Remove "weknow.ac" Malware in Chrome?

iMac (Retina 5K, 27-inch, Late 2015), 3.3 GHz Intel Core i5, 16 GB 1867 MHz DDR3, 1.7 TB free — Running High Sierra 10.13.6 (17G65). For a variety of reasons, Chrome is my default browser, and Google is my default search engine and homepage. While browsing with Chrome two days ago, I made the idiotic mistake of clicking on a Flash download popup and immediately noticed signs of infection by this malware. The main only noticeable effect is that my homepage, tab option, and search engine in the Chrome browser now default to this alien "weknow.ac" search engine, which produces results very different from Google's. I've tried three long phone troubleshooting sessions with Apple Help, including downloading and scanning with Malwarebytes, which read my computer as "clean." Also pursued other remedial steps I've seen suggested in other websites. (Although there are only a few that deal specifically with Chrome on Mac.) Uninstalled Chrome application, including trashing all its support folders from Library. However, the bug still keeps coming back. The "good" news is that Safari (so far) shows no sign of the infestation — so I'm using that as my only browser. However, I don't want my (still relatively new) iMac to go through the rest of its life with this alien entity ticking away in its innards. Can anyone here recommend a more permanent solution to my problem? Is there a third-party malware removal product that's both effective and trustworthy? Thanks in advance for any help.

iMac

Posted on Aug 15, 2018 6:51 AM

Reply
Question marked as Top-ranking reply

Posted on Jul 2, 2019 4:41 PM

I've noticed that a "Profile" was setup preventing the setting to be changed in Chrome.

  1. System Preferences > Profiles remove the unrecognized profile (if this is a work computer you may want to check with IT to see if the profile is supposed to be there, by default there shouldn't be a profile.
  2. Once removed O)pen Chrome and go to Chrome > Preferences > Choose the 3 lines on the top left choose "Search Options" (or something like that) you'll see the Search option WeKnow listed there. You can change that to something else. If you don't have the option to change it (greyed out) refer to step 1.
  3. Below that there should be Manage Search Engines which shows a list of options, like Google, Bing. .... etc You'll see WeKnow there, remove that and any other you aren't wanting included.


I also suggest running an Anti-Malware program at some point, before or after you do this.

310 replies

Feb 19, 2019 4:20 PM in response to Skanson

OMG!!!!!!! THANK YOUUUUUUUUUUUUU. I have been dealing with this stupid weknow.ac malware for almost 4 months. I have tried everything and it still shows up when I open a new tab. This fix worked beautifully!!!! At one point, I had to delete my Chrome and use Safari. I was sooooo frustrated. McAfee didn't help, it doesn't see it.


I originally download the weknow.ac from a request to update my java. I found out later, that Java updates are never pushed through as a message. THANK YOU again!!! WooHoo.

Feb 21, 2019 1:52 AM in response to Skanson

Yep, ditto, thanks so much for this. Although the apple guy was very helpful and patient, sorted Safari out for me, and spent ages with me trying different things with Chrome, he didn't seem to know about this particular solution and warned me against going into terminal in case I deleted files that don't need deleting. But I just wanted to try it... and it worked. Brilliant. Thanks.

Feb 27, 2019 6:52 PM in response to Skanson

Thank you!!! It appears to have worked. I wasn't able to figure out how to change my terminal from bash to c-shell, but figured I would try enter your command lines anyway, one at a time, and it seems to have worked beautifully. I went back and checked the chrome policy after restarting chrome and it looked a lot different than when "weknow.ac" was in control.

THANK YOU

Mar 3, 2019 2:23 PM in response to Reuben_Hood

Thank You!! The "weknow..." virus affected my wife's computer (Chrome). Has taken us a long time to find a solution. However, your magic worked! I don't know how you figured this out, but you did. You are fabulous. Also, considering how many people have gotten infected with this, it is surprising that Apple has not created a solution. (We used Apple support and they were, in this case, not able to fix the problem.)


Now the big question: how did you figure this out? (Rhetorical.)

Mar 4, 2019 2:17 PM in response to Skanson

THANK YOU!!! I had been able to fix everything except for opening a new tab in Chrome, and I called Apple four times (hoping to get anyone who could help - but no luck) to no avail.


For those, like me, who had no idea how to open "Terminal", it is in the Applications folder under "Utilities."


