How to Check a Mac for Malware Without Buying Anything
Short answer
macOS runs XProtect silently against known malware signatures, but it has no scan button and reports nothing, so checking means inspecting manually. Review System Settings → General → Login Items & Extensions, check browser extensions and homepage settings, and look at Profiles in System Settings — an unexpected configuration profile is the clearest sign of unwanted software on a Mac.
On this page
macOS protects itself with XProtect, which checks software against Apple’s signature list whenever an app launches. It updates in the background, it works, and it has no interface, no scan button and no report. There is nothing to open and nothing to run.
So “how do I check my Mac for malware” has an awkward answer: you check by looking in the places unwanted software has to live in order to do anything. It takes about ten minutes and requires no software at all.
What is actually on Macs
Setting expectations matters here, because the threat people imagine is not the threat that exists.
| Type | How common | What it does |
|---|---|---|
| Adware and browser hijackers | Common | Changes search engine, injects adverts |
| Fake cleaner and optimiser apps | Common | Reports invented problems, charges to fix |
| Malicious browser extensions | Common | Reads pages, redirects searches |
| Stealers targeting credentials | Occasional | Harvests passwords and wallet data |
| Self-replicating viruses | Very rare | Largely a Windows-era phenomenon |
The top three account for nearly everything a home user encounters, and all three arrive the same way: someone downloaded and approved them. Often through a search advert for a legitimate app, or a prompt claiming a plugin was needed.
The ten-minute manual check
Login items and background items
System Settings → General → Login Items & Extensions. This is the single most useful screen, because software that wants to persist has to start somehow.
Two lists matter. Login items are apps that open when you log in. Background items are components apps install to run continuously, and this list routinely surprises people — it names the developer behind each one.
Turn off anything you do not recognise. Disabling a background item does not uninstall the app, so this is a safe diagnostic step rather than a commitment.
Configuration profiles
System Settings → General and look for a Profiles entry. On a personal Mac with no work management, this section often does not appear at all, which is the correct state.
If it exists and lists a profile you did not install, treat it seriously. A profile can control your browser’s search engine, force a homepage, install certificates and block you from changing settings back. It is the clearest single indicator of adware on macOS, and removing the profile is usually what finally makes a hijacked browser stay fixed.
On a work Mac, profiles from your employer are expected and should be left alone.
Browser extensions and settings
Each browser separately, because they do not share this.
- Safari → Settings → Extensions. Remove anything unfamiliar.
- Chrome: open
chrome://extensionsand do the same. Check the search engine and startup page settings too, since hijackers change both. - Check each browser’s homepage and default search engine, and set them back.
An extension with permission to read and change data on all sites can do essentially anything a page can. Chrome running slowly with few tabs open is frequently an extension problem rather than a browser one, and the diagnosis overlaps.
Activity Monitor
Applications → Utilities → Activity Monitor, with View set to All Processes. Sort by CPU and look for anything running steadily that you cannot account for.
This is less diagnostic than it sounds, because macOS has many legitimately odd-looking process names and modern adware is deliberately quiet. Search an unfamiliar name before acting on it. It is useful mainly for the obvious cases — a cryptominer, or a process named after an app you removed months ago.
If the Mac is hot or slow and you are here because of that, the cause is far more often something mundane, and finding what is really running on a hot Mac covers reading that screen properly.
Applications and launch folders
Open the Applications folder and sort by date added. Anything that appeared around the time the trouble started is worth a search.
Persistence components also live in ~/Library/LaunchAgents and
/Library/LaunchAgents, reachable through Finder’s Go → Go to Folder. These
folders hold small configuration files that tell macOS to run something
automatically. Legitimate software uses them too, so look up a filename before
deleting it — but an entry referencing an app you have already removed is safe
to delete.
What the built-in tools do silently
Three mechanisms, none of which you interact with.
- XProtect checks launching apps against Apple’s known-malware signatures and blocks matches. Signature updates arrive in the background, separately from macOS updates.
- The Malware Removal Tool runs periodically and removes known infections it finds. It is entirely silent.
- Gatekeeper checks signatures and notarisation before first launch, which is the warning covered in what the unidentified developer message actually means.
Being honest about the limits: XProtect detects what Apple has added signatures for. New, modified or narrowly targeted software passes it. And none of these touch software you downloaded and approved yourself, which is how most adware arrives. The built-in protection is a floor, not a guarantee.
If you want to scan anyway
A reputable on-demand scanner is a reasonable addition. The useful criteria: it should run when you ask it to rather than installing a permanent background agent, it should be from a security company you can find a real history for, and a free version should exist.
Be sceptical of Mac security products advertised to you. Several of the most heavily promoted Mac cleaner and antivirus products use the same tactics as the software they claim to remove — invented problem counts, countdown pressure, subscriptions that resist cancellation. If you did not go looking for it, do not install it.
Realistic expectations
The manual check finds the common cases reliably, because adware has to be visible in at least one of those lists to function. Removing a configuration profile and a browser extension resolves the large majority of hijacked-search and pop-up complaints.
The honest limit is the other end. If you suspect something targeted — a Mac that was accessed by someone else, or credentials you believe were taken — no checklist settles it with confidence. The reliable response is to back up your documents, erase the Mac and reinstall macOS, then change your passwords from a device you trust. That is a day of work, and it is the only approach that does not depend on you having spotted everything.