What should I do if Malware Blocked Pop-Up won't close on my iMac?

The pop up has a big Yellow Triangle with an explanation mark in the middle and says Malware Blocked. “ServiceRecords” was not opened because it contains malware. This action did not harm your Mac, then there’s a blue box which states Done. I press that and it just reopens saying “ReceiverHelper” and the same message.


i’ve checked notifications, extensions, suspect applications, my software is up to date. I downloaded some anti malware software which said my Mac was clean. Any ideas for next steps?


[Re-Titled by Moderator]

iMac 24″, macOS 15.2

Posted on Dec 16, 2024 9:58 AM

Reply
Question marked as Top-ranking reply

Posted on Dec 16, 2024 10:11 AM

It may be caused by the Citrix app if you installed it on your computer. If that is the case uninstall it using the provided uninstaller and use an updated version if you choose to install it again.


If that is not the case or are still having problems with Citrix, then post the free EtreCheck report using the Additional Text option when posting. This does not show any personal information, but will show the apps that are launching in several system folders.

How to use the Add Text Feature When Post… - Apple Community

Similar questions

20 replies
Question marked as Top-ranking reply

Dec 16, 2024 10:11 AM in response to The Admiral London

It may be caused by the Citrix app if you installed it on your computer. If that is the case uninstall it using the provided uninstaller and use an updated version if you choose to install it again.


If that is not the case or are still having problems with Citrix, then post the free EtreCheck report using the Additional Text option when posting. This does not show any personal information, but will show the apps that are launching in several system folders.

How to use the Add Text Feature When Post… - Apple Community

Dec 17, 2024 4:14 AM in response to The Admiral London

I’m sorry but your Mac is now spoilt goods and must get a fresh start to life from scratch.


Reset to factory and set your Mac up afresh - What to do before you sell, give away, trade in, or recycle your Mac - Apple Support


Important: Do not use Time Machine at any point during the reset process. Copy user data files like PDFs, jpegs etc. manually to external disk and re-copy them back after your Mac is setup fresh.


Important: Do not re-install apps that are trouble: typically those downloaded from outside the Apple Store that claim to clean viruses and enhance performance.


Good luck!

Dec 18, 2024 10:18 AM in response to The Admiral London

The Admiral London wrote:

I've removed all the Citrix files, I'll try the EtreCheck next once I've got my head around it.

Some versions of Citrix require you to use their uninstaller to remove all the files in your launch folders, so if you still see the Malware warning after a restart, then they may still be there and we can identify them with the EtreCheck report.

Dec 24, 2024 6:07 AM in response to The Admiral London

The report is not showing. Follow the steps here to post the report.

How to use the Add Text Feature When Post… - Apple Community


Removing Citrix is going to be the key in resolving the pop up you are seeing. They do provide an uninstaller on their website, but if there are System Extensions, they may be much more difficult to remove, but we will do our best.

Dec 24, 2024 9:08 AM in response to Kyo317

Kyo317 wrote:

However, some viruses corrupt your system file, so, first shut down you Mac, boot it in to recovery mode, and click erase Mac in the menu bar.

It is not a virus, it is an old version of Citrix installed before the software was signed. While restoring may be required if the System Extension is embedded into the OS due to Apple locking system files, it sure doesn't hurt to try and remove it before using the Nuclear option and wiping the computer.

Dec 18, 2024 1:13 PM in response to John Galt

Agree with John Galt, no need for a factory reset as long as the extensions are not embedded in the OS from a long ago installation and Citrix is not considered Malware that would be detected by MalwareBytes, but versions of Citrix when unsigned will prompt the Malware warning if they are still in the launch folders after removing the application.

Dec 24, 2024 5:15 AM in response to Mac Jim ID

I've now managed to download and open Extrecheck and run the report (I had to do this in safe mode). There does appear to be some issues with my Mac. Hopefully I can be pointed in the right direction.


I did try to remove citrix but I noticed there were a number of elements that I couldn't remove. Citrix was originally installed on my previous Mac back in 2012/13 to enable me to connect with my employers network and work from home.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

What should I do if Malware Blocked Pop-Up won't close on my iMac?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.