Strange activity, generic Installer keeps showing up on desktop

msintros

macrumors member
Original poster
Jul 7, 2014
67
0
Several times recently I will be working in Firefox typing away and all of a sudden I'll find myself typing into the password field of the window that pops up when you are asked by an installer to log in. I cancel this, because I obviously have not started any installation progresses and when I go to the desktop there is a disk image there called "Installer" that I did not download manually and in it is an installer called "Installer" saying to double click it. So far I have just trashed these. I have no idea where it's coming from or what it's attempting to install.

I'm not sure if it's related or not, but in an effort to find out where it came from I checked my system log and I am seeing a lot of activity like this:

12/17/14 1:23:14.556 AM InstallerS: file is nil
12/17/14 1:23:14.559 AM InstallerS: &safari_install_err=0,&safari_install= 0
12/17/14 1:23:14.560 AM InstallerS: downLoadBrowser unknown
12/17/14 1:23:14.560 AM InstallerS: urlString: http://genieo-installer.appspot.com...nguage=&safari_install_err=0&safari_install=0
12/17/14 1:23:14.578 AM com.genieo.completer.update: FSPathMakeRef(/Volumes/Installer 1/Installer.app) failed with error -43.
12/17/14 1:23:14.684 AM InstallerS: >>>>>>>> JSON string :{"status":400,"error":"Bad request"}
12/17/14 1:23:14.685 AM InstallerS: >>>>>>>> JSON dict :(null)
12/17/14 1:23:14.685 AM InstallerS: >>>>>>>> isMonetied :(null)
12/17/14 1:23:14.686 AM InstallerS: InstallMac >>>> installComplete : {"publisherApp":1,"isHideSplashWindow":0}
12/17/14 1:23:14.686 AM InstallerS: >>>>>InstallMac onNewRequest event
12/17/14 1:23:14.686 AM InstallerS: >>>>>InstallMac onNewRequest URL : action://terminate?language=
12/17/14 1:24:13.593 AM com.amazon.cloud-player: objc[218]: Object 0x4a9ab0 of class __NSCFString autoreleased with no pool in place - just leaking - break on objc_autoreleaseNoPool() to debug
12/17/14 1:24:13.593 AM com.amazon.cloud-player: objc[218]: Object 0x187edf0 of class NSURL autoreleased with no pool in place - just leaking - break on objc_autoreleaseNoPool() to debug
12/17/14 1:24:13.593 AM com.amazon.cloud-player: objc[218]: Object 0x188b2b0 of class __NSCFString autoreleased with no pool in place - just leaking - break on objc_autoreleaseNoPool() to debug
12/17/14 1:24:13.594 AM com.amazon.cloud-player: objc[218]: Object 0x1e84fe0 of class __NSCFString autoreleased with no pool in place - just leaking - break on objc_autoreleaseNoPool() to debug
12/17/14 1:24:13.594 AM com.amazon.cloud-player: objc[218]: Object 0x187edf0 of class NSURL autoreleased with no pool in place - just leaking - break on objc_autoreleaseNoPool() to debug
12/17/14 1:24:13.594 AM com.amazon.cloud-player: objc[218]: Object 0x1e85110 of class __NSCFString autoreleased with no pool in place - just leaking - break on objc_autoreleaseNoPool() to debug
12/17/14 1:24:44.555 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10900]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:24:44.555 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10900]) Exited with code: 1
12/17/14 1:24:44.555 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:26:24.580 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10932]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:26:24.581 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10932]) Exited with code: 1
12/17/14 1:26:24.581 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:28:04.605 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10943]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:28:04.605 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10943]) Exited with code: 1
12/17/14 1:28:04.605 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:29:44.630 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10953]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:29:44.631 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10953]) Exited with code: 1
12/17/14 1:29:44.631 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:30:17.498 AM login: USER_PROCESS: 10960 ttys000
12/17/14 1:30:37.349 AM login: DEAD_PROCESS: 10960 ttys000
12/17/14 1:31:24.657 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10975]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:31:24.658 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10975]) Exited with code: 1
12/17/14 1:31:24.658 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:33:04.684 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10985]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:33:04.684 AM com.apple.launchd: (com.digidesign.fwfamily.helper[10985]) Exited with code: 1
12/17/14 1:33:04.684 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:34:44.709 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11001]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:34:44.710 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11001]) Exited with code: 1
12/17/14 1:34:44.710 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:36:24.736 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11012]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:36:24.737 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11012]) Exited with code: 1
12/17/14 1:36:24.737 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:38:04.764 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11022]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:38:04.764 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11022]) Exited with code: 1
12/17/14 1:38:04.764 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
12/17/14 1:39:44.791 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11032]) posix_spawn("/Library/Application Support/Digidesign/FireWire/DigidesignFireWireHelper", ...): No such file or directory
12/17/14 1:39:44.791 AM com.apple.launchd: (com.digidesign.fwfamily.helper[11032]) Exited with code: 1
12/17/14 1:39:44.791 AM com.apple.launchd: (com.digidesign.fwfamily.helper) Throttling respawn: Will start in 10 seconds
I don't have any Digidesign components that I'm aware of, so I'm not sure what this process is. Also I see a reference to Amazon cloud player, whatever that is. Does this make sense to anyone? Thanks.
 

aicul

macrumors 6502a
Jun 20, 2007
809
7
no cars, only boats
Strange indeed

I would consider these first actions

- check in preferences if there is an entry in your user-id startup items

- if your account has admin privs; create a new account with admin privs and demote your user-id to standard
 

msintros

macrumors member
Original poster
Jul 7, 2014
67
0
I did figure out one thing: I am pretty sure the thing trying to install itself is Genieo, which apparently is debatably malware. I am currently looking at this page: http://www.thesafemac.com/arg-genieo/ and it looks like many of these files are on my computer, although not the ones that would be there if the program had been actually installed. I'm taking the steps it suggests in removing them.

As for the digidesign entries in that log, I'm still not sure what that's about or how to figure out what program or action is trying to run.
 

busyangel1

macrumors newbie
Aug 30, 2008
5
0
Philly, PA
Uninstall Genio, InstallMac, Omnibar Firefox browser extension

These are ever changing guerrilla adware/ malware programs. I know i got it from downloading a file from CNET. This is hidden in an installer with options to install other programs checked and greyed out sometimes below the un-scrolled text window. If you ever see this after scrolling the text box, delete the installer and find the program or updater on the developers site ....even if its slow. Don't update software when overly tired as this is how I missed it and I'm a fairly advanced user.

Here's a link with detailed information on deleting these ##$** programs.
Of course the very best way is to be patient and just get your updates from slower developer sites and stay away from CNET and other pages that indiscriminately sell space to these hacker malware links that are characterized by crowded blinking buttons and mini frames on the same page urging you to quickly download your searched for, or pop-up updates.
Here's the link:

http://www.thesafemac.com/arg-genieo/

PS if you are not comfortable using some of these methods find a friend who is.
Try installing ClamXAV (MacWorld ed.choice award)to check for and uninstall malware/adware.
Good luck and happy computing.
 
Last edited:
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.