕМ Вашим контактам социальных сетей будет отправлено смс сообщение, о том что на вас заведено уголовное дело за просмотр ДЕТСКОЙ ПОРНОГРАФИИ. Попытки разблокировать телефон самостоятельно приведут к ПОЛНОЙ БЛОКИРОВКЕ Вашего телефона, а видео с Вашим участием будет ВЫЛОЖЕНО в социальные сети и УоиТиЬе с пометкой ПЕДОФИЛИЯ.А так же все данные с Вашего телефона будут переданны в ПРОКУРАТУРУ РФ для возбуждения уголовного дела.
Проверить оплату

How to remove “Your device has been blocked” ransomware from an Android tablet of phone?

Ransomware notifications (that are impossible to close) are loaded from third party rogue applications. For example: BaDoink, VideoViewer, VideoPlayer, Network Driver System, Video Render, and PornDroid among many others. To eliminate the screen-blocking message, you must uninstall the rogue application which causes it.

Boot your Android device into Safe Mode:

1. Hold down the power button on your device.

2. In the opened notification window, long-press the "Power off" option.

booting android device into safe mode step 1

3. In the opened window, confirm that you wish to boot into Safe Mode by tapping "OK".

booting android device into safe mode step 3

4. When your phone or tablet reboots, you should see a "Safe Mode" watermark (at the bottom of the screen). Go to your device Settings menu, tap “Apps” or “Application manager”. Touch the application you wish to uninstall (which causes the rogue ransom-demanding message to appear on your device, for example, PornDroid).

Some newer Android devices boot into Safe Mode by holding the volume up and volume down button simultaneously when restarting.

To protect your Android device from these ransomware infections, disallow third party application installation. Go to “Settings”, select “Security”, scroll down and uncheck the “Unkown sources” box.

android disabling unknown sources app installation

Adam Alvarado

I have a tab a galaxy tablet that has a block fbi virus and won't shut off or anything what can I do

THECHAMPISHERE!

That means the ransomware was in an app you installed yourself so.. be carefull

max

All it says is just uninstall the device(photoviewer, badoink, or porndroid) "in apps"and uncheck the "unknown sources" which is in the security and all this is in settings, but also you will have to reboot to safe mode. Thank you person who made this blog, you really helped if my mom and dad found out they would of kill me so thix.:)

Christine Hunter

I have a Samsung Note 2. I removed this easily last time it happened by the above method but this time uninstall is not highlighted. I tried going into system /security/device administrator and I activate it but it doesnt bring up a list of viruses fir me to check and system update remains unhighlighted and I cannkt uninstall please help

Layna

Okay, so my phone is an UK Samsung Galaxy III and the Police Virus appeared on my phone around 2 hours ago. You know, with the whole: “ATTENTION! Your phone has been blocked up for safety reasons" thing. My advice would be to scroll down these comments and read this article above. It saved my phone, absolutely.
1. So first you'd power down. (Hold the power button remove battery, etc)
2. Then you'd restart (press power button again, insert battery again, etc)
3. Whilst restarting you'd hold down the 'lower volume' button until you're phone would restart with a 'Safe Mode' feature at the bottom.
4. Then you'd go to Settings~ More~ Application Manager~ All
5. And then you'd scroll down the page until you'd find the 'System Update'~ 1.13 MB app. UNINSTALL THE DAMN THING IMMEDIATELY.
6. Et voila!
(I hope this helped, honestly. And another big thank you to 'Mike' on the comments for helping me.)

Layna

Thank you so much!!!!!! You have no idea how long I spent searching for the blasted app, and because of you I've found it! Thank you again!

lissa bridge

I cant get my phone in safe mode it comes up with manual and u use volume key to select but no option gor safe mode. I have a galaxy a3. My message cones up only in the internet browser asking for mobey, saying its blocked and ive commited an offence. Please help

David Molina Jr.

