ArchimedesLookup ads: what it is and how to remove it

ArchimedesLookup is an adware app that Mac users can download without intending to do so, as uses deceptive distribution techniques, such as fake Flash Player update prompts and software bundle packages. Once inside the system, it installs a browser extension which is clipped to Safari, Google Chrome, or Mozilla Firefox web browser, and then changes homepage and new tab URL to something else.

Facts checked October 6, 2026. Removal steps checked against Apple's current documentation and the security vendors' reports. We have not run the malware on a Mac. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your Mac is infected.

Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds before you decide anything.

If redirects to akamaihd.net keep coming back, a free scan can check extensions, programs and browser settings in one pass.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove ArchimedesLookup ads yourself 4 steps, about 12 minutes, no software needed.

Start the steps
ArchimedesLookup: adware mac virus
ArchimedesLookup as our 2020 report showed it.

ArchimedesLookup ads: summary

DistributionPirated software installers (torrents), software bundles, fake Flash Player update prompts
NameArchimedesLookup
TypeAdware, Mac virus
Malware familyAdload. Other members include CreativeSearch, SearchWebSvc, MainReady, DataQuest, ProductEvent, AgileHelp, etc.
SymptomsUnknown browser extensions are installed on the web browser with elevated permissions; search engine and new tab address altered to something else; redirects bring to unknown/malicious/scam sites, etc.
Associated risksAdditional malware/PUP infection, sensitive information disclosure to unknown parties/crybercriminals, identity theft, monetary losses due to encountered scams, etc.
Removal

Scan the Mac with security software to find the malware and anything installed with it. Fortect for Mac scans for malware and unwanted programs.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
TerminationManual elimination might sometimes be impossible since the app is installed with elevated permissions. The best way to get rid of ArchimedesLookup is to scan your device with anti-malware software
Detection namesNo Microsoft detection name is known
DamageNot recorded in the old report
Evidence4 write-ups by security sites; details still limited
Domainsakamaihd.net
Ads shown asRedirects through ad pages
BrowsersChrome, Edge and Firefox
First seen24 July 2020
Facts checked6 October 2026

What the ArchimedesLookup ads ads look like

redirects to an unknown domain

Can read sensitive information from webpages, including passwords, phone numbers, and credit cards on: all webpages

Is ArchimedesLookup ads dangerous?

From our report of Jul 2020 · not reviewed since

More from our earlier report on ArchimedesLookup

  • Permissions for "ArchimedesLookup" Webpage contents Can read sensitive information from webpages, including passwords, phone numbers, and credit cards on: all webpages Browsing History Can see when you visit: all webpages

How ArchimedesLookup ads got into your browser

From our report of Jul 2020 · not reviewed since

ArchimedesLookup - a malicious application that is widely spread among macOS users

ArchimedesLookup is an adware app that Mac users can download without intending to do so, as uses deceptive distribution techniques, such as fake Flash Player update prompts and software bundle packages. Once inside the system, it installs a browser extension which is clipped to Safari, Google Chrome, or Mozilla Firefox web browser, and then changes homepage and new tab URL to something else.

Since ArchimedesLookup virus is a part of a well-known Adload adware campaign, previous examples show that victims see Safe Finder as their default engine soon after the infection occurs. Additionally, users might also notice redirects to akamaihd.net subdomains, intrusive advertisements (popups, coupons, promos, deals, offers), and increased number of online scams.

Behind the scenes, ArchimedesLookup adware collects anonymous browser data, as well as sensitive information, as the browser extension is installed with elevated permissions on the browser. Those who found their browser settings changed suddenly by a malicious app, should investigate the matter further, as apps belonging to this adware campaign might be associated with OSX/Shlayer and Crescent Core malware infections.

Adload apps like ArchimedesLookup are known to be distributed via various deceptive and even malicious methods, similar to malware. The most common infection methods include:

In most cases, cybercriminals use social engineering to make users install malicious apps themselves. This tactic involves abusing human psychology to make them believe in things that are not actually true. For example, Flash Player is a flawed and outdated plugin that is generally not needed anymore. Yet, malicious actors claim that it is necessary and make users install malware on their machines.

