I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Anonymous
    2018-05-13T00:51:55+00:00

    Hi,    Just got the Trojan:js/fla at 7:40pm central. Msm page and went to yahoo/finance then it popped up.

    Please get rid of this soon as I am running out of patience.  I suggest the Microsoft take about 6 laptops and use them just like we do.  I'm sure you will get the pop ups just like us. That way you won't need feed backs from us.

    Guys, this isn't rocket science!  It's a matter of giving service.  If you don't have enough employees just tell us that you don't want to be in the business anymore.

    Jim

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-04-20T16:51:16+00:00

    Hi Randy,

    I'm still trying hard to work through the data to narrow the down the offending ad. One thing that would help would be a fiddler trace of the issue as it happens and it would be more insightful than any work I could do on my end. I haven't asked folks here to do that since it's cumbersome and the issue doesn't repro every time so having a running trace in the background could be very large and end up sharing more info than you'd want. If you get this very often, it might be worth a shot. If you're so inclined

    • Fiddler is available here: https://www.telerik.com/download/fiddler. Let me know if you are willing to do that. I'll still keep working with my team so I can analyze the anonymous data to find the culprit. I want this thread to be active until we reach resolution so I'll post updates as I have them.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-04-18T09:40:34+00:00

    I have just bought a brand-new computer with Windows 10 on it.  Today, I went online and clicked on an article about the East Bay fault.  On the top of my browser, a message stating that Windows had blocked Adobe Flash for my protection popped up.  A moment later, I was redirected to a page suggesting that I install Flash.  I quickly exited the page.  Seconds later, Windows Defender notified me that I had a threat on my computer, and it was JS/Flafisi.D

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-08T18:36:07+00:00

    Looking back through this entire thread it seems to me that it's likely this recent variation of this particular detection, which was dated Feb 02, has probably found a new method of manipulating the Edge browser's JavaScript in a way that allows it to trigger such popups.

    Since from other threads I see that a typical detection is simply for the flashplayer.hta file in the browser cache, it's still questionable whether any true malware is involved.  In fact, as I recall the more typical operation of real-time detections by Microsoft had been to completely ignore the cache, since in most cases these items were blocked by the security features in the browser itself.

    So what I think we may be seeing here is the operation of a modified detection designed to head off this particular family or specific variant due to a deeper problem with whatever vulnerability within the browser it's exploiting to execute its payload.

    In other words, exactly as Microsoft has always done with their antimalware products, they're using Defender to block the operation of a new type of malware exploitation until they can build, test and deploy the actual patch to the Edge code, possibly a flaw in hta handling, that's truly causing the problem.  This is what's causing the increase in "noise" for Defender, a drastic change from it's more typically quiet operation.

    I say all of this due to the discussion of symptoms and apparent change in operation that Greg and others here have mentioned, while for others like myself there's been no change at all, since the attack vector of advertisements is something some of us have always known and blocked as a workaround.

    If I'm correct the timing of the last two variants of this detection on Feb 02, with the later addition of a PowerShell variant on Feb 14th, implies we may see an update released within the typical March Black Tuesday package that deals with this deeper issue.

    Rob

    Furthering the above speculation, here's a possible candidate that may explain why these un-characteristic detections within the cache were added, as well as why the documentation for them seems so sparse.

    Google discloses ‘high-severity’ exploit in Windows 10 before it’s patched

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-07T17:24:51+00:00

    Evil is going on here, that's what.

    Now, here's the part that I find particularly frustrating. Edge is supposed to block pop-ups as a matter of course. That's what I ASSUMED this setting was for, anyway: 

    Now, while I fully realize that won't block ads, as such, it should be blocking SOMETHING!!!

    And Trojans would be a confoundedly good place to start!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments