can't find Genieo virus on my Mac, but it shows in anti-virus scan

I don't see Genieo on the browsers or in Finder files, but it still shows up when I run a Sophos Ant-Virus scan. Using Firefox browser, I downloaded new software to save space on my Mac. I uninstalled Firefox and the program that saves space on Mac afterwords, but Genieo keeps showing up on Anti-Virus scan.


I'm slow when it comes to computers so if you give me instructions on how to uninstall it, please tell me what exactly to click on to follow the commands. I have a MacBook Pro 10.6.8. Thanks.

MacBook Pro, Mac OS X (10.6.8)

Posted on Jul 20, 2014 5:40 PM

Reply
24 replies

Jul 21, 2014 10:02 AM in response to MadMacs0

How do you bring up the Downloads folder? I only see it when I click on something to download. However, the download history has been deleted. I set it up to delete downloads after I shut off my computer (to save space on my computer if that saves space). I see AppleScript Editor under Today in search box, but no TSmart.zip.


Also, my computer screen often goes black and does not come back on if I hit keys. It freezes black so I have to press the power button to restart my computer. Is this what a browser crash is? How do I fix this problem?

Jul 21, 2014 2:18 PM in response to okaren

okaren wrote:


How do you bring up the Downloads folder?

It's in your home folder. Fastest way to open it would be to select "Downloads" from the Finder's Go menu. It should also be located next to the Trash Can on the left of your Dock.

I set it up to delete downloads after I shut off my computer (to save space on my computer if that saves space).

I'm unaware of any such setting. How are you able to do that?

I see AppleScript Editor under Today in search box, but no TSmart.zip.

Then you probably have elected to open safe downloads and it already decompressed TSMART.zip, so you should be looking for the folder or app called TSM Adware Removal Tool.

Also, my computer screen often goes black and does not come back on if I hit keys. It freezes black so I have to press the power button to restart my computer. Is this what a browser crash is?

That's something different than a browser crash. If you see this

User uploaded file

it's a Kernel Panic (your system crashed). Otherwise it's probably a hardware problem.

How do I fix this problem?

Start a new topic with a different subject and describe the problem. You'll get help faster from the right troubleshooters that way.


If you suspect hardware run the Apple Hardware Test while you are waiting.

Aug 1, 2014 7:41 AM in response to John Galt

When I did an EtreCheck, I found I have the genieocompleter downloaded. In simple terms, how do I remove this?


User Launch Agents:

[loaded] com.adobe.AAM.Updater-1.0.plist Support

[loaded] com.adobe.ARM.[...].plist Support

[loaded] com.genieo.completer.download.plist Support

[loaded] com.genieo.completer.update.plist Support

[loaded] com.google.keystone.agent.plist Support

Aug 1, 2014 8:20 AM in response to okaren

I was finally able to download the TSM Adware Removal Tool. However, when I tried to use it during start up, a message stated that I needed to log in as administrator to use it. See, I am using a titled guest account instead of the administrator account. I use both accounts, but I accidentally downloaded the genieo on the guest account. I was able to run the TSM Adware Removal Tool on the administrator account, but not the guest account. I don't know how to log in as administrator on the guest account. There is no password for the guest account, and i'm not sure how to set one up for guest account on 10.6.8 since I only saw option for administrator account.

Aug 1, 2014 11:12 PM in response to okaren

I thought thomas_r. might drop by, but it looks like he hasn't been around today. If he doesn't notice this I'll drop him a line in case he wants to provide a built-in solution for this.


I don't see any easy way to give the Guest User admin privileges, so for now it looks like manual removal is your only choice. Instructions for that are at Adware Removal Guide - Genieo.


Since you have already run the tool in your admin account, all the common files should be gone already so the only ones you need to worry about are the ones in Step 3 on that start with ~/Library/ which can be found by holding down the <Option/Alt> key down while selecting "Library" from the Finder's Go menu. The only other thing to do is check any browsers used by the Guest for extensions and settings in Steps 5 & 6.

Aug 2, 2014 6:21 PM in response to okaren

okaren wrote:


See, I am using a titled guest account instead of the administrator account. I use both accounts, but I accidentally downloaded the genieo on the guest account. I was able to run the TSM Adware Removal Tool on the administrator account, but not the guest account.


You shouldn't have been able to install it on the Guest account. Even if you could authenticate to an admin user to install software from the Guest account, any components installed in the Guest user folder would be removed as soon as you log out. Are you actually using a standard (non-admin) account that you have named Guest?


In the case of a standard account where you authenticated to admin for the purpose of installing the adware, that's a situation that never occurred to me. I'm honestly not sure how to handle that, as far as the Adware Removal Tool is concerned. Some of the components can only be removed with root permissions, which can only be achieved from an admin account with AppleScript. However, if you log in as a different user, you don't get to remove the files from the other user's folder. I'm going to have to carefully consider how to handle this.


In the meantime, as MadMacs0 says, you'll have to remove those items manually.


BTW, this is a perfect illustration of how using a non-admin account is not really much more secure - since you managed to authenticate to install something nasty with root permissions anyway - and can introduce some pretty serious inconveniences.

Aug 2, 2014 7:18 PM in response to thomas_r.

It was another user account I added that is not the administrator account. I had to log onto my administrator account and click on the other user account under Accounts in System Preferences. Then, I checked to "allow user to administer this computer." When I logged back onto the other user account, I was able to run the adware removal tool. I'm confused why I now needed a password to log onto this user account since I didn't need one before. I have a password for my administrator account, but not my other user accounts. When I tried connecting to the Internet, a message appeared to enter the keychain password. I have no idea what that is. I didn't know the password or even recall setting one up. When I clicked on change password, it still required the old password. Since I couldn't connect to the Internet due to this keychain issue, I logged back onto my administrator account and unchecked "allow user to administer this computer." Then, I logged back onto the other user account and the message for the keychain password didn't appear again. I have no idea why it required a keychain password in the first place since my administrator account does not require one before I connect to the Internet. Anyway, the TSM Adware Removal Tool finally got rid of the Genieo. So, please keep creating these automatic malware remover programs so one doesn't have to risk screwing up their computer by trying to remove it manually.

Aug 2, 2014 7:27 PM in response to okaren

okaren wrote:


It was another user account I added that is not the administrator account.

Sorry, I should have asked yesterday, but since you used the word "Guest" I took that too literally or I would have suggested you do exactly what you did.

When I tried connecting to the Internet, a message appeared to enter the keychain password. I have no idea what that is.

It's always the same as one's Login password unless you choose to change it to something else.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

can't find Genieo virus on my Mac, but it shows in anti-virus scan

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.