Remove the Ikee virus from your iPhone

Oh bugger, I’ve been Rickrolled! I was out getting tea and I received a phone call – I spotted Rick’s face which shocked me for a bit, but then remembered reading about the virus which originated in Australia. I guess it crawled fast enough over to my iPhone from there. After doing research and reading several incomplete methods on cleaning up the virus, I’ve put together a comprehensive 2 part article – how to remove it, and how to secure your iPhone from getting infected by it.

If you haven’t heard, your iPhone is very vulnerable to getting hacked if you don’t change the root password that is set for all iPhones. The first worm or virus for the iPhone is rather docile, as it merely changes the wallpaper of your phone. Nonetheless, you don’t know what evil viruses may spring up next.

The default password for iPhones is alpine and a smart hacker can use that common password to their advantage. As such, it is vital that everyone changes the default password.

The Ikee Virus Summarized

  • This is the first virus for the iPhone.
  • Some Aussie dude named Ashley created this virus as a proof-of-concept (what an ass).
  • It only affects jailbroken phones.
  • Symptoms: your iPhone wallpaper changes to show a picture of Rick Astley, accompanied by the text Ikee is never gonna give you up.
  • There are 4 variants of the Ikee virus as of this moment – all of which can be removed with a bit of effort.

ikee-virus-rick-astley

My personal take is that I’m grateful the worm is not malicious and it has been a wake up call for me. I’ve now changed the default password on my iPhone.

Steps to remove the Ikee virus (variant A, B, C & D)

  1. If you haven’t already installed mobile terminal via Cydia, do so.
  2. Reboot your iPhone.
  3. Run mobile terminal, and at the prompt, type su.
  4. The default password is alpine (unless you’ve already changed it).
  5. Type in the following commands one line at a time, end press return after each line.
    You may get messages such as No such file or directory – but that’s fine, different variants may leave behind different files.

    rm /bin/poc-bbot
    rm /bin/sshpass
    rm /System/Library/LaunchDaemons/com.ikey.bbot.plist
    rm /var/lock/bbot.lock
    rm /var/log/youcanbeclosertogod.jpg
    rm /var/mobile/Library/LockBackground.jpg
    rm /System/Library/LaunchDaemons/com.saurik.Cydia.Startup.plist
    rm /usr/libexec/cydia/startup
    rm /usr/libexec/cydia/startup-helper
    rm /usr/libexec/cydia/startup.so

  6. When you’re done, reboot your iPhone.
  7. Now, change your wallpaper to something cool. You should be free of Rick’s ghost now.
  8. Follow the steps below to prevent getting hacked again.

Steps to change your iPhone root password (and minimize being hacked)

  1. Start mobile terminal (download and install via Cydia if you haven’t done so yet).
  2. Type su.
  3. Enter alpine as the password.
  4. At the prompt, type passwd.
  5. Enter your new root password. DO NOT FORGET THIS!
  6. Enter the same password again.
  7. You should now be secure from viruses that use the default password to hack into your phone.

128 Comments

  1. Afif - November 16, 2009

    If I never installed Mobile Terminal on my jailbreaked iPhone before, can I still get the virus? How does the virus spread? Through WiFi or 3G?

  2. Maung PN - November 16, 2009

    Big Thanks!!
    I’ve followed ur instruction & get rid of the virus.
    Have a nice day!!
    rgd,
    Maung

  3. yusri - November 17, 2009

    Thank You for your help. At first, I tried many times but seems it didnt work but after that, i realize there’s a space between “rm” and “/” …

  4. jux - November 17, 2009

    Thanks so much.. it work.. for the virus author.. you’re the best.. one of a kind.. but, help produce good apps, not viruses.

  5. Amar Amdan - November 19, 2009

    not familiar at all with linux. but if im being asked the confrimation, should i just type ‘y’ then enter? or should i just enter. please help thanks.

  6. Amar Amdan - November 19, 2009

    yes i have.. but when it comes to deleting the files. a message asking for confirmation appeared. what should i do at this stage? since im not a linux guy, therefore unable to command it to confirm.

  7. Nicholas Lim - November 20, 2009

    Thanks alot, i’m virus free now :)

  8. Anthony - November 21, 2009

    Thanks for the easy to follow instructions!
    The Rick has successfully been removed.

  9. Amar Amdan - November 21, 2009

    hey can somebody help me here… what should i do when it ask me for confirmation to remove the file? what command do i type?

  10. Lucas - November 22, 2009

    WOW! made it! it works! thanks!

  11. Jenny - November 23, 2009

    Thanks a million. It works!!!! The virus is gone :D

  12. Iphone user - November 23, 2009

    Done n TQ. Do remember to insert space between rm and /
    Hope ther are more good man in this world like you.

  13. gideon - November 24, 2009

    bro.. i have a problem over here.. im using iphone 2G
    and after downloading n reboot mobile terminal
    when i run it n trying to type in password.. it jst say command not found
    can help??

  14. TheBackpackr - November 25, 2009

    I’m glad this was able to help many of you. It annoyed me to no end.

    @Amar – I’m not sure why you’re having problems, so many others have cleaned it out.

    @gideon – which command did you type before the command not found one? su?

  15. georgechot - November 27, 2009

    I think I am the first victim in Malaysia. It happened this morning. First attempt failed. Then I saw comment by yusri on the “space after rm”. tried again and woila! the ikee ghost gone! Thanks dudes! Now got to change my pw.

  16. De Cruz - November 28, 2009

    hey guys i got a better method!!!

    1. try to restore yr iphone using the latest itunes. using the ‘iPhone2,1_3.1.2_7D11_Restore’ ( remember restore is using the shift + restore )

    2. once yr iphonee is restore , (never back up yr iphone to the latest date) choose set up as a new phone!!

    and everything is done, lastly

    Steps to change your iPhone root password (and minimize being hacked)

    1. Start mobile terminal (download and install via Cydia if you haven’t done so yet).
    2. Type su.
    3. Enter alpine as the password.
    4. At the prompt, type passwd.
    5. Enter your new root password. DO NOT FORGET THIS!
    6. Enter the same password again.
    7. You should now be secure from viruses that use the default password to hack into your phone.

    • TheBackpackr - December 1, 2009

      De Cruz, are you sure you won’t lose your existing data, with your method? I would rather not wipe out everything on my phone, if possible – hence using mobile terminal to delete the problematic files. I still think my method is easiest, dude.

  17. pG14 - November 29, 2009

    thanx backpackers =) i cleaned it up..yahoooooo!!!!!!!!!!!!!

  18. Pete - November 29, 2009

    Gone through the steps 3 times but I still have the iKee
    I’ve a 3GS with 3.12
    Any more ideas?

    Thanks

  19. Daryl - November 30, 2009

    I just did the steps to get rid of the virus but my iphone gets stuck at the loading screen with the apple logo

  20. Amiga - December 1, 2009

    The best way to remove the Ikee virus is making a clear restore .

  21. gideon - December 2, 2009

    hey bro! iam able to change my PW! but not the virus..
    i trying to type in
    Type in the following commands one line at a time, end press return after each line.
    You may get messages such as No such file or directory – but that’s fine, different variants may leave behind different files.

    rm /bin/poc-bbot
    rm /bin/sshpass
    rm /System/Library/LaunchDaemons/com.ikey.bbot.plist
    rm /var/lock/bbot.lock
    rm /var/log/youcanbeclosertogod.jpg
    rm /var/mobile/Library/LockBackground.jpg
    rm /System/Library/LaunchDaemons/com.saurik.Cydia.Startup.plist
    rm /usr/libexec/cydia/startup
    rm /usr/libexec/cydia/startup-helper
    rm /usr/libexec/cydia/startup.so

    as u told.. but yet i cant delete the virus.. can help me up??

