I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Anonymous
    2018-05-04T16:11:23+00:00

    After several weeks of pop-ups, Trojans, ransomeware etc they have now all stopped! Reset Windows saving all my files and have had no problems since!

    HMMM!  Isn't resetting MS Windows pretty hard core? Makes me nervous.  I've mentioned in other posts what I've done.  It's something I'm just anxiously co-existing with right now.  Although I noticed my PC (or uBlock) completely disabled Flash.  Well I "needed" it for something and re-enabled it.  LET'S SEE WHAT HAPPENS ?!?!?!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-05-04T16:04:45+00:00

    After several weeks of pop-ups, Trojans, ransomeware etc they have now all stopped! Reset Windows saving all my files and have had no problems since!

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-05-04T14:09:59+00:00

    Everyday I get a warning about a Trojan threat on my computer.

    Thank you.

    Since I installed uBlock Origin; I've stopped getting the Flashplayer and Microsoft driver update scam pop-ups.  That blocker pretty much seems to stop most EVERYTHING.  I did get a "warning" from them when a couple of pop ups tried to post when I was hunting for a site.  It's about as easy to understand as their blocking product.  Maybe I'm better off not knowing what I'm missing!!!!

    Good Luck to us all!

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-05-04T13:57:03+00:00

    Everyday I get a warning about a Trojan threat on my computer.

    Thank you.

    Was this answer helpful?

    0 comments No comments
  5. Rob Koch 26,160 Reputation points Volunteer Moderator
    2018-05-02T05:00:35+00:00

    Rodrigo,

    Is that the same telemetry data that the Windows Defender/Anti-Malware teams can provide, since I mentioned to Greg, the originator of this thread that he should suggest you contact them?

    They're obviously able to identify at least the incidents which invoke the Trojan identified in this thread, so I'd think that this might aid in narrowing those particular events down, though that also depends upon whether they can be traced back to the page which originally invoked the redirect.

    I would assume that these ads are not only being targeted at particular types of users, but also that the advertisers involved are using the same techniques that were identified by the Confiant security group in this article about the Ziconium group in January.  This allows them not only to filter for their targets, but also to avoid triggering the ads for security researchers and others trying to find them like your group.

    Uncovering 2017’s Largest Malvertising Operation – Confiant

    As a side note, I eventually realized that in my own case it's my relatively extreme privacy and other settings that allow me to avoid these completely.  Since I have the Advertising ID turned off and also normally use Internet Explorer with both tracking cookies blocked and IE Tracking protection enabled with the EasyPrivacy list, I'm an unlikely target for this type of attack.  My settings have less to do with malvertising than my own aversion to the noise that ads create, but apparently has the side effect of suppressing these type of targeted attacks as well.

    Rob

    Was this answer helpful?

    0 comments No comments