Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Constant HDD Activity and Unusual Partitions (Security Advice)

I've recently been hearing a lot of hard drive activity from my mac so i thought i'd check a few things, so i went to the terminal in recovery mode to see what partitions are in my machine and i found a list of lost of hard drives where i only have one. Is this normal? Is it possible that i have some sort of rootkit malware. It seems strange to me. Is there a way to scan to hidden malware in the recovery terminal?


Here is the outcome of the terminal when listing discs:


-bash-3.2# diskutil list

/dev/disk0

#: TYPE NAME SIZE IDENTIFIER

0: GUID_partition_scheme *500.1 GB disk0

1: EFI EFI 209.7 MB disk0s1

2: Apple_CoreStorage 499.2 GB disk0s2

3: Apple_Boot Recovery HD 650.0 MB disk0s3

/dev/disk1

#: TYPE NAME SIZE IDENTIFIER

0: Apple_partition_scheme *1.3 GB disk1

1: Apple_partition_map 30.7 KB disk1s1

2: Apple_HFS OS X Base System 1.3 GB disk1s2

/dev/disk2

#: TYPE NAME SIZE IDENTIFIER

0: untitled *5.2 MB disk2

/dev/disk3

#: TYPE NAME SIZE IDENTIFIER

0: untitled *524.3 KB disk3

/dev/disk4

#: TYPE NAME SIZE IDENTIFIER

0: untitled *524.3 KB disk4

/dev/disk5

#: TYPE NAME SIZE IDENTIFIER

0: untitled *524.3 KB disk5

/dev/disk6

#: TYPE NAME SIZE IDENTIFIER

0: untitled *524.3 KB disk6

/dev/disk7

#: TYPE NAME SIZE IDENTIFIER

0: untitled *524.3 KB disk7

/dev/disk8

#: TYPE NAME SIZE IDENTIFIER

0: untitled *6.3 MB disk8

/dev/disk9

#: TYPE NAME SIZE IDENTIFIER

0: untitled *2.1 MB disk9

/dev/disk10

#: TYPE NAME SIZE IDENTIFIER

0: untitled *1.0 MB disk10

/dev/disk11

#: TYPE NAME SIZE IDENTIFIER

0: untitled *524.3 KB disk11

/dev/disk12

#: TYPE NAME SIZE IDENTIFIER

0: untitled *524.3 KB disk12

/dev/disk13

#: TYPE NAME SIZE IDENTIFIER

0: untitled *1.0 MB disk13

/dev/disk14

#: TYPE NAME SIZE IDENTIFIER

0: untitled *6.3 MB disk14

/dev/disk15

#: TYPE NAME SIZE IDENTIFIER

0: Apple_HFS Macintosh HD *498.9 GB disk15

Logical Volume on disk0s2

Unlocked Encrypted


Help is much appreciated.


Kind Regards

MacBook Pro, OS X Yosemite (10.10.2), MacBookPro 8,2

Posted on Apr 1, 2015 7:02 PM

Reply
7 replies

Nov 7, 2015 12:43 AM in response to flow2015

Yeah, Apple forums used to be awesome in 2003. Now nobody gives a crap about being a "mac enthusiast" anymore. Its unfortunate and I would say its easily a side effect of apple now just being another faceless corporation as opposes to steve jobs little home that he invites you into. Secondly, apple is getting further and further away from allowing user freedom on mac. They once used to be an awesome platform for open source unix stuff and a great option for people who didnt want to use linux, but now they are pretty much just another microsoft. Nobody is excited anymore about Apple, and the app store has destroyed any sense of comunity in this forum. Its unfortunate because it used to kick *** and be one of the first thing that popped up when you googled an apple question.


Now, its fortunate i stumbled acceoss this, as I am having the exact same problem and its an absolute drag on my life. I have taken pretty much the exact same steps as you did and still having the same problems. At first, I thought I was being hacked, at second, I thought I was being havked or a virus. Third, i thought it could be a harddeive or logicboard problem. However, the symptoms dont really seem like its falling solely on the logic board. I have yet to find an answer, however after a ton of searches (no, visiting the apple store dodnt help. I also gave up on the 7th time).


There are few things it could be:

1) a rootkit efi infection

2) as noted in the lonk i post after this comment, it may quite possibly be as simple as a faulty sataII or III cable. I actually thought that is sttupid at first, until I remembered that I actually had a very similar problem years ago and it actually was just an unreliable cable that couldnt keep up with the speed at which data was processed. I am honna order a cable and give it a shot since apple just told me i have a defective logic board. Right apple. Your diagnostics are the worst and pretty much always wrong. Only way to know is to crack it open.


3) last option is that you actually do have a defective logic board, but these are technically pure symptoms of a faulty logic board. Especially if all of your other perepherals are working.


WIth all of these new zero day things coming out on mac, and apple being less concerned about security and privacy, and more about their investors, Im gonna go with it being a bootrom virus. I suppose it helps assuming that with all the news about China hacking everyone and us and china being in a secret cyber war. However, it definitely could be a faulty sata cable. For the sake of getting my mac back, i hope it is. It would be a **** of a lot easier than having to file a class action against apple for making faulty bootroms in macs made before 2014. Let me know if you find a solution or answer. I would love go know. I will do the same.

Constant HDD Activity and Unusual Partitions (Security Advice)

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.