How to Remove a virus from iPad

getting a daily virus message from Microsoft..how do I deal with it?



iPad 2, iOS 9

Posted on Dec 11, 2023 6:28 AM

Reply
Question marked as Top-ranking reply

Posted on Dec 11, 2023 1:48 PM

Okay, but where? Email? Text message?


Either way, it's a scam. Microsoft would never, ever send such a message. Not daily or otherwise. On top of that, there's no way for anyone to remotely scan your device to make such a determination.


If this is a repeating email, block the sender address, if possible.


If it's a text message, tap on the message to open it as if you were going to read it. At the top of the resulting screen, you'll see a very small right pointing arrow under the sender icon and name (or phone number, or email address). Tap that. On that resulting screen, tap the info button at the right. Scroll the screen up and tap, Block this Caller. You'll never see this message again. At least, not from that email address or phone number.


If the sender icon for a text shows a multiple person icon, tap that. You'll see a list of phone numbers and email addresses. All but one of these are other scam victims who got the same message you did. The oddball out will be at the bottom. That person is the one who actually sent the message. Do the same steps as above to block that person. There's no need to block the rest as they are all just other possible victims.

4 replies
Question marked as Top-ranking reply

Dec 11, 2023 1:48 PM in response to Shoofluff

Okay, but where? Email? Text message?


Either way, it's a scam. Microsoft would never, ever send such a message. Not daily or otherwise. On top of that, there's no way for anyone to remotely scan your device to make such a determination.


If this is a repeating email, block the sender address, if possible.


If it's a text message, tap on the message to open it as if you were going to read it. At the top of the resulting screen, you'll see a very small right pointing arrow under the sender icon and name (or phone number, or email address). Tap that. On that resulting screen, tap the info button at the right. Scroll the screen up and tap, Block this Caller. You'll never see this message again. At least, not from that email address or phone number.


If the sender icon for a text shows a multiple person icon, tap that. You'll see a list of phone numbers and email addresses. All but one of these are other scam victims who got the same message you did. The oddball out will be at the bottom. That person is the one who actually sent the message. Do the same steps as above to block that person. There's no need to block the rest as they are all just other possible victims.

Dec 11, 2023 3:22 PM in response to Shoofluff

Providing that you have not attempted to jailbreak your device - or have bypassed protections by side-loading third-Apps (if you don’t know what this is, then don’t worry about it), then it is highly unlikely that your device will actually have been infected with a virus or other malware.


However, there is one potential source of immediate issues with your iPad that you may need to check - this being for a vulnerability that is often exploited that gives the appearance of a malware infection. This involves your iPad/iPhone Calendar - the symptom being your Calendar appearing to have been populated with regular events that warn of malware infection.



Calendar Infection


Whilst not a malware infection in the traditional sense, if this exploit is observed on your device, it is highly probable that you were manipulated (via a simple click on a website link) into “subscribing” an additional (unwanted) Calendar to your device - and this unexpected Calendar is exposing unwanted calendar events and sending you unexpected “adverts” or other warnings. 


If you see this issue, you’ll need to check for what’s out of place...

iOS/iPadOS13 and earlier: Settings > Passwords and Accounts

iOS/iPadOS14 and later: Settings > Calendar > Accounts


Look for an “account” that shouldn’t be in the list of accounts - as this will likely include the Calendar that contains all the unwanted events. When/if you find the suspect account, tap - then select Delete Account. This should resolve this specific problem in its entirety.



Malware


Most alerts that you see are pop-up messages from websites - these being designed to scare the unwary into giving away sensitive information - or to fool you into doing something that you shouldn’t.


Due to the system architecture of iOS/iPadOS, unless jailbroken, your iPad is not susceptible to traditional malware infection per-se. However, as with all computer systems, there are still vulnerabilities and exploits to which you remain at risk.


Browser-based attacks can largely be mitigated by installing a good, trusted, Content and Ad-blocking product. One of the very best and most respected within the Apple App Store - designed for iPad, iPhone and Mac - is 1Blocker for Safari.

https://apps.apple.com/gb/app/1blocker-for-safari/id1365531024


1Blocker is highly configurable - and crucially does not rely upon an external proxy-service of dubious provenance. All processing takes place on your device - and contrary to expectations, Safari will run faster and more efficiently. 


Unwanted content is not simply filtered after download (a technique used by basic/inferior products), but instead undesirable embedded content blocked form download.


When using a good quality Content blocker, a high proportion of otherwise inescapable risk when using your Safari browser, or linking to external sources from email, is effectively mitigated before it even reaches you.


There are additional protections that can enhance protection further, such as using one of the better Recursive DNS Services in preference to automatic settings. This can either be set on a per-device basis in Settings, or can be set-up on your home Router. I recommend using one of the following services, for which IPv4 ad IPv6 server address are included here:


Quad9 (recommended)

9.9.9.9

149.112.112.112

2620:fe::fe

2620:fe::9


OpenDNS

208.67.222.222

208.67.220.220

2620:0:ccc::2

2620:0:ccd::2


Cloudflare+APNIC

1.1.1.1

1.0.0.1

2606:4700:4700::1111

2606:4700:4700::1001



Security focused DNS providers intentionally "sink hole" known bad or malicious websites and resources - this providing an additional layer of protection beyond that provided by your device and its Operating System. These DNS services will, when used alongside 1Blocker or other reputable Content Blocker, provide defence in depth.


There are advanced techniques to further “harden” iOS/iPadOS (such as using DoH, DoT and DNSSEC). Apple has introduced its new Private Relay to its iCloud+ subscribers - in part employing ODoH (a variant of DoH) as an element of this new functionality. If you have subscribed to iCloud+, and have a device capable of running iOS/iPadOS 15.x or later, this feature is included. 


I hope this reassurance and guidance proves to be helpful in resolving any issues with suspect malware and malicious websites.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How to Remove a virus from iPad

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.