Want to highlight a helpful answer? Upvote!

Did someone help you, or did an answer or User Tip resolve your issue? Upvote by selecting the upvote arrow. Your feedback helps others! Learn more about when to upvote >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Genieo Virus

I was hit with a Genieo virus application that somehow got onto my Mac OS X 10.9.8 (MBP)

and installed itself into my login startup list.


This virus (we have to call it that as I did not ask for nor authorize it) must have been attached to

something else, though I am unsure how they did this.


When I tried to uninstall the program Genieo it ask me to install Java-6 to do it.

That was a BIG mistake because everything crash in my Mac.


So tomorrow I have an appointment in the Genius Bar, to check my computer.

My listing here is done for two reasons:

(1) to document that genio is

sending out virus (look up who to complain)

and (2) to ask the community for guidance in protecting

my Mac from further Genio (and other similar) intrusions.


However, any comments would be very appreciated.


Regards

iMac G5 with Mac OS X version 10.5.3, Mac OS X (10.5.3)

Posted on Nov 12, 2013 3:33 PM

Reply
Question marked as Best reply

Posted on Nov 12, 2013 3:36 PM

Helpful Links Regarding Malware Protection


An excellent link to read is Tom Reed's Mac Malware Guide.

Also, visit The XLab FAQs and read Detecting and avoiding malware and spyware.

See these Apple articles:


Mac OS X Snow Leopard and malware detection

OS X Lion- Protect your Mac from malware

OS X Mountain Lion- Protect your Mac from malware

About file quarantine in OS X


If you require anti-virus protection I recommend using VirusBarrier Express 1.1.6 or Dr.Web Light both from the App Store. They're both free, and since they're from the App Store, they won't destabilize the system. (Thank you to Thomas Reed for these recommendations.)

51 replies
Question marked as Best reply

Nov 12, 2013 3:36 PM in response to azteca24

Helpful Links Regarding Malware Protection


An excellent link to read is Tom Reed's Mac Malware Guide.

Also, visit The XLab FAQs and read Detecting and avoiding malware and spyware.

See these Apple articles:


Mac OS X Snow Leopard and malware detection

OS X Lion- Protect your Mac from malware

OS X Mountain Lion- Protect your Mac from malware

About file quarantine in OS X


If you require anti-virus protection I recommend using VirusBarrier Express 1.1.6 or Dr.Web Light both from the App Store. They're both free, and since they're from the App Store, they won't destabilize the system. (Thank you to Thomas Reed for these recommendations.)

Nov 12, 2013 5:16 PM in response to azteca24

Back up all data, then disable the "Genieo" spyware as follows.


Triple-click anywhere in the line below on this page to select it:

/Library/Frameworks/GenieoExtra.framework


Right-click or control-click the line and select


Services Reveal

from the contextual menu.* A folder should open with an item selected. Move the selected item to the Trash. You may be prompted for your administrator password.

Repeat with each of these lines:


/Library/LaunchAgents/com.genieo.engine.plist

/Library/LaunchAgents/com.genieoinnovation.macextension.plist

/Library/LaunchDaemons/com.genieoinnovation.macextension.client.plist

/Library/PrivilegedHelperTools/com.genieoinnovation.macextension.client


Then reboot. Note: Some of these items may be absent, in which case you'll get a message that the file doesn't exist.

From the Safari menu bar, select

Safari Preferences Extensions

Uninstall any extension you don't recognize. If in doubt, uninstall all extensions. Do the equivalent for the Firefox and Chrome browsers, if you use either of those.

*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar, paste into the box that opens (command-V). You won't see what you pasted because a line break is included. Press return.

This procedure may leave a few files behind, but it should render Genieo permanently non-functional, as long as you never reinstall it.

Nov 13, 2013 3:57 AM in response to azteca24

I see that the others have already got you covered with removal instructions. Regarding a couple other issues:


(1) to document that genio is

sending out virus (look up who to complain)


The security community is already well aware of Genieo. Unfortunately, Genieo manages to skate the line, and most anti-virus software will not identify it as malware.


(2) to ask the community for guidance in protecting

my Mac from further Genio (and other similar) intrusions.


I know you're probably wondering if you need to install anti-virus software in order to protect yourself from Genieo. The answer is no, for a couple reasons.


