Can any malware, trojans or keyloggers infect Recovery HD?

Today I just went to "Get help online" in Recovery HD and went to some malicious websites. So I'm just wondering can Recovery HD get infected by malware, trojans, keyloggers or any kind of other stuffs? And if it gets infected then what should I do to remove the malware?

MacBook Air, Mac OS X (10.7.5)

Posted on Jul 24, 2017 9:04 AM

Reply
24 replies

Jul 24, 2017 8:51 PM in response to The_Old_Man

There have been no reports here that indicated infection of the Recovery Partition. So it is at least quite rare.


It also would take a more sophisticated programmer to get in there, rather than the thugs usually responsible for Virus attacks.


It uses a couple of RAM disks for its temporary storage, and those will be gone after Restart. In addition, your main Volume is not usually Mounted, so it can't directly modify files on your main drive (although I suppose it could clobber blocks of data).

Jul 25, 2017 6:13 AM in response to The_Old_Man

Internet Recovery is NOT full blown MacOS with paging, file caching, multitasking, or extended Graphics support. Some things WILL take longer. Internet Recovery is intended to be used when your situation is DIRE.


It takes really long to start up because that version of Safari and its support software has to be downloaded to you before it can be started up. In my opinion, the minor problems you are having are as expected.



The perceived slowness is NOT likely to be due to malware of any description.

Jul 25, 2017 7:56 AM in response to Grant Bennet-Alder

Also I'm sorry for off topic a bit but when I download Mac in Macintosh, the capacity that has been used on BOOTCAMP went from 310.8MB to 311.7MB even though I didn't do anything in BOOTCAMP. 310.8MB is the capacity used in BOOTCAMP when I haven't installed Mac. And when I install Mac on Macintosh, the amount that is used on BOOTCAMP is 311.7MB. I'm wondering is that some kind of weird thing that is happening. 😕

Aug 2, 2017 7:27 AM in response to The_Old_Man

Today I just went to "Get help online" in Recovery HD and went to some malicious websites.


'Recovery is hacked' is extremely unlikely.


What is far more likely is that the DNS number supplied by your Router have been hacked. When your things are working properly again, you should check those DNS number are either:

• exactly what your ISP suggests

• exactly what the upstream Router provides

• google DNS 8.8.8.8 and 8.8.4.4

• Open DNS 208.67.220.220 and 208.67.222.222

Aug 12, 2017 8:40 AM in response to The_Old_Man

I was attempting to show you what screen to look at. I did not explicitly suggest you use MY DNS numbers, which may not be right for your geographical location. It appears there is an OpenDNS server at the Address you cited.


What is showing for actual DNS numbers in your troubled Mac?


Also, that isolated local IP Address is the local Address of my local Server, which does authentication and file sharing for me. Most users should have no local IP Addresses at all in this pane. If the address of your Router is the only address shown, that is a problem that needs to be fixed.

Aug 13, 2017 9:29 AM in response to The_Old_Man

There have been no reports of malware affecting MacOS Base System, Recovery, or any of the other items you have inquired about. There are numerous safeguards in place to protect against such attacks.


If you are having unexplained symptoms, you will get the best results by laying out your SYMPTOMS rather that your 'unusual' theories, to allow the full ability of the many experts who frequent the forums to suggest potential solutions to your issues.


Asking your exceptionally narrow questions gets you exceptionally narrow answers, and these responses are unlikely to provide any actionable information whatsoever.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Can any malware, trojans or keyloggers infect Recovery HD?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.