I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Anonymous
    2018-04-09T21:31:57+00:00

    Thanks for the pin and for the heads up to reply to OP. I'll follow that guideline going forward.

    Was this answer helpful?

    9 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-29T18:31:40+00:00

    Microsoft sites generally are safe, and Microsoft has responded to previous malvertising incidents in short order, at least from what I can gather. But this current malvertising incident is still posing a security risk for unsuspecting viewers; and eroding consumer confidence – and it will soon be taking a big bite out of the site’s advertizing revenues as viewers are forced to deploy ad-blockers in order to protect themselves. So this is a no-win situation for all parties concerned, and I can only hope that it does get resolved soon, and recommend using an ad-blocker extension in the interim.

    Installing an ad-blocker extension in Edge is safe and easy, because the Settings menu will take you directly to the Microsoft Store, where you’ll find a good selection to choose from. I’m very impressed with the effectiveness of uBlock Origin in mitigating this issue, and also with the way it gives us such a clear window into the extensive domain connection activity that’s going on behind the scenes at all of the high-profile sites. But others have reported success with AdBlocker Ultimate, which is also very well-reviewed. And of course, these extensions are all free, so if you’re unhappy with the first one you pick, you can just switch over to another one:

    For Microsoft Edge, find an ad-blocker extension in the Microsoft Store:

    Settings and more > Extensions > Get Extensions from the Store

    The documentation for uBlock Origin (and the instructions for installing it on other browsers) is available here:

    https://github.com/gorhill/uBlock

    GreginMich

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-01T04:41:49+00:00

    I’ve reproduced the search engine issue on a couple of other PCs by just searching for “Trojan:JS/Flafisi.D”. Is this SEO poisoning gone crazy, or is there maybe a deeper issue here (it’s almost as bad as the local search engine issue). This is all too much extra work if I can’t find a usable search engine, so I’m inclined to just sit back and let things run their course. This issue definitely seems to be a parallel with the Yahoo issue, since these attacks are clearly site-specific – but then again, it’s hard to prove that there’s a general issue when the attacks are so sporadic. Tomorrow I’ll see if I can reproduce the detection/scam on a second machine, and maybe run some more scans on this one. So thanks for that tip, bhringer.

    GreginMich

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments
  4. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2018-03-01T03:52:06+00:00

    Ever tried ZHPCleaner? It targets browser issues.

    https://www.nicolascoolman.com/download/zhpcleaner/

    ~bhringer

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-20T13:49:27+00:00

    "So the payload is really irrelevant, and the point (once again) is that there’s an open malware channel on the MSN news pages."

    You can sit around and pontificate about who's truly responsible to manage the security of the advertising distributed from websites until you're blue in the face.

    Or if you have a modicum of intelligence, you'll realize that the only one truly responsible for your security is yourself, so by simply using an ad blocker or Internet Explorer's Tracking lists for reputable websites that honor it, you can avoid this issue entirely.

    I prefer methods that work to wishful thinking.

    Rob

    Did you miss my repeated recommendations for using uBlock Origin for blocking this malvertising campaign; and the fact that I’m currently testing it on designated “blocker-on” days? But if you’re suggesting that I should personally just leave uBlock Origin turned on and forget about this issue, then you’ve misunderstood things pretty badly. I set up this thread in order to monitor the status of this month-long malvertising issue on the MSN news portal. From the standpoint of monitoring things, turning on an ad-blocker just masks the underlying issue. As of yesterday today, MSN viewers are still being exposed to this malvertising campaign, presumably including users on older versions of Windows and/or with third-party AV apps who are reporting this issue by filename, but not reporting any associated AV detection.

    Looking around the web, it’s pretty clear that no one else in the security sphere has ever suggested that hosting a malvertising campaign is a no-action-needed scenario for website owners and administrators, and I’m still hopeful that we won’t be setting a new precedent here. But in the long term, malvertising won’t be manageable without local website analytics of some kind, and I was merely suggesting that Microsoft could establish a more advanced in-house website analytics that leverages feedback from Windows Defender Advanced Threat Protection telemetry and analytics. But they could also work with a third-party website security analytics firm that's demonstrated the capability for rooting out these compromised domains (like Malwarebytes).

    Since this thread is now only serving to divert attention from the issue at hand, I’ll only be monitoring the high-traffic thread. I'd rather spend my time on prototyping a noiseless directional UHF antenna for spectrum analyzers and RF imagers.

    Gadzooks, it’s two-for-one Tuesday at both Wendy’s and the MSN news portal:

    GreginMich

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments