Remove "weknow.ac" Malware in Chrome?

iMac (Retina 5K, 27-inch, Late 2015), 3.3 GHz Intel Core i5, 16 GB 1867 MHz DDR3, 1.7 TB free — Running High Sierra 10.13.6 (17G65). For a variety of reasons, Chrome is my default browser, and Google is my default search engine and homepage. While browsing with Chrome two days ago, I made the idiotic mistake of clicking on a Flash download popup and immediately noticed signs of infection by this malware. The main only noticeable effect is that my homepage, tab option, and search engine in the Chrome browser now default to this alien "weknow.ac" search engine, which produces results very different from Google's. I've tried three long phone troubleshooting sessions with Apple Help, including downloading and scanning with Malwarebytes, which read my computer as "clean." Also pursued other remedial steps I've seen suggested in other websites. (Although there are only a few that deal specifically with Chrome on Mac.) Uninstalled Chrome application, including trashing all its support folders from Library. However, the bug still keeps coming back. The "good" news is that Safari (so far) shows no sign of the infestation — so I'm using that as my only browser. However, I don't want my (still relatively new) iMac to go through the rest of its life with this alien entity ticking away in its innards. Can anyone here recommend a more permanent solution to my problem? Is there a third-party malware removal product that's both effective and trustworthy? Thanks in advance for any help.

iMac

Posted on Aug 15, 2018 6:51 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 20, 2018 6:37 AM

I was finally able to fix this for chrome after having no luck with anything posted here. This is what I discovered:


"weknow.ac" changes a group of Chrome policies so as to set a new default homepage, new tab behavior, etc. You can see your current Chrome policies by typing chrome://policy/ into your URL bar. If you're infected, it should be very obvious as the half-dozen or so policies changed by weknow will be displayed.


All I had to do then was use the command line to delete / modify the affected policies:


defaults write com.google.Chrome HomepageIsNewTabPage -bool false

defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"

defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"

defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


The changes will not take effect until you restart Chrome.


I recommend following some of the other pieces of advice in this thread, ie definitely do a malware scan too.

310 replies

Aug 17, 2018 5:18 PM in response to Reuben_Hood

I have been researching this all afternoon, and I saw on another forum that "weknow.ac" seems to have changed their technique sometime within the past week, as any posts about removing the malware from July 2018 and before do not completely work. I have followed every possible step, removed all the malicious apps and Library files mentioned, run Malwarebytes, and I still can't get rid of the default "weknow.ac" search page in Chrome. I deleted Chrome and all its support files, reinstalled it, and the problem persists. There is something installed in the OS that keeps reinstalling the malware. For all the frustrated users on this board - I'm one of you - any guides to solving this problem prior to August 2018 will not fix the issue entirely. I am hoping Malwarebytes figures this out and releases an update to their software to include this latest attack.

Oct 1, 2018 1:24 PM in response to Skanson

Thanks, I spent 2 hours researching how to remove weknow.ac and this works, However it now forces Chrome to always use the generic google home page for new windows and new tabs.

User uploaded file


If you want to use Chrome themes or have the base google homepage with most popular site visited (below the search bar) I found that you need to delete the first three via Terminal.

With Chrome closed, copy each line separately and past them in to the terminal.


defaults delete com.google.Chrome HomepageIsNewTabPage

defaults delete com.google.Chrome NewTabPageLocation

defaults delete com.google.Chrome HomepageLocation


Restart Chrome and should look like this with your most visited pages.


User uploaded file

Oct 24, 2018 2:03 PM in response to Reuben_Hood

OMG it worked on my OS and is simple. Only after 3 apple people couldn't help over 4 hours. ugh.


Go to your chrome browser

type in: chrome://policy/


if it says WeKnow anywhere you're 'effed! But not anymore 🙂


just go type in TERMINAL in search box. On the bottom right comes up a black box - select the box


User uploaded file


then this comes up:

User uploaded file


simply copy and paste everything in bold after the prompt:


defaults write com.google.Chrome HomepageIsNewTabPage -bool false

defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"

defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"

defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


then hit enter...


it may say nothing was changed... ignore the because it did change!


then CLOSE and QUIT your Chrome browser by Right clicking and selecting QUIT

User uploaded file

then open your Chrome browser and it should be normal!!


