A technician is troubleshooting a Windows 11 workstation. The user reports receiving frequent pop-up advertisements styled to resemble legitimate operating system security alerts in the bottom-right corner of the desktop, even when all web browser windows are closed. Full system antivirus and anti-malware scans complete with zero infected files detected. Which of the following is the MOST likely cause of these pop-ups?
- The user granted website notification permissions to a malicious domain within the web browser settings.Cevap
- BA Trojan has modified the Windows hosts file to point common system update URLs to an ad-serving IP address.
- CThe local system account has been compromised by ransomware executing scripts via Task Scheduler.
- DThe browser's Proxy Auto-Configuration (PAC) script setting was directed to a rogue remote server.
Cevap
The user granted website notification permissions to a malicious domain within the web browser settings.
The correct answer identifies that modern browsers utilize Web Push APIs integrated into the operating system notification framework. Websites frequently prompt users to allow notifications; if granted to a malicious or rogue site, advertisements formatted like system security warnings will appear on the desktop even when browser windows are closed, and antivirus scans will come up clean because no local malicious executable is installed.
Adım Adım Çözüm
Anahtar Kavram
Browser Site Permissions and Web Push Notification Security