Skip to content
  • Active
  • Severity: Medium
  • Adware
  • Mac
  • Verified · Feb 2025

How to remove OriginalAccessibilit Mac virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

OriginalAccessibilit is Mac virus that can compromise your online security

OriginalAccessibilit

OriginalAccessibilit is a potentially harmful application that falls under the Adload malware category, specifically targeting Mac users. Although users install it themselves, they are usually deceived into doing so – whether by unknowingly downloading it alongside pirated software from untrustworthy sources or by being misled by a fraudulent Flash Player update prompt.  

Once inside the system, OriginalAccessibilit begins making modifications that initially go unnoticed but soon become apparent when using browsers like Safari or Chrome. A newly attached extension bearing the same name appears, accompanied by various disruptions. Users might notice that their homepage and default search provider have been altered, and they may experience an increase in aggressive advertisements or be exposed to phishing content while browsing.  

Further complications of the OriginalAccessibilit infection often include the inability to remove the extension, malware components reappearing after deletion, and persistent tracking of user activity. Eliminating this threat as soon as possible is highly advised, as it poses serious risks to both personal security and the overall stability of the affected Mac.

Name OriginalAccessibilit
Type Mac virus, adware, browser hijacker
Malware family Adload
Distribution Third-party websites distributing pirated software, software bundles, fake Flash Player updates
Symptoms Installs a new extension and application on the system; changes homepage and new tab of the browser; inserts ads and malicious links; tracks sensitive user data via extension
Removal Running a complete system scan with SpyHunterCombo Cleaner security software is the simplest method of removing Mac malware. If you prefer to take it out by hand, follow the instructions below
Security tips Following the removal of the virus and all of its components, we advise using FortectIntego to scan your device in order to remove any remaining files from your browsers

Adload family characteristics and behavior

Adload is one of the most widespread malware families targeting macOS, with its presence traced back to at least 2017. Over the years, cybercriminals have introduced hundreds of variants, continuously adapting their techniques. Among the many threats associated with this malware strain, OriginalAccessibilit is one of the newer examples, sharing common traits with previously known variants.

Distribution

Like other Adload infections, OriginalAccessibilit primarily spreads through deceptive means, such as fake Flash Player update prompts and bundled installers for pirated software. Users never willingly install it—instead, they are tricked into doing so.

Flash Player was once widely used for online multimedia content, but it has since been discontinued by Adobe, and modern browsers no longer rely on it. However, cybercriminals continue to exploit outdated habits by pushing fake updates, deceiving unsuspecting users.

Another method used to distribute Adload malware is cracked software. Websites offering illegal downloads of popular applications and games frequently serve as a gateway for these infections. The safest approach is to avoid such sources and instead purchase official software licenses to ensure security.

OriginalAccessibilit virus

Effects on the device

At its core, OriginalAccessibilit operates as adware, embedding itself into Safari or other web browsers by installing an unwanted extension. This results in an overwhelming influx of advertisements, many of which originate from unreliable or even malicious ad networks. Because these networks often distribute misleading content, users may be exposed to scams, phishing attempts, or malware downloads.

What makes this threat particularly concerning is that the extension is granted elevated privileges, allowing it to intercept sensitive information such as passwords or financial details entered into the browser. This significantly increases the risk of data theft and privacy breaches.

Persistence

Although it infiltrates systems through deceptive means, the installation process requires users to enter their Apple ID credentials. Once granted access, the malware takes advantage of various exploits to secure its presence. Common techniques include using AppleScript to modify system settings and automatically generating new Login Items, Profiles, and Plist files. By leveraging these tactics, the infection can persist on the system while evading detection by macOS security mechanisms.

Quick removal

Although OriginalAccessibilit may appear to be a simple threat, its persistence mechanisms have allowed it to evade Apple's XProtect, making it difficult for macOS security systems to detect and remove. If not properly eliminated, the malware may continue running in the background, unnoticed by the user.

Third-party security tools such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes can be highly effective in detecting and removing OriginalAccessibilit. However, since the malware creates multiple files and system modifications post-infection, manually eradicating it can be challenging. If any infected components remain, the malware may return, making a thorough cleanup essential.

For those opting for manual removal, it is crucial to inspect Safari or any other affected browser and delete all malicious extensions or associated files. Additionally, clearing cookies and cached data can help improve security and protect privacy. Users who prefer an automated solution to repair malware-related damage can rely on specialized software such as FortectIntego, which efficiently handles the removal process.

Alternative solution

OriginalAccessibilit is designed to operate continuously in the background, launching its processes as soon as the system starts. This persistence ensures that the malware remains active at all times, making it more difficult to detect and remove. Identifying and stopping these hidden processes is a crucial step in preventing further system compromise.

To effectively deal with this infection, users must first locate and terminate the malicious processes running in the background. Doing so prevents the malware from interfering with the removal process and helps minimize its impact. Once these activities are successfully halted, users can proceed with removing OriginalAccessibilit manually or by using specialized malware removal tools. This method significantly increases the chances of fully eliminating the threat from the system.

  • Open Applications folder
  • Select Utilities
  • Double-click Activity Monitor
  • Here, look for suspicious processes and use the Force Quit command to shut them down
  • Go back to the Applications folder
  • Find the malicious entry and place it in Trash.Uninstall from Mac 1

Deleting unwanted profiles and Login Items is necessary when trying to eliminate malware from a Mac.

  • Go to Preferences and pick Accounts
  • Click Login items and delete everything suspicious
  • Next, pick System Preferences > Users & Groups
  • Find Profiles and remove unwanted profiles from the list.

The PLIST files are small config files, also known as the “Properly list.” They hold various user settings and hold information about certain applications. To remove the virus, you have to find the related PLIST files and delete them.

  • Select Go > Go to Folder.
  • Enter /Library/Application Support and click Go or press Enter.
  • In the Application Support folder, look for any dubious entries and then delete them.
  • Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and delete all the related .plist files.Uninstall from Mac 2

The browser extension associated with OriginalAccessibilit plays a crucial role in its functionality. It is programmed to modify browser settings by changing the homepage, new tab page, and default search engine. The primary goal of these alterations is to continuously redirect users to unwanted advertisements, generating revenue for the malware operators.

Beyond disruptive browsing changes, this extension also acts as a tool for data collection. During installation, the malware often requests elevated permissions, allowing it to access sensitive user information. Such unauthorized access poses significant privacy concerns, potentially leading to data theft or identity fraud. For this reason, removing the browser extension as soon as possible is essential.

Most security programs are capable of detecting and automatically removing such malicious extensions. However, if the extension persists after a security scan, users should manually uninstall it from their browser to prevent further security risks. Follow the instructions below to remove the extension from your specific browser.

Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2

Remove from Google Chrome

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2

Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.