First, as I said earlier, Genieo is not detected as malware by most anti-virus software. Neither are a number of other similar adware programs. Even the worst of the lot doesn't rank detection by even 50% of the anti-virus software out there. So anti-virus software really won't help with this.


Second, the reason that programs like Genieo aren't identified as malware by anti-virus software depends in part on the fact that they're not deceptive enough. You may find a Genieo download posing as something else, but in every case I've ever seen or heard of, what gets downloaded is a file named "Install Genieo". If you went to download Adobe Flash Player, for example, and what you got was a file named Install Genieo, then you shouldn't have installed it.


So, to protect yourself against such things, be careful about what you're downloading and where you're downloading it from. Always download directly from the developer's site. (For example, Adobe Flash Player should never be downloaded from anywhere other than Adobe's web site.) Never download software from a download site, like Download.com or Softonic, both of which have been known to insert adware into downloaded installers. (Download.com is, in fact, still doing that, with no shame whatsoever.) And, if what is downloaded looks suspicious (for example, it doesn't have the same name as what you were trying to download), don't install it until you verify whether it is legit.

Nov 13, 2013 4:55 AM in response to azteca24

We are sorry to hear that you want to uninstall Genieo.

Genieo is a personalized newspaper - style home page. It has the power of bringing you the news you want, from your favorite sources and offers many unique features that can enrich your browsing experience and keep you up to date with interesting articles and item in your topics of interest.

Genieo is 100% free, it’s totally private and requires zero managements.

Should you decide to remove, please visit our FAQ page http://www.genieo.com/faq#uninstall

And simply follow the instructions.

Once you are done, you can go to your browser settings and change the default homepage and search to match your decision.

Chrome:

Home page:

http://support.google.com/chrome/bin/answer.py?hl=en&answer=95421&topic=1735105&ctx=topic

Search provider:

https://support.google.com/chrome/answer/95426?hl=en&ref_topic=14676

IE: http://support.microsoft.com/kb/252464

FF:

Home page:

https://support.mozilla.org/en-US/kb/How%20to%20set%20the%20home%20page

Search provider

https://support.mozilla.org/en-US/kb/search-bar-easily-choose-your-search-engine

Safari: http://browsers.about.com/od/safar1/ss/safarihomepage_3.htm


For further assistance please contact support@genieo.com

Feb 19, 2014 9:47 PM in response to azteca24

Look at this page which has link used by Genieo posing as a free download of Mac OS Maverick:

http://alvinalexander.com/mac-os-x/mac-schedule-mac-tasks-reminders-events-ical

And the people at Genieo are calling themselves legitimate. Not only does this malware hijack my browser, Safari, it also caused older applications requiring Rosetta to crash. I ended up having to do a complete reinstall which I'm still working on as files and application other than system have to be installed/transferred manually without the assist of migration program. Their uninstaller did not fix the problem.

Feb 20, 2014 12:25 AM in response to Genieo support

The uninstaller still does not work. The installmac uninstaller (another genieo product) actually adds software even where none existed beforehand.


Don't use the installmac uninstaller


InstallMac uninstaller antics


If anyone has the genieo adware, they should try to carefully follow one of these removal procedures : don't trust the uninstaller.


You installed the "Genieo" scam product.


or Adware Removal Guide : Genieo

Mar 18, 2014 12:05 AM in response to ladewigk

ladewigk wrote:


Playing around with trying to unistall Genieo over an hour finally found this and best advice out of all.

Linc's instructions are four months old now and he has updated instructions posted elsewhere in the forum. thomas_r.'s instructions @ Adware Removal Guide : Genieo are similarly updated as new variants of this and related adware are uncovered.

Apr 4, 2014 3:26 PM in response to azteca24

Thanks to all for the useful info here. Somehow Genieo was installed on my iMac. I am following the directions @ thomas_r.'s instructions @ Adware Removal Guide : Genieo and I am stuck. I can only find one of the .dylib files and I get this message: The folder “libgenkit.dylib” can’t be opened because you don’t have permission to see its contents. I am the administrator and am logged in as myself. Any suggestions please??

Apr 4, 2014 4:09 PM in response to jillc12

You can try booting up in safe mode (Hold shift during startup).


Or you can try holding Control + Clicking the file > Get info > Sharing and permissions > Unlock the lock at the bottom right.


Press + sign > Add your user to list of permissions > Give your self read and write privilege.


-Try removing it again.

Genieo Virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.