I have been getting these when I go into a story featured on my.yahoo. Defender was allowing this to be displayed DESPITE setting the action to block from warn. So now I am using Norton Security Suite. The page/tab/website is removed along with a Norton message that it blocked an intrusion from 159.65.226.135 Fake Tech Support Website 165. I believe Norton is better at explaining what happened and does not let the page display. Perhaps Edge/Defender needs to do that.
I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page
Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:
In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.
Invisible resource thieves: The increasing threat of cryptocurrency miners
Especially important to report these occurrences or any other odd behaviors after using MSN website.
Moderator Edit: Provided update.
Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:
This one was easy to handle because it was just the old-fashioned dialog loop based scam:
– but what’s coming next Microsoft?
GreginMich
[Original Title: Surprised again]
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
386 answers
Sort by: Newest
-
Anonymous
2018-03-05T23:03:21+00:00 -
Anonymous
2018-03-05T02:18:15+00:00 -
Anonymous
2018-03-04T15:49:46+00:00 Thanks guys, but the issues with these unannounced real-time site-development episodes (?) are putting everything on hold for me. I only have access to this site on one of the three machines that I normally use on a day-to-day basis, and I’m not sure that I’ll be able to hold on to that for long. So now I’m going to have to be monitoring the ability of the more seriously affected machines to recover from this chaos and try to figure out why it would be machine specific, and I won’t have the time to work specifically for a resolution of this malware-site redirect issue. Of course there's a possibility that these two issues might be intertwined, so I'll eventually be looking at this.
[Edit for Update 2:44 PM 3/4/2018]
Nothing loads in the main page or profile now, but through some quirk of fate, when I search for “GreginMich” this thread is one of the 10 entries that show up in the search result. So thank you website gurus for providing me with this wormhole that allows me to reply to exactly one of the threads in your forum. This is another great confidence booster for me.
[end Edit]
[Edit 6:15 3/4/2018]
I was just reading the story about Trump’s turnabout on talks with North Korea when this appeared:
This was a slightly more sophisticated Tech Support Scam page, but it could still be broken with the Dialog Loop Protection checkbox.
[end Edit]
GreginMich
-
Rob Koch 26,075 Reputation points Volunteer Moderator
2018-03-04T10:12:14+00:00 bhringer has a good point Greg, while testing I tried to recall and reverse everything I had done that might protect me from such a drive-by attack, but had completely forgotten my own use of OpenDNS.
Think of this service as a more dynamic extension of the manually managed IP blocklists that were popular at the time of Windows XP, instead embedded within the operation of the OpenDNS servers themselves.
Though I use their free service for the entirely different purpose of DNS stability vs. the that of the notoriously flaky cable networks, I'm effectively protected by whatever site based anti-malware protection these servers might also provide. This may help explain why I have been unable to reproduce these attacks and very possibly others, since my own Win10 PC has been completely silent in these respects unless I purposefully browse manually into areas where I fully expect to see such attacks.
Obviously this doesn't resolve any of the deeper issues you've surfaced in this thread, but it may aid in understanding why certain individuals seem to encounter such attacks more often than others, despite the belief that it's caused by specific websites or advertising networks, which I've always felt is worth exploration.
Rob
-
bhringer-9380 4,350 Reputation points Volunteer Moderator2018-03-04T06:29:03+00:00 Just for shirts and giggles flush DNS cache and then use OpenDNS on test machine.
Britec09 has decent video for reference.
https://www.youtube.com/watch?v=xkx4tRWm5_Y
Video title "How To Increase Your Internet Speed with Open DNS" applies but also consider Cisco acquired OpenDNS a while back to enhance their security, has some effective blocking features.
~bhringer
Would have replied sooner if MS servers hadn't been experiencing issues.