how to remove weknow.ac from safari

Friend has Macbook. Managed to get weknow.ac installed from a fake adobe flash update.


Has highjacked Safari and she won't use any other browser. I deleted all the stuff I can see from the applications folder that look like secondary installs. But browser homepage can't be reset - blocked from changes.


I googled and found a ton of programs to do this but all have to be bought. Is there a manual procedure? And if not, what's the best removal program to install to get this done now and the next time she does this?


Thanks.

MacBook Pro (15-inch Late 2008)

Posted on Jul 7, 2018 12:51 AM

Reply
Question marked as Top-ranking reply

Posted on Jul 19, 2018 1:11 PM

I was running Malwarebytes when my Mac got infected. Malwarebytes was able to quarantine it but that didn't fix the browser issue. Their customer service department was able to help out about how to fix the browser issue once the other files were quarantined. Here was their advice:


Thomas Reed(Malwarebytes Support)

Jul 19, 05:48 PDT

Jim,


It looks like you have an adware-related configuration profile installed, which is preventing you from changing your home page setting.


To remove this, open System Preferences, then click the Profiles icon. You should see either two or three different items listed. One of them appears to be legitimate, but the other two (they may be combined into one entry) are not. You can identify which is bad by looking at the information for each profile. The bad entry (or entries) will say "com.myshopcoupon" somewhere, and should also refer to "weknow.ac". Any such entries should be removed. Leave the profile that refers to "com.Infomaniak", as I believe that one is legitimate.


After removing the profile, you'll need to fix the home page settings.

26 replies

Aug 20, 2018 4:20 AM in response to ibrahimswift52

The problem is that the weknow malware creates an alternate profile that will keep changing the search engine. I got this from Malwarebytes and it worked for me:


To remove this, open System Preferences, then click the Profiles icon. You should see either two or three different items listed. One of them appears to be legitimate, but the other two (they may be combined into one entry) are not. You can identify which is bad by looking at the information for each profile. The bad entry (or entries) will say "com.myshopcoupon" somewhere, and should also refer to "weknow.ac". Any such entries should be removed. Leave the profile that refers to "com.Infomaniak", as I believe that one is legitimate.


After removing the profile, you'll need to fix the home page settings.

Sep 12, 2018 7:39 PM in response to Akphotog83

I contacted Apple Support Chat just now with an Advisor, and it was fairly simple to resolve.


1) First, search for Malwarebytes and download it (it's legitimate, don't worry!). Install it, and run "Scan".


2) After it's finished scanning, don't click anything on Malwarebytes yet. Clear all history and data on *all* of your web browsers. Check Extensions, too (e.g. click on upper left "Safari", on the drop-down menu click "Preferences", then go to "Extensions"), and make sure nothing on there is suspicious, or that you don't remember having installed.


3) Quit your web browsers, then click "Confirm", and Malwarebytes will remove the detected threats for you. Just to be sure, you can double check by scanning again, after it deletes the threats. It should say "Congratulations, all clear!" or something of that sort.


The best way to also check that it's really gone - and this is for Chrome users - is to check Chrome homepage and see if it still says "Search". I tried so many different methods before, but this time it really went away!


This was the homepage that I kept on getting:

User uploaded file

Then I removed it from Safari and uninstalled Chrome because it wouldn't disappear of Chrome. But just today, my desktop showed me this and got me alerted:

User uploaded file


After you scan on Malwarebytes, it should look something like this:

User uploaded file


Good luck to everybody!!! If all else fails, make sure you contact Apple Support.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

how to remove weknow.ac from safari

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.