Skip to main content
FixMyTech

How to Check a Mac for Malware Without Buying Anything

By

Published

8 min read

Share

Short answer

macOS runs XProtect silently against known malware signatures, but it has no scan button and reports nothing, so checking means inspecting manually. Review System Settings → General → Login Items & Extensions, check browser extensions and homepage settings, and look at Profiles in System Settings — an unexpected configuration profile is the clearest sign of unwanted software on a Mac.

On this page

macOS protects itself with XProtect, which checks software against Apple’s signature list whenever an app launches. It updates in the background, it works, and it has no interface, no scan button and no report. There is nothing to open and nothing to run.

So “how do I check my Mac for malware” has an awkward answer: you check by looking in the places unwanted software has to live in order to do anything. It takes about ten minutes and requires no software at all.

What is actually on Macs

Setting expectations matters here, because the threat people imagine is not the threat that exists.

Type How common What it does
Adware and browser hijackers Common Changes search engine, injects adverts
Fake cleaner and optimiser apps Common Reports invented problems, charges to fix
Malicious browser extensions Common Reads pages, redirects searches
Stealers targeting credentials Occasional Harvests passwords and wallet data
Self-replicating viruses Very rare Largely a Windows-era phenomenon

The top three account for nearly everything a home user encounters, and all three arrive the same way: someone downloaded and approved them. Often through a search advert for a legitimate app, or a prompt claiming a plugin was needed.

The ten-minute manual check

Login items and background items

System Settings → General → Login Items & Extensions. This is the single most useful screen, because software that wants to persist has to start somehow.

Two lists matter. Login items are apps that open when you log in. Background items are components apps install to run continuously, and this list routinely surprises people — it names the developer behind each one.

Turn off anything you do not recognise. Disabling a background item does not uninstall the app, so this is a safe diagnostic step rather than a commitment.

Configuration profiles

System Settings → General and look for a Profiles entry. On a personal Mac with no work management, this section often does not appear at all, which is the correct state.

If it exists and lists a profile you did not install, treat it seriously. A profile can control your browser’s search engine, force a homepage, install certificates and block you from changing settings back. It is the clearest single indicator of adware on macOS, and removing the profile is usually what finally makes a hijacked browser stay fixed.

On a work Mac, profiles from your employer are expected and should be left alone.

Browser extensions and settings

Each browser separately, because they do not share this.

  • Safari → Settings → Extensions. Remove anything unfamiliar.
  • Chrome: open chrome://extensions and do the same. Check the search engine and startup page settings too, since hijackers change both.
  • Check each browser’s homepage and default search engine, and set them back.

An extension with permission to read and change data on all sites can do essentially anything a page can. Chrome running slowly with few tabs open is frequently an extension problem rather than a browser one, and the diagnosis overlaps.

Activity Monitor

Applications → Utilities → Activity Monitor, with View set to All Processes. Sort by CPU and look for anything running steadily that you cannot account for.

This is less diagnostic than it sounds, because macOS has many legitimately odd-looking process names and modern adware is deliberately quiet. Search an unfamiliar name before acting on it. It is useful mainly for the obvious cases — a cryptominer, or a process named after an app you removed months ago.

If the Mac is hot or slow and you are here because of that, the cause is far more often something mundane, and finding what is really running on a hot Mac covers reading that screen properly.

Applications and launch folders

Open the Applications folder and sort by date added. Anything that appeared around the time the trouble started is worth a search.

Persistence components also live in ~/Library/LaunchAgents and /Library/LaunchAgents, reachable through Finder’s Go → Go to Folder. These folders hold small configuration files that tell macOS to run something automatically. Legitimate software uses them too, so look up a filename before deleting it — but an entry referencing an app you have already removed is safe to delete.

What the built-in tools do silently

Three mechanisms, none of which you interact with.

  • XProtect checks launching apps against Apple’s known-malware signatures and blocks matches. Signature updates arrive in the background, separately from macOS updates.
  • The Malware Removal Tool runs periodically and removes known infections it finds. It is entirely silent.
  • Gatekeeper checks signatures and notarisation before first launch, which is the warning covered in what the unidentified developer message actually means.

Being honest about the limits: XProtect detects what Apple has added signatures for. New, modified or narrowly targeted software passes it. And none of these touch software you downloaded and approved yourself, which is how most adware arrives. The built-in protection is a floor, not a guarantee.

If you want to scan anyway

A reputable on-demand scanner is a reasonable addition. The useful criteria: it should run when you ask it to rather than installing a permanent background agent, it should be from a security company you can find a real history for, and a free version should exist.

Be sceptical of Mac security products advertised to you. Several of the most heavily promoted Mac cleaner and antivirus products use the same tactics as the software they claim to remove — invented problem counts, countdown pressure, subscriptions that resist cancellation. If you did not go looking for it, do not install it.

Realistic expectations

The manual check finds the common cases reliably, because adware has to be visible in at least one of those lists to function. Removing a configuration profile and a browser extension resolves the large majority of hijacked-search and pop-up complaints.

The honest limit is the other end. If you suspect something targeted — a Mac that was accessed by someone else, or credentials you believe were taken — no checklist settles it with confidence. The reliable response is to back up your documents, erase the Mac and reinstall macOS, then change your passwords from a device you trust. That is a day of work, and it is the only approach that does not depend on you having spotted everything.

Frequently asked questions

Do Macs get viruses?
Classic self-replicating viruses are rare on macOS, but adware, browser hijackers and fake optimiser apps are common and are what most people actually encounter. They typically arrive through downloads the user approved rather than through any exploit.
What is XProtect and does it run automatically?
XProtect is Apple's built-in malware detection, which checks apps against known signatures when they launch and quarantines matches. It updates in the background separately from macOS releases and has no interface, so you never see it working unless it blocks something.
Is the built-in protection enough on its own?
For most people it covers the known threats, but it only detects signatures Apple has added, so new or targeted software can pass. It also does nothing about adware you installed and approved yourself, which is the more common problem.
Do I need antivirus software on a Mac?
Most home users do not, and several widely advertised Mac security products are closer to the problem than the solution. A reputable on-demand scanner run occasionally is a reasonable middle ground, and free versions exist that do not install background agents.
How do I know if a configuration profile is legitimate?
On a personal Mac there should usually be no profiles at all, unless you installed one for a VPN or a beta programme. On a work Mac, profiles installed by your employer are expected. Anything you do not recognise on a personal machine is worth removing.

All Mac guides