This guide explains how to remove malware from your Mac without deleting legitimate system files or assuming every slowdown is an infection. You’ll isolate suspicious activity, clean up browser hijackers and startup items, run a second-opinion scan, and confirm that the unwanted behavior is gone.
These instructions focus on macOS Tahoe 26, with notes for older supported releases. Menu names can differ slightly on macOS Ventura 13 through Sequoia 15.
What Is Mac Malware?
Mac malware is unwanted software designed to display ads, redirect web searches, steal information, or change settings without clear permission. Common examples include adware, browser hijackers, fake security tools, and programs that reopen whenever you sign in.
A slow Mac is not automatically infected. Low storage, an overloaded browser, Spotlight indexing, an old app, or a failing external drive can also hurt performance. Malware is more likely when a slowdown appears alongside persistent redirects, unexpected pop-ups, unknown extensions, settings that change back, or unfamiliar apps that return after removal.
Prerequisites
Before starting, make sure you have:
- A Mac running macOS Big Sur 11 or later; the steps shown target macOS Tahoe 26
- An administrator account for changing Login Items, profiles, and security settings
- A backup of important documents, preferably on an external SSD or through Time Machine
- Temporary internet access for macOS updates and the Malwarebytes installer
- About 30–60 minutes for cleanup, scanning, and verification
- Your work or school administrator’s contact details if the Mac is managed
Important: Do not delete an unfamiliar process or system file based only on its name. Record what you find, check which app owns it, and use a reputable scanner for a second opinion.
Step-by-Step Guide
Step 1: Check for Clear Signs of Malware
Write down exactly what is happening and when it occurs. Stronger warning signs include:
- Searches redirecting to an unfamiliar site
- Ads or alerts appearing outside normal web pages
- A homepage or search engine changing without permission
- Unknown browser extensions
- Apps opening automatically after every restart
- Security settings being changed or disabled
- Repeated requests for administrator access
- Unexplained network activity while your apps are closed
If the only symptom is poor performance, restart the Mac and check free storage under Apple menu > System Settings > General > Storage. A nearly full drive or a resource-heavy app is often the real cause.
Next, open Apple menu > About This Mac and note the macOS name, version, and Mac model.
You can also open Terminal from Applications > Utilities and display the installed macOS version with:
sw_vers
Expected result: You have a written list of symptoms and know which macOS version your Mac is running.
Step 2: Disconnect From the Internet if the Threat Appears Active
Disconnect temporarily if files are changing by themselves, unknown apps are sending messages, the pointer appears remotely controlled, or you suspect account information is being transmitted.
Click Control Center in the menu bar, choose Wi-Fi, and turn it off. If you use Ethernet, unplug the Ethernet cable or USB-C hub.
Leave the network connected if you are only seeing mild browser redirects and need to download updates. You will also need to reconnect later to update macOS and Malwarebytes.
Warning: If this is a company or school Mac, contact its IT team before making major changes. They may need logs or other evidence from the device.
Expected result: An actively misbehaving Mac can no longer communicate over Wi-Fi or Ethernet.
Step 3: Inspect Activity Monitor Carefully
Open Finder > Applications > Utilities > Activity Monitor. Select the CPU tab, then click the % CPU column to place busy processes near the top.
Use the search field to find a process connected to a suspicious app. Double-click it and review the available details. If you recognize the app and it is clearly misbehaving, quit the app normally first.
Do not force-quit entries simply because they have technical names. Processes such as kernel_task, launchd, WindowServer, and mds are legitimate parts of macOS.
If a suspicious process immediately returns after you quit its associated app, record its exact name. You will check Login Items and run a scan later.
Expected result: You have identified resource-heavy or suspicious activity without deleting system components.
Step 4: Start the Mac in Safe Mode
Safe Mode prevents some third-party startup software from loading and performs basic startup checks. If the symptoms disappear there, a Login Item, extension, or other startup component is a likely cause.
On a Mac with Apple silicon
- Choose Apple menu > Shut Down.
- Wait until the screen is fully dark.
- Press and hold the power button until Loading startup options appears.
- Select your startup disk.
- Hold the
Shiftkey and click Continue in Safe Mode. - Sign in. macOS may ask you to sign in twice.
On an Intel-based Mac
- Choose Apple menu > Restart.
- Immediately press and hold
Shift. - Release the key when the login window appears.
- Sign in to your account.
You can verify the startup mode by opening Apple menu > System Settings > General > About, clicking System Report, and selecting Software. Look for Boot Mode: Safe.
Test the affected browser and watch for the original symptoms. Avoid signing in to banking, email, or other sensitive accounts until cleanup is complete.
