Jump to content

Removal instructions for Genieo


Recommended Posts

  • Staff
What is Genieo?

The Malwarebytes research team has determined that Genieo is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.

How do I know if my computer is affected by Genieo?

You may see these entries in your list of installed software:

warning4.png

and these warnings during install:

warning1.png

warning2.png

this new startpage:

startpage.png

and you will see these icons in your startmenu, taskbar and on your desktop:

icons.png

How did Genieo get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software.

How do I remove Genieo?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-{version}.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to:
    Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • If an update is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of Genieo?
  • No, Malwarebytes' Anti-Malware removes Genieo completely.
  • This PUP also installs the Java browser plugin if it was not pre-installed. It is up to the user if he wants to remove it or not.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Genieo hijacker. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

 

protection1.png


Technical details for experts

Possible signs in FRST logs:

 
 () C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe
 () C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe
 HKCU\...\Run: [GenieoUpdaterService] => C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe [294240 2015-05-17] ()
 HKCU\...\Run: [GenieoSystemTray] => C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe [539488 2015-05-17] ()
 FF SelectedSearchEngine: Search the web
 FF Homepage: hxxp://search.genieo.com/?v=genieo
 FF Keyword.URL: hxxp://search.genieo.com/results.html?v=genieo&q=
 FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\my-homepage.xml [2016-07-26]
 C:\Users\{username}\Desktop\Genieo.lnk
 C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Genieo
 C:\Users\{username}\AppData\Roaming\Genieo

Genieo (HKCU\...\genieo) (Version: 1.0.520 - Genieo Innovation Ltd.) <==== ATTENTION
ShortcutWithArgument: C:\Users\{username}\Desktop\Genieo.lnk -> C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe () -> hxxp://127.0.0.1:1886/extensions/redirect_to_startpage
ShortcutWithArgument: C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Genieo\Genieo.lnk -> C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe () -> hxxp://127.0.0.1:1886/extensions/redirect_to_startpage
FirewallRules: [{7950BEBA-22B2-4183-9764-D2B89233BD16}] => (Allow) LPort=1886
FirewallRules: [{6769A1E2-35A9-4AF4-9BC5-6D64DAFE594C}] => (Allow) LPort=1886
Alterations made by the installer:
 
