I believe this signature has been mislabeled as Windows only. The signature comes back as:
VIRUS NAME: Win.Trojan.Genieo TARGET TYPE: MACHO OFFSET: * DECODED SIGNATURE: okup__ZL20dtor_genieo_06041979v___tcf_0 stub which tells me it’s an OS X executable. Since it’s neither a false positive or false negative, I wasn’t sure how to report it. -Al- -- Al Varnell Mountain View, CA _______________________________________________ Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml