Big Sur 11.2 has EFI Bootloader and Windows MBR which I can't delete

I'm running Big Sur 11.2 on my 14,4 iMac and there is a 209.7MB partition at the start of the disk, which was formatted when I did the install from a USB created by downloading 11.2 from the App Store. When the partition is loaded it only has 23.04kb on it. Any USB drives which are formatted by the computer never fully format, and all contain the same size EFI partition.


I tried to clean install from USB, but it would boot from the USB and also from an internet recovery disk that was not ejectable. Some of the install options are missing and some of the terminal commands will not work when using this recovery mode.


/EFI/APPLE/CACHES/CAFEBEEF is the only folder structure on it, and the only file is BOOTLOG.EXE


When the BOOTLOG.EXE is run this is what it does:


/Volumes/EFI/BOOTLOG: line 1: SlingShot:: command not found

/Volumes/EFI/BOOTLOG: line 2: Disassociating: command not found

/Volumes/EFI/BOOTLOG: line 3: Booting: command not found

/Volumes/EFI/BOOTLOG: line 4: SlingShot:: command not found

/Volumes/EFI/BOOTLOG: line 5: Disassociating: command not found

/Volumes/EFI/BOOTLOG: line 6: Booting: command not found

/Volumes/EFI/BOOTLOG: line 7: SlingShot:: command not found

/Volumes/EFI/BOOTLOG: line 8: Disassociating: command not found

/Volumes/EFI/BOOTLOG: line 9: Booting: command not found

/Volumes/EFI/BOOTLOG: line 10: SlingShot:: command not found

/Volumes/EFI/BOOTLOG: line 11: Disassociating: command not found

/Volumes/EFI/BOOTLOG: line 12: Booting: command not found

/Volumes/EFI/BOOTLOG: line 13: SlingShot:: command not found

/Volumes/EFI/BOOTLOG: line 14: NetworkFinishOSRSHostInfoLookup:: command not found

/Volumes/EFI/BOOTLOG: line 15: GetStationAddressViaIpAgent:: command not found

/Volumes/EFI/BOOTLOG: line 16: GetStationAddressViaIpAgent:: command not found

/Volumes/EFI/BOOTLOG: line 17: GetStationAddressViaIpAgent:: command not found

/Volumes/EFI/BOOTLOG: line 18: GetStationAddressViaIpAgent:: command not found

/Volumes/EFI/BOOTLOG: line 19: GetStationAddressViaIpAgent:: command not found

/Volumes/EFI/BOOTLOG: line 20: NetworkFinishOSRSHostInfoLookup:: command not found

/Volumes/EFI/BOOTLOG: line 21: NetworkFinishOSRSHostInfoLookup:: command not found

/Volumes/EFI/BOOTLOG: line 22: NetworkFinishOSRSHostInfoLookup:: command not found

/Volumes/EFI/BOOTLOG: line 23: SlingShot:: command not found

/Volumes/EFI/BOOTLOG: line 24: SlingShotSetupAuthParams:: command not found

/Volumes/EFI/BOOTLOG: line 25: NetworkResolveDomainName:: command not found

/Volumes/EFI/BOOTLOG: line 26: DownloadChunkedAsset:: command not found

/Volumes/EFI/BOOTLOG: line 27: NetworkResolveDomainName:: command not found

/Volumes/EFI/BOOTLOG: line 28: SlingShotUpdateProgressUI:: command not found

/Volumes/EFI/BOOTLOG: line 29: SlingShotUpdateProgressUI:: command not found

/Volumes/EFI/BOOTLOG: line 30: SlingShotUpdateProgressUI:: command not found

/Volumes/EFI/BOOTLOG: line 31: SlingShotUpdateProgressUI:: command not found

/Volumes/EFI/BOOTLOG: line 32: SlingShotUpdateProgressUI:: command not found

/Volumes/EFI/BOOTLOG: line 33: SlingShotUpdateProgressUI:: command not found

/Volumes/EFI/BOOTLOG: line 34: SlingShotUpdateProgressUI:: command not found

/Volumes/EFI/BOOTLOG: line 35: syntax error near unexpected token `>>'

/Volumes/EFI/BOOTLOG: line 35: `>>>>>>: [0:07] to go, Remaining in Sec = 396, Ho'rs = 0, Minutes = 7, Bytes Left = 616094933


Is this normal? I've been having many issues with the computer that a format or clean install just won't fix. DarwinDumper shows the right version of Big Sur that I am running, but calls it an unknown OS. If anyone wants to take a look at the DarwinDumper file I have the zip file. Here is some of the text from the kernel bootlogger.


Also a snapshot of the drive shows a Windows loader MBR, but I never installed Boot Camp or tried to load windows.



I booted the drive in GPARTED live, and in single user mode, but both of those did not help as the boot drive was not writeable and I was unable to see the Windows loader to be able to remove it, but I was able to delete a copy of windows from booting using the alt key.


If anyone could please help me try to get rid of the all the data on the drive and be able to boot from USB without loading the unejectable internet recovery disk, I would really appreciate it.


Thank you.

Posted on Feb 14, 2021 2:39 AM

Reply

Similar questions

2 replies

Feb 14, 2021 2:45 AM in response to soundboy13

soundboy13 wrote:

I'm running Big Sur 11.2 on my 14,4 iMac and there is a 209.7MB partition at the start of the disk, which was formatted when I did the clean install. I tried to clean install from USB, but it would boot from the USB and also from an internet recovery disk that was not ejectable. When the partition is loaded it only has 23.04kb on it.

