Third-party tool identifies Agent-BGP Trojan in macOS dyld shared cache file

Norton just told me that I have two instances of Agent-BGP which is labeled as a Trojan.


Apparently they are in the same file.


I can't find any mention of such a Trojan.


Norton told me that it can't remove the file.


The file is located at /System/Volumes/Preboot/Cryptexes/Incoming/OS/System/Library/dyld/

dyld_shared_cache_arm64e.01


Agent BGP seems legit based on this AI summary "The term agent BGP MAC typically refers to the role of a Border Gateway Protocol (BGP) routing agent handling Layer 2 Media Access Control (MAC) address advertisements, most commonly seen in BGP EVPN (Ethernet VPN) architectures or specialized OVN BGP Agents in cloud networking. [1, 2]"


Has Norton AI misidentified this file as containing a Trojan?


If not any thoughts on how to proceed?


Thanks




Mac Studio (2023)

Posted on Sep 28, 2026 12:52 PM

Reply
Question marked as Top-ranking reply

Posted on Sep 28, 2026 1:16 PM

Throw Norton in the trash. Never use it again.


The file it flagged is in the System folder. Nothing and no one other than Apple can so much as touch the contents of this encrypted volume.

5 replies

Sep 28, 2026 1:24 PM in response to trinko

Agreed! Delete Norton. False positives is how they attempt to justify that it is working for you and is the primary source of their revenue stream. Your Mac already has Malware protection called XProtect that performs 3 different types of scans on your computer at regular intervals.


Also a Google search gives this Gemini result:

  • The file dyld_shared_cache_arm64e.01 is a core, cryptographically signed system file built into macOS, and any antivirus flag on it is a false positive.

Sep 28, 2026 7:07 PM in response to trinko

While I agree "Norton" should be trashed, use caution not to merely drag its app icon to the Trash. Uninstall it in accordance with its uninstallation instructions, and hope that they actually work. For those instructions consult its documentation.


Removing earlier versions of that **** ranged from difficult to impossible, as in the only way to completely eradicate it was to erase the Mac.


Rule 1 of Macs is don't install junk.

Sep 28, 2026 1:18 PM in response to trinko

trinko wrote:
Norton just told me that I have two instances of Agent-BGP which is labeled as a Trojan.

You don't.


Norton told me that it can't remove the file.
The file is located at /System/Volumes/Preboot/Cryptexes/Incoming/OS/System/Library/dyld/
dyld_shared_cache_arm64e.01

Thanks to Apple for preventing this kind of damage.


Agent BGP seems legit based on this AI summary "The term agent BGP MAC typically refers to the role of a Border Gateway Protocol (BGP) routing agent handling Layer 2 Media Access Control (MAC) address advertisements, most commonly seen in BGP EVPN (Ethernet VPN) architectures or specialized OVN BGP Agents in cloud networking. [1, 2]"

Gibberish.


Has Norton AI misidentified this file as containing a Trojan?

Oh yeah.

Third-party tool identifies Agent-BGP Trojan in macOS dyld shared cache file

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.