weknow malware

bfrench
Contributor III

Today I had the pleasure of trying to remove some weknow malware that happened to install Profiles on a laptop. The profiles prevented the changing of search engines and home pages in the browsers that were installed. Will adding a Profile restriction prevent Profiles from being installed by malware? Or just prevent a user from installing one manually. Our staff have admin accounts - any other way to prevent these Profiles from installing?

1 REPLY 1

lkrasno
Contributor II

Was this a signed profile?

Have a look at @rtrouton excellent presentation

and

macOS-enterprise-privileges