You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

My iPad Air got a virus, what should I do?

I got a FaceBook Messenger post from someone I know. Unfortunately I clicked on the link therein.


twenty-four hours later I watched as my iPad sent the same infected message to everyone in my contacts.


These are the steps I took immediately:


Deleted Facebook Messenger


Posted message on Facebook warning that my Facebook Messenger had been hacked and to delete all messages from me


Changed Facebook password


Emailed everyone in my contacts telling them to delete Facebook Messenger posts from me.


Questions:


Is there anything else I should do?


Does the (?) virus still reside on my devices (IPad Air, IPhone XS, IMac, Mackbook Pro, Apple Watch 6)?


if its still there, how do I remove it?


Thanks for your knowledgeable suggestions.

iPad Pro 12.9-inch, 2nd Gen, Wi-Fi

Posted on Dec 30, 2020 11:21 PM

Reply
Question marked as Top-ranking reply

Posted on Dec 31, 2020 1:42 AM

Providing that you have not attempted to jailbreak your device - or have bypassed protections by side-loading third-Apps (if you don’t know what this is, then don’t worry about it), then it is highly unlikely that your device will actually have been infected with a virus or other malware.


However, there is one potential source of immediate issues with your iPad that you may need to check - this being for a vulnerability that is often exploited that gives the appearance of a malware infection. This involves your iPad/iPhone Calendar - the symptom being your Calendar appearing to have been populated with regular events that warn of malware infection.



Calendar Infection


Whilst not a malware infection in the traditional sense, if this exploit is observed on your device, it is highly probable that you were manipulated (via a simple click on a website link) into “subscribing” an additional (unwanted) Calendar to your device - and this unexpected Calendar is exposing unwanted calendar events and sending you unexpected “adverts” or other warnings. 


If you see this issue, you’ll need to check for what’s out of place...

iOS/iPadOS13 and earlier: Settings > Passwords and Accounts

iOS/iPadOS14: Settings > Calendar > Accounts


Look for an “account” that shouldn’t be in the list of accounts - as this will likely include the Calendar that contains all the unwanted events. When/if you find the suspect account, tap - then select Delete Account. This should resolve this specific problem in its entirety.



Malware


Most alerts that you see are pop-up messages from websites - these being designed to scare the unwary into giving away sensitive information - or to fool you into doing something that you shouldn’t.


Due to the system architecture of iOS/iPadOS, unless jailbroken, your iPad is not susceptible to traditional malware infection per-se. However, as with all computer systems, there are still vulnerabilities and exploits to which you remain at risk.


Browser-based attacks can largely be mitigated by installing a good, trusted, Content and Ad-blocking product. One of the very best and most respected within the Apple App Store - designed for iPad, iPhone and Mac - is 1Blocker for Safari.

https://apps.apple.com/gb/app/1blocker-for-safari/id1365531024


1Blocker is highly configurable - and crucially does not rely upon an external proxy-service of dubious provenance. All processing takes place on your device - and contrary to expectations, Safari will run faster and more efficiently. 


Unwanted content is not simply filtered after download (a technique used by basic/inferior products), but instead undesirable embedded content blocked form download. A further benefit on metered services, such as cellular connections where you data may be capped or chargeable, this not only improves speed but also saves you money.


When using a good quality Content blocker, a high proportion of otherwise inescapable risk when using your Safari browser, or linking to external sources from email, is effectively mitigated before it even reaches you.


There are additional protections that can enhance protection further, such as using one of the better Recursive DNS Services in preference to automatic settings. This can either be set on a per-device basis in Settings, or can be set-up on your home Router. I recommend using one of the following services, for which IPv4 ad IPv6 server address are included here:


Quad9 (recommended)

9.9.9.9

149.112.112.112

2620:fe::fe

2620:fe::9


OpenDNS

208.67.222.222

208.67.220.220

2620:0:ccc::2

2620:0:ccd::2


Cloudflare+APNIC

1.1.1.1

1.0.0.1

2606:4700:4700::1111

2606:4700:4700::1001


Use of the above DNS services will help to shield you from “known bad” websites and URLs - and when used alongside 1Blocker, provides defense in depth.


