Until I understand them better, the Exploit Protection settings are strictly off-limits as far as I’m concerned – and I don’t really see anything there that jumps out as a potential remedy for
these malware-website redirects. I had already applied the Attack Surface Reduction rules that apply to JavaScript, and that appear to be general in scope, although I’m not sure that they actually are:
Rule:
Block JavaScript or VBScript from launching downloaded executable content
Rule:
Block execution of potentially obfuscated scripts
These would seem to be the only obvious defenses against JavaScript-based attacks that might apply generally to the browser. On the other hand, these rules don’t seem to cover the case of JavaScript-based
redirects, and there haven’t been any detections for these events in response to the malware-website redirects on this PC. But I just had my seventh detection for Trojan:JS/Flafisi.D yesterday, as well as my second Tech Support Scam incident the day before
that – so I’ve decided that it’s time to test the popular idea that these redirects are the handiwork of some kind of JavaScript-based redirection that comes packaged with the MSN advertizing stream – and that they can be eliminated by using an ad-blocker.
Therefore, I’ve installed uBlockOrigen, which seems to be the most-recommended extension for blocking ads at the Microsoft Store:
Settings and more > Extensions >
Get Extensions from the store
For testing, I’m simply going to alternate between ad-blocker on and ad-blocker off for my news browsing sessions, and see what happens. Since this and other ad-blockers are available for other
browsers, this test can be applied generally by anyone who’s experiencing this issue on another browser or another homepage.
GreginMich