I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Newest
  1. Anonymous
    2018-03-07T04:05:38+00:00

    OK. Just got hit again while visiting the MSN homepage. Didn't even click on a story. The Trojan just appeared: 

    Microsoft is going to have to escalate this issue. Yes, Defender intercepted and quarantined it until I could remove it manually. But I am disinclined to get my news from MSN while this is happening.

    I mean...just how VULNERABLE IS this site, anyway?

    Yeah. It's gone. I am undamaged. But, as GreginMich has pointed out:

    It should NOT be there!

    Are the Techs at Microsoft actually DOING anything about this?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-06T20:57:29+00:00

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-03-06T20:55:10+00:00

    Sounds good.

    I might mention since I have been working with those Exploit Protection Settings (turning some on that were off by default) I have visited the MSN page and read a few stories without again being attacked by anything. But that may just have been "the luck of the draw" in that nothing was prowling around when I was there.

    Or maybe these changes made a difference.

    What I CAN say is that none of my functions have been impaired by the changes which is always a good thing.

    Will let you know when another attack hits and, after a month or so if nothing has.

    Yo keep us informed on your progress too!

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-03-06T19:49:09+00:00

    Until I understand them better, the Exploit Protection settings are strictly off-limits as far as I’m concerned – and I don’t really see anything there that jumps out as a potential remedy for these malware-website redirects. I had already applied the Attack Surface Reduction rules that apply to JavaScript, and that appear to be general in scope, although I’m not sure that they actually are:

    Rule: Block JavaScript or VBScript from launching downloaded executable content

    Rule: Block execution of potentially obfuscated scripts

    These would seem to be the only obvious defenses against JavaScript-based attacks that might apply generally to the browser. On the other hand, these rules don’t seem to cover the case of JavaScript-based redirects, and there haven’t been any detections for these events in response to the malware-website redirects on this PC. But I just had my seventh detection for Trojan:JS/Flafisi.D yesterday, as well as my second Tech Support Scam incident the day before that – so I’ve decided that it’s time to test the popular idea that these redirects are the handiwork of some kind of JavaScript-based redirection that comes packaged with the MSN advertizing stream – and that they can be eliminated by using an ad-blocker. Therefore, I’ve installed uBlockOrigen, which seems to be the most-recommended extension for blocking ads at the Microsoft Store:

    Settings and more > Extensions > Get Extensions from the store

    For testing, I’m simply going to alternate between ad-blocker on and ad-blocker off for my news browsing sessions, and see what happens. Since this and other ad-blockers are available for other browsers, this test can be applied generally by anyone who’s experiencing this issue on another browser or another homepage.

    GreginMich

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-03-06T16:12:34+00:00

    And the others on the same page, I hasten to add.

    and there are still more settings but it snowed last night and I can't get to the Kodak store for more film.

    Was this answer helpful?

    0 comments No comments