Mac Virus & Malware Removal Guide
Macs can get malware โ and it's more common than Apple likes to admit. This guide covers how to detect it, remove it yourself, and lock down your Mac to prevent future infections.
As an Amazon Associate we earn from qualifying purchases. This costs you nothing extra and helps keep this site free.
โก Recommended for This Repair
Tools and accessories matched to this guide.
64 bits, pro-grade โ for serious DIY repair only
Required for safe electronics cleaning
64 bits, pro-grade โ for serious DIY repair only
Required for safe electronics cleaning
๐จ Signs Your Mac Has Malware
Macs don't usually get traditional "viruses" โ but adware, browser hijackers, and cryptominers are very real. Watch for:
- Browser is redirecting to unfamiliar search engines or sites
- Pop-up ads appearing constantly, even on normal websites
- Mac is running slow with fans spinning for no reason
- New toolbars or extensions appeared in Safari/Chrome you didn't install
- Homepage changed without you changing it
- CPU usage is high (Activity Monitor shows unknown processes using 80-100%)
- Fake security alerts appearing in browser ("Your Mac is infected! Call Apple Support!")
Note: "Your Mac is infected" alerts that appear IN the browser are always fake. Real malware doesn't announce itself. Close the tab and ignore them.
๐ Step 1: Check Activity Monitor for Suspicious Processes
- Open Activity Monitor (search with Spotlight: โ+Space)
- Click the CPU tab, sort by % CPU descending
- Look for unknown process names using high CPU constantly
- Click the Memory tab โ look for processes consuming gigabytes for no reason
Suspicious process names to watch for:
- Anything with "miner," "coin," or "crypto" in the name
- Random letter strings: "xjhab," "dklwp," etc.
- Processes masquerading as system processes (check the path โ real system processes live in /System/ or /usr/)
- "com.adobe.gsp.helper" or similar fake Adobe processes (if you don't have Adobe)
If you find a suspicious process: note the name, then Google it to confirm it's malware before killing it.
๐ก๏ธ Step 2: Run MalwareBytes (Free)
MalwareBytes for Mac is the gold standard for free malware scanning. It catches adware, browser hijackers, and PUPs (Potentially Unwanted Programs) reliably:
- Download MalwareBytes from malwarebytes.com (free version is enough)
- Install and open it
- Click Scan โ wait for the full scan to complete
- Review the results and quarantine/remove everything flagged
- Restart your Mac
The free version doesn't include real-time protection, but its on-demand scan is excellent. Run it whenever you suspect something is wrong.
๐ Step 3: Clean Your Browsers
Most Mac "infections" are actually browser-level adware. Clean all browsers you use:
Safari:
- Safari โ Settings โ Extensions โ remove any you don't recognize
- Safari โ Settings โ Search โ change Search Engine back to Google or your preferred engine
- Safari โ Settings โ General โ check Homepage โ reset if hijacked
- Safari โ Clear History (History menu) โ select "all history"
Chrome:
- chrome://extensions โ remove any suspicious extensions
- chrome://settings/searchEngines โ remove unknown search engines, set default to Google
- chrome://settings โ On startup โ reset if pages are hijacked
- Consider: chrome://settings โ Reset settings โ Restore settings to original defaults
Firefox:
- about:addons โ remove suspicious extensions
- about:preferences#search โ reset search engine
- Help โ More Troubleshooting Info โ Refresh Firefox (nuclear option if needed)
๐ Step 4: Remove Malicious Apps & Login Items
Check Applications folder:
- Open Finder โ Applications
- Look for apps you don't remember installing โ especially anything with "Mac Cleaner," "Advanced Mac," "MacKeeper," or generic names
- Drag them to Trash โ then use AppCleaner (free app) to remove all associated files
Check Login Items (things that launch at startup):
- Apple menu () โ System Settings โ General โ Login Items
- Review everything listed โ remove anything suspicious or unknown
- Also check "Allow in the Background" items below Login Items
Check LaunchAgents (advanced):
- Open Finder โ Go โ Go to Folder (โ+Shift+G)
- Type: ~/Library/LaunchAgents
- Look for .plist files you don't recognize โ Google the filename if unsure
- Move suspicious ones to Desktop (not Trash yet โ in case you need to restore)
- Restart and see if the problem is gone
๐ Step 5: Lock Down Your Mac Going Forward
Prevention is worth 10x the cure:
- Only install apps from the App Store or developers you trust completely
- Never install software prompted by a website โ especially fake "Flash Player," "Codec," or "System Update" prompts
- Keep macOS and apps updated โ Apple patches security vulnerabilities regularly
- Enable FileVault (System Settings โ Privacy & Security โ FileVault) โ encrypts your drive
- Enable Firewall (System Settings โ Network โ Firewall)
- Use a password manager โ reduces risk of phishing stealing credentials
- Don't use admin account for daily work โ create a standard user account for everyday use
โ ๏ธ MacKeeper & Mac "Cleaner" Apps
Apps like MacKeeper, CleanMyMac (from sketchy sources), Advanced Mac Cleaner, and similar products are often the malware themselves. They're typically installed through deceptive ads, they report fake problems to scare you into buying, and removing them can be tricky.
To remove MacKeeper specifically:
- Open MacKeeper โ click MacKeeper in menu bar โ Uninstall MacKeeper
- If that doesn't work, use AppCleaner to force remove it
- Run MalwareBytes after to catch any remnants
๐ Nuclear Option: Reinstall macOS
If malware is deeply embedded and nothing else works, a clean macOS reinstall is the most reliable solution:
- Back up important files to an external drive or Time Machine
- Restart in Recovery Mode: hold โ+R (Intel) or hold Power button (Apple Silicon)
- Choose Disk Utility โ Erase your startup disk (Macintosh HD)
- Exit Disk Utility โ Reinstall macOS
- Restore your data from backup after
Don't restore from a Time Machine backup taken while infected โ restore files manually instead.
๐ง Need Professional Help?
Deep malware removal, data recovery after infection, or clean macOS installs โ we handle it all.
๐ Call: (856) 914-1074
๐ข PC Medics of NJ
๐ฆ Mail-In Repair Service
Not comfortable doing this yourself? Send your device to a professional repair shop.
๐ Recommended Products
The #1 repair kit โ 64 bits, pro tools, lifetime warranty
EZ Fit tray โ foolproof install, 9H tempered glass 2-pack
Charge iPhone, Watch & AirPods โ one compact cube