File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Engine\bin
       Adds the file debugInfoCollector.exe"="5/17/2015 4:59 PM, 28000 bytes, A
       Adds the file debugInfoCollector.l4j.ini"="1/18/2010 5:39 PM, 115 bytes, A
       Adds the file genieo.l4j.ini"="1/18/2010 5:39 PM, 115 bytes, A
       Adds the file genieo_console.l4j.ini"="1/18/2010 5:39 PM, 118 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Engine\conf
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Engine\lib
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Engine\res
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\FirstTime
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\license\iehv
       Adds the file iehv.chm"="9/30/2009 10:18 AM, 15456 bytes, A
       Adds the file readme.txt"="9/30/2009 10:18 AM, 10543 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\license\MozillaHistoryView
       Adds the file MozillaHistoryView.chm"="9/30/2009 10:18 AM, 14618 bytes, A
       Adds the file readme.txt"="9/30/2009 10:18 AM, 6388 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\MiniFeedReader
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\genieo\bin
       Adds the file license.exe"="5/28/2015 3:50 PM, 78051 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\genieo\conf
       Adds the file partner.properties"="5/17/2015 4:52 PM, 11927 bytes, A
       Adds the file partnerBannedList.dat"="5/31/2010 2:48 PM, 66 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\genieo\css
       Adds the file miniview_partner.css"="5/23/2011 5:50 PM, 0 bytes, A
       Adds the file notify_partner.css"="8/27/2012 4:16 PM, 13 bytes, A
       Adds the file partner.css"="12/13/2011 2:08 PM, 1590 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\genieo\html
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\genieo\img
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\genieo\js
       Adds the file partnerConfig.js"="2/14/2011 1:26 PM, 937 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\genieo\text
       Adds the file en_text.properties"="5/29/2013 8:45 AM, 2021 bytes, A
       Adds the file fr_text.properties"="5/29/2013 8:45 AM, 2348 bytes, A
       Adds the file LicenseAgreement.txt"="5/29/2013 8:45 AM, 22952 bytes, A
       Adds the file ru_text.properties"="5/29/2013 8:45 AM, 3505 bytes, A
       Adds the file text.properties"="5/29/2013 8:45 AM, 2021 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\uninstall
       Adds the file genuninstallui.exe"="5/28/2015 3:50 PM, 64779 bytes, A
       Adds the file partner_uninstall.exe"="5/28/2015 3:50 PM, 42464 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\uninstall\genieo
       Adds the file genuninstallui.exe"="5/28/2015 3:50 PM, 64779 bytes, A
       Adds the file partner_uninstall.exe"="5/28/2015 3:50 PM, 42464 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\uninstall
       Adds the file firsttime_uninstall.exe"="7/26/2016 9:22 AM, 33397 bytes, A
       Adds the file framework_uninstall.exe"="7/26/2016 9:14 AM, 34521 bytes, A
       Adds the file trayapp_uninstall.exe"="7/26/2016 9:14 AM, 34453 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater
    Adds the folder C:\Users\{username}\AppData\Roaming\Genieo\Data
    Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Genieo
       Adds the file Genieo.lnk"="7/26/2016 9:22 AM, 2211 bytes, A
       Adds the file Uninstall Genieo.lnk"="7/26/2016 9:22 AM, 1337 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins
       Adds the file my-homepage.xml"="7/26/2016 9:15 AM, 755 bytes, A
    In the existing folder C:\Users\{username}\Desktop
       Adds the file Genieo.lnk"="7/26/2016 9:22 AM, 2219 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_CURRENT_USER\Software\Genieo]
       "active_hours"="REG_SZ", "2016-07-26_09"
       "client_localization"="REG_SZ", "en"
       "country_by_ip"="REG_SZ", "NL"
       "DataDir"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Data"
       "DisableUI"="REG_SZ", "0"
       "extracted_reported_campaign"="REG_SZ", "1"
       "extracted_reported_campaign_v0"="REG_SZ", "1"
       "InstallDir"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Application"
       "installed"="REG_SZ", "1"
       "InstalledVersion"="REG_DWORD", 18242
       "InstalledVersionPartner"="REG_DWORD", 18242
       "InstalledVersionUpdater"="REG_DWORD", 18242
       "ip_addr"="REG_SZ", "86.85.22.217"
       "ip_update_time"="REG_SZ", "1469517316042"
       "is_homepage_chrome"="REG_SZ", "0"
       "is_homepage_chrome_url"="REG_SZ", "http://search.genieo.com/?v=genieo"
