Mac Virus “Virus” Removal (Mac/Safari Guide) Dec. 2019 Update

Parasite may reinstall itself multiple times if you don't delete its core files. We recommend downloading ComboCleaner to scan for malicious programs installed with it. This may save you hours and cut down your time to about 15 minutes. 

Download ComboCleaner Anti-Malware

More information about ComboCleaner and steps to uninstall. Please review ComboCleaner's EULA and Privacy Policy. Keep in mind, only ComboCleaner’s scanner is free. If it detects a malware, you'll need to purchase its full version to remove it.

Many users have reported unpleasant Internet/browser disturbances caused by a page-redirecting browser hijacker called “Virus”. This redirecting program spreads via software bundling and through other similar tricky software installation techniques.

As soon as the hijacker becomes part of your system, it usually changes the address of your homepage, replaces your default search engine and begins to cause sudden page redirects with every new search. According to the information we have, “Virus” is not malicious and, apart from the above-described browsing modifications, it normally does not seek to harm your PC, corrupt your data or cause serious issues. Still, if your Safari, Chrome or Firefox  is affected and you want to reset your previous browsing settings, we advise you to remove the browser hijacker. You can use the instructions given in the Removal Guide under the article or uninstall “Virus” with the help of the professional removal tool below. is a browser hijacker that causes unwanted browser changes!

The browser hijackers are pieces of software which are usually considered to be potentially unwanted. Their purpose is to initiate a number of redirects to specific sponsored websites and force the customers to use a new homepage or an imposed sponsored search engine for their daily searches. Such actions could be very unpleasant. Moreover, you should keep in mind that the installed search engine may not be entirely “honest” with you. Its main purpose is likely to show you ads, banners, and pop-ups of different types and prompt you to click on them because every click it manages to generate brings profits for the hijacker developers via Pay-Per-Click campaigns. So if you need relevant and organic search results, you should better consider uninstalling “Virus” and its imposed components from your system. They will mostly deliver sponsored results from various advertising platforms.

Additional threats related to “Virus” and its suspicious search engine:

As a typical browser hijacker, may include third-party links in the search results it provides with the intention of making you visit certain webpages. Unfortunately, there is no guarantee that these external pages are safe to use. You may find yourself on pages that ask you to install suspicious programs, updates, or click on different banners and pop-ups. You may also be redirected to illegal websites, which may infect you with Ransomware, Trojans and other nasty viruses. That’s why, you should better refuse the installation of any items and avoid interaction with the content, delivered by the browser hijacker.

The other thing that can be bothering regarding hijackers is your privacy. Once you start using the computer infected with a browser hijacker, you risk disclosing confidential information about your browsing habits to the creators of the software and other third parties. Typically, every hijacker, including, may try to collect information about the users’ searches, a list of visited web pages, an IP address, and other browsing information. Such data typically contains non-personal information. This information usually reaches the servers of the hijacker’s developers, but you cannot be sure that the company stores it securely.  That’s why exposing such information to unfamiliar companies and other third-party marketers is generally not a good idea. Finally, we have to say that such information is extremely valuable to those who want to use it for malicious purposes and you never know when and how they may get their hands on it. For this reason, we encourage you to ask yourself if it’s a good idea to trust a company that creates a browser-hijacker and let it monitor your web activity every day.

How to keep browser hijackers like “Virus” away?

Programs like are usually distributed via software bundles. Software bundling is a technique, which allows the distribution of several programs together (in a package) as one single. For this reason, you should be careful when selecting the installation settings of any new software that you are about to install. It is best to select the User or Advanced setup settings for the software installation, because, this way, you will see a full list of all bundled programs and you will be able to remove the unwanted ones. Our team suggests that you refuse the installation at all. In most cases, programs distributed in this way are usually useless or annoying, and, in some rare cases, they might even be used as distributors of Ransomware, Trojans and other nasty computer threats.


