Threat Description

Trojan: HTML/Browlock


Category: Malware
Type: Trojan
Platform: HTML
Aliases: Trojan:HTML/Browlock.[variant]


Trojan:HTML/Browlock is ransomware that prevents users from accessing the infected machine's Desktop; it then demands payment, supposedly for either possession of illegal material or usage of illegal software.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.


For more information, see Removing 'Police-themed' Ransomware.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more assistance.

Technical Details

Trojan:HTML/Browlock has been reported to target users in multiple countries, including the United States, the United Kingdom and Canada. Typically, it will display a 'lock screen' purportedly from a local or federal law enforcement authority, claiming that the machine has been locked and encrypted due to 'illegal activities'. A 'fine' is then demanded to restore the system.

This malware was also covered in our Labs Weblog blogpost:

A lock screen used by one Browlock variant is shown below:


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

F-Secure Community

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More