ArchimedesLookup is a relatively primitive computer infection, although it performs the action it was designed for very well. For example, it establishes persistence on the system by creating new profiles and dropping malicious .plist files in Library and other folders. Hence, users who just place the app into the Trash will not remove ArchimedesLookup successfully unless they delete those files manually.

One of the most dangerous ArchimedesLookup virus traits is that it can abuse the built-in AppleScript within Mac computers in order to perform malicious activities on the system. Thus, those who are infected with this adware might find that there are several browser extensions and applications installed without permission.

During the time when users are infected with ArchimedesLookup malware, they are at great risk of having their privacy violated, as the app gathers anonymous and personal data via the web browser, as is stated in the extension description:

To make matters worse, due to established configuration settings, ArchimedesLookup removal becomes almost impossible for users who are less familiar with computer operation principles. Luckily, powerful anti-malware, such as can be used for the elimination process. Besides performing a full system scan, users should also ensure that they reset their web browsers and perform further checks with to ensure the best Mac performance.

  • Fake Flash Player updates that can be encountered on various websites;
  • Repacked installers, software cracks, torrents, and similar unsafe downloads;
  • Software bundle packages downloaded from third-party sites.
ArchimedesLookup: adware mac virus
ArchimedesLookup in our 2020 report.
ArchimedesLookup: malware adload family
ArchimedesLookup in our 2020 report.

From our report of Jul 2020 · not reviewed since

Mac adware is commonly distributed via fake Flash Player installers

Mac computers are considered to be much more secure than the Windows counterparts.

However, malicious actors manage to break these defenses by convincing users to let malware in. Therefore, you should be aware that your computer security is in your own hands, and you should take care of it if you want to avoid financial losses, sensitive data leak, or identity theft.

First of all, you should not download apps from sources that are not approved by Apple. For security reasons, all unapproved apps require your password to access your device, so you should ensure that no malicious applications gain access to your computer. Thus, carefully choose where the software is coming from, and avoid high-risk websites such as torrents altogether.

Finally, you should not download anything related to Flash Player. Previously, it used to be used for multimedia playback purposes, and almost all websites used it. However, the technology is outdated and is filled with security flaws.

Most modern web browsers, such as Google Chrome, have the functionality built-in within it, so there is no need to install the plugin in the first place. Adobe will discontinue Flash Player at the end of 2020. For all these reasons, security experts recommend eliminating Flash from a computer and never using it again.

ArchimedesLookup: virus detection rates
ArchimedesLookup in our 2020 report.

Check your browser and PC

  • Address: akamaihd.net

How to remove ArchimedesLookup ads

How to remove ArchimedesLookup from a Mac

Remove the app and what starts it, then check the browsers.

  1. Step 1: Delete apps and downloads you did not intend to install

    Open the Applications folder and your Downloads folder. Drag any app you did not install, and any disk image (.dmg), installer (.pkg) or archive (.zip) that came from ArchimedesLookup or a site you do not trust, to the Bin, then empty the Bin.

    Also check ~/Library/Application Support for a folder with the same name as the app you removed.

  2. Step 2: Remove unknown login items and background items

    Open System Settings > General > Login Items & Extensions. Under Open at Login and Allow in the Background, switch off or remove anything you do not recognize, especially items whose developer is shown as an unknown name or that appeared on the day you ran the command.

    Then open Finder, choose Go > Go to Folder and check ~/Library/LaunchAgents, /Library/LaunchAgents and /Library/LaunchDaemons for property list (.plist) files you did not add. Drag suspicious ones to the Bin, then restart the Mac.

  3. Step 3: Check the browsers for extensions and changed settings

    In Safari open Settings > Extensions and General (homepage). In Chrome open chrome://extensions, in Firefox about:addons.

    Remove any extension you did not add, and reset the homepage and search engine if they changed. Browsers hold saved passwords and cookies, which is why the password step comes first.