Type Browser Hijacker
Danger Level Medium (nowhere near threats like Ransomware, but still a security risk)
Symptoms You may start experiencing sudden page redirects and also your browser might receive a new homepage or a new search engine which would replace your default ones.
Distribution Method Mostly distributed via software bundles, free downloads and automatic software installation managers, ads, spam, torrents. 
Detection Tool “Virus” Removal


We get asked this a lot, so we are putting it here: Removing parasite manually may take hours and damage your system in the process. We recommend downloading ComboCleaner to see if it can detect parasite files for you.

The first thing you need to do is to Quit Safari (if it is opened). If you have trouble closing it normally, you may need to Force Quit Safari:

You can choose the Apple menu and click on Force Quit.

Alternatively you can simultaneously press (the Command key situated next to the space bar), Option (the key right next to it) and Escape (the key located at the upper left corner of your keyboard).

If you have done it right a dialog box titled Force Quit Applications will open up.

In this new dialog window select Safari, then press the Force Quit button, then confirm with Force Quit again.

Close the dialog box/window.



To remove parasite on your own, you may have to meddle with system files and registries. If you were to do this, you need to be extremely careful, because you may damage your system.

If you want to avoid the risk, we recommend downloading ComboCleaner
a professional malware removal tool.

More information on ComboCleaner, steps to uninstallEULA, and Privacy Policy.

Start Activity Monitor by opening up Finder, then proceed to activity-monitor

Once there, look at all the processes: if you believe any of them are hijacking your results, or are part of the problem, highlight the process with your mouse, then click the “i” button at the top. This will open up the following box:


Now click on Sample at the bottom:


Do this for all processes you believe are part of the threat, and run any suspicious files in our online virus scanner, then delete the malicious files:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at:

Scan Results

Virus Scanner Result


The next step is to safely launch Safari again. Press and hold the Shift key while relaunching Safari. This will prevent Safari’s previously opened pages from loading again. Once Safari is opened up, you can release the Shift key.

On the off chance that you are still having trouble with scripts interrupting the closing of unwanted pages in Safari, you may need to take some additional measures.

First, Force Quit Safari again.

Now if you are using a Wi-Fi connection turn it off by selecting Wi-Fi off in you Mac’s Menu. If you are using a cable internet (Ethernet connection), disconnect the Ethernet cable.


Re-Launch Safari but don’t forget to press and hold the Shift button while doing it, so no previous pages can be opened up. Now, Click on Preferences in the Safari menu,

Preferences in Safari

and then again on the Extensions tab,

extensions in safari

Select and Uninstall any extensions that you don’t recognize by clicking on the Uninstall button. If you are not sure and don’t want to take any risks you can safely uninstall all extensions, none are required for normal system operation.

The threat has likely infected all of your browsers. The instructions below need to be applied for all browsers you are using.

Again select Preferences in the Safari Menu, but this time click on the Privacy tab,
Privacy in Safari

Now click on Remove All Website Data, confirm with Remove Now. Keep in mind that after you do this all stored website data will be deleted. You will need to sign-in again for all websites that require any form of authentication.

Still in the Preferences menu, hit the General tab

General Tab in Safari

Check if your Homepage is the one you have selected, if not change it to whatever you prefer.
Default Home Page

Select the History menu this time, and click on Clear History. This way you will prevent accidentally opening a problematic web page again.

firefox-512 How to Remove From Firefox in OSX:

Open Firefoxclick on mozilla menu (top right) ——-> Add-onsHit Extensions next.

pic 6

The problem should be lurking somewhere around here –  Remove it. Then Refresh Your Firefox Settings.

chrome-logo-transparent-backgroundHow to Remove From Chrome in OSX:

Start Chrome, click chrome menu icon —–>More Tools —–> Extensions. There,  find the malware and  select  chrome-trash-icon.

pic 8

Click chrome menu icon again, and proceed to Settings —> Search, the fourth tab, select Manage Search Engines.  Delete everything but the search engines you normally use. After that Reset Your Chrome Settings.

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

Leave a Comment