The ultimate guide to removing adware from macOS
Adware on a Mac can appear as constant pop-ups, unfamiliar search results, new browser tabs, or advertisements that follow you across unrelated websites. Some unwanted programs are merely disruptive, while others track browsing activity, alter browser settings, or expose users to malicious downloads.
macOS includes useful security controls, but they do not prevent every potentially unwanted application from being installed. Adware may arrive through bundled freeware, fake updates, deceptive advertisements, pirated software, or a browser extension that requests excessive permissions.
A careful cleanup involves more than deleting one unfamiliar application. You should examine running processes, login items, browser extensions, configuration profiles, and notification permissions before checking whether the unwanted behavior has stopped.
What adware looks like on macOS
Common symptoms include a sudden change to the default search engine, redirects to unfamiliar pages, fake virus warnings, and advertisements appearing on websites that previously looked normal. Safari, Chrome, and Firefox may also open tabs automatically or display extensions that you do not remember installing.
Performance changes can provide another clue. A Mac affected by adware may run slowly, use excessive processor resources, drain its battery quickly, or show repeated network activity when no demanding applications are open. These signs can have other causes, so they should be assessed alongside recently installed software and browser changes.
Before removing unwanted software
Save open work and create a current backup of important documents. A backup gives you a recovery option if you remove the wrong application or discover that the issue involves a more serious threat. Do not download random “Mac cleaners” advertised through pop-ups, since many imitate security tools while installing additional unwanted software.
Disconnecting from the internet is useful when suspicious activity is persistent, although it is not required for every cleanup. If the Mac is used for banking, work accounts, or sensitive files, change important passwords from a separate trusted device after the system has been checked.
Find and remove suspicious apps
Open Finder and review the Applications folder for unfamiliar programs, especially those installed shortly before the advertising began. Select a suspicious app, move it to the Trash, and empty the Trash only after checking that its name is not associated with a legitimate utility. If macOS refuses to remove it, restart the Mac and try again rather than forcing deletion of system components.
Next, open Activity Monitor from Applications > Utilities. Sort processes by CPU or memory use and investigate names that are unfamiliar or consistently consuming resources. Search the process name online using a trusted security source before taking action. Avoid terminating Apple processes or deleting files from protected system directories without reliable identification.
| Location to inspect |
Signs of adware |
Safe action |
| Applications |
Unknown recently installed software |
Uninstall the app after verifying its identity |
| Login Items |
Suspicious programs launching at startup |
Disable or remove the item |
| Browser extensions |
Unfamiliar toolbars or search helpers |
Uninstall the extension |
| Configuration profiles |
Profiles you did not add |
Remove only unrecognized profiles |
| Notifications |
Repeated alerts from strange sites |
Revoke website notification permission |
Check startup behavior in System Settings > General > Login Items. Disable unfamiliar background items and remove login items that clearly belong to unwanted software. If a suspicious app returns after removal, the adware may have installed a helper component or configuration profile that needs separate attention.
Clean browsers and configuration settings
Remove unfamiliar extensions from Safari, Chrome, or Firefox. In Safari, review Settings > Extensions and Website Settings. In Chrome, open Extensions and examine the default search engine, startup pages, and notification permissions. Firefox users should check Add-ons and Themes, Home, and Search settings.
Clear browsing data after removing the unwanted extension, then restart the browser. If redirects continue, reset the browser profile or use its built-in restore settings. Guidance about browser redirect problems can help distinguish a browser setting issue from a deeper infection.
Open System Settings and search for Profiles or Device Management, depending on the macOS version. A profile installed by an employer, school, or security administrator may be legitimate and should not be deleted. Remove only profiles that are clearly unfamiliar and connected with the adware symptoms.
Scan, recover, and verify
Run a scan with a reputable, current anti-malware application designed for macOS. Download it directly from the vendor’s official website, update its malware database, and allow the scan to finish. A security scan can identify launch agents, bundled applications, browser hijackers, and other components that are difficult to find manually.
If adware has altered files, browser data, or settings, restore affected items from a clean backup when appropriate. Do not restore suspicious applications or unknown system folders. Restart the Mac after cleanup and test each browser without reinstalling the removed extensions.
Verification should include checking the homepage, search engine, pop-up behavior, CPU usage, login items, and notification permissions. If symptoms return immediately, investigate recently installed software again and consider starting the Mac in Safe Mode to remove persistent components with fewer third-party processes active.
Prevent another adware infection
Keep macOS, browsers, and commonly used applications updated. Use the Mac App Store or official developer websites for downloads, and read installation screens carefully. Choose custom or advanced installation options when available so bundled browser extensions and promotional utilities can be declined.
Gatekeeper, XProtect, and browser warnings provide valuable protection when they are allowed to work. Avoid disabling security prompts to install software from an unknown source. For broader Windows-focused security information, the site’s Windows threat guides provide additional malware prevention context.
Practical habits that reduce risk
- Verify the publisher before installing free utilities, media tools, or system optimizers.
- Avoid clicking “urgent virus detected” messages shown inside ordinary web pages.
- Review browser extensions and login items every few weeks.
- Block notifications from websites that do not provide a clear reason to send them.
- Keep a separate, regularly updated backup of important files.
Use these steps whenever advertisements, redirects, or unexplained system changes appear. Early inspection limits the time adware has to modify browser settings or expose you to more dangerous downloads, while a reputable scan provides an additional check that manual cleanup missed nothing.