  22. gideon - December 2, 2009

    i try it out again today..
    each line of command is not working..
    it pop up saying cannot remove … no such file or directory..

    i seriously need help on this

  23. gideon - December 2, 2009

    yep.. i know there’s a space between rm /

  24. Khairul - December 3, 2009

    once the password changed, i wonder is it come to default password when the firmware is restored back?

  25. ferhad - December 3, 2009

    Thanks bro…
    You great bro…
    Now my phone work as usual without Rick’s ghost

  26. Pidde - December 9, 2009

    Thanks man.
    That did the trick.

  27. jaws - December 12, 2009

    i am also infected, but i cant seem to delete any of the files?
    There seem to be non of the files found in my iphone?
    i did a manual delete from mobileterminal and also winscp into the phone to look for the files..

    No such file or directory

    So far i am able to delete # Remove: /var/mobile/LockBackground.jpg ONLY

    plz advise

  28. wesley - December 14, 2009

    thanks bro. pls try to change password first then only use the above method. it works. my phone now clear with that piece of ugly photo. thanks to the author. good work.

  29. gideon - December 16, 2009

    hey bro.. i think i have the same problem as “jaws”
    any solution to it??

  30. journeyman - December 18, 2009

    thanks bro…worked after i read that there was a space between rm and the /

  31. collin ng - December 20, 2009

    you have been a great help thanks man!!!!! keep up the good work

  32. matt g - December 22, 2009

    Hey mate, have same problem as gideon and jaws, always says file not found…

  33. Ariff88 - December 23, 2009

    Big TQ to u…
    i follow all the command…
    IT WORKS!!!!

    KEEP IT UP….!!
    have a nice day….

    Thanks Again….!!!
    IM SO HAPPY NOW….
    GO to HELL IKEE VIRUS…

  34. Anya - December 24, 2009

    Guys i cant do the last two ones!
    rm /usr/libexec/cydia/startup-helper
    rm /usr/libexec/cydia/startup.so
    I did eveyrthing exactly as it is but it says no such file.=(
    Help mee

  35. Omid - December 25, 2009

    WOW its work .. ty Bro

  36. gideon - December 25, 2009

    welll i think he’s not helping out even we cant solve the problem..

  37. Zharld - December 25, 2009

    I have the same Problem as Jaws, im sure im typing it correctly :S
    any ideas why this would occur?

  38. aussiegandu - December 27, 2009

    thanks a lot buddy, it did work for me. good on ya

  39. Oscar - December 28, 2009

    Thanks heaps backpackr! was stuck with that pic for weeks!

    thanks again.

    ps get stuffed iKee!

  40. Edr1ck - December 29, 2009

    thxxx uuu!!! finally remove this worm from my iphone

  41. Docker - December 30, 2009

    All I can say is Thank You so much……….
    You are the life saver……..
    To all,
    This really works…….
    Again……. Thank you so much……

  42. alireza - December 31, 2009

    i have problem same as gideon.what can i do?

  43. 23 - January 2, 2010

    thanks guys for the great work

  44. alireza - January 2, 2010

    If you see this message :no such file or directory..
    Go to cydia and download ifile and find all adress that type in terminal. Some of them is hidden or remove befor but some of them us stile there.
    And for better result check A B C methods. After you find that file. Remove it.

    It’s work for me after I can’t work white terminal.

    Good luck

  45. DanDaMan - January 4, 2010

    I tried this several times, off several websites…
    I got a bum steer somewhere cause the file path:
    ” /var/mobile/Library/LockBackground.jpg”
    was missing the sub-directory “/Library”

    I think the original variant worked too but so it’s probably worth giving them both a shot.

    Works good now but… Cheers ey

  46. Lim - January 10, 2010

    Hey!! thanks a heap!! it worked :)!!!!

  47. jon - January 14, 2010

    Hey whenever I try to delete the files I get a “permission denied”, any way to solve this??

  48. chris - January 19, 2010

    not working for me man!!! i’ve followed instructions step by step and it is not working at all.
    i hope you can help me

    chris

  49. Julie - January 21, 2010

    thanks a lot !!! it’s work for me :) it pissed me to the max to see my wallpaper with ricky :o but now it’s GONE !! yeayyyy

    thanksssss loadsssssssssss

  50. shaun - January 26, 2010

    it worked! thank you!

