How can you remove malware or ransomware from a MacPro laptop?

My daughter has a refurbished 13" MacPro laptop computer. She recently told me that she is unable to use her computer and to get on the Internet due to possible ransomware/malware. She encounters issues and problems using her computer unless she pays a fee to remove the ransomware/malware. How can she safely remove the ransomware/malware so that we can install a software program like Avast to prevent this problem and issue from happening again. I would appreciate any suggestions, feedback, sharing experiences and advice. Thank you in advance. Take care. Happy holidays. Stay safe and healthy.

Posted on Dec 21, 2020 7:22 AM

Reply
Question marked as Top-ranking reply

Posted on Dec 21, 2020 7:32 AM

The only way to get ransomware on your Mac - software that encrypts your data and then demands a fee to send you a decryption code - can only get there by installing it yourself. In other words, by engaging in high risk online usage such as installing illegally cracked commercial software. DO NOT pay for any such code. It only:


  1. Encourages criminals to keep doing this.
  2. The code often doesn't work.
  3. They never send the code (because they never had it to begin with).
  4. They demand more money before they'll send it.


AV software will not help. Not even a little. There are no self-installing/spreading Mac viruses. None. There are plenty of Trojans, such as the possible ransomware she installed. No AV software will make the slightest attempt at stopping you from installing a Trojan since it can't know what you're installing/running until after the fact. All AV software is useless.


If you truly have ransomware on the Mac, boot into Internet Recovery Mode (restart and hold down the Command+Option+Shift keys). Erase the drive. Reinstall the OS from scratch and restore your last Time Machine backup made before the malware was installed. If you can't be sure the TM backup isn't infected, don't restore it. Treat the Mac as a brand new device out of the box (which is how it will be after installing the OS to as erased drive) and reinstall only legally obtained third party software.

Similar questions

1 reply
Question marked as Top-ranking reply

Dec 21, 2020 7:32 AM in response to dwight161

The only way to get ransomware on your Mac - software that encrypts your data and then demands a fee to send you a decryption code - can only get there by installing it yourself. In other words, by engaging in high risk online usage such as installing illegally cracked commercial software. DO NOT pay for any such code. It only:


  1. Encourages criminals to keep doing this.
  2. The code often doesn't work.
  3. They never send the code (because they never had it to begin with).
  4. They demand more money before they'll send it.


AV software will not help. Not even a little. There are no self-installing/spreading Mac viruses. None. There are plenty of Trojans, such as the possible ransomware she installed. No AV software will make the slightest attempt at stopping you from installing a Trojan since it can't know what you're installing/running until after the fact. All AV software is useless.


If you truly have ransomware on the Mac, boot into Internet Recovery Mode (restart and hold down the Command+Option+Shift keys). Erase the drive. Reinstall the OS from scratch and restore your last Time Machine backup made before the malware was installed. If you can't be sure the TM backup isn't infected, don't restore it. Treat the Mac as a brand new device out of the box (which is how it will be after installing the OS to as erased drive) and reinstall only legally obtained third party software.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How can you remove malware or ransomware from a MacPro laptop?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.