Remove "weknow.ac" Malware in Chrome?

iMac (Retina 5K, 27-inch, Late 2015), 3.3 GHz Intel Core i5, 16 GB 1867 MHz DDR3, 1.7 TB free — Running High Sierra 10.13.6 (17G65). For a variety of reasons, Chrome is my default browser, and Google is my default search engine and homepage. While browsing with Chrome two days ago, I made the idiotic mistake of clicking on a Flash download popup and immediately noticed signs of infection by this malware. The main only noticeable effect is that my homepage, tab option, and search engine in the Chrome browser now default to this alien "weknow.ac" search engine, which produces results very different from Google's. I've tried three long phone troubleshooting sessions with Apple Help, including downloading and scanning with Malwarebytes, which read my computer as "clean." Also pursued other remedial steps I've seen suggested in other websites. (Although there are only a few that deal specifically with Chrome on Mac.) Uninstalled Chrome application, including trashing all its support folders from Library. However, the bug still keeps coming back. The "good" news is that Safari (so far) shows no sign of the infestation — so I'm using that as my only browser. However, I don't want my (still relatively new) iMac to go through the rest of its life with this alien entity ticking away in its innards. Can anyone here recommend a more permanent solution to my problem? Is there a third-party malware removal product that's both effective and trustworthy? Thanks in advance for any help.

iMac

Posted on Aug 15, 2018 6:51 AM

Reply
Question marked as Top-ranking reply

Posted on Jul 2, 2019 4:41 PM

I've noticed that a "Profile" was setup preventing the setting to be changed in Chrome.

  1. System Preferences > Profiles remove the unrecognized profile (if this is a work computer you may want to check with IT to see if the profile is supposed to be there, by default there shouldn't be a profile.
  2. Once removed O)pen Chrome and go to Chrome > Preferences > Choose the 3 lines on the top left choose "Search Options" (or something like that) you'll see the Search option WeKnow listed there. You can change that to something else. If you don't have the option to change it (greyed out) refer to step 1.
  3. Below that there should be Manage Search Engines which shows a list of options, like Google, Bing. .... etc You'll see WeKnow there, remove that and any other you aren't wanting included.


I also suggest running an Anti-Malware program at some point, before or after you do this.

310 replies

Mar 15, 2019 9:19 AM in response to mry50

Hi - I open the finder go to applications, along with all my apps is the utilities folder and in there I can open the terminal.

Weknow can be a challenge to remove in Chrome.

Even after following the instructions to change Chrome policies I uninstalled Chrome completely - then reinstalled it!!!

Keep us posted. I learned a lot trying to get rid of this little monster.



Mar 26, 2019 6:49 AM in response to Skanson

hello.


i did exactly what you recommended after seeing the same thing in another website.

it worked fine. weknow was gone, and i haven't seen that new tab page since.

HOWEVER,

now, when i open a new tab, i simply get an about:blank screen, rather than the normal chrome new tab :/ (see below)


im pretty sure this is due to the delete statements, but im not sure. is there any way i can set it back? i will try using the "write" commands on this later and see if it works but i dont know. please help me out here

Apr 16, 2019 6:46 AM in response to Skanson

I'm not quite sure what search you are referencing. On the screen there is a box with the words "filter policy by name". I typed terminal there and got the response, no policy. At the very top right on my Mac, next to the time is a search icon. I typed terminal there, and got a listing of"possible hits", such as documents, other, PDF documents developer, and show in finder. I see I have chrome policies that have been affected. I feel like I'm so close, but not understanding terminal application. Thank you for any help you can give me!!!


May 10, 2019 3:45 AM in response to Skanson

Sadly, this didn't work for me. It seemed to take the first three write commands, but when I enter the three delete commands Terminal responds with "Domain (com.google.Chrome) not found. Defaults have not been changed." Any other suggestions? I've never had this much trouble removing it before. Obviously, they're getting better at this. Very frustrated!

May 11, 2019 3:45 AM in response to Reuben_Hood

Hi,

Please can you help me ?

