Skip to main content
FixMyTech

How to Check Your Mac for Malware

By

Published

8 min read

Share

Short answer

Check System Settings → General → Login Items & Extensions for startup entries and background items you do not recognise, then your browser's extensions. Those two places hold the overwhelming majority of real Mac infections, which are adware rather than viruses. Malwarebytes for Mac, run once on demand, catches most of what remains.

On this page

The useful question on a Mac is rarely “do I have a virus”. Self-replicating viruses are not the realistic threat on macOS. The things that do reach Macs in volume are adware, browser hijackers and unwanted “cleaner” applications that arrived bundled with something else and now want money to fix problems they invented.

That matters because it changes where you look. Scanning the whole drive is slow and usually finds nothing. The things that are actually there live in four specific places, and you can check all of them by hand in about ten minutes.

Decide whether anything is wrong first

Many people arrive here because the Mac feels slow, which is weak evidence. Storage pressure, a browser with forty tabs, and a login item installed three years ago all produce the same feeling.

Symptom Likely malware? More likely explanation
Browser homepage or search changed Yes Hijacker extension
Ads on sites that never had them Yes Adware
Pop-up warnings about infection No A web page advert
Unfamiliar app in the menu bar Possibly Bundled installer
Mac slow, fans loud Rarely Storage, browser, indexing
Random restarts Rarely Hardware or a failing update

The top two rows are the genuine signals. If your search engine changed on its own, something is installed that should not be, and removing a browser hijacker covers that specific cleanup in detail.

If the only symptom is slowness, start with what is filling up the system data on your Mac instead. That resolves the complaint far more often than any scanner.

Check the four places that matter

Work through these in order. They are ranked by how often they hold the answer.

Login items and background items

System Settings → General → Login Items & Extensions.

Two lists here. Open at Login holds applications that start with you and is usually short and recognisable. Allow in the Background is the important one, and on most Macs it is longer than people expect.

Entries are listed by their developer name, which is sometimes the parent company rather than the product, so a name you do not recognise is not automatic grounds for alarm. What should concern you is an entry with a generic name, no identifiable developer, or one that appeared around the time the trouble started.

Switch off anything you cannot account for. Turning a background item off does not delete the application, so this is reversible and safe to experiment with.

Browser extensions

This is where hijackers and adware live, in every browser.

  • Safari: Safari → Settings → Extensions
  • Chrome: the ⋮ menu → Extensions → Manage extensions
  • Firefox: the ☰ menu → Add-ons and themes

Remove anything you did not deliberately install. Pay particular attention to extensions with permission to read and change data on all websites, and to anything describing itself as a search enhancement, a coupon finder, a download helper or a video downloader. Those four categories are where most of this comes from.

While you are in the browser, check that the homepage and default search engine are what you set them to.

Profiles

System Settings → Privacy & Security → Profiles. If that entry does not appear, there are none, which is normal and good.

A configuration profile can enforce browser settings, proxies and DNS servers at system level, which means it survives every browser-level cleanup you attempt. On a personal Mac with no employer or school management, any profile present is suspicious and should be removed.

The Applications folder and the launch folders

Open Applications and sort by Date Added in list view. Anything that arrived at a time you cannot explain is worth examining, particularly “optimisers”, “cleaners”, “VPNs” you do not remember buying, and media players you did not choose.

For the more technical check, these folders hold items set to run automatically:

~/Library/LaunchAgents
/Library/LaunchAgents
/Library/LaunchDaemons

Reach them with Finder → Go → Go to Folder and paste the path. Legitimate software appears here too, and the filenames usually identify the vendor clearly (com.google.keystone.agent.plist, for example). Do not delete anything from these folders unless you can identify what it belongs to — removing the wrong file can stop a legitimate application from working, and the repair is reinstalling that application.

Run one on-demand scan

If the manual pass found nothing and something still feels wrong, scan once with a reputable tool.

Malwarebytes for Mac is the practical choice. The free version scans on demand without installing permanent real-time protection, which is the right trade for most people, and it is specifically good at the adware and potentially-unwanted-program categories that affect Macs. Download it from the vendor’s own site and nowhere else.

Do not install three scanners. They interfere with each other, and a second opinion from a product you found through a pop-up is not a second opinion. Be particularly wary of anything called MacKeeper, Mac Cleaner, Advanced Mac Cleaner or similar — those are frequently the problem, not the solution.

What macOS is already doing

Worth knowing before you buy anything, because the baseline is better than the advertising implies.

Gatekeeper refuses to run applications that are not signed by an identified developer and notarised by Apple, unless you override it manually. Overriding it is the step that most Mac malware needs a user to perform.

XProtect is a signature scanner built into macOS. It runs silently when applications launch and updates in the background, separately from system updates.

The Malware Removal Tool removes known malware families and runs during updates without telling you.

None of these have a user interface, which is why people assume macOS has no protection. It does. It is also not comprehensive, which is why the manual checks above are still worth doing.

What does not help

  • “Mac cleaner” applications promising to find hundreds of problems. The problems are cache files and language packs. The category overlaps heavily with the thing you are trying to remove.
  • Resetting the SMC or NVRAM for a suspected infection. Those address hardware behaviour and have nothing to do with software that is installed.
  • Reinstalling macOS as a first step. A full day’s work for a problem that is usually one extension and one login item.
  • Paying for a subscription scanner after a free scan found nothing. Nothing found means nothing found.

Realistic expectations

Most Macs checked this way turn out to be clean, and the slowness that prompted the check turns out to be storage or a browser. That is the common outcome and it is a legitimate result, not a failed search.

Where something is found, it is nearly always one adware extension and one matching background item, removed in five minutes, with the browser settings restored afterwards. Genuine persistent Mac malware that survives this process is rare enough that if you reach that point, the sensible next step is a fresh install of macOS and restoring documents only — not applications, and not a full system backup, which would bring the problem straight back.

Frequently asked questions

Does macOS have built-in malware protection?
Yes, three layers of it. Gatekeeper checks that apps are signed and notarised before they run, XProtect scans against known malware signatures, and the Malware Removal Tool removes some known families during updates. All run silently with no interface.
Is "Your Mac is infected" in Safari a real warning?
No. macOS never warns you about infection through a web page, a browser pop-up or a countdown timer. Those are advertisements designed to sell software or start a fake support call, and closing the tab is the entire fix.
Why does my Mac feel slow if there is no malware?
Usually storage pressure, a browser holding many heavy tabs, or a login item you forgot about. Slowness on its own is poor evidence of infection and good evidence that something ordinary needs attention.
Should I leave an antivirus running all the time on a Mac?
For most people, no. An on-demand scanner used when something seems wrong gives nearly all the benefit without a permanent process inspecting every file. The free version of Malwarebytes is built for exactly that pattern.
Can a Mac pass a virus to a Windows PC?
Yes, by forwarding an infected file or attachment, even though the file cannot run on macOS. It is one of the few genuine arguments for scanning a Mac in a household that shares files with Windows machines.

All Security guides