I have been getting these when I go into a story featured on my.yahoo. Defender was allowing this to be displayed DESPITE setting the action to block from warn. So now I am using Norton Security Suite. The page/tab/website is removed along with a Norton message that it blocked an intrusion from 159.65.226.135 Fake Tech Support Website 165. I believe Norton is better at explaining what happened and does not let the page display. Perhaps Edge/Defender needs to do that.
I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page
Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:
In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.
Invisible resource thieves: The increasing threat of cryptocurrency miners
Especially important to report these occurrences or any other odd behaviors after using MSN website.
Moderator Edit: Provided update.
Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:
This one was easy to handle because it was just the old-fashioned dialog loop based scam:
– but what’s coming next Microsoft?
GreginMich
[Original Title: Surprised again]
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
386 answers
Sort by: Oldest
-
Anonymous
2018-03-05T23:03:21+00:00 -
Anonymous
2018-03-06T19:49:09+00:00 Until I understand them better, the Exploit Protection settings are strictly off-limits as far as I’m concerned – and I don’t really see anything there that jumps out as a potential remedy for these malware-website redirects. I had already applied the Attack Surface Reduction rules that apply to JavaScript, and that appear to be general in scope, although I’m not sure that they actually are:
Rule: Block JavaScript or VBScript from launching downloaded executable content
Rule: Block execution of potentially obfuscated scripts
These would seem to be the only obvious defenses against JavaScript-based attacks that might apply generally to the browser. On the other hand, these rules don’t seem to cover the case of JavaScript-based redirects, and there haven’t been any detections for these events in response to the malware-website redirects on this PC. But I just had my seventh detection for Trojan:JS/Flafisi.D yesterday, as well as my second Tech Support Scam incident the day before that – so I’ve decided that it’s time to test the popular idea that these redirects are the handiwork of some kind of JavaScript-based redirection that comes packaged with the MSN advertizing stream – and that they can be eliminated by using an ad-blocker. Therefore, I’ve installed uBlockOrigen, which seems to be the most-recommended extension for blocking ads at the Microsoft Store:
Settings and more > Extensions > Get Extensions from the store
For testing, I’m simply going to alternate between ad-blocker on and ad-blocker off for my news browsing sessions, and see what happens. Since this and other ad-blockers are available for other browsers, this test can be applied generally by anyone who’s experiencing this issue on another browser or another homepage.
GreginMich
-
Anonymous
2018-03-06T20:55:10+00:00 Sounds good.
I might mention since I have been working with those Exploit Protection Settings (turning some on that were off by default) I have visited the MSN page and read a few stories without again being attacked by anything. But that may just have been "the luck of the draw" in that nothing was prowling around when I was there.
Or maybe these changes made a difference.
What I CAN say is that none of my functions have been impaired by the changes which is always a good thing.
Will let you know when another attack hits and, after a month or so if nothing has.
Yo keep us informed on your progress too!
-
Anonymous
2018-03-06T20:57:29+00:00 PS: Good Article here: https://www.ghacks.net/2017/10/25/configure-windows-defender-exploit-guard-in-windows-10/