Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iOS virus

I need to know how to remove the redirect virus that affects iOS and redirects random links to filthy sites, including personal ad sites and streaming sites. It is a SERIOUS issue that needs to be addressed IMMEDIATELY. I have never jail broken this or any iOS device on my network, and have only had this iPad for a few weeks and it is infected. Researching this exploit on the Internet shows that it stems from the root user having a password that any device on the same network can exploit... This is a SERIOUS ISSUE and A COMMON ISSUE that hundreds of people have. Tis needs to be addressed immediately. Please report here If you notice even a momentary redirect in safari or any other app, as it's not limited to just the browser. If you have ever seen your iOS device randomly restart and you thought it was a crash, that is how the exploit works.


This is a video of the exploit/virus in another form.. Now it doesn't block search results from coming up... I know that it is in iOS because it happens in sites that I manage, and random sites/apps constantly. Please acknowledge and fix this exploit IMMEDIATELY.


http://www.youtube.com/watch?v=eRWyMmXKosI


I've already wiped this iPad and completely restored it from a backup, and set it up as a new device as well. This continues to be infected and there is no way I can remove it.

iPad 2, iOS 5.0.1, Redirect virus help!

Posted on Mar 7, 2012 5:07 AM

Reply
92 replies

Mar 8, 2012 4:47 AM in response to latexink

No such thing exists as a virus for iOS. Never. If you visit "spurious" web sites, you will get pop up windows redirecting you to other spurious sites. Go into your Safari settings and clear cookies and data and clear history. You might want to turn private browsing on if you're going to visit "those" type of sites. And turn on block pop ups as well. Before you blame Apple for infecting your device, check whose using it first, they might be visiting websites that will bring you this type of grief. If you say you manage these sites, then check that the latest version of javascript is being used to develop your page. Certain websites do crash the browser if javascript isn't compatable.


The only thing that needs to be addressed immediately, is the total lack of understanding of how iOS works here.

The fix is in your hands. If you have to restore your device, then set it up as a new device. Corrupt third party data files will return with a restore from a backup.

Mar 8, 2012 4:48 AM in response to latexink

Your iPad is not infected with anything, as there are no viruses that affect an iOS device that has not been jailbroken. Further, cookies and other stored web data have nothing to do with it as Andrew J implies. If you are having redirect problems, you are either using a poisoned DNS server or your wireless router has been hacked. See:


When I try to visit a web site, I get redirected to a different site!


(Note that my pages contain links to other pages that promote my services, and this should not be taken as an endorsement of my services by Apple.)

Mar 8, 2012 5:41 AM in response to thomas_r.

There are no "documented" viruses... This is an exploit that is not limited to the safari browser. My router is more secure than fort knox and doesn't allow external ip access at all, and this is happening on a device that has only been used for a few days... I've wiped to try and get rid of it and only visited a few sites that are built with open-source software to avoid exposing this thing to ANY sites (including *****). I use my ISPs DNS servers (including Verizons 3G service) and this only happens on this device... I don't install any apps that don't come from reputable sources on the app store either.. I have taken extraneous precautions to avoid this crap, and having many years of experience in the tech support/IT industry keeps me from not knowing the basics of any computing device.. At worst, this is an exploit that gets unsigned code running on iOS, and at best is multiple ISPs DNS server being compromised... This happens on 3G data networks as well, so it's not my network, it is this device. I hope others are smart enough to realize when to happens to their iOS devices, and don't pass it off as a "pop up"... Any os is vulnerable to attack, and iOS is no exception.

Mar 8, 2012 5:49 AM in response to latexink

There is no POSSIBILITY of a virus on an iOS device. The only code that is allowed to run is code from the App Store. It is conceivably possible for a malicious app to make it past Apple's screening, but that would not be something properly termed a virus, and it would not be able to affect how Safari loads a web page due to the tight sand boxing in iOS. You are barking up the wrong tree.


You have not provided much in the way of details, and the video you referred to is gone. What sites are you seeing redirects with, and where does it redirect you?

