Malware has setup a hidden partition

Malware has setup a hidden 70 gig partition. The only way I found it was to save a web page as a pdf and it asked where. Under possible locations a "k" drive was an option. I then reset the computer to see hidden devices and hidden files. I found a 70 gig drive hidden. It seems to have been activated on May 14th. I can't unmount or eject from the sidebar.It's not allowing me to do anything with it because I don't have permission. I downloaded the flashback security file from Apple and it says that my drive doesn't meet the requirements for this update.


How do I get the permission to get this off and how do I get it off?

Mac mini, OS X Mountain Lion (10.8.3)

Posted on May 27, 2013 9:55 AM

Reply
55 replies

May 27, 2013 11:58 AM in response to Royal Cascadian

What you are seeing is not due to malware of any kind. As Topher says, you just renamed your hard drive accidentally.


The reason that your diskutil output appears to show three drives is, I believe, because you must be using FileVault encryption. The first item, /dev/disk0, is the overall schema of the hard drive. The main partition there, disk0s2, I believe contains the encrypted contents of your hard drive. The second, /dev/disk1, is a virtual "disk" mounted much like a disk image file, representing the unencrypted contents of your hard drive. The third, /dev/disk2, is your Flashback Removal disk image, which you had open at the time that command was executed.


For more information about malware that exists on Mac OS X, see my Mac Malware Guide. Note that there is no known malware that creates hidden partitions on a Mac OS X system.

May 27, 2013 12:30 PM in response to Royal Cascadian

Aha, that throws some new light on matters. That "l k" item is your computer's name. Go to System Preferences -> Sharing and change it there. You have checked the first box under Devices in the General pane of the Finder's preferences to show that item in the sidebar. When you select that item, it shows you all possible devices you have. It looks like you have a disk image mounted, two shared folders, your hard drive (named Macintosh HD), the Network item (which allows you to browse for other devices to connect to on the network, and a Remote Disc item which, I believe, allows you to share the optical drive of another Mac that is on your local network.


None of this is related to malware.

May 27, 2013 1:23 PM in response to MadMacs0

Well, I don't think it's just my computer got renamed arbitrarily by me and coincidentally the same day my HD is modified. Why is it just May 14th?. The day most likely I downloaded a malicous program, which I did. In fact I noticed something a few days later was downloading another file automatically to my download folder. So i looked at what it was. When I had the windor opened I was going to throw it in the trash from the download folder, it disappeared. Not until the yesterday when a l k showed up did I care to find out what happened.


So I did download something that in turn downloaded something that then became hidden on my computer.

I didn't do anything because I figured it was dealt with when it disappeared. But after my computer was renamed and now file shareing was turned back on (which I just turned off deliberatly) it makes much more sense that the strange file that was downloaded and disappeared was what renamed my computer and allowed for files to be shared.


What are the odds?

May 27, 2013 1:56 PM in response to Royal Cascadian

If you have Java installed, reinstall Java for OS X 2013-002 otherwise reinstall OS X Mountain Lion v10.8.3 which will run the Malware Removal Tool. It will either tell you that it found and removed something or be silent, in which case it didn't find anything.


If you are still uncomfortable download and run one of the anti-malware applications reviewed by Thomas Reed in his Mac Malware Guide.


I'm sure I speak for the rest of us here when I say that there is no currently known OS X malware that would do what you have described. You say you downloaded a malicious program and earlier you indicated that it was Flash Player related. Can you give us a better description of exactly what happened. Did you have Java enabled in your browser at the time? Was your OS X fully up-to-date at the time? Do you recall the name of the file that was downloaded and do you still have it? I assume you launched the downloaded file and allowed it to install something at the time. Did you notice anything unusual about the installation.


The latest Flash Update is 11.7.700.203, I believe dated 5/22/2013 and should be in /Library/Internet Plug-Ins/. There was one about a week before that, but I don't have the exact date at the moment.


Full disclosure: I do uncompensated tech support for the ClamXav Forum.

May 27, 2013 1:58 PM in response to Royal Cascadian

If you believe you're infected with something, then just get a copy of Sophos and scan your hard drive.


However, nothing that you're telling us sounds anything like the symptoms of any known Mac malware. I can't say what's going on, as I can't entirely follow your description of what you've seen, but it certainly doesn't sound like malware. Honestely, it sounds like you're simply misinterpreting normal behaviors as malicious somehow.


I'd recommend that you take a look at my Mac Malware Guide to learn more about this topic.

May 27, 2013 2:19 PM in response to thomas_r.

Thanks for your time and thoughts, I'm just going to reinstall OS X ML. Although didn't help on my PC.


I know that this is unusual that's why I'm here.

But the fact that my browers are supposed to automatically update flash, yet tell me to update the flash player exernally with the one on my computer, which I didn't install, would seem likely that it is malware. This exact same thing happened to my PC.


My PC has been so deeply infected by malware that the BIOS is out of my control. I can't even get virus protection on the machine. I know what malware is and how it behaves.


Just because you personally haven't run into this, doesn't mean it's impossible, just unlikely, yet.


Have you never heard of a malware program automatically downloading more files? What do you think flashback was? And do you not think there are already newer versions of that? This is just the beginning for Macs.

May 27, 2013 2:32 PM in response to Royal Cascadian

Nobody's saying its impossible to be malware, but rather that it's improbable. Many folks here are well-versed in the Mac malware scene and while there's the possibility of a new threat out there that behaves like this, so far it's not been documented.


It's possible this has arisen from malicious activities, but do keep in mind that both the Flash plugin and the Flash system preferences can detect if Flash is out of date and inform you of an update. Additionally Apple's XProtect security feature in OS X may block the plugin if it's out of date, and inform you of the need to update, so there are several modes by which the system can issue you requests to update Flash, without it being malware.


However, if you don't want to take any chances, then formatting and reinstalling OS X is one way to clear any unknown items that may have been installed.

May 27, 2013 2:44 PM in response to Royal Cascadian

There are many malicious web sites out there that will display fake Flash update notices. Just ignore and close them. Make sure that you don't have Java enabled in your web browser, and use a Flash blocker (like ClickToFlash), and don't install anything that gets downloaded as a result.


It sounds like you have had some bad experiences with malware on Windows, but do not use your experience with Windows malware to extrapolate behavior on the Mac. Of course malware will often download more files, but it certainly does not do so in a way that the average user would notice. Regarding Flashback, no, there aren't newer versions. It is extinct at this point. No new infections have been seen in about a year.


You are not well served by making assumptions about your issues that are not grounded in fact. We can help you determine what is going on if you could simply post clear, detailed descriptions of the behavior, without interpretation.

May 27, 2013 3:31 PM in response to Royal Cascadian

Now I'm having a strange problem with restarting my mac to reinstall ML. I have clicked off the require password after sleep or screen saver begins. Yet, as improbable as it is, it still asks for a password on every restart. Any suggestions? Or is better for another forum?

Is Users & Groups set to Automatic Login?

Do you have FileVault enabled?


Based on all the other issues, do you have disk corruption that is manifesting in all sorts of weird behavior?

May 27, 2013 3:35 PM in response to Royal Cascadian

For instance I had to call Apple support last week because I my password wouldn't reset.


I can't comment much on that, because there's no real concrete information there. If the issue has to do with a redirect in Chrome, see:


Eliminating browser redirects and advertisements


I have clicked off the require password after sleep or screen saver begins. Yet, as improbable as it is, it still asks for a password on every restart.


That setting only controls whether the password is requested on waking from sleep or dismissing the screen saver. It has nothing to do with passwords at startup.


If you are being prevented from reinstalling the system by a password, that's either a firmware password or a request for the password for the Apple ID used to purchase Mountain Lion.

May 27, 2013 4:45 PM in response to Royal Cascadian

Your directory structure looks to be messed up as the top item should be a physical description of the drive such as, MATSUSHITA 500GB....

The indented items will be logical volumes on the hard drive.

Select the very top Macintosh HD and try repairing it. That should repair the directory.


I'm also confused that the Macintosh HD is on the top. That usually indicates the boot drive, which would explain not being able to erase it. However, I haven't been in Recovery in a while, so that may be correct for recovery.

That's normal for Recovery.

May 28, 2013 1:42 PM in response to Royal Cascadian

I held off responding as you seemed to have chosen a path and I didn't want to distract from that. Hope you have everything working now.

Royal Cascadian wrote:


But the fact that my browers are supposed to automatically update flash, yet tell me to update the flash player exernally with the one on my computer, which I didn't install, would seem likely that it is malware.

The automatic update capability of System Preferences->Flash Player->Advanced tab has never worked. I gave up and set mine to Notify. Chrome is the only one of my browsers that automatically updates.

Just because you personally haven't run into this, doesn't mean it's impossible, just unlikely, yet.


Have you never heard of a malware program automatically downloading more files? What do you think flashback was? And do you not think there are already newer versions of that? This is just the beginning for Macs.

At least three of us folks who have tried to help you here have an ulterior motive for being here and that is in case you are right about new malware. We spend a good portion of our days scanning the Internet and reading the security blogs for any sign of a new mac threat. It would not be the first time that we have stumbled across a zero-day infection that none of the A-V labs, etc. have run across yet. That's why we keep insisting on details and answers to detailed questions. I realize that your first priority must be getting your computer back on track, but hopefully you appreciate that in doing so you can help the community out before things get out of control as they did about a year ago.


Of course we know about Trojan downloaders. That's the way almost all drive-by infections occur. Neither I nor any of the other contributors said that wasn't a possibility, just that we are currently unaware. I believe the Flashback developers retreated from the OS X market because it wasn't cost effective for them, even after collecting advertising fees for ~600,000 users for a short time. Are they working on the next version? Certainly possible, and some of us want to be on top of it should they choose to open that market up again.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Malware has setup a hidden partition

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.