My app is the same but it is set as administrator and i cant take it off. I try to take it off so it wont be administrator but the safe mode thing turns off

Ashie

Yes I saw it on my S3 too ! I didnt unistall it but its gone now..weird..at leats I know what to uninstall when it will happen again :D

Mike

My android phone just got hit with this virus today. It freaked me out at first because I wasn't aware of it. The whole "pay us $200 in iTunes gift vouchers" thing gave it away as unofficial though.
Thanks for the comments on this site because it helped me know how to get rid of the virus. It was called "System Update" on my phone, but had a different icon as can be seen on the image I've included.

I'm on a Galaxy S3 and got into safe mode by holding the volume down button when the animated samsung logo appeared.

Thanks again

nathanial

I love you internet

Jack Marascio

jack from brooklyn ny would like to thank you
my acer iconia tab had the security virus
i followed your steps and the virus is gone
in apps mine was security update

thank you

Apple jack

This is the only site that helped me since the cyber.police police virus got on my mom's tab 2 and it was taking me a while on how to go in to safe mode and this site helped me with that and with finding the virus app. The comments helped me figure it out after uninstalling a bunch of apps and you guys made me realize it was security update which I would have have never thought of without reading these comments. Thanks so much everyone.

Becky Mantle

what next will it be safe after this and it was under system update aswell.

MarkG

"To protect your Android device from these ransomware infections, disallow third party application installation. Go to “Settings”, select “Security”, scroll down and uncheck the “Unkown sources” box."....My Galaxy Note 10.1 was infected even though this box was already unchecked....Was easy to get rid of though....I would love to get my hands on one of you hackers

Frank

Thanks a lot.. I got "Systém Update" as well on Galaxy Tab 2 and it was possible to unistall directly from safe mode through settings -> apps -> downloaded...

mve

Thanks very much for the advice. I was able to access safemode and remove the virus from my Galaxy Note 10.1. FYI my app was called 'System Update'. Rebooted and the tablet is fine.

jimbo

Go on settings > security > system administration. You will see a list, you need to untick the virus as it has admin over your phone currently. It may be under a different name but once deautherised you can delete,

..........

thank you God bless you

Ray

John... thanks for this advice... it got me into the safe mode and I deleted systems update which has worked the trick. Once again thanks for sharing

teimoor

tnx for replaying this virus installed an xxvideo app that i cant uninstall it

Sue Wright

i was just hit with the virus im holding the power button down but the fbi screan is still there and i cant see the power off screan what do i do

ash

I woke up this morning, and couldn't get access threw my phone. I was so worried like what the HELL just happened. thanks to this website it helped me get threw it. I tried pressing long on the power off button, but it didn't work for my type of phone, however, i tried holding on the volume down button and it worked. thanks to u again

keith hope

Hi my name is keith and I had a malicious virus on my Samsung Note 2 . thanks to your advice I at last managed to erase the culprit after several hours of pulling my hair out!! you are a star!!!

Craig

Imy still not sure how to do this I went to application manager but I don't know what to do from there if I get on something it says I can Uninstall updates but I can't get rid of it and this is on Samsung galaxy s4 please help I need to get back into my tablet I have very important stuff to take care of. And if you help thank you and thank you anyways for this advice.

ruth

I Stupidly paid the money as could not see anything to show that it wasn't legit! until I could get back on the web! that's money down the drain!!!

ANON50

Yes my husband has had this happen to him 3 times on hs cell whoever is doing this needs to spend time in prison for scamming and falsely accusing someone of porn that is not looking at. How did they get my husband's pic when there isnt any on his phone?

Partyless

System Update was the culprit on my case too. Thanks for this.

Meredith

SUCCESS.

So. . . this happened to me this morning. I'm in the U.S. and using an older Pantech droid. Got the scary FBI- looking-msg of "Pay Now. Your phone is locked" etc. etc. Turned off the phone, took the battery out, turned it back on. Nope. Message still there. (Repeat. Feeling more and more panic coming on).

I contacted my Verizon service provider, but, ultimately they said I should probably call Tech Support. I called one of the local outlets to see if they assist with getting rid of viruses and they told me a) maybe get a new phone - (of course. And I don't want that option) or b)it may have to come down to them doing a Factory Reset - which would delete everrrrryything. Okay. I decided I would keep that as my last option. I just want to use my dumb, simple little phone again.

