Virus warnings from "apple.com-genius.website"

Are these legitimate warnings from apple.com-genius.website?


The first pop up read "your mac is heavily damaged" 3 x Virus names: Tapsnake; CronDNS; Dubfishicv and asked me to download MacCleaner (I didn't)

A second pop up read "safari detected a trojan virus (e.tre456_worm_osx)

Third pop up read " a full system scan is required" and that my passwords, photos, bank details etc are at risk.


I closed safari down asap and restarted my Mac. No further virus messages but I am so worried now that i have done something stupid.

MacBook Pro, Mac OS X (10.7.5)

Posted on Aug 23, 2016 8:33 PM

Reply
4 replies

Jul 30, 2017 7:46 PM in response to Belle_Button

I don't know about Safari, but if the problem is limited to Chrome you may not have to install antivirus software or do a major reset of your browser.


I had this problem using Chrome, and when I tried to look it up I found there were a lot of sites that had 1) instructions to get rid of it that didn't seem to work for me, and 2) ads at the end for their own antivirus software. It looked like a lot of these sites were just duplicates of each other.


I didn't install any of those, but I did go looking for reputable antivirus programs, and I tried a couple (including ones recommended on this site), but they didn't detect or remove this problem.


Finally I went to my Chrome extensions and unchecked every one of them, and when I restarted Chrome, and the problem was gone. Then I turned each extension back on, one by one, and restarted after each one. I found one extension that, when I checked the box and restarted Chrome, seemed to be the problem, because the ads and virus warnings came back. I deleted that extension, and the problem seems to be gone. After that I was able to turn on all the other extensions and continue as normal.


In this case, the bad extension had a title related to Amazon, but that may not be the case for you -- they will deliberately make their fake extension look like something safe, and they will keep changing the name, so if it happens again, I'll do the same thing and check every extension no matter how safe it looks, till I find the problem.

Aug 25, 2016 4:48 PM in response to Belle_Button

Unless you clicked "Download" on anything on those pages, you should be fine.


Those are absolutely not legit warnings. It is an increasingly common scam. See: A Browser Pop-up Scam has Taken Over Safari.


(Note that I may receive some form of compensation, financial or otherwise, from my recommendation or link, because some pages on the site contain small banner ads).

Aug 25, 2016 4:48 PM in response to Belle_Button

You did the right thing by not downloading MacCleaner. "apple.com-genius.website" is definitely not a real Apple site since its address ends in ".website". A real Apple message would have come from "apple.com" but Apple doesn't put up virus warnings like that. (Apple does have some silent anti-malware features in OS X that are there and working even though you never see them.)


Chances are your Mac is fine, I think those warnings were fake and only existing in your web browser. If you are still concerned, you could go in to Safari Preferences, Privacy and click Remove All Website Data to purge any cookies or other markers that might have been left behind.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Virus warnings from "apple.com-genius.website"

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.