If anyone could please help me try to get rid of the all the data on the drive and be able to boot from USB without loading the unejectable internet recovery disk, I would really appreciate it.

Thank you.


From the Terminal.app copy and paste:

diskutil list internal


Is this what you are asking about in the OS? <EFI ⁨ 314.6 MB disk0s1>

This would be normal, yes.



MacBook-Pro ~ % diskutil list internal

/dev/disk0 (internal, physical):

#: TYPE NAME SIZE IDENTIFIER

0: GUID_partition_scheme *1.0 TB disk0

1: EFI ⁨EFI⁩ 314.6 MB disk0s1

2: Apple_APFS ⁨Container disk1⁩ 1.0 TB disk0s2


/dev/disk1 (synthesized):

#: TYPE NAME SIZE IDENTIFIER

0: APFS Container Scheme - +1.0 TB disk1

Physical Store disk0s2

1: APFS Volume ⁨Macintosh HD⁩ 14.9 GB disk1s1

2: APFS Snapshot ⁨com.apple.os.update-...⁩ 14.9 GB disk1s1s1

3: APFS Volume ⁨Macintosh HD - Data⁩ 279.7 GB disk1s2

4: APFS Volume ⁨Preboot⁩ 281.5 MB disk1s3

5: APFS Volume ⁨Recovery⁩ 655.5 MB disk1s4

6: APFS Volume ⁨VM⁩ 1.1 GB disk1s5


Feb 14, 2021 3:17 AM in response to leroydouglas

% diskutil list internal

/dev/disk0 (internal, physical):

#: TYPE NAME SIZE IDENTIFIER

0: GUID_partition_scheme *500.1 GB disk0

1: EFI ⁨EFI⁩ 209.7 MB disk0s1

2: Apple_APFS ⁨Container disk1⁩ 499.8 GB disk0s2


/dev/disk1 (synthesized):

#: TYPE NAME SIZE IDENTIFIER

0: APFS Container Scheme - +499.8 GB disk1

Physical Store disk0s2

1: APFS Volume ⁨Untitled - Data⁩ 166.8 GB disk1s1

2: APFS Volume ⁨Preboot⁩ 293.5 MB disk1s2

3: APFS Volume ⁨Recovery⁩ 610.8 MB disk1s3

4: APFS Volume ⁨VM⁩ 1.1 GB disk1s4

5: APFS Volume ⁨Untitled⁩ 19.5 GB disk1s5

6: APFS Snapshot ⁨com.apple.os.update-...⁩ 19.5 GB disk1s5s1


I wondered if the EFI could have something wrong with it because it seems to copy itself onto any devices which are formatted with the computer, and all of the mac hidden files are the same on every disk.


This is the version of the firmware the computer says it is using, and it checks out on apple’s list, but it’s not the current one. I’m not sure if version 430 of the boot rom is out yet or not?


IM144.88Z.F000.B00.2012171743  (Boot ROM Version: 430.0.0.0.0)


Whatever the issue is, something is not right with the computer, and a secureerase format using diskutil in terminal when the computer is rebooted with a USB installer will not resolve the issue. I know the USB is booted because it won't allow me to eject it, but at the same time there is an Internet Recovery volume of around 2gb in size which also will not allow me to eject it.


Weird stuff happens. The computer will hang at shut down, or it will restart every time you try to turn it off. My password can change at any time behind my back. Terminal commands are disabled. even from a boot disk. I can’t view hidden files. Windows installs automatically after evert format, without me running boot camp. Updates which appear to come from the App Store are unsigned and come back with bad SHA256 values. Any drive which is inserted into the computer gets hidden files copied onto it, which are contained in the 209.7 EFI partition.


Any disks which are formatted with this computer are not fully erased, they all come back with the first partition hidden with an EFI partition the same size, containing hidden files. 


Recovery mode won’t work and it has a feature which asks for your wifi and password, even if you are plugged in Ethernet, then it saves your airport password and will connect even when you have the wifi disabled.


When I format I have no choice but to use the APFS file system when I install Big Sur or Catalina, and the space of the 5 partitions can change drastically without me downloading anything. I think the issu allows someone to connect to your computer using SSH and basically do whatever they want. I was surprised to find windows installed when I rebooted the computer and pressed option, it was there.


There is a firmware update called “Mac EFI Security Update 2015-002” which is supposed to fix the security flaws in the EFI, but I can’t install it without running Mavericks 10.9.5 but I'm unable to find a verified installer because the certificate has expired. 


It seems the virus is loads a modified kernel which basically owns the computer and I have no way to flash the bios or fix the thing. 


I ran Darwin Dumper and I have a .HTML file with all of the info it could get. The boot kernel is vary long and contains commands which disable booting from USB, and all sorts of other stuff. Check the text I posted. I'm sure someone who is knowledgeable about boot kernels could look at it and determine if there is an issue there, but there is a lot more text which I could not fit into the window.


If it is not the EFI, then it may be something else related to the internet recovery disk which won't eject or firmware issues. All I can think of is going back to Mavericks and trying to flash the UEFI, but I have to keep formatting the computer because the longer I leave it on to try to get stuff done, the more commands and features get disabled and then I have to format again because the hard drive fills up with programs I did not install and data which I can't find.


Does any of this sound like a known virus?



This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Big Sur 11.2 has EFI Bootloader and Windows MBR which I can't delete

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.