Expected result: The Mac starts in Safe Mode. If the problem stops, unwanted startup software is probably involved.
Step 5: Remove Suspicious Safari Extensions and Restore Settings
Open Safari and choose Safari > Settings > Extensions. Select an extension you do not recognize, confirm that it is not required by an app you trust, and click Uninstall. Safari may direct you to remove the app that installed it.
Then check these areas:
- Safari > Settings > General: Restore Homepage, New windows open with, and New tabs open with.
- Safari > Settings > Search: Choose your preferred Search engine.
- Safari > Settings > Websites > Notifications: Deny or remove sites sending unwanted alerts.
- Safari > Settings > Websites: Review permissions for pop-up windows, downloads, camera, microphone, and location.
- Safari > Settings > Privacy > Manage Website Data: Remove data for the redirecting site, or remove all website data if the problem persists. Removing all data signs you out of websites.
Expected result: Safari opens the page and search engine you selected, without the unwanted extension or notification prompts.
Step 6: Remove Suspicious Chrome Extensions and Restore Settings
Open Chrome and enter this address:
chrome://extensions/
Review each extension. Click Remove only for an item you identify as unwanted, then confirm the removal.
Open Chrome > Settings and review:
- On startup: Remove unknown pages and choose your preferred startup behavior.
- Search engine: Restore your preferred search provider.
- Privacy and security > Site settings > Notifications: Remove or block unwanted sites.
- Reset settings > Restore settings to their original defaults: Use this if changes keep returning.
A Chrome reset disables extensions and restores key settings, but it does not normally erase bookmarks or saved passwords. You may still need to sign back in to websites.
Expected result: Chrome no longer loads unknown startup pages, redirects searches, or displays notifications from suspicious sites.
Step 7: Remove Suspicious Firefox Extensions and Restore Settings
Open Firefox and enter:
about:addons
Select Extensions, click the three-dot menu beside an unwanted extension, and choose Remove.
Next, enter:
about:preferences
Review these sections:
- Home: Restore the homepage and new-window settings.
- Search: Choose the correct default search engine and remove unknown search shortcuts.
- Privacy & Security > Permissions > Notifications > Settings: Block or remove unwanted sites.
- Help > More Troubleshooting Information > Refresh Firefox: Use this if the hijack persists.
Refreshing Firefox keeps important data such as bookmarks and passwords, but removes extensions and custom settings.
Expected result: Firefox uses your chosen homepage and search provider without the suspicious add-on.
Step 8: Remove Rogue Login Items
Restart normally by choosing Apple menu > Restart. Then open Apple menu > System Settings > General > Login Items & Extensions.
Under Open at Login, select an app you have confirmed is unwanted and click the minus button. Review Allow in the Background as well. Turn off an entry only when you recognize the related app and no longer want it running.
Removing an entry from this screen stops automatic launching; it may not uninstall the app. To remove the app itself, open Finder > Applications, locate the confirmed unwanted app, and use its official uninstaller if one is included. Otherwise, move the app to the Trash and empty the Trash after scanning.
Expected result: Confirmed unwanted apps no longer open or run in the background when you sign in.
Step 9: Check for Unfamiliar Configuration Profiles
In macOS Tahoe 26, open Apple menu > System Settings > General > Device Management. On some earlier macOS versions, the section may be named Profiles. It may not appear at all when no profiles are installed.
Select any unfamiliar profile and examine its organization, description, and settings. A malicious profile can enforce a homepage, proxy, certificate, or other setting that keeps returning.
Do not remove a profile belonging to your employer, school, mobile device management service, or security software. Contact the administrator first. Removing a legitimate management profile can break access to email, Wi-Fi, virtual private network services, and company apps.
If this is your personal Mac and you confirm that a profile is unwanted, select it and use the displayed removal control. Enter an administrator password if requested.
Expected result: No unapproved profile remains to restore hijacked settings.
Step 10: Install and Run Malwarebytes as a Second Opinion
Reconnect to the internet. Visit the official Malwarebytes for Mac download page and make sure the address ends in malwarebytes.com.
Open the downloaded disk image from Finder > Downloads, launch the included installer, and follow its current on-screen directions. macOS may request administrator approval or access required for scanning.
Open Malwarebytes from Applications and let it update its detection data. Start a manual scan using the scan control shown in the current app version.
A paid Malwarebytes subscription is not required for a manual scan. Paid plans add ongoing protection and other features, but pricing and plan contents can change. Check the official Malwarebytes pricing page before subscribing.
Review every detection. Use the app’s current remediation or quarantine control for items Malwarebytes identifies as threats or potentially unwanted programs, then restart if requested.
