Genieo Virus

I was hit with a Genieo virus application that somehow got onto my Mac OS X 10.9.8 (MBP)

and installed itself into my login startup list.


This virus (we have to call it that as I did not ask for nor authorize it) must have been attached to

something else, though I am unsure how they did this.


When I tried to uninstall the program Genieo it ask me to install Java-6 to do it.

That was a BIG mistake because everything crash in my Mac.


So tomorrow I have an appointment in the Genius Bar, to check my computer.

My listing here is done for two reasons:

(1) to document that genio is

sending out virus (look up who to complain)

and (2) to ask the community for guidance in protecting

my Mac from further Genio (and other similar) intrusions.


However, any comments would be very appreciated.


Regards

iMac G5 with Mac OS X version 10.5.3, Mac OS X (10.5.3)

Posted on Nov 12, 2013 3:33 PM

Reply
51 replies

Apr 4, 2014 4:38 PM in response to jillc12

jillc12 wrote:


I can only find one of the .dylib files and I get this message: The folder “libgenkit.dylib” can’t be opened because you don’t have permission to see its contents.

You normally won't find all of the files listed. You must have accidentally double-clicked the file so it thinks you want to open it. Just click and hold on it once and drag it to the trash. You will be asked to authenticate it with your admin password.

Apr 4, 2014 8:02 PM in response to azteca24

Thanks for the suggestions. Ok, I have tried all of the above and am about to pull my hair out! I am by no means a computer guru. I am working off of a limited knowledge of being a "recreational" mac user for the last 10 years. I have to follow very specific instructions :) My iMac has not been updated to Maverick if that makes a difference? Believe it is 10.6.8 off the top of my head. The dylib file is the only one I can find on the list. I am definitely not double clicking it. Almost immediately it says no folder found but at the same time I get the message that I do not have permission to view it. Also, after this post earlier, I may be crazy but every time I tried to come to this discussion via my email on iMac (opened in Firefox) I would try to sign in and it would tell me "sorry request cannot be completed at this time"... Just in a plain black script looked nothing like the support site. Argh! So frustrated and don't know what to do next.

Don't want to sound stupid but is there not a program for mac like there are for other computers to detect these things and prevent/delete them??

Thanks for any help!

Apr 4, 2014 8:39 PM in response to jillc12

jillc12 wrote:


The dylib file is the only one I can find on the list. I am definitely not double clicking it. Almost immediately it says no folder found but at the same time I get the message that I do not have permission to view it.

OK, you didn't double-click it then what did you do just before you got this message? Are you looking at a Finder window labled /usr/lib/ and you see a file named libgenkit.dylib? Now you say almost immediately, but immediately after what action?

after this post earlier, I may be crazy but every time I tried to come to this discussion via my email on iMac (opened in Firefox) I would try to sign in and it would tell me "sorry request cannot be completed at this time"... Just in a plain black script looked nothing like the support site.

Not sure I'm following you on this. You use Firefox to read your e-mail? Then what, are you seeing a message with one of our replies and clicking the link that says view the full discussion then when you get to the site you need to Sign in in order to post? And clicking Sign in which should take you to a My Apple ID site where you enter your Apple ID and Password, but instead you see the sorry message?


I don't recall seeing this, but it's certainly possible that the Sign in site was either down or too busy at the time you tried. Since the sign in site is different from this site and services all Apple ID sign ins, it should not look like the forum.

Apr 4, 2014 8:56 PM in response to MadMacs0

Sorry if my info was not clear, I was getting a bit out of sorts over this stuff earlier! I will try to explain a bit better.


Yes, after opening mail and clicking the link to view the full discussion in Firefox I wasclicking "Sign In', entering my Apple ID and password, then getting the sorry message. Must have been unrelated, I was just a bit paranoid, because I was now able to sign in this way.



Here is how I am getting the permission message.....Finder, then Go to Folder. Cut and paste /usr/lib/libgenkit.dylib and as soon as I press "Go" in the grey Go to the Folder box it says "The folder can't be found" and almost simultaneously a second box pops up with the Finder icon (blue face?) that says "The folder “libgenkit.dylib” can’t be opened because you don’t have permission to see its contents." I then have to click on "OK". Am I doing something wrong or is there another issue?

Apr 4, 2014 9:13 PM in response to jillc12

jillc12 wrote:


Here is how I am getting the permission message.....Finder, then Go to Folder. Cut and paste /usr/lib/libgenkit.dylib

That's what I would have guessed.


The only thing that should be pasted into "Go to Folder" is /usr/lib/. That's the folder you want to look into. After that you just need to drag "libgenkit.dylib" (and any of the others should they also somehow be there) to the trash and authenticate the move.

Apr 4, 2014 9:29 PM in response to jillc12

jillc12 wrote:


the first file I am supposed to remove is /private/etc/launchd.conf Should that entire line not be copied and pasted as well?

It would be a good idea. It would seem that something has changed about libgenkit.dylib making it look like a folder or else, as Thomas indicated, permissions on that file have become corrupt in your case.

Apr 5, 2014 2:45 AM in response to MadMacs0

The only thing that should be pasted into "Go to Folder" is /usr/lib/. That's the folder you want to look into.


It's been a while since I've used Snow Leopard, but on more recent versions of Mac OS X, if you put a full path including a filename, such as "/usr/lib/libgenkit.dylib", into the Go to Folder window, then what should happen is that the folder (/usr/lib/ in this case) opens and the file (libgenkit.dylib) is selected.


MadMacs0, I know you still have a Snow Leopard system... can you test this on that and see if it behaves differently? If so, I need to make a modification to my instructions!

Apr 5, 2014 2:49 AM in response to thomas_r.

thomas_r. wrote:


It's been a while since I've used Snow Leopard, but on more recent versions of Mac OS X, if you put a full path including a filename, such as "/usr/lib/libgenkit.dylib", into the Go to Folder window, then what should happen is that the folder (/usr/lib/ in this case) opens and the file (libgenkit.dylib) is selected.

Which is what happens with my sample, but her's seems to be appearing as a directory. It's either a new variant or as you speculated before, permission corruption. If the former we should try to figure out where she got it from.

I know you still have a Snow Leopard system... can you test this on that and see if it behaves differently? If so, I need to make a modification to my instructions!

It may be awhile before I can get to that as I have way too much going on right now.

Apr 5, 2014 4:24 AM in response to andyBall_uk

andyBall_uk wrote:


You're welcome. There is a new version (new icon at least). Although it looks very similar, I've not tested an install yet. Newer files inside are dated 27 March.

Interesting. But the problem is that the installer is just a downloader that phones home for most of the payloads, so you can't really keep up with what all is actually being installed without testing it periodically.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Genieo Virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.