Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

3Hotdogs

(13,343 posts)
Wed Sep 22, 2021, 12:21 PM Sep 2021

iMac and iPad infected last night. Screen was taken over with notice that a virus infected iMac.

It had poor punctuation and am m1-888 number I needed to call in order to resolve the problem. Re-boots didn't resolve the problem.

iPhone wasn't affected..

Then about 2 hours later, it went away.

Thoughts?

11 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
iMac and iPad infected last night. Screen was taken over with notice that a virus infected iMac. (Original Post) 3Hotdogs Sep 2021 OP
Do you have an apple store nearby? If this is occuring widely, I'd imagine they've encountered it. hlthe2b Sep 2021 #1
Macs now twice as likely to get infected by adware than PCs, according to research ItsjustMe Sep 2021 #2
Adware is a lot different than a virus. ret5hd Sep 2021 #4
I updated my IPad and couldn't get it to start up past the welcome kimbutgar Sep 2021 #3
Have you updated to iOS 14.8? Hokie Sep 2021 #5
Yes, it was updated. 3Hotdogs Sep 2021 #6
iOS 15 SoCalNative Sep 2021 #7
If you got a popup with a number to call, it's almost certainly a scam. SeattleVet Sep 2021 #8
Missing info ... CloudWatcher Sep 2021 #9
It was taken over, days after the last reboot. It happened when I tried to logon to Amazon.com 3Hotdogs Sep 2021 #10
Ah, so your browser was locked up CloudWatcher Sep 2021 #11

hlthe2b

(106,051 posts)
1. Do you have an apple store nearby? If this is occuring widely, I'd imagine they've encountered it.
Wed Sep 22, 2021, 12:23 PM
Sep 2021

But, the past two IOS updates for iphone and Ipad (maybe Mac) have been "emergency" updates for a serious security issue, so I'd not assume it is resolved.

kimbutgar

(23,164 posts)
3. I updated my IPad and couldn't get it to start up past the welcome
Wed Sep 22, 2021, 12:34 PM
Sep 2021

So I took a small needle and poked the small hole next to the two volume knobs and was able to get it to reboot.

I suspect a virus hit my iPad.

Hokie

(4,298 posts)
5. Have you updated to iOS 14.8?
Wed Sep 22, 2021, 12:42 PM
Sep 2021

I think that update was pushed out last week to fix some really bad malware that showed up.

3Hotdogs

(13,343 posts)
6. Yes, it was updated.
Wed Sep 22, 2021, 01:21 PM
Sep 2021

Interesting part (to me), it infected both the Mac and Pad even though the pad wasn't turned on. Yet it didn't it the iPhone.

SeattleVet

(5,582 posts)
8. If you got a popup with a number to call, it's almost certainly a scam.
Wed Sep 22, 2021, 02:58 PM
Sep 2021

Been going around for a while now.

Do NOT call the number.

There are plenty of YouTube videos (various scam-baiters and scambusters) where they follow through and contact the scammers.

The popups would have probably gone away if you had cleared your browser caches when you rebooted.

CloudWatcher

(1,922 posts)
9. Missing info ...
Wed Sep 22, 2021, 03:10 PM
Sep 2021

I'm pretty confused about what you're observing. Did the Mac's screen get "taken over" as soon as you rebooted? Or did it only happen once you've launched a browser?

Infecting an iPad while it's turned off is quite a trick (i.e. my skeptical flag has been raised pretty high). Note a "locked screen" is not turned off. That's just a low power mode with the screen off (usually locked). Some background processing is allowed in this mode.

Most likely though ... I can imagine that if your browser settings (bookmarks) are sync'd between the Mac and iPad (via sharing Safari info with iCloud on both devices) ... then if Safari on your Mac has been screwed up, those settings could be shared with the iPad the next time you used it.

But ... otherwise I'm drawing a blank how your iPad could have been "infected" while turned off (we'll ignore Pegasus for now, it's not likely you were a target of the people that had that available, and they didn't try and scam with an 888 number).

If the offending source was really something on the network, then any number of changes could have been responsible for it going away. E.g. an infected web site should have been shut down (or added to Apple's block-'em list). Or the domain-name system could have been fixed (e.g. routing "www.cnn.com" to an offending site).

Of course the very last thing you every want to do is call the 888 number for "help". They're the bad guys.

It wouldn't hurt to make sure that all your Apple devices are running the latest software. And .. make sure your internet router (usually a WiFi base station) is also updated to their latest firmware.

If you don't know how to check, get some help

3Hotdogs

(13,343 posts)
10. It was taken over, days after the last reboot. It happened when I tried to logon to Amazon.com
Wed Sep 22, 2021, 06:34 PM
Sep 2021

Screen on iAd was locked. Unit was not turned off.

iPad and iMac are sync'd but so is iPhone. Phone did not get "hit."

Thanks for info.

CloudWatcher

(1,922 posts)
11. Ah, so your browser was locked up
Thu Sep 23, 2021, 01:30 AM
Sep 2021

The good news is that your devices (Mac, iPad, iPhone, router) are mostly likely just fine.

It's really pretty easy for the bad guys to publish a web page that "takes over" your screen and tries to prevent you from leaving (while putting up a phone number to call for "help" ).

I believe they often appear from ad sites that others (e.g. amazon.com) serve up in addition to their actual home page.

Since your Mac and iPad (and iPhone) share web browser history they could easily appear to both be hit at the same time. And just luck-of-the-draw that the iPhone wasn't hit as well.

Most useful thing to do: learn how to kill your browser when it's locked up like this.

On the Mac, you can tell the 'Finder' to "Force Quit..." and pick Safari. Then hold the shift key down when you relaunch Safari and you should be fine.

On the iPhone & iPad you can double-click the home button and then swipe up to kill off a process. When you launch again, if it's still trapped, do the kill again, but then use the Settings app to clear the Safari cache before starting it up again.

There's a really good reference & description for all of this in the Apple forum message:

Phony "tech support" / "ransomware" popups and web pages
https://discussions.apple.com/docs/DOC-8071

Latest Discussions»Help & Search»Computer Help and Support»iMac and iPad infected la...