    I wanna point out it’s very easy to make a mistake when you are typing in the root menu as there is no spellcheck

  51. Shunhui - January 29, 2010

    Hi All,

    I tried entering all the commands twice and some files were removed and some were not found but still the ugly face of ikee is still there.

    Then I tried the 3rd time with case sensitive and some files were removed.
    And the virus is gone now.

    So I would like to share my experience that you must type in the commands as per what you see. If it is capital letter, type it as capital letter.

    Thanks alot for the help.

  52. Deniece - February 1, 2010

    Thank you so muchhh for the help in removing this annoying virus !!

    Yes you need to follow step-by-step from the beginning till the end and remember after the rm, there’s a space in between and again it’s case sensitive. If it’s capital letter, then follow.

    Thanks againnn !! So glad that I don’t need to see Rick’s face anymore! haha

  53. Sepideh - February 4, 2010

    Hi,
    I have this Ikee virus and really don’t know what to do. The version of my mobile is 1.1.4. Please give me the link to download mobile terminal.
    Thank you

  54. fad - February 4, 2010

    hi all! i cant be able to remove the last 2 steps, the ‘startup-helper’ and ‘startup.so’ but nevertheless i got rid of the irritating picture!!! thanks to the author! im using 16G 3GS, 3.1.2 firmware. so its proven right! thanks again!

  55. linus - February 6, 2010

    I have an iPhone 1:st gen and this worked perfectly thx!!!

  56. asy - February 7, 2010

    works like a charm.

    thanks a lot!

  57. Sonn - February 7, 2010

    The easiest way to delete those files is by using DiskAid -(just follow the path) and use the terminal to change the password..

  58. chetu - February 14, 2010

    TheBackpackr thanks very much for your hardwork!!!

    I’ve been infected yesterday 13.02.2010 and am living in Spain.

    It worked! Now I’m clean again.

    Rgds,

  59. bob - February 17, 2010

    what an asshole that dude is he should go to jail for the years strangers have had to waste fixing his stupid prank

  60. mohdrais - February 18, 2010

    thanks. Its works and finally – i have my own wallpaper :)

  61. Ken Ng - February 19, 2010

    Thanks a bunch! Been procrastinating this for the past few months but finally decided i’ve had enough of Rick Astley…

  62. Nalina - February 20, 2010

    Hiii,

    I’m from sri lanka.Thanks alot finally it did work.

    thanks onece again

  63. Thomas - February 22, 2010

    I got this ugly picture for the past 2 weeks, then I upgraded the Iphone latest version hopefully to reset everything back. Of course, Cydia was gone as well. Now the question is, how do I install the mobile terminal without Cydia?

    Can someone help?

    Thanks

  64. alex - March 3, 2010

    dude you are the best man!! thanks alot :D

  65. shiG - March 8, 2010

    I’ve tried everything but it didn’t work for me?! is there any other way? pls let me know, thnx

  66. Aizat - March 18, 2010

    Thanks a lot. My iphone now is totally free from the ‘gay-face’. Thanks again.

  67. mahesha - March 22, 2010

    it was a great help and thanks a lot for the solution

  68. مشكل فايروس ikee لمـ يرحل (جربت كل الطرق المتوفرة في الانترنت ) - ماك ارابيا، mac، ماكنتوش، ابل - April 1, 2010

    [...] الطريقه اللي بالرابط و ان شاءالله كل شي راح يضبط معاج : Remove the Ikee virus from your iPhone | TheBackpackr.com بالتوفيق ان شاءالله اختي [...]

  69. Bob - April 3, 2010

    Omg Thank you so much

  70. Yun - April 5, 2010

    Hi,

    As you mentioned, if cannot remove certain files, it is because it have a different variant of the ikee virus. So what should i do?? bcoz it doesn’t seem to cure. Thanks.