Each time I open Google Chrome, Weknow appears ! I deleted from everywhere also.

I followed your instructions through the Terminal application but WeKnow is still there.


Do I have to copy/paste this : defaults write com.google.Chrome HomepageIsNewTabPage -bool false OR this : com.google.Chrome HomepageIsNewTabPage -bool false


Thanks for helping me

May 22, 2019 11:46 PM in response to Skanson

I get through the top three commands and then when I enter any of these, I keep getting the same message:


defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


2019-05-22 23:40:26.646 defaults[58696:687519] 

Domain (com.google.Chrome) not found.

Defaults have not been changed.


I am at my wits end!


Help!



May 23, 2019 8:07 AM in response to pobzeb224

Can those still having problems try this? Or are these the commands you've tried?


Enter the following commands, pressing enter after each line:

defaults write com.google.Chrome HomepageIsNewTabPage -bool false
defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"
defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"
defaults delete com.google.Chrome DefaultSearchProviderSearchURL
defaults delete com.google.Chrome DefaultSearchProviderNewTabURL
defaults delete com.google.Chrome DefaultSearchProviderName

Re-open Chrome and the issue should be resolved.


Also see this thread...

https://support.google.com/chrome/thread/3396218?msgid=4124217



Aug 6, 2019 8:14 PM in response to Reuben_Hood

Well, Youtube has some videos with mixed results.

  1. Going to Systems preference and deleting the profile icon works only in part.
  2. Using Terminal - I struggle with this one. They refer to full list of commands to copy to terminal, only it does not say how to bring that list up on the screen.


My Safari and Chrome were affected. FireFox was much better in blocking the We know.ac virus.

Check Safari preference and go to the website tabs. We know is hidden in there and I have not been able to delete it.

In Chrome, removing profile from Systems preference allowed me to edit and remove weknow from the search engine, but it still comes up if i do a File, and new window.


I have found nothing that totally removed the we know.ac virus.


I tried many malware removal tools and none of them even recognized the virus.

Sep 4, 2018 7:37 PM in response to Reuben_Hood

The adware behind this has gotten very sneaky about how these changes are made. The changes to the Chrome profile are non-trivial to reverse, and as a representative of Malwarebytes, I would not recommend relying on Malwarebytes to fix those settings. Even if the changes made by the adware were trivial, poking at the contents of undocumented Chrome-related files could potentially cause Chrome-related data loss, so it's not the sort of thing currently done by Malwarebytes for Mac.


Currently, my advice is to completely delete Chrome and all Chrome data files from the computer. Then reinstall a fresh copy of Chrome, and set it up from scratch. If you have Chrome bookmarks you don't want to lose, export those first and import them after reinstalling.


You also need to think about Chrome sync. If you're using it, you could end up syncing malicious changes right back onto your device, or onto other devices. You'll want to reset Chrome sync.


For Safari, there are a variety of techniques being used to change the settings. One is to add a bookmark and change Safari's settings to load "tabs for" that bookmark item at startup. This is easy to miss, since the homepage entry can be left untouched, making it appear that something is still installed if you're not observing carefully.


User uploaded file

Sep 20, 2018 7:29 AM in response to Skanson

Thanks for this response....can you please explain how to use the command line to delete / modify the affected policies? I can see that my policies are affected as described..


Applies toLevelSourcePolicy namePolicy ValueStatus

Current user

Recommended

Platform

DefaultSearchProviderEnabled

true

OK

Current user

Recommended

Platform

DefaultSearchProviderName

WeKnow

OK

Current user

Recommended

Platform

DefaultSearchProviderNewTabURL

Show value

OK

Current user

Recommended

Platform

DefaultSearchProviderSearchURL

Show value

OK

Current user

Recommended

Platform

HomepageIsNewTabPage

true

OK

Current user

Recommended

Platform

HomepageLocation

Show value

OK

Current user

Recommended

Platform

NewTabPageLocation

Show value

OK


not sure what to do once i get to the page chrome://policy/

thanks!!!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Remove "weknow.ac" Malware in Chrome?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.