Remove "weknow.ac" Malware in Chrome?

iMac (Retina 5K, 27-inch, Late 2015), 3.3 GHz Intel Core i5, 16 GB 1867 MHz DDR3, 1.7 TB free — Running High Sierra 10.13.6 (17G65). For a variety of reasons, Chrome is my default browser, and Google is my default search engine and homepage. While browsing with Chrome two days ago, I made the idiotic mistake of clicking on a Flash download popup and immediately noticed signs of infection by this malware. The main only noticeable effect is that my homepage, tab option, and search engine in the Chrome browser now default to this alien "weknow.ac" search engine, which produces results very different from Google's. I've tried three long phone troubleshooting sessions with Apple Help, including downloading and scanning with Malwarebytes, which read my computer as "clean." Also pursued other remedial steps I've seen suggested in other websites. (Although there are only a few that deal specifically with Chrome on Mac.) Uninstalled Chrome application, including trashing all its support folders from Library. However, the bug still keeps coming back. The "good" news is that Safari (so far) shows no sign of the infestation — so I'm using that as my only browser. However, I don't want my (still relatively new) iMac to go through the rest of its life with this alien entity ticking away in its innards. Can anyone here recommend a more permanent solution to my problem? Is there a third-party malware removal product that's both effective and trustworthy? Thanks in advance for any help.

iMac

Posted on Aug 15, 2018 6:51 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 20, 2018 6:37 AM

I was finally able to fix this for chrome after having no luck with anything posted here. This is what I discovered:


"weknow.ac" changes a group of Chrome policies so as to set a new default homepage, new tab behavior, etc. You can see your current Chrome policies by typing chrome://policy/ into your URL bar. If you're infected, it should be very obvious as the half-dozen or so policies changed by weknow will be displayed.


All I had to do then was use the command line to delete / modify the affected policies:


defaults write com.google.Chrome HomepageIsNewTabPage -bool false

defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"

defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"

defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


The changes will not take effect until you restart Chrome.


I recommend following some of the other pieces of advice in this thread, ie definitely do a malware scan too.

310 replies

Sep 3, 2018 3:02 PM in response to Kurt Lang

No, I'm not talking about MalWareBytes for Mac. I'm talking about the link How To Remove Weknow.ac Redirect (Virus Removal Guide)


That takes you to https://malwaretips.com/blogs/remove-weknow-ac/

AND malwaretips.com is NOT malwarebytes.com - so you are just downloading someone else's malware IMHO.


I was able to finally unscrew the links that were causing the issue by going in to the Library and removing com.MacMechanic.Mac-Mechanic.plist and com.macmechanic.mmhlpr.plist and then going in to Settings, scrolling down to Search Engine, clicking on manage search engines and then changing it from weknow search engine back to google and then deleting the weknow search engine. You must change it from the weknow search engine to something else before you can delete it btw.

Oct 7, 2018 8:28 PM in response to Skanson

We ended up having the same problem and were able to get rid of most everything except for the new tab page, which was hijacked by weknow.ac. Apple care found this post and your solution. Before we used terminal, I decided to try using App Cleaner & Uninstaller to completely delete chrome and this appeared to work for us (just did the free option). I went ahead and still used the Terminal solution just in case, but for those wary of using the command line interface, this seemed to work for us.

Dec 29, 2018 1:04 PM in response to can200

I deleted Chrome MANY times. But what you have to do is go to Terminal app on your laptop (go to Spotlight search) and then copy and paste these lines.


defaults write com.google.Chrome HomepageIsNewTabPage -bool false

defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"

defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"

defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


Restart Chrome. Works a treat!! I've had this problem for months to the point I just gave up using Chrome.

Sep 25, 2018 6:56 PM in response to carrie4321

Carrie, I am not the most tech savvy person but I created my own website and no one touches it except myself so I am more tech-savvy than most I guess but I will definitely not be using the right terminology to explain things.


So Terminal is used to tell your computer to do something when you want it to do something to the whole computer. It's on every single Mac so it has to be there.


If you cannot find it by searching then go to Applications and then to Utilities and it should reside in Utilities.


Then open it up and copy and paste the commands one by one and then restart Chome. It really was a life saver. It's not the first time my mom or dad have downloaded something like this. My mom is usually savvy enough with not being tricked but this one got her and it really is one of the worst.

Oct 17, 2018 10:36 PM in response to Reuben_Hood

So I have tried the copy and pasting the commands to terminal but they did not work for me. The solution I found was way more simpler than I expected. I found the video on youtube which was extremely hard to find, my gosh! I recommend copy and pasting the link. This "virus" annoyed me to the core. But it's gone now. All is right with my Mac. 🙂

SUPER MALWARE, "Weknow.ac" aimed at Mac-users, how to remove. - YouTube

https://www.youtube.com/watch?v=SrG_UKtpDEM

These are the same links I posted both just in case one works and one doesn't.

Hope this helps,

Cheers!

Feb 13, 2019 6:02 PM in response to lambadger

Clean My Mac could be part of the problem, most here recommend removing that by Uninstalling it.


EtreCheck is a simple little app to display the important details of your system configuration and allow you to copy that information to the Clipboard. It is meant to be used with Apple Support Communities to help people help you with your Mac.


http://www.etresoft.com/etrecheck

Mar 5, 2019 12:58 PM in response to bennett_betsy

Thank you, bennett, for a lot of good stuff here.


I think lulubo's tip below of deleting the fake admin profiles might've removed weknow already, but just in case, I just checked Applications and didn't see Flash Player or MacKeeper. I then went to Chrome Settings and Google was now identified as my default search engine. Weknow was still listed as a search engine, but unlike before, when I now clicked on the 3 vertical dots to the right, I was able to remove weknow from the list of search engines. Yesterday, I'd restored Chrome to the default settings.


Bottom line, this was a lot of mystery to me as well, but, fingers crossed, I'm rid of weknow now (and hopefully permanent).

Mar 26, 2019 8:52 AM in response to Muhsin7

Goto setting and under startup check " open the new tab page "

under Appearance check " Show Home Button "

next line ... New Tab page Change ... click change and select Use the new tab page


close the setting page and restart chrome and you should be all set.


Also...

https://chrome.google.com/webstore/detail/blank-new-tab-page/jaadjnlkjnhohljficgoddcjmndjfdmi?hl=en


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Remove "weknow.ac" Malware in Chrome?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.