October 17, 2025

The ultimate guide to removing the Bing redirect virus from Mac

Maksym Sushchuk
Written by
Experienced tech writer with 15 years of translating complex Mac concepts into clear, user-friendly content.

Maksym Sushchuk

Alex Holovchenko
Approved by
The content has been reviewed and approved by our team member, an Apple Certified Support Professional, who provides technical support to Nektony’s users.

Alex Holovchenko

Share

If you’re reading this, most probably your Mac has fallen victim to the infamous Bing redirect virus. You might notice that every browser search gets forced through Bing, even if you’ve set Google or another engine by default. On top of that, annoying pop-ups or ads may keep appearing, and strange extensions or even unknown configuration profiles might have sneaked into your system.

In this guide, I’ll walk you through how to track down the culprit and remove it step by step. By the end, you’ll restore control over your browser and get your Mac back to its clean, safe state.

Before you start

Removing the Bing redirect virus can take time, especially if it has spread across different parts of your system. To make the process faster, you can use App Cleaner & Uninstaller by Nektony.

This tool scans your Mac for applications and their hidden files to help you completely remove unwanted or suspicious software. It also lets you manage system extensions and startup items, and those are the places where the Bing redirect virus usually hides.

What’s really hiding behind the Bing redirect virus

The Bing redirect virus is not a classic virus but a type of browser hijacker. Instead of infecting your whole system, it quietly changes your browser’s behavior: searches get rerouted through Bing, ads and popups appear more often, and your chosen settings no longer stick.

On macOS, these hijackers usually sneak in through free apps from unverified sites or come bundled with seemingly useful extensions. Starting with macOS 15, Apple’s security makes it harder for suspicious apps to launch at all.

macOS pop-up about suspicious app

Still, hijackers can disguise themselves as ordinary browser add-ons. That means the problem hasn’t gone away; it has just shifted to hiding in places that look harmless.

And once users notice it, the way to get rid of them is often far from obvious, as you can see from various Reddit threads and Apple discussions.

How to remove the Bing redirect virus from Mac

Getting rid of the Bing redirect virus requires you to inspect different areas of your Mac: system settings, browser extensions, and installed applications. Once that’s done, it’s a good idea to run a virus scan to make sure nothing is left hiding in the background.

Let’s start with the system-level settings where hijackers often leave their traces.

Check System Settings

Hijackers may install configuration profiles or background agents that let them reset your browser settings even after you’ve changed them. Here’s what to check:

1. Delete unknown configuration profiles

Go to System Settings → Users & Groups. If you see profiles you didn’t create yourself, often with names like AdminPrefs, ChromeSettings, or SafariSettings, delete them.

the Users & Groups settings in macOS

2. Inspect LaunchAgents and LaunchDaemons

Hijackers sometimes add background files to your system that relaunch their settings after each restart. Check these folders:

  • /Library/LaunchAgents/

    Copy

  • /Library/LaunchDaemons/

    Copy

  • ~/Library/LaunchAgents/

    Copy

The easiest way to open these folders is to open Finder and press Command+Shift+G. This opens the Go to folder dialog, where you can paste the wanted path and hit Enter to open it.

the Go to folder dialog in Finder with LaunchAgents folder location inserted

Once you open the mentioned folder, look for suspicious files with names containing words like search, bing, hlpr, update, or agent.

If you find them and are sure they don’t belong to trusted apps, move them to the Trash.

a Bing-related preferences file in the LaunchAgents folder

Clean up your browsers

Once you’ve checked system settings, move on to your browsers. This is where the Bing redirect hijacker does most of its damage.

Safari

  1. Open Safari → Settings and go to the Extensions tab. Remove anything you don’t recognize.

    Note:

    If an extension refuses to uninstall and shows an error, click Show in Finder, delete the related file manually, then empty the Trash and restart your Mac.

    the Extensions window in Sagari with Adblock installed

  2. In the General tab, check the homepage and set it to the site you prefer.

    the Homepage setting in Safari preferences

  3. In the Search tab, choose Google or another search engine you trust.

    Search engine settings in safari Now, clear the browser data to flush out leftovers.

  4. Enable Show features for web developers in Settings → Advanced.

    Advanced options in Safari's settings

  5. Then in the Develop menu, select Empty Caches.

    the Empty Caches options in Safari

Chrome and Chromium-based browsers (Brave, Vivaldi, Edge, etc)

  1. Open Menu → Settings.
  2. Under Search engine, click Change and select your preferred engine. Search engine settings in Chome and Chrome-based browsers
  3. Go to Extensions and remove anything suspicious.
  4. In the On startup section, make sure Chrome opens either a blank page or a site you’ve set yourself. On startup settings in Chrome

    Now, let’s delete browsing data.

  5. In Settings, select Privacy and security.
  6. Click Delete browsing data. On startup settings in Chrome
  7. Delete Cookies and other site data, as well as Cached images and files with the time range of All time.

