Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Malware Removal

I recently noticed my Safari browser is using Yahoo search with Google as my default. Yes I have the bug bad on a one year old Mac Air with macOS Big Sur v11.2.3. When I search, the malware redirects me quickly to something it wants me to see but much of the site inaccessible. I've done all the reasonable attempts to remove or quarantine the malware including Malwarebytes, Avast etc. Those two antivirus programs don't even see the virus. It appears to be a common problem. What should be my next step? Would uninstalling/reinstalling Safari help? Should I reinstall MacOS? Can't Apple come up with a reasonable fix for this?

Posted on Apr 17, 2021 8:11 AM

Reply
Question marked as Best reply

Posted on Apr 17, 2021 10:12 AM

Anesthesia12 Said:

"Malware Removal. [...]Yes I have the bug bad on a one year old Mac Air with macOS Big Sur v11.2.3. When I search, the malware redirects me quickly to something it wants me to see but much of the site inaccessible. Those two antivirus programs don't even see the virus. It appears to be a common problem. What should be my next step? Would uninstalling/reinstalling Safari help? Should I reinstall MacOS? Can't Apple come up with a reasonable fix for this?"

-------


Please Clarify:

What makes you suspect you have malware? The issue going on with Yahoo and Google is typical, and is being worked on. It's posted a lot on these forums, and has yet to be fixed.


Boot into Safe Mode:

[Hold Down: shift key upon boot] and then perform the following:


A. Remove Login items:

See if what Login Items you have. If any, remove them as such and then restart the Mac, seeing if it/they no longer load(s) at login.  Go Here: Change Users & Groups Login Items Preferences on Mac - Apple Support.


B. Uninstall Security Software:

Uninstall it Avast. Use an Uninstaller for to do so, getting the Uninstaller directly from my Developer’s site, as getting it else where may result in Malware or Spyware being installed. If you are uncertain which to download, then as the Developer: Avast.


C. Then, Scan your Mac for Malware: 

Use MalwareBytes for Mac --- This is software that searches for malware/adware. So, scan with it and then remove what is found. Once removed, uninstall MalwareBytes for Mac. Then restart the Mac. Malwarebytes is made by longtime users of these forums, making it the only Security Software reliable for Macs.

Downloads:

  1. Malwarebytes Anti-Malware for Mac
  2. Malwarebytes Uninstaller


Similar questions

5 replies
Question marked as Best reply

Apr 17, 2021 10:12 AM in response to Anesthesia12

Anesthesia12 Said:

"Malware Removal. [...]Yes I have the bug bad on a one year old Mac Air with macOS Big Sur v11.2.3. When I search, the malware redirects me quickly to something it wants me to see but much of the site inaccessible. Those two antivirus programs don't even see the virus. It appears to be a common problem. What should be my next step? Would uninstalling/reinstalling Safari help? Should I reinstall MacOS? Can't Apple come up with a reasonable fix for this?"

-------


Please Clarify:

What makes you suspect you have malware? The issue going on with Yahoo and Google is typical, and is being worked on. It's posted a lot on these forums, and has yet to be fixed.


Boot into Safe Mode:

[Hold Down: shift key upon boot] and then perform the following:


A. Remove Login items:

See if what Login Items you have. If any, remove them as such and then restart the Mac, seeing if it/they no longer load(s) at login.  Go Here: Change Users & Groups Login Items Preferences on Mac - Apple Support.


B. Uninstall Security Software:

Uninstall it Avast. Use an Uninstaller for to do so, getting the Uninstaller directly from my Developer’s site, as getting it else where may result in Malware or Spyware being installed. If you are uncertain which to download, then as the Developer: Avast.


C. Then, Scan your Mac for Malware: 

Use MalwareBytes for Mac --- This is software that searches for malware/adware. So, scan with it and then remove what is found. Once removed, uninstall MalwareBytes for Mac. Then restart the Mac. Malwarebytes is made by longtime users of these forums, making it the only Security Software reliable for Macs.

Downloads:

  1. Malwarebytes Anti-Malware for Mac
  2. Malwarebytes Uninstaller


Apr 17, 2021 9:38 AM in response to Anesthesia12

No, you do not have a virus. Macs can not get viruses. Ever. They have their own built in antivirus protection. Malwarebytes is very good at removing any malware you might have. If you wish to change your search engine, you can do so in Safari's preferences. As for Avast, you need to remove it immediately. It will seriously slow down your computer and can cause other problems. Use their uninstaller to completely remove all of it. Finally, Safari can not be individually removed or installed. It is installed or upgraded as part of your operating system.

Apr 17, 2021 10:03 AM in response to Anesthesia12

Macs can get malware, and since you’ve already tried the obvious stuff first, please post the EtreCheck data. Download and run that, and then open a new reply here and then press the button that looks like a printed page to get a text input box big enough to paste the hardware and software configuration report here.


If there is an add-on VPN client here, remove it, and try your tests again. I prefer to consider at least some of the add-on VPN clients a form of malware.


Also have a very careful look at your router and router settings, as malware can access and adjust those. That’s usually due to an old and unmaintained router, or a router with down-revision firmware. Check and update any firmware.

Apr 17, 2021 2:27 PM in response to TheLittles

You guys are great. I uninstalled Avast as per the first post Ronasara and got the message "uninstalled successfully". I used the Avast uninstaller because I didn't know at that time that that could be a problem too. I also scanned with Malwarebytes which found nothing. I'll work on this tonight re: MrHoffman and EtreCheck data and post reports if I can figure it out. No VPN client here. I will say I recently installed a new router from ATT. (Arris BGW 210). We were having buffering issues with an old router so ATT sent a new router. I operate a digital ham radio repeater here for local use, Columbia, SC area. Yaesu Wires-X C4FM node on a designated PC which I use for nothing else. It's basically a radio operators connection to the internet for VOIP. Local hams can connect my node to anywhere in the world and use other transmitting towers. It requires forwarding 5 ports on the router. I had problems keeping ports open. It would allow traffic for several days then required some router tweaking and rebooting. Hopefully I didn't cause my own problems. Thanks again, I'll work a bit on the next response....

Apr 17, 2021 7:12 PM in response to Anesthesia12

Anesthesia12 Said:

"Malware Removal. You guys are great. I uninstalled Avast as per the first post Ronasara and got the message "uninstalled successfully". I used the Avast uninstaller because I didn't know at that time that that could be a problem too. I also scanned with Malwarebytes which found nothing [...]No VPN client here. I will say I recently installed a new router from ATT. (Arris BGW 210). We were having buffering issues with an old router so ATT sent a new router. [...]"

-------


Restart:

On my part, thank for that complement. Make sure you restart your Mac, once all is uninstalled. That way all is up and running as it should (meaning without Security Software installed).


Router Upgrading:

As for all of this buffering getting in the way - buffering can be caused by lots going on at once(multitasking), which seems to be the case with the router. The modem takes in the signal, whereas the router broadcasts it. So, be certain that you have a router made for such use. A good one to consider is one for gaming, and Netgear has the Nighthawk series made for such use, which can be found at you local retailer.

Malware Removal

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.