I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Anonymous
    2018-09-23T15:34:54+00:00

    Hi again,

    Actually what Mindy reported was what happened to me with the same screen shot she provided. So should we have posted new threads? I only responded to Greg's reply as I elieve I saw that same screen shot in this thread.

    Hello Vito. As your screen is the same as Mindy's, you can of course wait for Mindy to create the thread but you're in his/her hands so why not create the new thread in V&M yourself?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-08-16T11:13:42+00:00

    Yes and I do not know what to do to fix this , someone is controlling my desk top as well it is areal problem.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-08-13T08:47:54+00:00

    I don't know what was it used for

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-06-16T01:14:45+00:00

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-05-13T22:24:57+00:00

    Thanks, bhringer. I’ve reported multiple issues along the way in this thread, and my guess here is that PaulSey... is responding to my reports about problems with the way that Windows Defender Antivirus and Windows Defender SmartScreen handle detections, and that the announcement at the Feedback Hub is actually announcing corrections for the issues that I previously described in this report:

    https://aka.ms/AA1abe5

    There might also have been some confusion regarding the inability to detect my submission of the FlashPlayer.hta file as malware, which in hindsight might also be related to the issue described by Catalin Cimpanu:

    Researchers noted a curious thing about this campaign. The downloaded files — the JavaScript and HTA files — wouldn't execute on a computer if the PC's IP address didn't pass the same ISP and geo filters. The purpose of this second check was to limit analysis from security researchers.

    https://www.bleepingcomputer.com/news/security/malvertising-group-spreading-kovter-malware-via-fake-browser-updates/

    But these issues are incidental to the malvertising issue that Rodrigo is trying to help us with here, and they’re also not being described accurately in the Feedback Hub announcement, so while I sincerely appreciate the efforts to fix Defender’s detections, the malvertising issue is the main topic of this thread, and it takes precedence over any other issues.

    My own experience with the MSN news pages has improved drastically in the last couple of days: The runaway resource utilization that I’ve been seeing on most news pages is gone, and I also haven’t seen any of the fake Adobe Flash Payer update screens or Tech Support Scam pages for a couple of days now – but of course it’s still too soon to say for sure that everything is “all better”.

    In fact, in order to see the changes that PaulSey... is talking about, I had to click on my link to the Yahoo Home page. I just opened up the article on the Schneiderman case and waited for a couple of minutes – and sure enough, the fake Adobe Flash Player update screen popped up. But this time there wasn’t any immediate detection for Trojan:JS/Flafisi.D. So I proceeded to download the FlashPlayer.hta file to my desktop, and at that point it was detected as a virus and deleted – but with no notification of the detection by Windows Defender. When I looked in the Full History page, however, I saw that Defender had indeed make a silent detection for Trojan:JS/Flafisi.D.

    I didn’t have the time to do any detailed testing of this new detection scheme, but if these changes actually resolve the general issue with Windows Defender’s detections that I originally pointed out in this thread, and in my bug report, then I certainly do appreciate the efforts along that line – but once again, please note that these issues with the way that Defender processes detections were not specific to Trojan:JS/Flafisi.D detections, and therefore not directly relevant to the malvertising issue that we’re discussing here.

    GreginMich

    RICKCOE here.  I'm done-I quit.  MY problems really ramped up when I installed the latest POS upgrade to Windows 10 from Microsoft. (No offense meant Rolando).  I installed uBlock Origin which has basically ended EVERY pop-up that comes near my PC.  However, It's about as user friendly as the instructions to build an F-18.  I am going to uninstall it, go back to ADB if that works on windows (can't remember) and go from there.

    I don't know WHAT MS had in mind with the problems created by this latest upgrade to Windows 10.  Specifically the changes to the "sleep" procedures and why because I use Malwarebytes; I can no longer use a lot of Windows Defender items.  IE: Ransomware protection and folder access protection.  MBytes & Defender used to play very well together.  Not anymore!!!!  You rocket scientists make things SO f-ing difficult for those of us that aren't as brilliant as you are.  Thanks!!!!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments