Genieo Search – a fake search tool that specializes in showing Mac users sponsored content for profit
Genieo Search – a browser hijacker which uses “bundling” or other rogue websites to enter the user’s computer system and infect web browsers.
Genieo Search, also known as Go.searchgenieo.com, is a potentially unwanted program, which can start pushing sponsored content via Internet Explorer, Google Chrome, Mozilla Firefox or other web browsers out of nowhere. It is part of Genieo adware[1], which is also known as „content recommendation“ software.
Initially not considered malicious, Genieo Search was seen being installed on thousands of users’ Macs via software bundle packages and then modifying browsers’ homepage, URL bar, and default search engine without asking for the users’ permission. However, as the time went by, new versions of Genieo Search virus were seen intercepting macOS’ Keychain, which grants access to users sensitive data, such as credit card details, usernames, passwords, etc.[2]
Genieo Search deception does not finish there, however, as it is also known to be distributed via fake Flash Player updates, and is also often offered via various shady software installers that use deception in order to make users install the browser-hijacking application on Macs.
Name | Genio Search |
---|---|
Homepage | Go.searchgenieo.com |
Type | Adware, browser hijacker |
Targeted systems | macOS |
Release date | 2013 |
Propagation | Users install the potentially unwanted program unintentionally – they are often tricked by a fake Flash Player update. Malware was also found being presented as a codec needed to view various videos on Macs. Finally, software bundling is also often used to distribute Genio on third-party websites like Softonic |
SYMPTOMS | Installs an extension on the browser, displays ads on all visited sites, sets search.genieo.com as a homepage and new tab and redirects all searches to Yahoo, promotes potentially dangerous software |
Risks | Installation of other potentially unwanted applications, malware infection, sensitive data disclosure to malicious parties (cybercriminals), money loss, identity fraud, etc. |
Removal | You can get rid of the PUP automatically by using anti-malware software or by following manual removal guide below |
optimization | Scan your macOS with Reimage Reimage Cleaner to optimize it |
For a long time, Genieo virus started bothering Mac users,[3], and soon was included in Apple’s XProtect anti-malware services database – listed as malware – and rightfully so. A potentially unwanted application that can gain access to most private user data is malicious and should be terminated as soon as possible.
Once installed, Genieo Search changes the infected browser’s homepage setting it to search.genieo.com and adds this search site as the main search provider. While the PUP sets a customized search engine, it redirects all searches to Yahoo, although it diverts users to non-organic search results, i.e., top links are sponsored ads that benefit Genieo Search financially as long as users click on them. This behavior can only be stopped by terminating the PUP.
Nevertheless, such browser-hijacking apps[4] can redirect you not only to developer-promoted pages but also to potentially dangerous ones. In order to avoid such unwanted consequences, you need to remove Genio Search virus from your computer system permanently and get rid of all PUP-added content from your affected web browsers.
Finally, it is known that Genieo Search may start collecting information about people’s browsing habits and accumulate information about their search terms, most visited websites, time that they spend there, data that they enter, saved bookmarks, pictures, and videos viewed, IPs, etc. If you don’t want to run into privacy-related issues, you should be very careful with that.
If you never intended to install Genieo Search on your computer, you should follow a guide that is given below and get rid of this browser hijacker. Of course, the easiest way to do this is to run a full system scan with updated anti-malware, although you can also perform a full Genieo Search removal manually by following our guide below.
Additionally, we highly recommend scanning the machine with Reimage Reimage Cleaner for the best results, as well as resetting all the installed browsers.
Genio Search PUP – a browser hijacker-related app which modifies the browser’s settings and changes the default search engine.
Everything you need to know about Genieo on Mac
Genieo on Mac is a potentially unwanted program that can arrive in tandem with another application or be installed after clicking on an Internet ad promoting it. Once installed, it drops a bunch of files onto Mac OS to set itself up and remain on the computer as long as it is possible. DieViren.de experts[5] advise removing this unwanted application from Mac as soon as possible, although it can seem like a challenging task at first.
Mac users have been complaining about ads, redirects, altered search settings and other problems caused by Genieo Search virus. Despite being non-malicious, this browser hijacker-related software tracks the user at all times and keeps delivering even more Internet ads daily. Besides, users have noticed that Genieo keeps coming back even after removing its components from the system.
If you have been experiencing problems when trying to remove Genieo from Mac, please read the full instructions on how to do it properly. We have added the directions right below this article and also provided informative screenshots to help you locate and delete Genieo-related files from OS X.
Strategies used for promotion of suspicious programs
According to IT experts, various potentially unwanted programs such as browser-hijacking apps are promoted by spreading them through suspicious websites. Third-party websites often might include unwanted content in a form of a link which, once clicked, might relate in a secret installation of the potentially unwanted application. To avoid such risk, stay away from all questionable web pages.
Furthermore, browser hijackers are very likely to be spread via a deceptive marketing technique called “bundling”[6]. Such PUPs and all their components come included together with regular software that users download from the Internet. You can avoid such secret installation if you choose the Custom/Advanced installation mode over the Quick/Recommended one. Here you will be able to control all incoming downloads and opt-out the unwanted ones.
Remove Genieo Search from Mac or Windows
Genieo Search – a PUP which can redirect you to potentially dangerous websites.
Complaints shared by affected computer users prove that it can be tough to remove Genieo Search virus from Mac or Windows. The browser-hijacking application leaves a variety of files on the system and tries to stay undetected. Typically, users identify the issue causing browser redirects and ads only after running a security software on the affected computer.
Therefore, if your security software detected PUP.Genieo or a similar entry on your system, make sure you wipe the suspicious files using an anti-spyware or anti-malware program. You can use a computer security application from our suggested list or feel free to perform the elimination by using any program of your own.
You can also try to perform Genieo Search removal manually – here are the files you need to delete from your system after making sure that the app is not running the in the background via the Activity Monitor:
- /Applications/Genieo
- /Applications/InstallMac
- /Applications/Uninstall Genieo
- /Applications/Uninstall IM Completer.app
- ~/Library/Application Support/com.genieoinnovation.Installer/
- ~/Library/Application Support/Genieo/
- ~/Library/LaunchAgents/com.genieo.completer.download.plist
- ~/Library/LaunchAgents/com.genieo.completer.update.plist
- /Library/LaunchAgents/com.genieoinnovation.macextension.plist
- /Library/LaunchAgents/com.genieo.engine.plist
- /Library/LaunchAgents/com.genieo.completer.update.plist
- /Library/LaunchDaemons/com.genieoinnovation.macextension.client.plist
- /Library/PrivilegedHelperTools/com.genieoinnovation.macextension.client
- /usr/lib/libgenkit.dylib
- /usr/lib/libgenkitsa.dylib
- /usr/lib/libimckit.dylib
- /usr/lib/libimckitsa.dylib
You may remove virus damage with a help of Reimage Reimage Cleaner . SpyHunter 5Combo Cleaner and Malwarebytes are recommended to detect potentially unwanted programs and viruses with all their files and registry entries that are related to them.
Remove Genieo Search from Windows systems
To remove Genieo Search virus from Windows computer, use given guidelines. However, experts hardly ever recommend deleting this computer infection manually:
- Click Start → Control Panel → Programs and Features (if you are Windows XP user, click on Add/Remove Programs). Windows 10 / Windows 8 user, then right-click in the lower left corner of the screen. Once Quick Access Menu shows up, select Control Panel and Uninstall a Program.
- Uninstall Genieo Search and related programs
Here, look for Genieo Search or any other recently installed suspicious programs. - Uninstall them and click OK to save these changes.
- Remove Genieo Search from Windows shortcuts
Right click on the shortcut of Mozilla Firefox and select Properties. - Go to Shortcut tab and look at the Target field. Delete malicious URL that is related to your virus.
Repeat steps that are given above with all browsers’ shortcuts, including Internet Explorer and Google Chrome. Make sure you check all locations of these shortcuts, including Desktop, Start Menu and taskbar.
Erase Genieo Search from Mac OS X system
To remove Genieo Search on Mac, follow the given directions and clear the Applications folder from Genieo virus remains:
- If you are using OS X, click Go button at the top left of the screen and select Applications.
- Wait until you see Applications folder and look for Genieo Search or any other suspicious programs on it. Now right click on every of such entries and select Move to Trash.
Eliminate Genieo Search from Internet Explorer (IE)
If Internet Explorer got hijacked, you can perform these steps to eliminate all unwanted components from the web browser:
- Remove dangerous add-ons
Open Internet Explorer, click on the Gear icon (IE menu) on the top right corner of the browser and choose Manage Add-ons. - You will see a Manage Add-ons window. Here, look for Genieo Search and other suspicious plugins. Disable these entries by clicking Disable:
- Change your homepage if it was altered by virus:
Click on the gear icon (menu) on the top right corner of the browser and select Internet Options. Stay in General tab. - Here, remove malicious URL and enter preferable domain name. Click Apply to save changes.
- Reset Internet Explorer
Click on the gear icon (menu) again and select Internet options. Go to Advanced tab. - Here, select Reset.
- When in the new window, check Delete personal settings and select Reset again to complete Genieo Search removal.
Uninstall Genieo Search from Microsoft Edge
Microsoft Edge can be a target of various potentially unwanted programs too. If such thing happened, perform the cleaning process by reading these guidelines:
Reset Microsoft Edge settings (Method 1):
- Launch Microsoft Edge app and click More (three dots at the top right corner of the screen).
- Click Settings to open more options.
- Once Settings window shows up, click Choose what to clear button under Clear browsing data option.
- Here, select all what you want to remove and click Clear.
- Now you should right-click on the Start button (Windows logo). Here, select Task Manager.
- When in Processes tab, search for Microsoft Edge.
- Right-click on it and choose Go to details option. If can’t see Go to details option, click More details and repeat previous steps.
- When Details tab shows up, find every entry with Microsoft Edge name in it. Right click on each of them and select End Task to end these entries.
Resetting Microsoft Edge browser (Method 2):
If Method 1 failed to help you, you need to use an advanced Edge reset method.
- Note: you need to backup your data before using this method.
- Find this folder on your computer:
C:\Users\%username%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe.
- Select every entry which is saved on it and right click with your mouse. Then Delete option.
- Click the Start button (Windows logo) and type in window power in Search my stuff line.
- Right-click the Windows PowerShell entry and choose Run as administrator.
- Once Administrator: Windows PowerShell window shows up, paste this command line after PS C:\WINDOWS\system32> and press Enter:
Get-AppXPackage -AllUsers -Name Microsoft.MicrosoftEdge | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register $($_.InstallLocation)\AppXManifest.xml -Verbose}
Once these steps are finished, Genieo Search should be removed from your Microsoft Edge browser.
Delete Genieo Search from Mozilla Firefox (FF)
You can clean your Mozilla Firefox web browser form all suspicious content by using these guidelines:
- Remove dangerous extensions
Open Mozilla Firefox, click on the menu icon (top right corner) and select Add-ons → Extensions. - Here, select Genieo Search and other questionable plugins. Click Remove to delete these entries.
- Change your homepage if it was altered by virus:
Click on the menu (top right corner), choose Options → General. - Here, delete malicious URL and enter preferable website or click Restore to default.
- Click OK to save these changes.
- Reset Mozilla Firefox
Click on the Firefox menu on the top left and click on the question mark. Here, choose Troubleshooting Information. - Now you will see Reset Firefox to its default state message with Reset Firefox button. Click this button for several times and complete Genieo Search removal.
Get rid of Genieo Search from Google Chrome
If Google Chrome got infected with the browser-hijacking application, you should follow the instructions to get rid of all unwanted components from your browser:
- Delete malicious plugins
Open Google Chrome, click on the menu icon (top right corner) and select Tools → Extensions. - Here, select Genieo Search and other malicious plugins and select trash icon to delete these entries.
- Change your homepage and default search engine if it was altered by your virus
Click on menu icon and choose Settings. - Here, look for the Open a specific page or set of pages under On startup option and click on Set pages.
- Now you should see another window. Here, delete malicious search sites and enter the one that you want to use as your homepage.
- Click on menu icon again and choose Settings → Manage Search engines under the Search section.
- When in Search Engines…, remove malicious search sites. You should leave only Google or your preferred domain name.
- Reset Google Chrome
Click on menu icon on the top right of your Google Chrome and select Settings. - Scroll down to the end of the page and click on Reset browser settings.
- Click Reset to confirm this action and complete Genieo Search removal.
Remove Genieo Search from Safari
Clean and refresh Safari by performing our given instructions:
- Remove dangerous extensions
Open Safari web browser and click on Safari in menu at the top left of the screen. Once you do this, select Preferences. - Here, select Extensions and look for Genieo Search or other suspicious entries. Click on the Uninstall button to get rid each of them.
- Change your homepage if it was altered by virus:
Open your Safari web browser and click on Safari in menu section. Here, select Preferences as it was displayed previously and select General. - Here, look at the Homepage field. If it was altered by Genieo Search, remove unwanted link and enter the one that you want to use for your searches. Remember to include the “http://” before typing in the address of the page.
- Reset Safari
Open Safari browser and click on Safari in menu section at the top left of the screen. Here, select Reset Safari…. - Now you will see a detailed dialog window filled with reset options. All of those options are usually checked, but you can specify which of them you want to reset. Click the Reset button to complete Genieo Search removal process.