Remove "weknow.ac" Malware in Chrome?

iMac (Retina 5K, 27-inch, Late 2015), 3.3 GHz Intel Core i5, 16 GB 1867 MHz DDR3, 1.7 TB free — Running High Sierra 10.13.6 (17G65). For a variety of reasons, Chrome is my default browser, and Google is my default search engine and homepage. While browsing with Chrome two days ago, I made the idiotic mistake of clicking on a Flash download popup and immediately noticed signs of infection by this malware. The main only noticeable effect is that my homepage, tab option, and search engine in the Chrome browser now default to this alien "weknow.ac" search engine, which produces results very different from Google's. I've tried three long phone troubleshooting sessions with Apple Help, including downloading and scanning with Malwarebytes, which read my computer as "clean." Also pursued other remedial steps I've seen suggested in other websites. (Although there are only a few that deal specifically with Chrome on Mac.) Uninstalled Chrome application, including trashing all its support folders from Library. However, the bug still keeps coming back. The "good" news is that Safari (so far) shows no sign of the infestation — so I'm using that as my only browser. However, I don't want my (still relatively new) iMac to go through the rest of its life with this alien entity ticking away in its innards. Can anyone here recommend a more permanent solution to my problem? Is there a third-party malware removal product that's both effective and trustworthy? Thanks in advance for any help.

iMac

Posted on Aug 15, 2018 6:51 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 20, 2018 6:37 AM

I was finally able to fix this for chrome after having no luck with anything posted here. This is what I discovered:


"weknow.ac" changes a group of Chrome policies so as to set a new default homepage, new tab behavior, etc. You can see your current Chrome policies by typing chrome://policy/ into your URL bar. If you're infected, it should be very obvious as the half-dozen or so policies changed by weknow will be displayed.


All I had to do then was use the command line to delete / modify the affected policies:


defaults write com.google.Chrome HomepageIsNewTabPage -bool false

defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"

defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"

defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


The changes will not take effect until you restart Chrome.


I recommend following some of the other pieces of advice in this thread, ie definitely do a malware scan too.

310 replies

May 10, 2019 3:45 AM in response to Skanson

Sadly, this didn't work for me. It seemed to take the first three write commands, but when I enter the three delete commands Terminal responds with "Domain (com.google.Chrome) not found. Defaults have not been changed." Any other suggestions? I've never had this much trouble removing it before. Obviously, they're getting better at this. Very frustrated!

May 11, 2019 3:45 AM in response to Reuben_Hood

Hi,

Please can you help me ?

Each time I open Google Chrome, Weknow appears ! I deleted from everywhere also.

I followed your instructions through the Terminal application but WeKnow is still there.


Do I have to copy/paste this : defaults write com.google.Chrome HomepageIsNewTabPage -bool false OR this : com.google.Chrome HomepageIsNewTabPage -bool false


Thanks for helping me

May 22, 2019 11:46 PM in response to Skanson

I get through the top three commands and then when I enter any of these, I keep getting the same message:


defaults delete com.google.Chrome DefaultSearchProviderSearchURL

defaults delete com.google.Chrome DefaultSearchProviderNewTabURL

defaults delete com.google.Chrome DefaultSearchProviderName


2019-05-22 23:40:26.646 defaults[58696:687519] 

Domain (com.google.Chrome) not found.

Defaults have not been changed.


I am at my wits end!


Help!



May 23, 2019 8:07 AM in response to pobzeb224

Can those still having problems try this? Or are these the commands you've tried?


Enter the following commands, pressing enter after each line:

defaults write com.google.Chrome HomepageIsNewTabPage -bool false
defaults write com.google.Chrome NewTabPageLocation -string "https://www.google.com/"
defaults write com.google.Chrome HomepageLocation -string "https://www.google.com/"
defaults delete com.google.Chrome DefaultSearchProviderSearchURL
defaults delete com.google.Chrome DefaultSearchProviderNewTabURL
defaults delete com.google.Chrome DefaultSearchProviderName

Re-open Chrome and the issue should be resolved.


Also see this thread...

https://support.google.com/chrome/thread/3396218?msgid=4124217



Aug 6, 2019 8:14 PM in response to Reuben_Hood

Well, Youtube has some videos with mixed results.

  1. Going to Systems preference and deleting the profile icon works only in part.
  2. Using Terminal - I struggle with this one. They refer to full list of commands to copy to terminal, only it does not say how to bring that list up on the screen.


My Safari and Chrome were affected. FireFox was much better in blocking the We know.ac virus.

Check Safari preference and go to the website tabs. We know is hidden in there and I have not been able to delete it.

In Chrome, removing profile from Systems preference allowed me to edit and remove weknow from the search engine, but it still comes up if i do a File, and new window.


I have found nothing that totally removed the we know.ac virus.


I tried many malware removal tools and none of them even recognized the virus.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Remove "weknow.ac" Malware in Chrome?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.