Remove "weknow.ac" Malware in Chrome?

iMac (Retina 5K, 27-inch, Late 2015), 3.3 GHz Intel Core i5, 16 GB 1867 MHz DDR3, 1.7 TB free — Running High Sierra 10.13.6 (17G65). For a variety of reasons, Chrome is my default browser, and Google is my default search engine and homepage. While browsing with Chrome two days ago, I made the idiotic mistake of clicking on a Flash download popup and immediately noticed signs of infection by this malware. The main only noticeable effect is that my homepage, tab option, and search engine in the Chrome browser now default to this alien "weknow.ac" search engine, which produces results very different from Google's. I've tried three long phone troubleshooting sessions with Apple Help, including downloading and scanning with Malwarebytes, which read my computer as "clean." Also pursued other remedial steps I've seen suggested in other websites. (Although there are only a few that deal specifically with Chrome on Mac.) Uninstalled Chrome application, including trashing all its support folders from Library. However, the bug still keeps coming back. The "good" news is that Safari (so far) shows no sign of the infestation — so I'm using that as my only browser. However, I don't want my (still relatively new) iMac to go through the rest of its life with this alien entity ticking away in its innards. Can anyone here recommend a more permanent solution to my problem? Is there a third-party malware removal product that's both effective and trustworthy? Thanks in advance for any help.

iMac

Posted on Aug 15, 2018 6:51 AM

Reply
Question marked as Top-ranking reply

Posted on Jul 2, 2019 4:41 PM

I've noticed that a "Profile" was setup preventing the setting to be changed in Chrome.

  1. System Preferences > Profiles remove the unrecognized profile (if this is a work computer you may want to check with IT to see if the profile is supposed to be there, by default there shouldn't be a profile.
  2. Once removed O)pen Chrome and go to Chrome > Preferences > Choose the 3 lines on the top left choose "Search Options" (or something like that) you'll see the Search option WeKnow listed there. You can change that to something else. If you don't have the option to change it (greyed out) refer to step 1.
  3. Below that there should be Manage Search Engines which shows a list of options, like Google, Bing. .... etc You'll see WeKnow there, remove that and any other you aren't wanting included.


I also suggest running an Anti-Malware program at some point, before or after you do this.

310 replies
Question marked as Top-ranking reply

Jul 2, 2019 4:41 PM in response to Reuben_Hood

I've noticed that a "Profile" was setup preventing the setting to be changed in Chrome.

  1. System Preferences > Profiles remove the unrecognized profile (if this is a work computer you may want to check with IT to see if the profile is supposed to be there, by default there shouldn't be a profile.
  2. Once removed O)pen Chrome and go to Chrome > Preferences > Choose the 3 lines on the top left choose "Search Options" (or something like that) you'll see the Search option WeKnow listed there. You can change that to something else. If you don't have the option to change it (greyed out) refer to step 1.
  3. Below that there should be Manage Search Engines which shows a list of options, like Google, Bing. .... etc You'll see WeKnow there, remove that and any other you aren't wanting included.


I also suggest running an Anti-Malware program at some point, before or after you do this.

Sep 3, 2019 12:14 PM in response to Reuben_Hood

I had this issue for the past like 6 months and did the malwarebytes scans, and even the default boot writes in terminal for my hijacked chrome browser. The we know hijacker writes an additional administrative profile which was the last thing I hadn't removed and none of the scans picked up on. If you've done everything a million times and it still doesn't work I recommend doing this.


  1. Go to system preferences.
  2. Next to Accessibility there may be an icon with a checkmark that says "Profiles" this is causing the redirect although the virus is gone.
  3. Select profiles.
  4. Delete the adminpref by clicking on the (-).


Below is the link that showed me how to do this if you are confused, I recommend doing terminal default boot writes, malwarebyte scans, and a system restart one last time as well.


https://www.pcrisk.com/removal-guides/13007-weknowac-redirect-mac


Regards,

Jan 16, 2019 7:43 PM in response to Reuben_Hood

if using terminal doesn't work for you. The problem is that now We Know Ac is set as an Admin for your MAC directly affecting your terminal and if you input something there, it will not work as We Know Ac blocks it. So:

1. Go to your system preferences (the settings of our MAC), and look for a profiles icon.

2. Click on there (since in a default mac that shouldn't be there).

3. Remove all of the Admin blocks found.

4. And boom, you have a chrome free of malware.

This video & comment section ultimately saved me https://www.youtube.com/watch?v=C0xRhWCX2Is&vl=en

Mar 5, 2019 10:36 AM in response to Reuben_Hood

Also, if weknow.ac still pops up after you follow all of Skanson's steps, it is because weknow.ac installs itself as your iOS's administer. To remove weknow.ac as the administer, follow these steps:

  • Go to your Mac's System Preference (It will appear after you click the "Apple" icon on the menu
  • Look for "Profile" icon (which should not appear if you are the only Mac's administer)
  • Click the "Profile" icon
  • Remove all the profiles by clicking the "-" sign
  • Restart the computer to make the elimination effective

Jan 31, 2019 11:14 AM in response to robinhenry

Hi everyone. Not a mac guy, not a computer guy, so all of this is over my head. But I wanted to share how I dealt with this on my wife's iMac. On the we know search page that forces its way on to your computer, on the bottom left was a FAQ's link. And in there was an uninstall link. I was skeptical but desperate. Cleaned everything right up. My 2 cents. Good luck..

Jan 4, 2019 4:39 PM in response to saylah

  1. First, launch the Google Chrome and click the Menu icon (icon in the form of three dots).
  2. It will show the Google Chrome main menu. Choose More Tools, then click Extensions.
  3. You’ll see the list of installed extensions. If the list has the plugin labeled with “Installed by enterprise policy” or “Installed by your administrator”, then complete the following steps: Remove Chrome extensions installed by enterprise policy.
  4. Now open the Google Chrome menu once again, click the “Settings” menu.
  5. Next, click “Advanced” link, that located at the bottom of the Settings page.
  6. On the bottom of the “Advanced settings” page, click the “Reset settings to their original defaults” button.
  7. The Google Chrome will open the reset settings dialog box as on the image above.
  8. Confirm the internet browser’s reset by clicking on the “Reset” button.
  9. To learn more, read the blog post How to reset Google Chrome settings to default.


Feb 13, 2019 6:02 PM in response to lambadger

Clean My Mac could be part of the problem, most here recommend removing that by Uninstalling it.


EtreCheck is a simple little app to display the important details of your system configuration and allow you to copy that information to the Clipboard. It is meant to be used with Apple Support Communities to help people help you with your Mac.


http://www.etresoft.com/etrecheck

Mar 5, 2019 12:58 PM in response to bennett_betsy

Thank you, bennett, for a lot of good stuff here.


I think lulubo's tip below of deleting the fake admin profiles might've removed weknow already, but just in case, I just checked Applications and didn't see Flash Player or MacKeeper. I then went to Chrome Settings and Google was now identified as my default search engine. Weknow was still listed as a search engine, but unlike before, when I now clicked on the 3 vertical dots to the right, I was able to remove weknow from the list of search engines. Yesterday, I'd restored Chrome to the default settings.


Bottom line, this was a lot of mystery to me as well, but, fingers crossed, I'm rid of weknow now (and hopefully permanent).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Remove "weknow.ac" Malware in Chrome?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.