Mar 8, 2012 6:01 AM in response to latexink

Can you get past your ranting and give us some information. Your youtube video was removed by you, so what you are saying is just nonsense. What is happening? When is it happening? Which app are you using when it happens? You talk about root user passwords. Root user passwords are only acessable when a device is jailbroken and SSH has been switched on. Momentary redirect? What are you smoking? Are we talking pop ups, or new tabs opening, what? You only get filthy redirections from bad sites anyway. Give us some URL's so we can test out your claim.

Mar 8, 2012 6:11 AM in response to thomas_r.

This happens on any site and redirects to generic "personal ad" sites.. This happens randomly irregardless of the site, even clicking on a link to itself. It sometimes goes back to the original link selected, to one of the personal sites, to google.com or just multiple sites in rapid succession, then to a blank page. This happens on open-source phpbb-driven forums with NO ads, randomly searching google.com, or any other site I happen to be on. And it is possible for unsigned code to run, that's the whole premise of a jailbreak.. I just think that a similar exploit is gaining root access and editing a hosts file in the device... That is the only way I can think of to redirect regardless of the site short of altering the safari browsers SIGNED code.. Again, this happens on BOTH my home/any network and the 3G network.


I have NEVER been to any "spurious" websites on this device. You'll just have to take my word that I manage severs via SSH and in no way shape or form am visiting these sites on my own in this device... No one else has used this device outside of my direct supervision either.

Mar 8, 2012 6:29 AM in response to latexink

I don't think you understand how hard it is to write unsigned code to self exploit on an iOS device, in fact it's not possible without your knowledge. The hackers who write the jailbreaking code, work for months to work on exploits, and they are the best in the world. If you are so concerned about someone hacking into your device, then do this. Restore your device. Set it up as a new device. DO NOT RESTORE FROM BACK UP!!! Sync your things back and you have a totally clean device.

Mar 8, 2012 6:31 AM in response to latexink

And it is possible for unsigned code to run, that's the whole premise of a jailbreak.


That requires very specific and difficult steps, involving replacing backed up iPad files on your computer with hacked versions and then restoring the hacked system back to your iPad. That is not something that you are likely to have done. You've gotta let the malware thing go, it's just going to keep you from finding a solution.


On your iPad, go to Settings -> General -> Network -> Wi-Fi and tap the little blue '>' button next to your selected wireless network. Is the DNS server what you expect it to be? Try changing that to something else, like the Google or OpenDNS servers I referred to in the link I gave you earlier.

Mar 8, 2012 7:12 AM in response to latexink

It appears that you are trolling and/or have absolutley bo understanding of how iOS works on your device.


If you are genuine (doubt it) go into Settings > General > Network > WiFi, then tap the blue circle next to your wireless network, go to the DNS entry. make a note of the current DNS entry. Now delete out the address then put in 208.67.222.222 and try browsing.


If you can browse without redirects AND the previous DNS entry is the same as the Gateway address then you need to check the DNS in your router.


If you are still being redirected then you are telling porkies.

Mar 10, 2012 3:34 PM in response to PogoPossum

Actually, I've had the same or similar "symptoms" for the last week on Safari 5.1.2 on 10.6.8.


I've been to Thomas A Reed's page that he's linked to in other threads with other user's describing similar symptoms. I've switched the DNS settings (using Open DNS for now), I've installed Safari anew, and, significantly, the problem persists regardless of whose WiFi network I'm on – i.e., not my own.


To be clear, the problem for me is: when clicking on search results from Google, I am sometimes (not always, sometimes) redirected to various sites such as happili.com, ChinaFlix.com, etc. When I return to the previous Google results page and click the link a second time there is no redirect. This began about a week, perhaps 10 days ago.


There are at least a half-dozen recent threads in the forums describing a similar if not identical problem. (Thomas, you've participated in some of these as well.)


None of the solutions tendered have worked for me – barring a clean wipe / complete reinstall. I have an appt with a Genius bar and will post what they suggest here in other threads that are unresolved.


Thanks,

J

iOS virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.