You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Will erasing you hard drive and reinstalling Ventura get rid of malware on the shelll?

I have been hacked at the core level. A bad actor has screen share and control access. I have used disk utility to erase my start up hard drive and using the remote install utility I am reinstalling Ventura. Will this clear core access and make this computer malware free?

MacBook Pro 15″, macOS 13.4

Posted on Jun 26, 2023 3:51 PM

Reply
Question marked as Top-ranking reply

Posted on Jun 26, 2023 4:33 PM

Hello producer_man,


Yes, a factory reset would remove any persistence a hacker may have on your computer. However, you will lose all data. Brining any data over could risk reintroducing the hacker's persistence method. Before factory resetting your MacBook Pro, I'd suggest the following


It's a little more advance, but Activity Monitor can be used to track unknown and unwanted applications - Activity Monitor User Guide for Mac - Apple Support. It is advised to go through this. The Network tab is usually the most interesting. Kill any process you do not recognize.


Go through the sections of Privacy & Security within the Settings app and revoke access to apps that shouldn't have certain permissions. I would be careful with:

  1. Files and Folders
  2. Microphone
  3. Screen Recording
  4. Camera
  5. Full Disk Access
  6. Location


For your scenario, I would revoke all app access to ALL of these fields.


I would suggest looking at Privacy & Security within the Settings app and going through Safety Check. Revoke access to people and apps that are utilizing privileges you believe they shouldn't have. Changing your Apple ID password and device passcodes might also be smart.


To prevent future incidents:

  1. Do not interact with unknown senders.
  2. Do not click on unknown links or attachments.
  3. Do not travel to sketchy and unknown websites.



9 replies
Question marked as Top-ranking reply

Jun 26, 2023 4:33 PM in response to producer_man

Hello producer_man,


Yes, a factory reset would remove any persistence a hacker may have on your computer. However, you will lose all data. Brining any data over could risk reintroducing the hacker's persistence method. Before factory resetting your MacBook Pro, I'd suggest the following


It's a little more advance, but Activity Monitor can be used to track unknown and unwanted applications - Activity Monitor User Guide for Mac - Apple Support. It is advised to go through this. The Network tab is usually the most interesting. Kill any process you do not recognize.


Go through the sections of Privacy & Security within the Settings app and revoke access to apps that shouldn't have certain permissions. I would be careful with:

  1. Files and Folders
  2. Microphone
  3. Screen Recording
  4. Camera
  5. Full Disk Access
  6. Location


For your scenario, I would revoke all app access to ALL of these fields.


I would suggest looking at Privacy & Security within the Settings app and going through Safety Check. Revoke access to people and apps that are utilizing privileges you believe they shouldn't have. Changing your Apple ID password and device passcodes might also be smart.


To prevent future incidents:

  1. Do not interact with unknown senders.
  2. Do not click on unknown links or attachments.
  3. Do not travel to sketchy and unknown websites.



Jun 26, 2023 4:50 PM in response to producer_man

I'm sorry about that!


To prevent future incidents:

  1. Do not interact with unknown senders.
  2. Do not click on unknown links or attachments.
  3. Do not travel to sketchy and unknown websites.


Be very careful what apps you assign these privileges too

  1. Files and Folders
  2. Microphone
  3. Screen Recording
  4. Camera
  5. Full Disk Access
  6. Location


An app and a hacker can't just take control of your device. They need your consent to get access to specific parts of the MacBook. Which can be prevented. For example, I never give any app "Full Disk Access" and neither should you!


Jun 26, 2023 7:27 PM in response to producer_man

Something that you can do that's a little less drastic than a factory reset:


Download and run the free version of Malwarebytes. The site and the application will try to get you to purchase a version that does real-time protection, but running the free version might find and clean off some of the malware that you've picked up.


https://www.malwarebytes.com/


I can't guarantee that it will find and remove everything … some malware is really sneaky, or is so new that it might not be detected by the latest version of the program.


But on the scale that MacAddict once used to rate applications, it's "Better than poking your eye out with a sharp stick."

Jun 26, 2023 11:11 PM in response to Servant of Cats

Your Mac does not need any sort of anti virus, cleaner, etc. No application can be downloaded and have full access to macOS. The end-user has to grant this access, which is why it’s advised to always verify you’re downloading for the legitimate website and only grant access to aspects (camera, microphone, folders and file, etc.) that you believe it needs access too. Never give anything (except Apple apps that need it) Full Disk Access.


Privacy & Security within Settings will list all apps that have permissions to various aspects of macOS. This is why it’s also recommended to go through here and revoke access to any application that you believe is abusing its permissions.


This is why the App Store is the best place to download content as it’s been vetted and approved by Apple. Obviously this is a lot harder on macOS, which is why you only download from official and known websites.

Will erasing you hard drive and reinstalling Ventura get rid of malware on the shelll?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.