iMac infected with virus that creates hidden windows partition, won’t boot from USB or internet recovery

I have an iMac that has got a serious virus on it. The hard drive is 500gb, but when I format it using disk utility, the drive says it is only formatted to 465 gb, then when I load it in OSX Catalina, it says the drive is 500gb and doesn’t show a bunch of hidden partitions the virus has created.


It seems the virus has its own boot loader and it disables booting from USB and internet recovery. I can start internet recovery but then the Apple symbol comes up and it boots from the virus’s recovery disk, which is sometimes a Catalina disk and sometimes it’s a Snow Leopard or El Capitan boot menu.


The virus has created hidden windows partitions and hidden Mac partitions which are ejectable hidden drives that I can only see from using hdutil list in terminal when I boot from the fake internet recovery.


I was able to use GPT fdisk to remove one of the windows partitions, but when I go to delete the other partitions they come right back after I zero the drives in terminal from the fake internet recovery, and I can’t boot from USB. I’m pretty sure the list of partitions I see in terminal is a fake list because it doesn’t propagate the window fully when I open the terminal to a different sized window from the one I originally ran hdutil list in.


Im totally stuck, if I boot in verbose mode I can sometimes get it to work, but I can’t boot from USB or a real internet recovery because the virus’s fake boot loader denies access to a real install disk and has a hidden 40gb partition that I can’t delete and it just puts the virus right back on after I format.


Can anyone please help me figure this out?

Posted on May 25, 2020 10:35 AM

Reply

Similar questions

62 replies

May 25, 2020 10:49 AM in response to soundboy13

There's no virus. Catalina formats your disk using APFS. APFS creates one visible volume and four invisible volumes. As an example, if you name your disk "Macintosh HD," then that is the only visible volume you will see mounted on your Desktop. There are four invisible volumes named: Macintosh HD - Data, Preboot, Recovery, and VM. Of these four, only the Data volume will be shown by Disk Utility. The whole array, however, will be displayed if you use diskutil in the Terminal.


These five volumes are all grouped under what APFS calls a "container." Containers are similar to partitions but unlike partitions, containers can share the available space on the storage device. They have many more features you can read about.


When should you use APFS Containers, Volumes, and Folders?

Partition Drives & Create APFS ‘Containers’ for Space Sharing with Disk Utility

Tech 101- Explaining the New Apple File System (APFS)

Copy, move and clone files in APFS, a primer

Add, delete or erase APFS volumes in Disk Utility on Mac - Apple Disk Utility User Guide


May 25, 2020 11:16 AM in response to rkaufmann87

Well there is a hidden 35gb windows partition on the drive, so maybe the virus is written in windows and they use boot camp to get it on the Mac.


Every time I erase it, it comes right back because I think the boot loader has created a raid in the hidden partition, and it just puts the files right back where they were after I deleted them.


also the Catalina install disk that the virus uses is only 2gb, but the real install disk should take up more space than that.



here is proof that the 500gb drive is only formatting to 465gb

May 25, 2020 11:36 AM in response to rkaufmann87

https://www.google.com/amp/s/www.vox.com/platform/amp/recode/2020/2/12/21134681/mac-pc-virus-malware-malwarebytes


Just because you don’t think that macs can have a virus doesn’t mean it isn’t so.


My iMac with the 35gb hidden partition and the boot loader that won’t allow me to use the real internet recovery or boot from a USB and do a clean install would beg to differ.


Is there any program I can use to restart the computer and boot to a partitioning program aside from disk utility that doesn’t boot from USB? If I can erase the drive without using the fake disk utility that is provided by the 2gb “Catalina” disk that is also part of the hidden partition, then maybe I can delete the virus.

May 25, 2020 12:50 PM in response to Kurt Lang

What others suggested in loading Etrecheck is a good idea. It will reveal hidden launch daemons that might have installed as trojan horses. Quite different from viruses, these are software that promote their value to the unsuspecting user and encourage you to install them. Where a virus will come onto your computer without even provocation.


Examples of trojan horses are software made by Macpaw and Zeobit that are purported optimizers.

Website extensions that force Chrome to load a different start website like weknow.ac.


There phishing websites that look like the real thing unless you reveal the full link to the website. Those are known as adware, and can be very dangerous if you use your machine for personal information.


And while you could technically run a script that could cause some significant damage, it won't do so without root account access, which requires you divulge the administrative password to a software that does not need it.


Let's start by identifying the launch daemons:

https://discussions.apple.com/docs/DOC-250002463


And once we do, we will restart in safe mode (using the shift key), to remove the said programs using EasyFind, also documented in the tip. But first we need to ensure you only delete that which does not belong.


May 25, 2020 1:50 PM in response to Old Toad

Paragon software allows read/write access to PC formatted hard drives in the NTFS format. That's where you are getting the PC partition, to allow it to manage your ability to write to PC formatted hard drives. That's a feature of the program, not so much virus. Because it is sifting back and forth between two file systems, that can slow read/writes into the other file system of large files.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

iMac infected with virus that creates hidden windows partition, won’t boot from USB or internet recovery

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.