So, I turned off the phone and did some online searching on the office PC. But after reading all sorts of articles, nothing really made me feel confident that I'd be able to get rid of this thing - - I'm not really tech-savvy. (Er, hence the older model of phone).

Anyway, I figured out how to do the Safe Mode thing (on mine, when I decided to turn on the phone again, I kept pressing the Volume key down and that's how I got to Safe Mode. Those two words appeared on the bottom right of my screen).

So, the culprit wasn't visible at first. But, as I still delete cache and cookies from individual apps, I was able to single out one app that simply didn't belong, and yes, it disguised itself as a 'Security Update' or something akin to that nature. It didn't have the little droid guy next to it, but, instead it almost looked like an Eye. Not kidding. I uninstalled that piece of junk STAT and hoped for the best. Then I turned off my phone, waited a bit, took a deep breath before turning it back on annnd - - -

Voila! Things seem normal!! (Sure hope they are).

THANK YOU THANK YOU to all the Internet Army who go online and try to help others like me in this situation. Viruses and the awful people who make and send them are just evil.

Good Luck to everyone else out there - - there's hope!!

Julia Themelis

hey, how exactly did you do it on the s2?? i've been trying to figure it out for hours, thanks

Aaron Lowe

Happened on my Samsung S2. Uninstalled "Systems update" fixed the problem thanks. I was just about to storm to the police station and yell at the police lol

stuart hitchens

I recently installed an app on my phone which used clickjacking ransomware to gain admin access and now I cant unadmin it no matter how much I click deactivate. Help!

Karen

thank you so much, your instructions worked, and i've gotten rid of the Ukash virus. relieved!

David

Just had this happen to my phone been trying for 2days to get it into safe mode,when I finally did couldn't find virus in application manager to delete it then I spotted your post,and found it under system update,cheers.

PLUKKIE3

Hi All, even as an experienced IT-consultant, it took me several hours to find the offending app/process that caused the Interpol message and locked a customer's Note 10.1 tablet. In my case, the offending package was named "com.reclaimable.rectilinear" and appeared as a 'System Update' with a green android icon in the Apps list (size around 1,20 Mb) .
This looks to me like a new variant, since I could not find the package name anywhere using Google or other search engines.

Steps I followed to remove the Ransomware:

Phase 1 (Failed attempt to resolve the issue in SAFE mode):
- Started the tablet in Safe Mode
- Tried to uninstall the 'System Update'. This wasn't possible, all buttons were greyed out.
- When checking Security/Device Administrators, there was NO option (in SAFE mode that is) to remove the ransomware app from the list
- Used ADB tracking and analyzed the list of processes using 'adb shell ps', but could not initially identify problematic processes (it was hidden well as it later turned out...)

Phase 2 (Restoring access to the device in NORMAL mode):
- Started the tablet in NORMAL Mode
- Ensured that the Interpol malware would lock up the device and ensured that it was prominently visible on the screen
- Used DDMS (Android Device Monitor) (invoke from ./tools/monitor.bat) from the connected Windows PC and click the 'Dump View Hierarchy for UI Monitor' in order to create a dump.
- In the created dump , under Node Detail, under package, 'com.reclaimable.rectiliniear' is mentioned
- Issued an "adb shell am force-stop com.reclaimable.rectiliniear"
- SUCCESS: This command effectively kills the malware, and immediately brings the tablet back to life !!

Phase 3 (Structurally removing the ransomware from the device):
- Ran Avast Mobile Security, MalwareBytes Anti-Malware and Avast Anti-Ransomware for Android (from the Play Store, see Notes below regarding the results).
- Although both Avast as well as MalwareBytes actually found the ransomware, I decided to uninstall it myself as follows:
- When checking Security/Device Administrators, the ransomware becomes visible now as ‘Update’ (please note that this wasn’t visible when in SAFE mode earlier !)
- Removed the checkbox (so that the App can be uninstalled in the next step)
- Through Apps, the ‘System Update’ app can now be successfully uninstalled (button to remove the ransomware is now active)
- SUCCESS: This action has completely removed the ransomware from the device !