  71. jacob - April 5, 2010

    guys… keep in mind that it is cap sensitive.. i just remove all of them! its works! thankiu host

  72. denny - April 8, 2010

    I have already follow the steps u display. But i still cannot remove the virus. Can u help me out please?

  73. Geez - April 12, 2010

    Hey, dunno if it can happen to any of u guys, but I had my Iphone 3G jailbroken, and it had some hardware problem so I got new one (same Iphone 3G), don’t plan to jailbreak it, and when i got it to sync with my itunes, the lkee virus got affacted, as i know this virus is only active through jailbroken iphones right? can anyone explain why my new Iphone (not jailbroken) got this virus? is this through my itunes? and how to fix it? thanks in advance…

  74. zoe - April 24, 2010

    Hi

    I follow the instruction that you teach, but whe some of th commands need capitalisation, it’s doesn’t work, it’s only always stay in small capital letter. Pls help me and tell the way to make it work.

    THANK YOU

  75. zoe - April 24, 2010

    hi

    i solved the problem already.Anywhere, thank’s a lot your help. You are so nice person.

    Thank you.

  76. Infra - April 29, 2010

    Another way to remove the virus is to use iFile (something like explorer from Cydia). Some of the files cannot be remove via terminal..well at least it happen to me. Maybe it will help those who followed the instructions above but still unable to set their wallpaper after reboot. It is best to use iFile to browse those infected path and make sure the variants are removed. Cheers !

  77. Toni - May 6, 2010

    Moltes gràcies.
    Thanks!

  78. Ally - May 16, 2010

    Thanks a lot for your guideline! I have removed the virus successfully!

  79. Alex - May 25, 2010

    THANKYOUUUUUUUUUUUUUUUUUUUUU :)

  80. najibcool - May 26, 2010

    thankyou!!!!

  81. Joanne Lim - May 28, 2010

    Thanks !!!!!!
    Really Thank you~~~~!!!!
    It works~!!!
    Get rid of that ghost photo~!!

  82. baa uribaba - May 29, 2010

    thx i luv you finally d ugly ikee went away
    but im still goin 2 keep him as my wallpaper
    ikee ROCKS!!!!!!!!! (jk)

  83. Moso - June 1, 2010

    Hay Guys Its Work …..

    Remmemberrrrrrrrrrrrrrrrrrrr Its Case Sensitive…

    Capetal Letters and Small must be the same as the Instructions

  84. ade - June 8, 2010

    Thks bro…thks alot..finally i dont need to see Rick Astley face anymore!!!!!

  85. luke - June 13, 2010

    WORKED follow everystep carefully, make sure you use capitols when needed!

  86. Wendy - June 22, 2010

    Hey i need quick replies. I am from Singapore. But thru Cydia, i cant find the app “mobile terminator” what do i do?

  87. Wendy - June 22, 2010

    this totally works! i was so vexed before that.. and i didnt know after jailbreaking, it take so long to reboot that make me almost thought that my phone is gone.

    THANKS SO MUCH.

    worked on 22 June 2010.

  88. dr henri pugibet - June 29, 2010

    Where do i get cydia? Where do i download mobile terminal app? Please help me! Can i do this directly on my iphone? I have a 2g versión 1.4. Wanted to update but have no idea how! Thank u and god bless u!

  89. Richard Goh - July 21, 2010

    I managed to get rid of it.Yahoooooooooooooooo.

    Enough of Rick Ashley.
    It really works but need alot of patience.
    Thank you very much…………….Richard from Singapore…//

  90. igi - August 1, 2010

    Seriously guys, this method works like a charm, it didn’t work for me at the first time but then again i saw i’m missing a space between “rm” and “/”
    so keep a space and type all that, mostly the last two commands will tell cannot delete hay what the hec, don’t worry, just type everything there,

    dont forget guys, change your password, i did it before i remove the worm.

    Good luck guys and stay safe!!!

