How to Remove Malware from Mac and Get Rid of Adware in 2026
By NorwegianSpark Editorial · Published September 6, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Almost nothing that infects a Mac is a virus in the sense people mean. The realistic Mac threat is adware, browser hijackers, fake "cleaner" utilities that manufacture problems in order to sell the fix, and configuration profiles that quietly redirect your search results. They are annoying, they are persistent, and they are removable — usually without reinstalling anything.
This is the order to work in. It starts with the steps that fix the common cases and ends with the ones you should only reach for if the earlier steps fail.
First, work out what you are actually seeing
The symptoms tell you which branch you are on.
- New search engine, new home page, results that go somewhere unexpected — browser hijack or a configuration profile. Almost always fixable in ten minutes.
- Pop-ups outside the browser, or adverts appearing on sites that do not carry them — adware with a system component.
- An app you do not remember installing, asking for money to fix problems — a scareware "cleaner". Nothing it reports is real.
- The fan running constantly, everything slow, an unfamiliar process at the top of Activity Monitor — could be adware, could be a crypto miner, could be Spotlight indexing after an update. Check before assuming.
- A full-screen warning saying you are infected and to call a number — that is a web page, not your Mac. Close the tab. Nobody is being alerted about you.
That last one accounts for a large share of the panic in this category, and the correct response is to force-quit the browser and reopen it without restoring tabs.
Step one: disconnect, then look
If you believe something is actively running, take the machine off the network first. It costs nothing and stops any ongoing upload of what it has collected.
Then open Activity Monitor from Applications, then Utilities. Sort by CPU and look at the top of the list. You are looking for a process you do not recognise consuming resources for no reason. Do not start quitting things at random — many legitimate macOS processes have unhelpful names. Search the exact process name before acting on it.
Step two: start in safe mode
Safe mode is the single most useful tool here, because most adware persists by loading something at startup. Apple's own description, quoted from its support documentation: "Starting up your Mac in safe mode can help you identify whether issues you're experiencing are caused by software that loads as your Mac starts up."
Apple's steps differ by processor, which is where most guides get vague.
On an Apple silicon Mac: shut down from the Apple menu and wait for the shutdown to complete. Press and hold the power button until "Loading startup options" appears. Select a volume. Hold the Shift key, then click Continue in Safe Mode. The Mac restarts, and "Safe Boot" should appear in the menu bar.
On an Intel-based Mac: turn on or restart the Mac, then immediately hold Shift until the login window appears. Log in. You might be asked to log in a second time. "Safe Boot" should appear in the menu bar on either login screen.
If the symptoms vanish in safe mode, you have confirmed the problem is something loading at startup, which is exactly the class the next steps remove.
Step three: the four places adware hides
Work through all four even if the first one seems to solve it, because these things install several components.
- Login items. System Settings, then General, then Login Items. Remove anything you do not recognise, both in the startup list and in the background-items list beneath it.
- Configuration profiles. This is the one most people never check and it is where browser hijacks live. If a Profiles section appears in System Settings and your Mac is not managed by an employer or school, a profile there is a red flag. Select it, remove it, confirm.
- Browser extensions. In each browser you use, open the extensions list and remove anything you did not deliberately install. Then reset the home page and default search engine, because the extension usually leaves those changed behind it.
- Applications. In the Applications folder, drag anything unfamiliar to the Trash and empty it immediately. Fake cleaners and "Mac optimisers" live here.
Restart normally after all four and check whether the symptoms are gone.
Step four: scan with something reputable
If the manual pass did not clear it, or you would rather not do the manual pass at all, a scanner designed for macOS will find components in places you would not think to look. Choose a tool built for the platform rather than a Windows suite ported across — Intego is Mac-specific, and Bitdefender and Malwarebytes both maintain real Mac products.
Be careful about what you download to do this. A meaningful share of Mac "infections" arrive as a cleaner utility the user installed on purpose after a scary pop-up. Get the tool from the vendor's own site or the App Store, never from the advert that told you about the problem. Our comparison is best antivirus for Mac, and the prior question is answered in do Macs need antivirus.
Step five: only if the above failed
Reinstalling macOS is the last resort, not the first move, and it is worth being precise about when it is warranted: when the symptoms survive safe mode, a full manual clean and a reputable scan, or when you have reason to think something with system-level access got in.
Before that, back up your files — and be aware that restoring a backup taken after the infection can reintroduce it. Back up documents and photos, not applications and system settings. Our general guide is how to back up your data.
Afterwards: the step everyone skips
If anything malicious ran with your privileges, assume it read whatever your browser had saved. That means passwords and session cookies.
From a different, clean device, change the passwords for your email first, then banking, then everything else that shares a password with either. Changing them on the machine you have just cleaned is safer than it was, but a different device removes the doubt entirely. Then turn on two-factor authentication where it is not already on — two-factor authentication guide — and check whether anything of yours has surfaced, using how to check if your data is on the dark web.
Keeping it out next time
Apple's own guidance is source-based rather than scanner-based, and it is quoted here from Apple's Mac User Guide. On the Privacy and Security setting that governs where apps may come from, Apple describes the App Store option as "the most secure setting to protect your system from malware", on the basis that "all the developers of apps in the Mac App Store are known by Apple and each app is reviewed before it's accepted". The looser App Store and Known Developers option allows apps from registered developers who "can optionally upload their apps to Apple for a security check". Apple also warns that "scripts, web archives and Java archives have the potential to harm your system", and to "exercise caution when opening any such downloaded file".
Practically, that translates into a short list:
- Install from the App Store or the developer's own site, and nowhere else.
- Keep macOS updated. Apple ships malware definition updates outside the visible OS release cycle, and they only arrive if updates are on.
- Never install anything a pop-up told you that you needed. That is the delivery mechanism for most of this category.
- Treat "your Mac is infected, call this number" as an advertisement, because that is what it is.
- Be sceptical of discounted software keys and cracked applications, which are a persistent malware vector — see cheap software keys.
The honest counter-argument
Macs are not immune, and the "Macs do not get viruses" line has been wrong for years. But the threat profile genuinely is different, and pretending otherwise sells software rather than helping.
The realistic Mac risk is adware and social engineering, not silent system compromise. Gatekeeper, notarisation and the platform's background malware definitions handle a meaningful share of what would otherwise land. Which means the most valuable thing you can do for a Mac is not necessarily to buy a scanner: it is to keep updates on, install from known sources, and be sceptical of anything that arrives with urgency attached.
A scanner earns its place if you share the machine, if you download widely, or if you would rather have something checking than rely on your own judgement every time. Those are good reasons. "Macs are riddled with viruses" is not one, and neither is the pop-up that said so.
The general habits are in Mac security essentials, and the Windows version of this guide is how to remove malware step by step.
Work in order: identify, disconnect, safe mode, the four hiding places, then scan. Reinstall last, and change your passwords from a clean device afterwards. This is general guidance, not security advice for a specific threat model.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Sources
Factual claims above were checked against these primary sources. Verify directly on the source for anything time-sensitive before relying on it.
Continue reading
antivirus
Do You Actually Need Paid Antivirus?
Built-in protection has improved enormously. An honest look at when a paid suite is worth it and when it isn’t.
vpn
Best VPN for Privacy in 2026
What actually makes a VPN private — no-logs policy, jurisdiction, audits — and how to cut through the marketing.
guides
Best Malware Scanners in 2026: What the Labs Actually Found
On-demand scanners vs always-on protection, with the real AV-TEST and AV-Comparatives 2026 figures — detection, false positives and system impact on low-end hardware.
