Q: Removing Genieo Files
So today I decided to run a scan of my computer files and so downloaded Clamxav. The scan returned a couple of Genieo files, which I don't recall ever installing. A bit of research showed these to likely be malware, and so I would like to get rid of them.
I referenced the Adware Removal Guide: Genieo on The Safe Mac (http://www.thesafemac.com/arg-genieo/) and attempted to follow the step-by-step removal process. However, I've hit a number of roadblocks.
The biggest "problem," if you could call it that, is that most of the files mentioned on the list are not showing up on my computer, either through manual path following or via terminal.
Clamxav returned only three results: Completer.app, Application.app (which is within Completer.app), and a Safari extension called Omnibar. Looking up each of the files specified on The Safe Mac guide, all I can find are:
~/Library/Application Support/com.genieoinnovation.Installer/
~/Library/LaunchAgents/com.genieo.completer.download.plist
~/Library/LaunchAgents/com.genieo.completer.update.plist
and also the "my-homepage.xml" listed in ~/Library/Application Support/Firefox/Profiles/
According to The Safe Mac guide, it's possible that Genieo isn't actually installed on my computer, but rather that some of the files were downloaded but, for one reason or another, were never installed. If those four files (plus Omnibar) are all that are present, then I should be able to delete them without any issues.
The reason I began this process in the first place was that I got a sudden pop-up warning on Safari saying that malware may have been installed. However, the pop-up itself seemed somewhat fishy, as it prevented me from doing anything on Safari. I was forced to quit Safari in order to do anything again, but I haven't noticed any changes or problems. I did find Omnibar under the Extensions category of Sarari Preferences, but I simply clicked to uninstall it and it went away without a fuss.
It's worth mentioning that all of the Genieo files I can find were last modified in July of this year, indicating that that's when they were downloaded and that they've been inactive since then.
So, after all that, my questions are twofold:
1. Is it safe to delete these few files from my computer? Since I can't find the noteworthy /private/etc/launchd.conf file mentioned on The Safe Mac it should be okay, but even so I figured I'd check first.
2. Are there any more potential problems I should be looking for?
All this fuss is due to the repeated warnings I've seen that failing to properly delete Genieo files in the correct order could permanently freeze my computer. I've already been through one broken hard drive, and I'm not looking to repeat the experience.
Thanks in advance for any help.
MacBook Pro, Mac OS X (10.6.8)
Posted on Sep 6, 2014 12:44 PM