How to Check Your Mac for Malware
Short answer
Check System Settings → General → Login Items & Extensions for startup entries and background items you do not recognise, then your browser's extensions. Those two places hold the overwhelming majority of real Mac infections, which are adware rather than viruses. Malwarebytes for Mac, run once on demand, catches most of what remains.
On this page
The useful question on a Mac is rarely “do I have a virus”. Self-replicating viruses are not the realistic threat on macOS. The things that do reach Macs in volume are adware, browser hijackers and unwanted “cleaner” applications that arrived bundled with something else and now want money to fix problems they invented.
That matters because it changes where you look. Scanning the whole drive is slow and usually finds nothing. The things that are actually there live in four specific places, and you can check all of them by hand in about ten minutes.
Decide whether anything is wrong first
Many people arrive here because the Mac feels slow, which is weak evidence. Storage pressure, a browser with forty tabs, and a login item installed three years ago all produce the same feeling.
| Symptom | Likely malware? | More likely explanation |
|---|---|---|
| Browser homepage or search changed | Yes | Hijacker extension |
| Ads on sites that never had them | Yes | Adware |
| Pop-up warnings about infection | No | A web page advert |
| Unfamiliar app in the menu bar | Possibly | Bundled installer |
| Mac slow, fans loud | Rarely | Storage, browser, indexing |
| Random restarts | Rarely | Hardware or a failing update |
The top two rows are the genuine signals. If your search engine changed on its own, something is installed that should not be, and removing a browser hijacker covers that specific cleanup in detail.
If the only symptom is slowness, start with what is filling up the system data on your Mac instead. That resolves the complaint far more often than any scanner.
Check the four places that matter
Work through these in order. They are ranked by how often they hold the answer.
Login items and background items
System Settings → General → Login Items & Extensions.
Two lists here. Open at Login holds applications that start with you and is usually short and recognisable. Allow in the Background is the important one, and on most Macs it is longer than people expect.
Entries are listed by their developer name, which is sometimes the parent company rather than the product, so a name you do not recognise is not automatic grounds for alarm. What should concern you is an entry with a generic name, no identifiable developer, or one that appeared around the time the trouble started.
Switch off anything you cannot account for. Turning a background item off does not delete the application, so this is reversible and safe to experiment with.
Browser extensions
This is where hijackers and adware live, in every browser.
- Safari: Safari → Settings → Extensions
- Chrome: the ⋮ menu → Extensions → Manage extensions
- Firefox: the ☰ menu → Add-ons and themes
Remove anything you did not deliberately install. Pay particular attention to extensions with permission to read and change data on all websites, and to anything describing itself as a search enhancement, a coupon finder, a download helper or a video downloader. Those four categories are where most of this comes from.
While you are in the browser, check that the homepage and default search engine are what you set them to.
Profiles
System Settings → Privacy & Security → Profiles. If that entry does not appear, there are none, which is normal and good.
A configuration profile can enforce browser settings, proxies and DNS servers at system level, which means it survives every browser-level cleanup you attempt. On a personal Mac with no employer or school management, any profile present is suspicious and should be removed.
The Applications folder and the launch folders
Open Applications and sort by Date Added in list view. Anything that arrived at a time you cannot explain is worth examining, particularly “optimisers”, “cleaners”, “VPNs” you do not remember buying, and media players you did not choose.
For the more technical check, these folders hold items set to run automatically:
~/Library/LaunchAgents
/Library/LaunchAgents
/Library/LaunchDaemons
Reach them with Finder → Go → Go to Folder and paste the path. Legitimate
software appears here too, and the filenames usually identify the vendor clearly
(com.google.keystone.agent.plist, for example). Do not delete anything from
these folders unless you can identify what it belongs to — removing the wrong
file can stop a legitimate application from working, and the repair is
reinstalling that application.
Run one on-demand scan
If the manual pass found nothing and something still feels wrong, scan once with a reputable tool.
Malwarebytes for Mac is the practical choice. The free version scans on demand without installing permanent real-time protection, which is the right trade for most people, and it is specifically good at the adware and potentially-unwanted-program categories that affect Macs. Download it from the vendor’s own site and nowhere else.
Do not install three scanners. They interfere with each other, and a second opinion from a product you found through a pop-up is not a second opinion. Be particularly wary of anything called MacKeeper, Mac Cleaner, Advanced Mac Cleaner or similar — those are frequently the problem, not the solution.
What macOS is already doing
Worth knowing before you buy anything, because the baseline is better than the advertising implies.
Gatekeeper refuses to run applications that are not signed by an identified developer and notarised by Apple, unless you override it manually. Overriding it is the step that most Mac malware needs a user to perform.
XProtect is a signature scanner built into macOS. It runs silently when applications launch and updates in the background, separately from system updates.
The Malware Removal Tool removes known malware families and runs during updates without telling you.
None of these have a user interface, which is why people assume macOS has no protection. It does. It is also not comprehensive, which is why the manual checks above are still worth doing.
What does not help
- “Mac cleaner” applications promising to find hundreds of problems. The problems are cache files and language packs. The category overlaps heavily with the thing you are trying to remove.
- Resetting the SMC or NVRAM for a suspected infection. Those address hardware behaviour and have nothing to do with software that is installed.
- Reinstalling macOS as a first step. A full day’s work for a problem that is usually one extension and one login item.
- Paying for a subscription scanner after a free scan found nothing. Nothing found means nothing found.
Realistic expectations
Most Macs checked this way turn out to be clean, and the slowness that prompted the check turns out to be storage or a browser. That is the common outcome and it is a legitimate result, not a failed search.
Where something is found, it is nearly always one adware extension and one matching background item, removed in five minutes, with the browser settings restored afterwards. Genuine persistent Mac malware that survives this process is rare enough that if you reach that point, the sensible next step is a fresh install of macOS and restoring documents only — not applications, and not a full system backup, which would bring the problem straight back.