Now your browser should be clean of Bing redirect virus.

Firefox

  1. Open Settings via the application menu or by pressing ⌘,. the application menu in Firefox
  2. In the Search section, set the search engine you want. the Search section of Firefox settings
  3. In Extensions, delete anything you don’t recognize. the Extensions tab in Firefox Now, let’s delete browsing data in Firefox.
  4. In Settings, select Privacy and security.
  5. Now scroll down to the Cookies and Site data and click Clear data… Privacy and security settings in Firefox
  6. Select When: Everything, and tick Cookies and other site data, as well as Temporary cached files and pages, with the time range of All time. browsing data clearing UI in Firefox

    Restart your Mac afterwards.

Remove suspicious applications

Another common hiding place for hijackers is in applications you don’t remember installing. Starting with macOS 15, apps flagged as unsafe (such as unsigned software or malware) will not even launch. Instead, the system shows a warning and recommends deleting them right away.

Open your Applications folder and look for anything unfamiliar. Pay extra attention to so-called “optimizers,” “cleaners,” or fake Flash Player updaters, which are a classic disguise for adware. If you didn’t install an app yourself, it’s safer to remove it.

You can delete suspicious apps manually by dragging them to the Trash. To make sure every single related file is gone, use App Cleaner & Uninstaller by Nektony:

  1. Download and launch App Cleaner & Uninstaller to let it scan your system.
  2. Find the suspicious app or the one that triggered a macOS warning.
  3. Select it and click Uninstall. App Cleaner and Uninstaller's main window
  4. In the Review and Remove window, confirm removal and enter your admin password if required. the Review and confirm removal of selected items window in App Cleaner & Uninstaller
  5. Empty the Trash and restart your Mac.

This ensures not just the app itself but also its hidden support files are removed for good.

Run an Antivirus Scan (Optional)

Once you’ve removed suspicious apps, profiles, and extensions, the Bing redirect virus shouldn’t bother you anymore. Still, for an extra layer of reassurance, you might want to run a quick antivirus or diagnostic scan and confirm that nothing malicious is left behind.

For example, the screenshot below shows a report generated by the EtreCheck app, which I used to check for potential issues on my Mac.

EtreCheck reporting minor issues

Running such a scan gives some users peace of mind that the Bing redirect virus is fully gone, and their Mac is back under your control.

How to stay safe after removal

In this article, I showed how to get rid of the hijacker often called the Bing Redirect Virus. But one more question remains: how did it end up on your Mac in the first place? Most likely, it slipped in through a shady browser extension with permission to change your search engine, a free or cracked app bundled with unwanted components, or even a malicious file that was opened without caution.

To avoid running into the same problem again, consider limiting access to your Mac for other users, disabling extension sync in your browser if you use multiple Macs, and always double-checking what you install.

A few extra seconds of attention can save you hours of cleanup later.

A personal closing note

Hijackers like “Bing redirect virus” are frustrating because they often linger quietly. They don’t crash your Mac or lock your files, so they can sit unnoticed while making money from ads, redirects, or by selling browsing data.

What had been puzzling me for ages is why Bing is almost always the landing spot, not Google. The reason turned out to be more practical than mysterious. Bing’s search results can be accessed and repackaged more easily, and its partner ad networks are simpler for shady operators to monetize. That combination makes Bing the preferred disguise, even though Google would look much more credible to most users.

Frequently asked questions

Is the Bing redirect virus actually a “virus“?

Not in the traditional sense. It’s a browser hijacker or adware, which means it changes browser settings without permission. It doesn’t replicate like a true virus, but the effects, like constant redirects, pop-ups, and altered search results, feel just as annoying.

Is my personal data and financial information at risk?

These hijackers usually focus on browsing data such as search queries, visited websites, and clicks on ads. They are not designed to steal banking details directly, but any software that monitors your activity lowers your privacy. It’s always better to remove them quickly.

What if I can’t find or delete the malicious application?

Some hijackers don’t show up clearly as apps. In that case, check system profiles, LaunchAgents, and browser extensions as described in this guide. If the problem persists, using a dedicated removal tool like MacCleaner Pro or running a Malwarebytes scan can help uncover hidden components.

Can this Bing redirect virus come back after I’ve removed it?

If you delete only the visible part (like the browser extension) but leave behind hidden files or launch agents, the hijacker may reinstall itself. That’s why it’s important to go through all the steps, including checking profiles and background folders.

How to check Activity Monitor for any malicious processes?

Open Activity Monitor (from the Applications folder → Utilities) and look for processes with suspicious names often containing “search”, “agent” or “update”. If you spot one you don’t recognize, quit it and cross-check whether it matches a legitimate app you installed.

Is the virus that’s causing Chrome to redirect to Bing dangerous?

It’s more invasive than outright dangerous. It doesn’t encrypt files or spread across your system, but it manipulates how you browse the web and may expose you to shady ads or tracking. That makes it a security and privacy risk, even if it isn’t destructive.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top