  4. Step 4: Quit what is running that you do not recognize

    Open Activity Monitor (in Applications > Utilities, or search for it with Command + Space).

    In the CPU or Network tab, look for a process you did not install or whose name is random, select it, click the stop button (the octagon with an X) and choose Quit or Force Quit.

    Note the name first: you will look for the same name in the next steps. Malware that comes back after a restart is handled in the next two steps.

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Remove from Google Chrome

Google Chrome might still have malicious settings on it, even after you get rid of the infection. Thus, reset the browser as explained below:

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2
Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge
Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge
Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2
Delete from Safari

You should reset Safari if you can't uninstall malicious extensions in a regular way:

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari
Delete from macOS

Get rid of ArchimedesLookup manually, follow these steps:

Remove the unwanted application:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).Uninstall from Mac

Delete leftover files and folders:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
  3. Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.Delete leftover files from Mac
  4. Finally, empty the Trash to permanently remove the leftovers.
Reset Internet Explorer

Remove dangerous add-ons:

  1. Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
  2. Pick Manage Add-ons.
  3. You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.Remove add-ons from Internet Explorer

Change your homepage if it was altered:

  1. Open IE and click on the Gear icon.
  2. Select Internet Options.
  3. In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
  4. Click Apply and then select OK.Reset IE homepage

Delete temporary files:

  1. Press on the Gear icon and select Internet Options.
  2. Under Browsing history, click Delete...
  3. Select relevant fields and press Delete.Clear temporary files from Internet Explorer

Reset Internet Explorer:

  1. Click on Gear icon > Internet options and select Advanced tab.
  2. Select Reset.
  3. In the new window, check Delete personal settings and select Reset.Reset Internet Explorer

Stream videos without limitations, no matter where you are

There are multiple parties that could find out almost anything about you by checking your online activity.

While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.

Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.

Data backups are important - recover your lost files

Ransomware is one of the biggest threats to personal data.

Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.

While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.

From our report of Jul 2020 · not reviewed since

Get rid of ArchimedesLookup to ensure your online safety

ArchimedesLookup is not your typical Mac adware that will spam you with ads every time you open your browser (although it will also do that).

The app acts more like malware does, and also abuses built-in operating system features in order to stay on it as long as possible. Besides, if you choose to ignore the infection for long enough, you will be infected with even more potentially unwanted programs and malware, so you should take care of ArchimedesLookup removal as soon as possible.

As mentioned above, the best way to remove ArchimedesLookup from your system is by letting a powerful anti-malware software doing it for you. Simply download a reputable security application, bring it up to date, and then perform a full system scan.

This method is not perfect, however, as not all security apps might be able to detect the infection. In such a case, we suggest checking the following places on the machine and eliminating all the suspicious files:

As soon as you delete the ArchimedesLookup virus from your Mac, you should also reset your web browser to get rid of malicious settings established by the adware.

  • System Preferences > Accounts> Login Items
  • ~/Library/LaunchAgents
  • ~/Library/Application Support
  • ~/Library/LaunchDaemons

Questions about ArchimedesLookup ads

akamaihd.net opens when I click links. What causes it?

When every click leads to akamaihd.net first, an extension or a script on the page is rewriting the links. If it happens only on one site, that site uses aggressive ads; close it and use another source. If it happens everywhere, open the browser in a private window, where extensions are normally off, and try again.

No redirect in the private window means one of your extensions is responsible: remove the ones you do not know. A redirect in the private window too means the cause is outside the extensions, such as a notification permission, a changed search setting or a program installed on the PC. The removal steps in this guide cover each of those.

Did akamaihd.net install a virus on my PC?

Very unlikely, unless you downloaded and opened something from the pages it led to. Redirect domains such as akamaihd.net sell your visit to advertisers; they do not need to install anything to make money.

What can be installed is the thing that causes the redirects in the first place, such as an extension or an ad-supported program that came with free software. That is why the checks in this guide look at extensions, notification permissions and Installed apps.

A full scan with Microsoft Defender afterwards gives you a clear answer about the rest of the PC. If the scan is clean and the redirects stop after removing the cause, you are done.

