Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

How to remove osx.trojan.geneio-1

my macbook is infected with osx.trojan.geneio-1. It won't let safari run. ClamXav anti-virus found it and quarantined it, but machine still infected. How to remove this virus?

Posted on Feb 4, 2015 6:46 AM

Reply
Question marked as Best reply

Posted on Feb 4, 2015 9:51 AM

Hi Irmcvan. Clamxav does not get rid of al the file for this adware virus. One that I know does is Adware medic. but you need to be running 10.7 or higher to use it. You do not say what your operating system is so I will give you the link for adware medic. http://www.adwaremedic.com/index.php If you have to remove it manually,here is that link. http://www.wikihow.com/Delete-Genieo

15 replies
Question marked as Best reply

Feb 4, 2015 9:51 AM in response to lrmcvan

Hi Irmcvan. Clamxav does not get rid of al the file for this adware virus. One that I know does is Adware medic. but you need to be running 10.7 or higher to use it. You do not say what your operating system is so I will give you the link for adware medic. http://www.adwaremedic.com/index.php If you have to remove it manually,here is that link. http://www.wikihow.com/Delete-Genieo

Feb 4, 2015 10:51 AM in response to my ginger

Well it looks as though I was a little premature on that assessment. Safari still not working correctly. Unable to get to Preferences to change home page. Pop-up screens still popping up. Appears as though AdawareMedic did not even run, although it displayed scan complete - no adware found screen. Let me take another look.

Feb 4, 2015 11:39 AM in response to lrmcvan

Hi Irmcvan. I was going to tell you to delete the files that clamx quarantined, but you would need to go into the quarantined file to make sure that they are only the files for geneio. That other link I gave you shows the files that are part of this virus. You should write them down. As to safari. Are you saying that you cannot open safari preferences at all? Can you click safari upper left and click reset? And then try to use the preferences.You maystill have something in the extensions that is causing the popups.

Feb 4, 2015 11:59 AM in response to my ginger

Well thanks for your support here! This looks bad!



Yes I am unable to access Preferences or Extensions in Safari - greyed out.

Reset also greyed out.

Unable to take Snapshot or Scan in AdwareMedic - greyed out.

Running OS 10.7 on 13" macbook circa 2007.

Pop up in Safari directs me to www.geek-techies.com, but cannot go to ANY website in Safari. Cannot close the popup.

Looked in Applications for Geneio but its not listed, nor are any other related apps that AdwareMedic suggests I check (MPlayer, LightSpark etc.)

Do I have a more potent version of Genieo?


Will look over procedures for manually removing this malware.


How can I notify the author of the AdwareMedic app of this situation?

Feb 4, 2015 12:33 PM in response to lrmcvan

I think clamx grabbed some things out of safari it shouldn't have and and Quarantined them Did you look in the clamx quarantine file to see. In you home folder /library /preferences delete safari plist and try safari again. If still the same ,go and click on safari/about safari and take note of the version. Go to apple/support/ downloads/browse by product and inter into the search the safari version you have and download and then reinstall it. When you get to the support page the download and update link is down at the bottom.

Feb 4, 2015 2:13 PM in response to lrmcvan

lrmcvan wrote:


Unable to take Snapshot or Scan in AdwareMedic - greyed out.


I'm the author of AdwareMedic. Are you getting any kinds of error messages in AdwareMedic, or are all its menus and the buttons in its main window simply grayed out and unresponsive?


It sounds like you were able to run a scan earlier and it reported that no adware was found. Any files that ClamXav quarantined would not be detected, because they have been removed.

Feb 4, 2015 5:11 PM in response to thomas_r.

downloaded and ran your AdwareMedic, but did not see any change in behavior of Safari. home page still changed, Unable to delete popup or access menu items. Thought the Adware Medic was unsuccessful. Tried to run it again, and yes, the Scan and Snapshot menu options were greyed out. I'm thinking this is getting worse. But then I noticed a pop up window in Safari mentioned geek.techies.com

googling that led me to this site

https://sites.google.com/site/appleclubfhs/support/advice-and-articles/browser-p opup-hijack-safari

Realized I had two problems.The osx.trojan.genieo-1 was removed by your software, but now I had something else hijacking Safari.


removed two files, and was then able to reset safari and manually change homepage.

Did another scan with AdwareMedic and things look good.

Popups seem to be gone. Safari runs normally, but I wonder if I got it all or not.


Thank you so much for your concern and the AdwareMedic program.

Feb 7, 2015 4:50 PM in response to Genieo_support

There are times when I'm glad that I'm not at all smart enough to understand everything that's being said here.


All I know is my secretaries computer became compromised when she inadvertently allowed Genieo to install itself, after which she found it very difficult to get any work done, since much of her work was web based and she was perpetually interrupted by adverts popping up.


I ran Thomas's adwaremedic software and the problem was gone. I certainly wasn't going to trust anything from Genieo that's for sure.


There are times when you really don't need to be all smart to see what's going on. Adwaremedic works, why risk using anything else.

How to remove osx.trojan.geneio-1

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.