       "is_homepage_ff"="REG_SZ", "1"
       "is_homepage_ff_url"="REG_SZ", "http://search.genieo.com/?v=genieo"
       "is_homepage_ie"="REG_SZ", "0"
       "is_homepage_ie_url"="REG_SZ", "http://search.genieo.com/?v=genieo"
       "is_search_provider_chrome"="REG_SZ", "0"
       "is_search_provider_ff"="REG_SZ", "1"
       "is_search_provider_ie"="REG_SZ", "1"
       "license_options"="REG_SZ", "set_homepage=1&set_searchProvider=1"
       "original_homepage_ff"="REG_SZ", "previous"
       "original_searchProvider_ff"="REG_SZ", "Google"
       "set_homepage"="REG_SZ", "1"
       "set_homepage_do_ff"="REG_SZ", "0"
       "set_searchProvider"="REG_SZ", "1"
       "set_searchProvider_do_ff"="REG_SZ", "0"
       "state"="REG_SZ", "2"
       "supported_langs"="REG_SZ", ";en;"
       "uid"="REG_SZ", "{1134A339-E326-4C9A-AE0A-0DC898B1DBD3}"
       "updater_status"="REG_SZ", "%2Fstatus%3Fday%3D0%26partner%3Dgenieo"
    [HKEY_CURRENT_USER\Software\Genieo\Components\FirstTime]
       "default_partner"="REG_SZ", "genieo"
       "DeskIconName"="REG_SZ", "Genieo"
       "Main"="REG_SZ", "1"
       "StartMenuName"="REG_SZ", "Genieo"
       "UninstallUrl"="REG_SZ", "http://www.genieo.com/uninstall/local/"
    [HKEY_CURRENT_USER\Software\Genieo\Components\Framework\Personalization Framework]
       "Path"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Application\Engine"
    [HKEY_CURRENT_USER\Software\Genieo\Components\Framework\Personalization Framework\Components]
       "Main"="REG_SZ", "1"
       "Upgrading"="REG_SZ", "0"
    [HKEY_CURRENT_USER\Software\Genieo\Components\Partner]
       "active_partner"="REG_SZ", "genieo"
       "default_partner"="REG_SZ", "genieo"
       "default_partner_version"="REG_SZ", "1.0.520"
       "install_monetizer_url"="REG_SZ", ""
       "installed_partner"="REG_SZ", "genieo"
       "Main"="REG_SZ", "1"
    [HKEY_CURRENT_USER\Software\Genieo\Components\TrayApp\Personalization Tray Application]
       "Path"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Application"
    [HKEY_CURRENT_USER\Software\Genieo\Components\TrayApp\Personalization Tray Application\Components]
       "Main"="REG_SZ", "1"
    [HKEY_CURRENT_USER\Software\Genieo\Components\Updater\Genieo]
       "FirstTime"="REG_SZ", "0"
       "LastComponentsUpdate"="REG_DWORD", 1469517768
       "log"="REG_SZ", "1"
       "Path"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater"
       "PostUpdateTask"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe"
       "PrepEnv"="REG_SZ", "0"
    [HKEY_CURRENT_USER\Software\Genieo\Components\Updater\Genieo\Components]
       "ComponentsRevision"="REG_DWORD", 18242
       "ComponentsUpdateRetries"="REG_DWORD", 0
       "LastUpdateTime"="REG_SZ", "2016 07 26 09 11"
       "Main"="REG_SZ", "1"
    [HKEY_CURRENT_USER\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
       "firefox_ext_dl"="REG_SZ", "60"
       "firefox_ext_inst"="REG_SZ", "10"
       "framework_dl"="REG_SZ", "0"
       "framework_inst"="REG_SZ", "0"
       "genieo_dl"="REG_SZ", "0"
       "genieo_inst"="REG_SZ", "0"
       "ieplugins_dl"="REG_SZ", "60"
       "ieplugins_inst"="REG_SZ", "10"
       "jre_dl_and_install"="REG_SZ", "0"
       "trayapp_dl"="REG_SZ", "0"
       "trayapp_inst"="REG_SZ", "0"
    [HKEY_CURRENT_USER\Software\Genieo\Properties]
    [HKEY_CURRENT_USER\Software\JavaSoft\Prefs\com]
    [HKEY_CURRENT_USER\Software\JavaSoft\Prefs\genieo]
       "active/Browser"="REG_SZ", "/U/N/K/N/O/W/N"
       "active/Browser/Last/Calc/Time"="REG_SZ", "1469517762839"
       "analytics/Report/Once/Done"="REG_SZ", "true"
       "campaign"="REG_SZ", "null"
       "chrome/Fix/No/New/Tab/Pref/Done"="REG_SZ", "true"
       "chrome_set/Homepage/Xed"="REG_SZ", "false"
       "counter_feeds_processed"="REG_SZ", "16"
       "counter_startpage_start_load"="REG_SZ", "2"
       "counter_startpage_user_active"="REG_SZ", "1"
       "counter_startpage_views_normal"="REG_SZ", "1"
       "data.version"="REG_SZ", "8"
       "debug/Mode"="REG_SZ", "false"
       "default/Browser"="REG_SZ", "/F/I/R/E/F/O/X"
       "default/Browser/Last/Calc/Time"="REG_SZ", "1469517762839"
       "enable.notification"="REG_SZ", "true"
       "end/Of/Bootstrap/Feed/Registration/Time"="REG_SZ", "1469517762776"
       "facebook.first/Login/Happened"="REG_SZ", "false"
       "feed/Update/Slot/Start"="REG_SZ", "1469517340073"
       "feeds/Db/Migration/Done"="REG_SZ", "true"
       "ff_set/Homepage/Xed"="REG_SZ", "false"
       "first/Time/Startpage/Opened"="REG_SZ", "1469517839810"
       "firsttime.show/Registration/Popoup"="REG_SZ", "2"
