Thanks, bhringer. I’ve reported multiple issues along the way in this thread, and my guess here is that
PaulSey... is responding to my reports about problems with the way that Windows Defender Antivirus and Windows Defender SmartScreen handle detections, and that the announcement at the Feedback Hub is actually announcing
corrections for the issues that I previously described in this report:
https://aka.ms/AA1abe5
There might also have been some confusion regarding the inability to detect my submission of the FlashPlayer.hta file as malware, which in hindsight might also be related to the issue described by Catalin Cimpanu:
Researchers noted a curious thing about this campaign. The downloaded files — the JavaScript and HTA files — wouldn't execute on a computer if the PC's IP address didn't pass the same ISP and geo filters. The purpose of this second check was to limit analysis from security researchers.
https://www.bleepingcomputer.com/news/security/malvertising-group-spreading-kovter-malware-via-fake-browser-updates/
But these issues are incidental to the malvertising issue that Rodrigo is trying to help us with here, and they’re also not being described accurately in the Feedback Hub announcement, so while I sincerely appreciate the efforts to fix Defender’s detections,
the malvertising issue is the main topic of this thread, and it takes precedence over any other issues.
My own experience with the MSN news pages has improved drastically in the last couple of days: The runaway resource utilization that I’ve been seeing on most news pages is gone, and I also haven’t seen any of the fake Adobe Flash Payer update screens
or Tech Support Scam pages for a couple of days now – but of course it’s still too soon to say for sure that everything is “all better”.
In fact, in order to see the changes that PaulSey... is talking about, I had to click on my link to the Yahoo Home page. I just opened up the article on the
Schneiderman case and waited for a couple of minutes – and sure enough, the fake Adobe Flash Player update screen popped up. But this time there wasn’t any immediate detection for Trojan:JS/Flafisi.D. So I proceeded to download the FlashPlayer.hta
file to my desktop, and at that point it was detected as a virus and deleted – but with no notification of the detection by Windows Defender. When I looked in the Full History page, however, I saw that Defender had indeed make a silent detection for Trojan:JS/Flafisi.D.
I didn’t have the time to do any detailed testing of this new detection scheme, but if these changes actually resolve the general issue with Windows Defender’s detections that I originally pointed out in this thread, and in my bug report, then I certainly
do appreciate the efforts along that line – but once again, please note that these issues with the way that Defender processes detections were not specific to Trojan:JS/Flafisi.D detections, and therefore not directly relevant to the malvertising issue that
we’re discussing here.
GreginMich
RICKCOE here. I'm done-I quit. MY problems really ramped up when I installed the latest POS upgrade to Windows 10 from Microsoft. (No offense meant Rolando). I installed uBlock Origin which has basically ended EVERY pop-up that comes near my PC. However,
It's about as user friendly as the instructions to build an F-18. I am going to uninstall it, go back to ADB if that works on windows (can't remember) and go from there.
I don't know WHAT MS had in mind with the problems created by this latest upgrade to Windows 10. Specifically the changes to the "sleep" procedures and why because I use Malwarebytes; I can no longer use a lot of Windows Defender items. IE: Ransomware
protection and folder access protection. MBytes & Defender used to play very well together. Not anymore!!!! You rocket scientists make things SO f-ing difficult for those of us that aren't as brilliant as you are. Thanks!!!!