Expected result: The scan completes, identified threats are quarantined or removed, and the Mac restarts normally if required.
Step 11: Update macOS and Automatic Update Settings
Open Apple menu > System Settings > General > Software Update. Install any update offered for your Mac by clicking Update Now or the equivalent button displayed.
Click the information button beside Automatic Updates. Enable these options when available:
- Check for updates
- Download new updates when available
- Install macOS updates
- Install Security Responses and system files
Older Intel Macs may not support the newest major macOS release. Install the latest update Apple offers for that specific model instead of using an unsupported installer. You can learn about the current stable release on Apple’s macOS page.
Also open Malwarebytes and check for app or detection updates using the option available in your installed version.
Expected result: macOS and the scanner are current for your supported Mac.
Step 12: Verify That the Mac Is Clean
Restart the Mac normally and repeat the actions that previously triggered the problem. Check that:
- Browsers retain the correct homepage and search engine
- Redirects and unwanted pop-ups do not return
- Removed extensions stay removed
- Unknown apps do not reopen at login
- No unwanted profile reappears
- Activity Monitor no longer shows the same suspicious behavior
- A second manual scan reports no unresolved detections
Test for at least one or two normal work sessions. One clean scan is useful evidence, but it cannot guarantee that every threat is gone.
If you entered passwords while the Mac was behaving suspiciously, change those passwords from a different, trusted device. Turn on two-factor authentication for your Apple Account, email, banking, and other important services.
Expected result: The original symptoms remain gone after restarts and normal browser use.
Configuration
These settings reduce the chance of another infection:
- Keep System Settings > General > Software Update > Automatic Updates enabled.
- Leave System Settings > Privacy & Security > Allow applications from set to App Store or App Store and Known Developers.
- Install software from the Mac App Store or the developer’s official website.
- Treat browser notification requests like app permissions. Click Don’t Allow unless the site genuinely needs them.
- Review System Settings > General > Login Items & Extensions every few months.
- Keep Time Machine backups on a dedicated external SSD.
- Avoid “cleaner,” “codec,” or “urgent virus removal” downloads promoted by pop-ups.
- Use a password manager and two-factor authentication for sensitive accounts.
Tips and Troubleshooting
The Mac Is Still Slow, but Scans Are Clean
Why it happens: Low storage, too many browser tabs, Spotlight indexing, memory pressure, or an aging drive can resemble malware.
Fix: Check System Settings > General > Storage and the Memory and Disk tabs in Activity Monitor. Remove unneeded large files or move them to an external SSD, but do not delete system folders.
The Browser Hijack Returns After Restarting
Why it happens: A background item, profile, synced browser extension, or notification permission may be restoring it.
Fix: Recheck extensions, startup pages, search settings, notifications, Login Items, and Device Management. If browser sync restores the extension, remove it from the synced browser account and other connected computers too.
An Unfamiliar Process Keeps Returning
Why it happens: It may be a legitimate macOS service, a helper for an installed app, or persistent unwanted software.
Fix: Record its name and check which installed app it belongs to. Do not delete files from /System or /Library based only on the process name. Update your scanner and run another scan.
Malwarebytes Does Not Open or Finish Scanning
Why it happens: The installer may be outdated, the app may lack required permission, or its detection update may have failed.
Fix: Restart the Mac, download a fresh installer from the official site, and follow any permission prompts shown by macOS. Avoid copies hosted on download portals.
A Profile Cannot Be Removed
Why it happens: The Mac may be managed by a work or school organization, or the profile may require administrator authorization.
Fix: Contact the listed administrator. Do not try to bypass mobile device management on an organization-owned Mac.
Symptoms Return After Cleanup and a Second Scan
Why it happens: A component may remain, a browser account may be resyncing bad settings, or a compromised online account may be involved.
Fix: Disconnect the Mac, stop using it for sensitive tasks, and contact Apple Support or a qualified Mac technician. For a business Mac, notify its security team immediately. A full erase and clean macOS installation may be appropriate, but only after protecting your documents and confirming the recovery plan.
Wrapping Up
| Step | Action | Applies To |
|---|---|---|
| 1–4 | Confirm symptoms, isolate the Mac, and test Safe Mode | All Macs |
| 5–7 | Remove extensions and restore browser settings | Safari, Chrome, Firefox |
| 8–9 | Inspect Login Items and profiles | macOS Ventura 13 through Tahoe 26 |
| 10–12 | Scan, update, restart, and verify | All supported Macs |
Most Mac adware and browser hijackers can be removed without digging through system folders. In my view, careful manual cleanup plus a reputable second-opinion scan is safer than trusting either method alone, especially when unfamiliar processes or managed profiles are involved.