this post was submitted on 28 Jun 2024
139 points (96.0% liked)

Technology

59219 readers
4404 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

cross-posted from: https://infosec.pub/post/14206569

Hi all,

First off: Can't switch to Linux, Windows is a work requirement. Please spare me.

With that out of the way, here's my problem:

Since 2-3 days I've been seeing ads disguised as a minimized video player popup on my Windows 10 Login Screen image.

Initially I thought I might have been watching something on youtube and forgot to close the tab and it autoplayed in the background until reaching this stuff by chance; but that turned out not to be the case (I'm also using Firefox exclusively, which I thought wouldn't integrate with Windows, but I wasn't 100% sure on that end).

I tried to research this a bit, but the only similar case I found was in an old reddit thread saying that some Windows update installed the LinkedIn App for them, which is not the case here.

Antivirus (Bit Defender) and Malwarebytes both give me a clean report.

So I did some more digging and right click that thing with my firewall set to deny all to figure out where this is taking me, and surprise...

Image

There's a total of 100 connection attempts from Windows Search to around 10 different IP addresses, all of which belong to Microsoft.

I have not installed any updates in the last 14 days, no new software, and have not changed any system settings.

What did change is that I am currently not in China, where I normally live, but am on a business trip to Malaysia, where a bunch of services that are blocked in China might be accessible, and are now splicing in those (somewhat disguised) ads.

Does this happen to anyone else, and if so, do you have an idea how to get rid of it?

Thanks a lot in advance!

you are viewing a single comment's thread
view the rest of the comments
[–] dalakkin@lemmy.world 5 points 4 months ago* (last edited 4 months ago) (2 children)

Most likely it's an ad from one of your open Firefox tabs. Try exiting all your web browsers and see if that fixes it.

[–] systemglitch@lemmy.world 7 points 4 months ago

I've never seen ff do that for anyone.

[–] viking@infosec.pub 2 points 4 months ago

Thought of that as well, but all ads are blocked and I get this popup even with the browser closed and after a full reboot (not just suspend and reactivate), so it must happen on system level, I assume. Checked my run on startup applications and services, and they appear to be clean as well.