  91. usop - August 19, 2010

    hei you guys,
    i know this seems a tad bit outdated.
    but just tot it might help those of ya’ll whose still bummed up over this shitty ass problem.
    spent 5 bagazillion times writing the instructions above and yet rick’s goddamn face is still there >.<
    finally did it right this time round tho.
    realised the problem was i didnt follow exactly what it says there.
    and when i say exactly, i mean, EXACTLY!!!
    hint hint: FOLLOW THE CAPS IF REQUIRED! small caps n big caps!!!

    cheers :D

  92. usop - August 19, 2010

    @ wendy:
    at first, i cudnt find the terminal in cydia as well.
    but heres how u can find it:

    1. launch cydia
    2. scroll down to “openSSH Access How-To” and click.
    3. scroll all the way down to “change default password” and click
    4. at the top u see “0: install mobileterminal package”

    there ya go :D

  93. marino - September 5, 2010

    i didnt get that picture bur the virus is in my procces
    and makes my phone very very slow
    gonna try to get it out now

  94. Farzad - September 10, 2010

    Thank’s alot. after 5 times it worked, ofcourse with capitalization

  95. Janette - September 16, 2010

    I followed exactly what it says leave space, FOLLOW THE CAPS, small caps n big caps but still it didn’t work. What should i type when it says “remove write-protected regular empty file ‘xxxxx’?” Do I type in “YES”?? When i did so, it says ” rm: cannot remove “xxxxx” : Permission denied. For some, after I key in the command, it straightaways say rm: cannot remove “xxxxx” : No such file or directory. Please help!!!!

  96. hafizans - September 25, 2010

    thanks for the guideline..really appreciate! finally i can remove the virus as well.use the instruction carefully.

  97. Sticktron - November 29, 2010

    Don’t erase the Cydia stuff. It’s not part of the infection.

  98. FaceIT - February 7, 2011

    Why is the creator “an ass”? It’s clearly Apple’s fault for making root so easy accessible.

  99. FaceIT - February 6, 2011

    Why is the creator “an ass”? It’s clearly Apple’s fault for making root so easy accessible.

  100. Azim900 - February 23, 2011

    Whenever i open the mobile terminal, it just goes off…(close itself),,,why is this so???..i seriously need help…

  101. sara sami - April 2, 2011

    my iphone dont start :( why???

  102. lee - May 13, 2011

    i followed the instruction .. and can now change and background and it still remains.
    no astley stuff.. but how do i know if the virus is still in my phone?

  103. Havokhectic - May 13, 2011

    thanks man really!! it works guys and stay away u fuckin homo ikee virus shit!

  104. Yannickng - May 14, 2011

     how to remove this virus if my cydia missing after got this virus, anyone? help pls, many thanks

  105. Rob - May 27, 2011

    How would i delete this

    /var/mobile/library/preferences/com.nakedproductions.applocket.plist

  106. Dr Henripugibet - July 2, 2011

    I do not have cydia installed, I have a jailbroken iphone running on 1.1.4 firmware, how can I get rid of this Ikee virus, only have installer….

  107. donAL - July 27, 2011

    thank you man, you are a God … I noticed this virus while I installed the cracked version of LockInfo … stay away from that

  108. Chris Travis - November 9, 2011

    Finally, I’ve had this shit for over a week now and it really started to get to me.
    Thanks alot!

  109. John Doe - July 26, 2012

    Thank you, it worked perfectly!

  110. Tahsan - August 8, 2012

    Awesome!!! Thanks a lot. God bless.

  111. Daryoush - November 13, 2012

    Dear friends to get rid of the virus above instruction by mobile terminal not always acts sufficiently .
    You may need ifile from cydia to directly remove the infected files that mentioned their addresses above.
    Be successful

  112. Awesome - February 12, 2013

    Awesome thanks

  113. mohsen jafari - April 17, 2013

    Thanks a lot

  114. Faisal - November 14, 2013

    Thanks a lot !! it works perfectly !!

    Don’t forget to put the space after “rm”
    Worked on 14 Nov 2013

    Have a nice day ! :)

Leave a reply