A MacBook that suddenly fills your browser with pop-ups, redirects searches or asks for passwords at odd moments needs attention. Knowing how to remove malware from MacBook devices quickly can protect your files, bank details and work accounts – but rushing to delete random files can create a bigger problem. Start by stopping the threat, then work through the checks below carefully.
Malware on a Mac is less common than many people assume, but it is very real. It often arrives through fake update messages, copied software, rogue browser extensions, phishing emails or apps downloaded from unofficial websites. The warning signs are not always dramatic. A slow Mac, unfamiliar login items, a hot battery, unexplained advertising or a changed homepage can all point to unwanted software.
First, contain the problem
If you think somebody may be accessing your MacBook remotely, or you see files being encrypted or renamed, disconnect from WiFi immediately. Do not enter any passwords, call numbers shown in pop-up warnings or install a “cleaner” suggested by an advert. Genuine Apple security messages do not ask you to telephone a stranger or pay to unlock your device.
For less urgent symptoms, take a moment to save open work and make a safe backup of important documents, photographs and business files. Use a trusted external drive or cloud service you already use. Avoid copying applications, installers or unknown folders to the backup, as these may carry the unwanted software with them.
If the MacBook belongs to your business, tell your IT provider or manager before signing into Microsoft 365, banking or customer systems. One compromised device can affect shared accounts, email contacts and network storage.
Check for the common signs of Mac malware
Malware does not always call itself malware. It may look like a browser add-on, a download manager, a video player or a system utility. Look for changes that you did not make, especially if they appeared soon after downloading a file or visiting a suspicious website.
Common signs include repeated browser redirects, adverts appearing on pages that normally have none, a default search engine changing without permission, new apps in the Applications folder, or a MacBook becoming unusually slow when no demanding software is open. You may also notice a menu bar icon you do not recognise, security alerts from an unfamiliar app, or unexpected requests for your administrator password.
One symptom alone is not proof of an infection. A full startup disk, an outdated macOS version or too many background applications can also slow a Mac. The key question is whether something changed without your approval.
How to remove malware from MacBook step by step
1. Update macOS and restart
Open System Settings, choose General, then Software Update. Install available macOS updates and security updates before going further, unless the Mac is actively being controlled or files are being encrypted. Apple updates often close security weaknesses and improve built-in threat protection.
Restart the MacBook once the update is complete. A restart can clear temporary processes, although it will not remove a persistent infection by itself.
2. Remove unfamiliar applications
Open Finder and select Applications. Review the list slowly. Delete only applications you are confident you do not need or did not install. Move them to Bin, then empty the Bin.
Be cautious with names that imitate trusted software or use vague terms such as “Search”, “Helper”, “Player” or “Mac Cleaner”. If you are unsure what an app does, do not guess. Removing a legitimate system component can cause other issues, while leaving a malicious app in place may allow it to reinstall browser settings after you clean them.
Also check your Downloads folder for suspicious installation files. Delete old .dmg and .pkg files that came from sources you no longer trust.
3. Review login items and background activity
Go to System Settings, General, then Login Items & Extensions. Check the list of apps set to open when you log in and remove anything unfamiliar. Review the section for background activity as well, as adware often uses a background process to return after a restart.
Next, open Activity Monitor from Applications > Utilities. Sort processes by CPU or Memory and look for software consuming an unusual amount of resources. If you find an app you recognise as unwanted, select it and use the stop button to quit it. Do not force-quit processes simply because their names look technical. Many genuine macOS services have unfamiliar names.
4. Clean your browser properly
Most apparent Mac malware is browser-based adware. Check every browser you use, not just Safari. Remove unknown extensions, review the homepage and default search engine, and delete website notifications you did not approve.
In Safari, open Settings and check Extensions, Search and Websites. In Chrome or Edge, open the Extensions area and remove anything you did not choose. Then clear browser history and website data. This may sign you out of websites, so make sure you know your important passwords first.
If pop-ups continue after removing extensions, reset the browser settings where available. Do not restore an old browser profile until you are certain the issue has gone, as a synchronised extension can bring the problem back.
5. Check device profiles and sharing settings
Some unwanted software installs a configuration profile that controls browser settings, certificates or network behaviour. In System Settings, look under General for Device Management or Profiles, depending on your macOS version. A work-managed MacBook may have a legitimate company profile, so confirm with your employer before removing it. On a personal Mac, a profile you do not recognise deserves investigation.
It is also sensible to review Sharing settings. Turn off Remote Login, Remote Management, Screen Sharing and Remote Apple Events unless you specifically use them. If a person claiming to be support staff asked you to enable these settings, treat that as a serious warning sign.
6. Run a reputable malware scan
Use a well-known, legitimate security tool downloaded directly from its official publisher, not from a pop-up advert or a sponsored search result. Run a full scan and follow its recommendations for quarantining or removing detected threats.
A scanner is useful, but it is not a replacement for checking login items, extensions and profiles. Some adware is better removed by correcting the settings it changed. Equally, a clean scan does not mean you should ignore evidence of unauthorised account access.
7. Change passwords from a clean device
If you typed passwords after the symptoms began, change them using another device you trust. Start with your Apple Account, primary email account, banking and work logins. Use unique passwords and switch on two-factor authentication wherever possible.
Check your email account for unusual forwarding rules, sent messages or recovery details. For business users, reset affected Microsoft 365 credentials and ask an IT professional to check sign-in activity. Changing the password on the infected MacBook before it is cleaned may expose the new password too.
When a reset is the safer option
A clean reinstall of macOS is often the most reliable route if the MacBook shows persistent pop-ups after cleaning, repeatedly reinstalls unknown software, has signs of remote access, or may contain a password-stealing threat. Back up personal files first, erase the Mac only after confirming the backup is safe, then reinstall macOS and restore documents selectively.
This takes more time than deleting an app, but it can be the right trade-off for a MacBook used for client data, banking, school work or business email. Never restore every old application automatically if you do not know where the infection started.
Avoid the same problem next time
Keep macOS and browsers updated, download software from the App Store or recognised publishers, and be sceptical of urgent pop-ups. Avoid pirated software and fake Adobe, Flash or video-player updates, as these remain common routes for adware and credential theft. A standard user account for day-to-day use can also limit the damage if something malicious is downloaded.
For families and small businesses, the best protection is a simple routine: regular backups, strong unique passwords, two-factor authentication and a clear rule that nobody grants remote access because of an unexpected phone call or browser warning.
If the MacBook will not start, the pop-ups keep returning, or you are worried that files or business accounts have been exposed, stop experimenting with it. A2z Computer Solutions can provide practical Mac malware removal and same-day support across London, helping you get back to a clean, secure device without unnecessary delay.