Why does ArchimedesLookup show me ads?

Because that is its whole purpose. ArchimedesLookup is an adware extension, and its operators are paid for every ad it displays and every click it gets. In this case the ads take the form of redirects through ad pages.

They are chosen by ad networks that accept almost any advertiser, which is why so many look like warnings or prizes. The ads are not a sign that your PC is broken or infected with something worse; they are a sign that something on it, or in the browser, has permission to advertise. Removing that permission or program stops them.

Do I have to clean every browser?

Yes, if you use more than one. We saw ArchimedesLookup in Chrome, Edge and Firefox, and each browser keeps its own extensions, notification permissions and settings. Chrome and Edge share the same extension format, so one installer can add the same adware to both, while Firefox has its own add-ons.

Check every browser on the PC, including ones you rarely open. If you sync a browser with an account, clean it while signed in, so that the removal reaches your other computers rather than the adware returning from them.

How do I know the ads come from ArchimedesLookup?

Look for redirects to akamaihd.net. That is the trace ArchimedesLookup leaves, and it shows up as redirects through ad pages. Ads that appear on every site, including ones that never carried ads before, point to something on your PC or in the browser rather than to the sites themselves.

A quick test is a private window, where extensions are off by default: if the ads disappear there, an extension is responsible. If they appear even with the browser closed, the source is a notification permission or a program in Windows.

Can adware slow down my PC?

Yes. Adware runs in the background, loads ad scripts, opens extra tabs and contacts its servers, all of which use processor time, memory and bandwidth. Ad-heavy extensions also slow down every page, because they inspect and change it before you see it.

The effect is strongest on older PCs and when several adware programs arrived together. After removal, restart the PC and check Task Manager for anything still using a lot of resources that you do not recognise. Speed usually returns to normal once the ads stop.

An ad showed a phone number and I called it. What now?

The number belongs to scammers, not to Microsoft or an antivirus company. If you only talked, hang up and do not call back. If you let them connect to the PC, disconnect it from the internet, uninstall the remote access program they used, such as AnyDesk, TeamViewer, ScreenConnect or UltraViewer, and run a full and offline scan.

If you paid or gave bank details, call your bank at once on the number printed on your card. Change any passwords you typed while they were connected, and report the call.

Does adware steal passwords?

Ordinary adware is built to show ads, not to steal logins, and most of it never touches saved passwords. The line is blurry, though. Extensions that can read every page could capture what you type, and adware ads sometimes lead to phishing pages that ask for passwords directly.

If you entered credentials on a page reached through an ad, change that password from a clean device and turn on two-step verification. Otherwise, removing adware extension and clearing cookies is usually enough.

Why didn't my antivirus catch ArchimedesLookup?

Many security products do not block adware or notification sites by default, because users often agreed to them, even through a misleading prompt. Notification spam installs nothing at all, so there is no file to detect.

In Windows 11 you can make Microsoft Defender block potentially unwanted apps: open Windows Security > App & browser control > Reputation-based protection settings and turn on Potentially unwanted app blocking. If notifications caused the pop-ups, no scanner will report them; the fix is in the browser's site settings.

Will Fortect remove ArchimedesLookup?

Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds on your Mac before you decide anything.

For ArchimedesLookup, follow the plan on this page as well: removing a launch item or an app is done in macOS itself, and a scanner cannot undo what was typed or entered on the infected Mac, such as saved passwords that were copied.

Change your passwords from another device first, and if the page tells you to erase the Mac, a scan is not a substitute. The free scan costs nothing and the full-featured product needs a license.

Sources

  1. Intego: Adobe Flash Player is dead, yet 10% of Macs are infected with fake Flash malware (read October 6, 2026)
  2. Wikipedia: AppleScript (read October 6, 2026)
  3. Google Chrome Help: Use notifications to get alerts (no longer online) (read October 6, 2026)
  4. FTC: How to recognize, remove and avoid malware (read October 6, 2026)
  5. Microsoft Learn: Microsoft Defender Offline (read October 6, 2026)

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: ArchimedesLookup ads

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year