Type in chrome://policy/ and you should see the following:

User uploaded file

Done! You're no longer 'offed!!

Oct 28, 2018 9:58 AM in response to Reuben_Hood

I've done as instructed and still no luck. Here is what is displayed after each line was copied and pasted:



Steves-MBP:~ stevehayko$ defaults write com.google.Chrome HomepageIsNewTabPage -bool false

Steves-MBP:~ stevehayko$ defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"

Steves-MBP:~ stevehayko$ defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"

Steves-MBP:~ stevehayko$ defaults delete com.google.Chrome DefaultSearchProviderSearchURL

2018-10-28 09:54:58.921 defaults[7694:440908]

Domain (com.google.Chrome) not found.

Defaults have not been changed.

Steves-MBP:~ stevehayko$ defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

2018-10-28 09:55:08.057 defaults[7695:441072]

Domain (com.google.Chrome) not found.

Defaults have not been changed.

Steves-MBP:~ stevehayko$ defaults delete com.google.Chrome DefaultSearchProviderName

2018-10-28 09:55:15.569 defaults[7696:441253]

Domain (com.google.Chrome) not found.

Defaults have not been changed.

Steves-MBP:~ stevehayko$

Dec 2, 2018 9:37 AM in response to macjack

No, it won’t. Not even the $40 paid subscription version will do so.


Nor did the cryptic Terminal commands help me, as Weknow had infected Chrome, Safari and Firefox.


I called Apple Support, and for free the technician directed me to Profiles in System Settings; one of the many places this virus hides. In ten minutes - again, for no charge - the tech fixed my problem.


I’d strongly recommend calling Apple to remove WeKnow. It costs nothing, and the technicians seem to know all the places this persistent, difficult virus hides.

Dec 2, 2018 10:58 AM in response to anthonyfromreston

With me has worked and in a few seconds of copy/paste i fixed the issue. What can be different is that at the same moment i discovered the malware i start trying to fix the issue. Probably if the virus stays there more time will affect several other applications and browsers (they call it "virus" for this reason i guess)

My opinion is that the malware is installed exactly form the same people that pop up few second later with a "free" cleaner that will cost 39$ to work.. It is also possible that paying those 40$ you replied the virus in other areas aof the OS and Applications.

I was ready to initialize my mac rather than give them money ;-)

Dec 4, 2018 7:43 PM in response to carola1984

The following code line wise need to be copied and pasted in "Terminal" app available in your launch pad.


defaults write com.google.Chrome HomepageIsNewTabPage -bool false

defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"

defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"

defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


You have to copy each and every line and then hit enter.


Everything worked out well after that, but, I like to have "New Tab Page" with recents and favourites being displayed, which is now displaying www.google.com when I hit the "+" to add new page. Except that every thing is good.


Appreciate if Skason can explain us how to get default New Tab Page in Chrome instead of www.google.com

Mar 4, 2019 11:52 PM in response to amishboy51

Amishboy, I can't give you an exact fix (because this is all a mystery to me!), but before I did the "Terminal" solution, I had already done a ton of other things. For example, I am pretty sure I got infected with "Weknow" by downloading either Flash Player and/or MacKeeper so I deleted those files from my applications. I also went through all of the settings in Chrome and Safari and had to reset the homepage, the default search engine, etc., as all of those items had been changed to Weknow. I literally opened every "setting" or "preference" type option I could in Chrome and Safari and manually reset every single thing I could find. I also followed the instructions of another post: https://forums.malwarebytes.com/topic/236261-how-to-remove-weknow-malware-and-others, which suggestion deleting a bunch of items in the Library and Application sections of my hard drive. Anyhow, the point is that I think removing WeKnow is a multi-step process that requires doing all of these things. I'm sorry I don't have a simpler answer - this is all over my head! Good luck!



This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Remove "weknow.ac" Malware in Chrome?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.