I hope this reassurance and guidance proves to be helpful in resolving any issues with suspect malware and malicious websites.

3 replies
Question marked as Top-ranking reply

Dec 31, 2020 1:42 AM in response to Crassbrassfrog

Providing that you have not attempted to jailbreak your device - or have bypassed protections by side-loading third-Apps (if you don’t know what this is, then don’t worry about it), then it is highly unlikely that your device will actually have been infected with a virus or other malware.


However, there is one potential source of immediate issues with your iPad that you may need to check - this being for a vulnerability that is often exploited that gives the appearance of a malware infection. This involves your iPad/iPhone Calendar - the symptom being your Calendar appearing to have been populated with regular events that warn of malware infection.



Calendar Infection


Whilst not a malware infection in the traditional sense, if this exploit is observed on your device, it is highly probable that you were manipulated (via a simple click on a website link) into “subscribing” an additional (unwanted) Calendar to your device - and this unexpected Calendar is exposing unwanted calendar events and sending you unexpected “adverts” or other warnings. 


If you see this issue, you’ll need to check for what’s out of place...

iOS/iPadOS13 and earlier: Settings > Passwords and Accounts

iOS/iPadOS14: Settings > Calendar > Accounts


Look for an “account” that shouldn’t be in the list of accounts - as this will likely include the Calendar that contains all the unwanted events. When/if you find the suspect account, tap - then select Delete Account. This should resolve this specific problem in its entirety.



Malware


Most alerts that you see are pop-up messages from websites - these being designed to scare the unwary into giving away sensitive information - or to fool you into doing something that you shouldn’t.


Due to the system architecture of iOS/iPadOS, unless jailbroken, your iPad is not susceptible to traditional malware infection per-se. However, as with all computer systems, there are still vulnerabilities and exploits to which you remain at risk.


Browser-based attacks can largely be mitigated by installing a good, trusted, Content and Ad-blocking product. One of the very best and most respected within the Apple App Store - designed for iPad, iPhone and Mac - is 1Blocker for Safari.

https://apps.apple.com/gb/app/1blocker-for-safari/id1365531024


1Blocker is highly configurable - and crucially does not rely upon an external proxy-service of dubious provenance. All processing takes place on your device - and contrary to expectations, Safari will run faster and more efficiently. 


Unwanted content is not simply filtered after download (a technique used by basic/inferior products), but instead undesirable embedded content blocked form download. A further benefit on metered services, such as cellular connections where you data may be capped or chargeable, this not only improves speed but also saves you money.


When using a good quality Content blocker, a high proportion of otherwise inescapable risk when using your Safari browser, or linking to external sources from email, is effectively mitigated before it even reaches you.


There are additional protections that can enhance protection further, such as using one of the better Recursive DNS Services in preference to automatic settings. This can either be set on a per-device basis in Settings, or can be set-up on your home Router. I recommend using one of the following services, for which IPv4 ad IPv6 server address are included here:


Quad9 (recommended)

9.9.9.9

149.112.112.112

2620:fe::fe

2620:fe::9


OpenDNS

208.67.222.222

208.67.220.220

2620:0:ccc::2

2620:0:ccd::2


Cloudflare+APNIC

1.1.1.1

1.0.0.1

2606:4700:4700::1111

2606:4700:4700::1001


Use of the above DNS services will help to shield you from “known bad” websites and URLs - and when used alongside 1Blocker, provides defense in depth.


I hope this reassurance and guidance proves to be helpful in resolving any issues with suspect malware and malicious websites.

Dec 31, 2020 1:45 PM in response to LotusPilot

Thank you for your comments and suggestions. I will get 1Blocker.


I am puzzled by the other comment (AKRBTN) about my problem, “You just fell for a fake Facebook message and replicated it to your contacts.” First off, it was not a facebook message and secondly it was on Facebook Messenger and thirdly, I watched as it sent out over 100 off the same fake Messenger messages without my assistance.


Can a single Facebook (or Messenger message) message access all of my contacts and send a message to them? If so, in my book that’s a virus.


thanks very much for you asssistance

My iPad Air got a virus, what should I do?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.