yes, the ransomware: intravenously.stream is the one of many https disabling my computer
I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page
Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:
In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.
Invisible resource thieves: The increasing threat of cryptocurrency miners
Especially important to report these occurrences or any other odd behaviors after using MSN website.
Moderator Edit: Provided update.
Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:
This one was easy to handle because it was just the old-fashioned dialog loop based scam:
– but what’s coming next Microsoft?
GreginMich
[Original Title: Surprised again]
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
386 answers
Sort by: Most helpful
-
Anonymous
2018-07-06T16:26:14+00:00 -
Anonymous
2018-03-08T23:44:22+00:00 Most likely it’s the same, or similar to, the FlashPlayer.hta that was identified and dissected here almost a year ago:
https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/
Defender detects this HTML app as soon as it’s offered for download; and I’ve always just closed the page at that point – so I can’t say for sure what would happen if someone actually clicked on “Run” or “Save”. But I certainly wouldn’t presume that this detection doesn’t involve any real malware, since it has all the hallmarks of a signature-based detection. And I honestly can’t recall ever having seen a real-time detection that didn’t have the browser cache as the detection path, so I don’t think that’s really anything out of the ordinary.
This is a no-blocker day for me here; and in the hour that I spent on the MSN news pages this morning, I had two detections for Trojan:JS/Flafisi.D and one more Tech Support Scam incident. One of the Trojan:JS/Flafisi.D detections was “invisible”, with no fake Adobe Flash Player update appearing in the browser. The invisible detection seems to have been a status update for a detection that was originally made on 3/5/2018:
Now, a status of “106” doesn’t appear in the documentation:
ThreatStatusID
Data type: uint8
Access type: Read-only
The Threat Status ID - Enumeration
Unknown (0)
Detected (1)
Cleaned (2)
Quarantined (3)
Removed (4)
Allowed (5)
Blocked (6)
CleanFailed (Blocked)
QuarantineFailed (102)
RemoveFailed (103)
AllowFailed (104)
Abondoned (105)
BlockedFailed (107)
But the status is indicated as “Abandoned” in the Full History details:
And this is all getting just a little too spooky for my liking.
GreginMich
-
Anonymous
2018-03-01T00:50:19+00:00 I’ve already run scans with Malwarebytes and the Kaspersky Virus Removal Tool, and nothing shows up – but I just noticed something odd when I went to research Trojan:JS/Flafisi.D: Except for the first item on the search results list, which is this local thread:
I just get pages and pages of SpyHunter sponsored sites in different languages. So now I’m wondering if my issue might be the effect of some undetected browser hijacker.
GreginMich
-
Rob Koch 26,075 Reputation points Volunteer Moderator
2018-02-28T22:25:16+00:00 I didn't say anyone was passing the buck here, though it's obviously possible in this scenario, it's just not possible to truly manage the security of these advertisements when such a convoluted, layered set of systems exists.
I don't think Microsoft is ignoring this or they'd be spewing far grater numbers of these similar to the issues that Le Boule mentioned Yahoo has been generating lately. I've personally never seen a single such popup generated by any Microsoft website and only one single popup in all my years of normal browsing.
On the other hand, I can experience dozens of these in a single session of purposefully risky browsing behavior, most generated directly by the websites being browsed. This is most likely where many of the reports we see here daily come from, though some number are also clearly experienced via advertising on news pages and the like.
I think that Microsoft is more focused on the future of Windows itself, including not only Windows 10 S, but also the Windows Core OS including the Polaris version targeted at consumers and other light-duty users. I suspect that this is where they'll actually solve these types of problems, since many of these problems exist due to legacy components more often used in business.
Rob
-
Rob Koch 26,075 Reputation points Volunteer Moderator
2018-02-28T19:06:18+00:00 I understand what you're saying and from what I've personally seen, Microsoft's pages receive less of these than most others. However, the design of the advertising structure itself is the real problem here and always has been.
As I understand it, the ad networks contract to provide advertising to the page owners like Microsoft, which they then use to supply access to particular demographic groups to the advertisers, who buy these by blocks of ads. With this isolation between advertiser and page owner, it's the ad networks that are responsible for vetting and with the margins they make, there's little interest by them in performing this action.
I believe I've seen mention of yet another layer in these transactions, but even without this it's easy to see why the problem exists. The page owner simply wants revenue, as does the ad network and the advertiser just wants their ad to reach lots of potentially valuable eyes. In the case of popup purveyors, the demographics are only partially important, since what they're truly after is simply potential targets who might be prone to responding to their scams, which could be anyone.
With the trends towards more targeted systems and apps, the interest in general web pages is declining, so this makes any additional effort to protect and maintain this avenue of less concern at all levels as well. I think we're simply seeing a symptom of this decline as the more knowledgeable user moves away from the browser to devices with apps, which by their nature are less susceptible to such simplistic forms of attack.
Just think back about the typical type of user we've seen here over time, with the more knowledgeable mostly disappearing as those still holding onto the older technology appear to be most common now. It might seem that this is due to the better protection provided by Windows 10 and current security it includes, which to an extent may be true, but I feel it's more a reflection of this migration to modern devices and apps within the consumer market.
Rob