Author: Rhena Inocencio   

 

AdWare.OSX.Geonei.b (Kaspersky), OSX/Adware.Genieo.A (ESET)

 PLATFORM:

Mac OS X

 OVER ALL RISK RATING:
 DAMAGE POTENTIAL::
 DISTRIBUTION POTENTIAL::
 REPORTED INFECTION:
 INFORMATION EXPOSURE:
Low
Medium
High
Critical

  • Threat Type:
    Adware

  • Destructiveness:
    No

  • Encrypted:
    No

  • In the wild::
    Yes

  OVERVIEW

Puede haberlo instalado manualmente un usuario.

  TECHNICAL DETAILS

File size: 495,439 bytes
File type: Other
Memory resident: Yes
INITIAL SAMPLES RECEIVED DATE: 10 de сентября de 2014
PAYLOAD: Displays message/message boxes, Connects to URLs/IPs, Steals information

Detalles de entrada

Puede haberlo instalado manualmente un usuario.

Instalación

Este malware infiltra el/los siguiente(s) archivo(s)/componente(s):

  • /private/etc/launchd.conf - detected as OSX_GEONCONF.SM or OSX_GEONCONF.SMA
  • /users/{user}/Library/Application Support/com.genieoinnovation.Installer/Completer.app
  • /users/{user}/Library/Caches/com.genieoinnovation.Installer/Cache.db
  • /Library/LaunchAgents/com.genieo.competer.update.plist
  • /Library/LaunchAgents/com.genieo.competer.download.plist
  • /Applications/InstallMac/Reset Search.app
  • /users/{user}/Library/Saved Application State/info.leifertin.Ez7z.savedState/windows.plist
  • /users/{user}/Library/Saved Application State/info.leifertin.Ez7z.savedState/data.data
  • /users/{user}/Library/Saved Application State/info.leifertin.Ez7z.savedState/window_{number}.data
  • /users/{user}/Library/Preferences/info.leifertin.Ez7z.plist
  • /users/{user}/Library/Application Support/Ez7z-QuickLook
  • /users/{user}/Library/Application Support/Ez7z.prefs
  • /Applications/Ez7z.app

  SOLUTION

Minimum scan engine: 9.700
First VSAPI Pattern File: 11.142.04
First VSAPI Pattern Release Date: 11 de сентября de 2014
VSAPI OPR PATTERN-VERSION: 11.143.00
VSAPI OPR PATTERN DATE: 12 de сентября de 2014
Did this description help? Tell us how we did.