NOTES:
- MalwareBytes Anti-Malware Mobile DID find the malware ! (Android/Trojan.Slocker.cx under /data/app.com.rectlinear-1.apk, which actually is the ‘System Update’ ransomware app)
- Avast Mobile Security DID find the ‘System update’ app and identified it as malware !
- Avast Anti Ransomware did not detect anything
REFERENCES:
- http://www.howtogeek.com/12576...

max

Just found this post and it worked on my samsung S3. Was security update on the main application manager screen. removed it no problem. many thanks

Memo

Dude thank u so much i was wondering how i was gonna break this to my dad

Peter van den Burg

What do I do when THE uninstall button is not highlited?

Marcelo

System Update here too! Thank you SO much!

Steve

Thanks a lot. I was using my samsung tablet to browse a japanese manga site when i suddenly got infected by the malware. Went into safe mode & removed "System Update" . Worked like a charm! =)

chelsea

Thank you too much ! This pup up came u and immediately went to paysafecard.com to check it out because i was soon worried I was gonna be filed with charges . ITS easy to remove it on iPhone , all i did was off my phone and then find safari in settings . After that , I block everything including frequently visited websites , search engine suggestions ,FRAUDULENT WEBSITE WARNING , DO NOT TRACK AND I PRESSED CLEAR HISTORY AND WEBSITE DATA . THEN , i press on ADVANCED .I deleted the passwords of the culprits off my phone and I saw all the passwords they used on my phone . LUCKILY I DIDNT WENT AND PAY THE FINE LIKE A BLIND MICE.

chelsea

Thank you so much , you have been so helpful

Emily

I need more help I have my tablet in safe mode however I cannot uninstall the application causing the virus. It is called xxx video and I hit uninstall and it just doesn't. Any suggestions? And I'm not even sure how this would happen the tablet belongs to my three year old daughter and when it locked up it showed a cyber police obviously fake site that had a girl fornicating with a dog. So please help me out with some good advice on how to rid this app it has already broken my heart my daughter seen that even if she doesn't understand. Thank you.

Allen

I saw the app before it locked my tablet, i immedietly uninstalled the app right before it locked. Now im in safe mode >settings>application manager> when i click the app the option to uninstal is not a availible to be pressed. What can i try from here?

Supercool

Hello to you all.....
I'm experiencing this also........
I have followed the steps include:
-turn your android phone into safe mode first (Mine is Samsung Galaxy Duos GT-19082)
(reference): https://www.youtube.com/watch?...
-Go to settings - tap "Security" - uncheck the "Unknown sources" box - tap "Device administrators" and tap on the application that is there (1 application for me) and it is the "System Update" - tap "Deactivate" (bottom right corner) - the app will disappear afterward.
-Then, enter "Application Manager" - find and tap "System Update" - easily tap the "Uninstall" button (Follow the previous step because once on "Safe Mode" some of your phone prevent the "Uninstall" button on the "System Update" app)
-Wait patiently for the app to be uninstalled, and you are done.
-Finally, turning your android into normal again (not "Safe Mode) just press and hold the power button and choose the "Restart" button.

Thank You for your cooperation and patience, hope you all succeeded. :) ;)

Semikolon

Thanks for this very helpful advice, it helped. Trough 'safe mode' to programs, and installed apps. Aim for Security Update (!) 1,17MB and uninstall. On my Samsung Note 10.1 N 8010. To get to safe mode is a bit difficult, but hold down volume up down simultanously while the startup goes, you'll make it. Don't give up. Thanks again!

Jay

I had this virus on my Samsung 10.1. thanks for the help. I removed it. You guys rock!!

Shawn

Thanks for the great advice. I went through two other help pages and did not remove the virus. Once you said it was security update I saw a similar app, System Update, and deleted it. This removed the virus.

Michael Chan

Thank you, thank you. My tablet was infected through an app called System Update or Program Update.

M

Hashashin_101

Mine is called Video Player V1.2 and there's no uninstall/disable option available please help