       "firsttime/Param"="REG_SZ", "p=genieo&u=http%3/A%2/F%2/Fsearch.genieo.com%2/F%3/Fv%3/Dgenieo&lang=en&user/Id=075/D5/E63/A/A/D21/B0/B/A054866/F49/B13316"
       "headlines.last/Update/Time"="REG_SZ", "1469517808651"
       "history/Sensor/Chrome-history/Update/Marker"="REG_SZ", "1469517762776"
       "history/Sensor/F/F-history/Update/Marker"="REG_SZ", "1469517762776"
       "history/Sensor/Opera-history/Update/Marker"="REG_SZ", "1469517762776"
       "history/Sensorie-history/Update/Marker"="REG_SZ", "1469517762776"
       "homepage_changed_from_genieo_ff"="REG_SZ", "/H/O/M/E/P/A/G/E_/N/O/T_/C/H/A/N/G/E/D"
       "ie_set/Homepage/Xed"="REG_SZ", "false"
       "installation/Time"="REG_SZ", "1469517315854"
       "last/Follow/Feeds/Calc/Time"="REG_SZ", "1469517762964"
       "last/Item/Html/Delete/Time"="REG_SZ", "1469517318448"
       "last/Rejected/Feeds/Clean/Time"="REG_SZ", "1469517762964"
       "last/Update/Preset/Config/Override/File"="REG_SZ", "1469517318448"
       "mainpage.sections"="REG_SZ", "0000000000000a"
       "pref.ver"="REG_SZ", "1"
       "prev/Engine/Version"="REG_SZ", "ver. 2.7.689, rev. 18242"
       "social/Bootstrap/Facebook/Last/Update/Time"="REG_SZ", "1469517808667"
       "social/Bootstrap/Twitter/Last/Update/Time"="REG_SZ", "1469517808667"
       "startpage.last.shown.items"="REG_SZ", "1469517899843"
       "startpage.tutorial.show"="REG_SZ", "true"
       "startpage/Last/Active/Time"="REG_SZ", "1469517853893"
       "visit/File/Last/Cleanup/Time"="REG_SZ", "1469517762964"
       "was/Startpage/Used"="REG_SZ", "1"
    [HKEY_CURRENT_USER\Software\JavaSoft\Prefs\genieo\bootstrap]
       "bootstrap_complete"="REG_SZ", "1469517762776"
       "bootstrap_download_and_handle_pages_complete"="REG_SZ", "1469517321260"
       "bootstrap_download_and_handle_pages_start"="REG_SZ", "1469517321260"
       "bootstrap_start"="REG_SZ", "1469517321104"
       "build_profile_complete"="REG_SZ", "1469517321276"
       "build_profile_start"="REG_SZ", "1469517321260"
       "crawl_for_portal_feeds_complete"="REG_SZ", "1469517336432"
       "crawl_for_portal_feeds_start"="REG_SZ", "1469517327714"
       "create_host_stats_complete"="REG_SZ", "1469517321292"
       "create_host_stats_start"="REG_SZ", "1469517321276"
       "detect_profile_complete"="REG_SZ", "1469517327667"
       "detect_profile_start"="REG_SZ", "1469517321307"
       "determine_download_candidates_start"="REG_SZ", "1469517321260"
       "freq_sites_creation_start"="REG_SZ", "1469517321292"
       "full_bootstrap_from_files_processing_complete"="REG_SZ", "1469517321260"
       "full_bootstrap_from_files_processing_start"="REG_SZ", "1469517321245"
       "generate_history_files_complete"="REG_SZ", "1469517321245"
       "generate_history_files_start"="REG_SZ", "1469517321104"
       "handle_files_complete"="REG_SZ", "1469517321276"
       "handle_files_start"="REG_SZ", "1469517321104"
       "prioritize_feeds_complete"="REG_SZ", "1469517327698"
       "prioritize_feeds_start"="REG_SZ", "1469517327698"
       "register_default_feeds_complete"="REG_SZ", "1469517327698"
       "register_default_feeds_start"="REG_SZ", "1469517327667"
       "update_feeds_complete"="REG_SZ", "1469517642760"
       "update_feeds_start"="REG_SZ", "1469517327698"
       "update_headelines_complete"="REG_SZ", "1469517362651"
       "update_headelines_start"="REG_SZ", "1469517327667"
    [HKEY_CURRENT_USER\Software\JavaSoft\Prefs\genieo\websync]
       "data/Changed/Since/Last/Sync"="REG_SZ", "true"
       "feed/Url"="REG_SZ", "http:\\my.genieo.com\feed\f5504ed023cf7f603f2d61980b8dcb12c662297b?v=1"
       "unique/Client/Id"="REG_SZ", "b792266c21bcd8b08916d2f306f7fc320de4055f"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
       "GenieoSystemTray"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe""
       "GenieoUpdaterService"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe" -wait 5"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\genieo]
       "DisplayIcon"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\uninstall\genieo\partner_uninstall.exe"
       "DisplayName"="REG_SZ", "Genieo"
       "DisplayVersion"="REG_SZ", "1.0.520"
       "EstimatedSize"="REG_DWORD", 28672
       "HelpLink"="REG_SZ", "http://www.genieo.com/faq"
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "Genieo Innovation Ltd."
       "UninstallString"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\uninstall\genieo\partner_uninstall.exe"
       "URLInfoAbout"="REG_SZ", "http://www.genieo.com/contact-us/"
Excerpt of the Malwarebytes Anti-Malware log (full log available on request):
 
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/26/2016
Scan Time: 9:34 AM
Logfile: mbamGenieO.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.07.26.03
Rootkit Database: v2016.05.27.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 317407
Time Elapsed: 8 min, 49 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe, 768, Delete-on-Reboot, [0893c7611783b18502f45152fe05f907]
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe, 3816, Delete-on-Reboot, [e1ba9c8c5b3f87af4ea7cdd6db28a65a]

Modules: 1
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Engine\lib\NativeUtils.dll, Delete-on-Reboot, [623958d09208ce6857ac5f4d39c9b34d], 

Registry Keys: 3
PUP.Optional.Genieo, HKCU\SOFTWARE\Genieo, Quarantined, [f0ab96922b6f48ee5ca9eda7030010f0], 
PUP.Optional.Genieo, HKCU\SOFTWARE\JAVASOFT\PREFS\genieo, Quarantined, [b7e472b6306a033339cd662e798a738d], 
PUP.Optional.Genieo, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\genieo, Quarantined, [306b2008e7b37bbbf116e6aede25db25], 

Registry Values: 2
PUP.Optional.Genieo, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GenieoUpdaterService, "C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe" -wait 5, Quarantined, [0893c7611783b18502f45152fe05f907]
PUP.Optional.Genieo, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GenieoSystemTray, "C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe", Quarantined, [e1ba9c8c5b3f87af4ea7cdd6db28a65a]

Registry Data: 0
(No malicious items detected)

Folders: 97
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Genieo, Quarantined, [702b62c6c1d9de58d51f2e75c24107f9], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo, Delete-on-Reboot, [623958d09208ce6857ac5f4d39c9b34d], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application, Delete-on-Reboot, [623958d09208ce6857ac5f4d39c9b34d], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Data, Delete-on-Reboot, [623958d09208ce6857ac5f4d39c9b34d], 

Files: 771
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.exe, Quarantined, [7526ae7ab0ea8ea86f331694b44d0000], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe, Quarantined, [2f6c6ebaf9a1c86e39efbb70b24f9d63], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\genieo_temp\genieo_setup.exe, Quarantined, [1883ba6e23770234d1d1e0cac93841bf], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\genieo_temp\InstallGenieo.exe, Quarantined, [316a9a8eb3e743f38d155654a75a738d], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\uninstall\updater_uninstall.exe, Quarantined, [653654d48911dc5a5250c5e545bc56aa], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Data\Updater\genieo_temp\framework_setup.gen, Quarantined, [b8e391971783c670f2b0adfdf011bd43], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Data\Updater\genieo_temp\genieo_setup.gen, Quarantined, [eab19395821859dd336fd4d60bf651af], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Data\Updater\genieo_temp\trayapp_setup.gen, Quarantined, [0e8de543bedcc76faef4694129d8d52b], 
PUP.Optional.Genieo, C:\Users\{username}\Desktop\InstallGenieo.exe, Quarantined, [82192008ddbdb185c761a8839071f709], 
PUP.Optional.Genieo, C:\Users\{username}\Desktop\Genieo.lnk, Quarantined, [a1fa65c31d7d2e08768ef99b699a46ba], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Genieo\Genieo.lnk, Quarantined, [702b62c6c1d9de58d51f2e75c24107f9], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Genieo\Uninstall Genieo.lnk, Quarantined, [702b62c6c1d9de58d51f2e75c24107f9], 
PUP.Optional.Genio, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\my-homepage.xml, Quarantined, [bcdfd553dfbbd165a6b0c822d42f0ef2], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe, Delete-on-Reboot, [0893c7611783b18502f45152fe05f907], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe, Delete-on-Reboot, [e1ba9c8c5b3f87af4ea7cdd6db28a65a], 
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "http://search.genieo.com/results.html?v=genieo&q=");), Replaced,[801b63c5b2e850e6c637158409fb639d]
PUP.Optional.Genieo, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "http://search.genieo.com), Replaced,[2675ff29e6b4cc6ac0a3b0efd23207f9]

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.