There was already some text in there, but after the existing "$" I copied each line (the entire line, starting with defaults), pasted, and hit return. I repeated all six lines. And it worked!


Thanks you!!!

Mar 4, 2019 4:14 PM in response to Reuben_Hood

Can someone tell me (in simple terms, please) what I've done wrong?


I've read the entire thread, found where the Terminal is, and copied and pasted several times, but despite quitting Chrome after each attempt, I still get that "we know/Search" in Chrome.


If you check out my Terminal screen below, I'm obviously doing something wrong (or my Mac is really messed up), because after I copy and paste the commands and then hit Enter, it actually says "Defaults have not been changed."


Bruces-iMac:~ brucezwecker$ defaults write com.google.Chrome HomepageIsNewTabPage -bool false


Bruces-iMac:~ brucezwecker$ defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"


Bruces-iMac:~ brucezwecker$ defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"


Bruces-iMac:~ brucezwecker$ defaults delete com.google.Chrome DefaultSearchProviderSearchURL


2019-03-04 19:04:28.141 defaults[2913:163766] 


Domain (com.google.Chrome) not found.


Defaults have not been changed.


Bruces-iMac:~ brucezwecker$ defaults delete com.google.Chrome DefaultSearchProviderNewTabURL


2019-03-04 19:04:54.120 defaults[2924:165760] 


Domain (com.google.Chrome) not found.


Defaults have not been changed.


Bruces-iMac:~ brucezwecker$ defaults delete com.google.Chrome DefaultSearchProviderName


2019-03-04 19:05:09.087 defaults[2925:167038] 


Domain (com.google.Chrome) not found.


Defaults have not been changed.


Bruces-iMac:~ brucezwecker$ 


Bruces-iMac:~ brucezwecker$ 


Bruces-iMac:~ brucezwecker$ 

Mar 6, 2019 1:46 PM in response to Skanson

Hey! Have had the We Know malware on my laptop for quite while now and havent had any luck in removing it. When i try to enter the policies or 'commands' into Terminal it says 'command not found'. Can anybody help please? Maybe i'm not copying and pasting the right info? could someone help me out please - what exactly need to be copied and pasted?

Mar 7, 2019 11:35 AM in response to Skanson

Your advice worked for me sort of.

While searching for solution I brought up duckduckgo and which worked great but not in the url. Every new tab opened in weknow, for convenience I added the duckduckgo extension.

I followed your directions to change Chrome polices in the terminal. The first time I stopped after the 3rd or 4th line. I spent several hours "cleaning up" the library with no success so tried your method again. That time everything seemed to work great!

Each tab opened to the google homepage, searches in search bar or URL showed no sign of weknow.

But duckduckgo was now the default search engine. I went to change that and found weknow was still there!

I uninstalled Chrome and moved to Safari (which I had earlier managed to free from weknow)

Next morning I reinstalled Chrome and weknow was in every page and tab.

I opened up the terminal to change the policies after the 4th line - “Domain (com.google.Chrome) not found. Defaults have not been changed”

I started removing apps and deleting files (malware searches come up clean).

I restarted & opened Chrome - Now I can search Google in search bar and weknow is still in the URL.

1st 3 lines are reflected in the policies, but no defaults shown in policy. I am going to try again, I guess starting with line 4.

....

Because weknow is only showing in Chrome now (even after un&re install) is the malware hiding in some file or app in a Chrome specific path?

Mar 13, 2019 3:55 AM in response to Skanson

Thanks a lot Skanson. It's been months that i have been struggling with this.

This solved my problem in an instant.


Just one suggestion - I'm a Mac newbie. So "Use the command line" part confused me a bit. I had to search around and then take a wild guess that you meant Terminal app. I was looking for a command prompt option in my Google Chrome app. (sorry, like i said, newbie!)


It will help people like me if you just mentioned Terminal before what the policies to be changed.


Rest of the answer was bang on. Thanks so much!


Mar 15, 2019 9:19 AM in response to mry50

Hi - I open the finder go to applications, along with all my apps is the utilities folder and in there I can open the terminal.

Weknow can be a challenge to remove in Chrome.

Even after following the instructions to change Chrome policies I uninstalled Chrome completely - then reinstalled it!!!

Keep us posted. I learned a lot trying to get rid of this little monster.



This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Remove "weknow.ac" Malware in Chrome?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.