Home Malware Programs Adware Genius Box

Genius Box

Posted: June 13, 2013

Threat Metric

Ranking: 2,875
Threat Level: 2/10
Infected PCs: 20,938
First Seen: June 13, 2013
Last Seen: October 15, 2023
OS(es) Affected: Windows

Genius Box is a browser add-on that currently is categorized as a Potentially Unwanted Program as a result of its questionable advantages, known drawbacks as an add-on and promotion by sites with confirmed ties to adware, browser hijackers and other PUPs. Although Genius Box is marketed as an add-on that helps you customize your web searches, Genius Box also includes advertisements that Genius Box sorts according to the keywords in your web-browsing history and also may change your homepage or redirect your searches. Presently, SpywareRemove.com malware researchers don't see much of a reason to avoid removing Genius Box, although they also have not seen Genius Box engaged in distributing PC threats that could be considered major security risks. To delete the browser changes related to Genius Box, as well as the actual Genius Box add-on, you usually should use specialized anti-malware software.

Genius Box: a Few Lines of Code Short of Being an Original Add-On

Even though Genius Box is being marketed as a completely original product, Genius Box actually appears to be part of a line of similar PUPs that are identical to Genius Box in everything but name, with another member verified as Genius Factory. The same company also is responsible for the PUP Translate Genius, and many of these questionable plugins, which SpywareRemove.com malware research team previously connected to various Potentially Unwanted Programs, adware programs and browser hijackers.

Using the path of least resistance typical to low-level PC threats, Genius Box claims to provide assistance with your online searches, but the most meaningful features about Genius Box all are related to its revenue-generating plan for its parent company. By displaying advertisements automatically, monitoring your browser history for topical information to transmit, and redirecting you to other websites, Genius Box makes money off of its users while providing negligible advantages, at best.

Outwitting this So-Called Genius Software

At this point, SpywareRemove.com malware experts haven't confirmed any reports of drive-by-downloads or even bundled installations that would indicate that Genius Box is being installed without the victim's consent, and thus, keeping abreast of the drawbacks in suspicious brands of browser add-ons should be sufficient to avoid a Genius Box installation.

PUPs usually resist being uninstalled, especially with respect to unwanted browser changes that can cause symptoms such as pop-ups or homepage hijacks. Anti-malware software usually should be capable of eliminating these issues efficiently while also removing Genius Box in any basic anti-malware scan. These symptoms also may affect most brands of browsers, including Internet Explorer, Firefox and Chrome, albeit only for Windows operating systems.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\TGF Interactive LLC\Translate Genius\TranslateGeniusAgent.exe File name: TranslateGeniusAgent.exe
Size: 53.23 KB (53232 bytes)
MD5: 370a5e83f1a04f134d42a541d3959082
Detection count: 7,722
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\TGF Interactive LLC\Translate Genius\TranslateGeniusAgent.exe
Group: Malware file
Last Updated: April 5, 2021
GeniusBoxInstaller.exe File name: GeniusBoxInstaller.exe
Size: 4.66 MB (4669456 bytes)
MD5: 21c1ef655f046ffe03928c3af86b8aab
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{413D8C2C-43F3-402F-95F0-6AB404692F8A}{709F3BE5-C718-4B6D-843C-95E8BE0E5E4A}{AC703A58-7A58-4891-9054-397867F43B45}File name without pathhttp_geniusbox.net_0.localstoragehttp_geniusbox.net_0.localstorage-journalhttp_geniusboxvideos.com_0.localstoragehttp_geniusboxvideos.com_0.localstorage-journalUninstall GeniusBox.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\GeniusBoxSoftware\geniusboxinstalledSoftware\GeniusBoxIUMSoftware\Microsoft\Internet Explorer\Approved Extensions\{709F3BE5-C718-4B6D-843C-95E8BE0E5E4A}Software\Microsoft\Internet Explorer\DOMStorage\geniusbox.netSoftware\Microsoft\Internet Explorer\DOMStorage\www.geniusbox.netSOFTWARE\Microsoft\Tracing\gb-installer_RASAPI32SOFTWARE\Microsoft\Tracing\gb-installer_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GeniusBoxSoftware\Search Extensions\GeniusBoxSOFTWARE\Wow6432Node\GeniusBoxSOFTWARE\Wow6432Node\Microsoft\Tracing\gb-installer_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\gb-installer_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\GeniusBox_setup_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\GeniusBox_setup_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{709F3BE5-C718-4B6D-843C-95E8BE0E5E4A}SOFTWARE\Wow6432Node\TGF Interactive\Genius BoxHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}GeniusBoxGeniusBoxBHO

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\TGF Interactive\Genius Box%APPDATA%\Microsoft\Windows\Start Menu\Programs\TGF Interactive\Genius Box%LOCALAPPDATA%\GeniusBox%LOCALAPPDATA%\GeniusBoxBHO%PROGRAMFILES%\GeniusBox%PROGRAMFILES%\TGF Interactive\Genius Box%PROGRAMFILES%\user extensions%PROGRAMFILES(x86)%\GeniusBox%PROGRAMFILES(x86)%\TGF Interactive\Genius Box%PROGRAMFILES(x86)%\user extensions%USERPROFILE%\Local Settings\Application Data\GeniusBox
The following URL's were detected:
Genius Box
Loading...