Unable to install OS, EFI password

Malicious hacker, using remotely via Custom URL Scheme Windshift APT has access to my newest MacBook Pro. The hack was quite sophisticated as I had on my Firewall, virus protection and VPN by F-Secure. Now I try to install the operational system again but the password allowing the access to the hard drive has been changed by the hacker.


What shall I do to be able to complete the reinstallation?


Janne J.


[Edited by Moderator]

Posted on Jun 7, 2021 5:45 PM

Reply
5 replies

Jun 8, 2021 11:40 AM in response to DeeperDiver

DeeperDiver wrote:

With your machine turned-off, turn on your Mac while holding down Command-R.

FYI, Internet Recovery Mode (Command + Option + R) is the better choice since Recovery Mode will access the hidden local recovery partition on the boot drive which may already be compromised. Internet Recovery Mode will bypass the local recovery partition and boot directly from the Apple servers. Plus a PRAM Reset as suggested by @LatriciaP is a good idea to clear out any potentially unwanted NVRAM settings. Powering off the laptop for a minute and booting directly into Internet Recovery Mode is good.

Jun 8, 2021 10:44 AM in response to janne34

If you don't care about your data, or you have it backed up somewhere then be sure and just reformat your drive and re-install MacOS.


With your machine turned-off, turn on your Mac while holding down Command-R. When you get the main panel, select "disk utility". Select the top-level storage device (usually a technical-sounding name, not "Macintosh HD") and click "erase".


Get out of disk utilities and re-install MacOS from Internet Recovery.


Would be interesting to know what website you visited. Sounds like a very technical attack.


Good luck.



Jun 8, 2021 10:25 AM in response to janne34

To add to @LatriciaP's advice in order to erase the whole physical drive you may need to click "View" within Disk Utility and select "Show All Devices" so that the physical drive appears on the left pane of Disk Utility. The physical drive will usually have the make & model number of the physical drive such as "Hitachi ....", or "Apple SSD ....", etc.


To access Internet Recovery Mode you need to boot using Command + Option + R which will bypass everything on the local drive.

https://support.apple.com/kb/HT204904


You do need to be careful restoring from backups since you want to make sure to restore from a time before you had these issues, otherwise the issue will be brought back from the backup and you will need to repeat the process again using an earlier backup.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Unable to install OS, EFI password

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.