Malware Octagon Security

i definitely have contracted some sort of malware. I’ve done a clean install. malwarebytes picks up nothing. Applications open on login and close before the icon can be seen on the dock (I have a video of it happening). The app at login that opens and vanishes does not do it if I startup holding the keys to prevent login itemsk at start.

Items and apps that I’ve never heard of sometimes appear under recent items, sometimes not.

A user profile I didn’t set up keeps appearing called ‘wheel’. There are no other users of my mac.

A few times files related to a Bitcoin wallet opened on my desktop without any prompt on my part.

The one name that I keep seeing no matter how many reinstalls are done are keygen wrap and octagon security.

I will post pics.

I don’t care about any files or anything I have saved on the Mac. I just want it to go away.

please help!

Mac mini, macOS 13.3

Posted on May 18, 2023 9:26 AM

Reply

Similar questions

19 replies

May 18, 2023 10:40 AM in response to mekyma

Thank you.


From part of your original post - A user profile I didn’t set up keeps appearing called ‘wheel’.


Wheel is owned by the OS. It's a root user of Unix (which macOS sits on top of). It means "the big wheel", or "the big cheese". The OS uses it to perform functions the user can't.


You EtreCheck report shows virtually nothing but a few standard Mac processes, except for this one:


DocumentPopoverV 4


This is an unsigned app. And nothing installed by Apple would be unsigned. So this has to be some sort of third party app.


The only thing I can find related to such a name is a bootstrap manager. Something only a few people have any real use for. This may be the wrong item related to that name, but it definitely shouldn't be there.


You may have to start up in Recovery Mode so you can completely erase the drive and reinstall the OS from scratch. DO NOT restore any backup, or you'll just get whatever this is back on the drive.

May 19, 2023 5:59 AM in response to mekyma

Yes, and I wasn't clear enough. Barney-15E is quite correct that many parts of Unix will appear as unsigned. I was referring to unsigned third party apps as being something to be wary of.


Check the locations of those unsigned apps. If they're in the System folder (and they likely all are), then there's nothing to worry about. Only Apple can put anything in the System folder.

Jul 13, 2023 5:38 PM in response to CurateHygge

There are unknown names in your Keychain this is totally normal on every system. As stated the octagon file is part of the OS security and should not be removed. Modifying keychains is only going to give you problems with your Mac requiring a Factory Reset.


Norton 360 is not recommended to install. You will see false claims of security issues. This is how they keep themselves relevant so you believe you need their software and will continue to pay more for it. Here are just 3 previous articles from this support forum:

https://discussions.apple.com/thread/254569992

Norton 360 deluxe - Do or don't? - Apple Community

Norton 360 Mobile Security - Apple Community


Your Mac has built in protection from viruses and continually gets Security Update. To make sure you keep your Mac safe, do not install any Cleaner App or Anti-Virus software. Along with that, do not install from a Safari notification saying you have a virus or from a pop up on a website. These are known scams.


More importantly is keeping your Apple ID password safe and avoid phishing messages. For more information about these:

Recognize and avoid phishing messages, phony support calls, and other scams - Apple Support


If you do think that your Apple ID has been compromised, then you can follow this support article:

If you think your Apple ID has been compromised - Apple Support


When using Safari, do not allow Notification or Pop-ups from every site you use. This is the source of common problems and in most cases, you do not need them.


Other than that, enjoy your Mac and try not to be looking for problems you do not have. If you do experience a specific problem when using it, feel free to create a new question with your concerns and issues you are having. At this point, there is nothing you should be concerned with from what you have posted.

May 23, 2024 6:38 AM in response to Chapmans4972

Chapmans4972 wrote:

Is there a tutorial anywhere that can help a layman, such as myself, identify threats by looking through the analytics. A red flag cheat sheet?

No. Interpreting analytics requires specialist training and software.


The best advice I can give (and which I have already given once in this thread) is this article:


Effective defenses against malware and ot… - Apple Community


It will tell you how to keep your Mac safe. Spoiler alert: the best defense is the stuff between your ears.

May 18, 2023 10:36 AM in response to mekyma

What do you have in Login Items at  > System Settings > General > Login Items? Also take a look at the Apps that are allowed to run in the background. You can disable with the switch or delete the associated app that is usually in the Applications folder. Don't worry about the AdobeAcrobatReader or OSMessageTracer if you have those.


Startup in Safe Boot mode and check these locations by copying and pasting at Finder > Go > Go to Folder:

  • /Library/StartupItems - Usually there are no items in there
  • /Library/LaunchAgents - Maybe just an Adobe file in there
  • /Library/LaunchDaemons - Maybe com.adobe or com.apple files in there

Feel free to ask about a file before deleting if you are unsure. I usually recommend a backup before deleting any System files, but you have made it clear that you are not concerned about the info you have on the device.



This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Malware Octagon Security

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.