I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Newest
  1. Anonymous
    2018-03-03T20:31:03+00:00

    Thanks for that firsthand report, Charles. A firsthand experience is way more convincing than a thousand words. But with each of my 5 detections, this threat was actually blocked rather than quarantined – and since your detection sounds a little “anomalous”, you might want to run a Full Scan for a double-check, or maybe even check the current status of the threat with the Get-MpThreatDetection command, as I’ve illustrated here:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_start-windows_10/if-i-buy-a-new-computer-running-windows-10-do-i/49a25783-647e-48ec-9e06-dbc0e56b8798

    We have been seeing a few reports of issues with the removal of this threat:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/defenders-finds-and-stops-trojanjsflafisib/531a257f-4470-4275-87be-c249d0a47074

    While it looks like we’ve come out unscathed this time, we really do have to wonder if we’ll be so lucky with the next threat that gets delivered through this malware-site-redirect attack vector – which is why my original question was “what’s next”. Windows Defender is getting stronger every day, but no AV app is really capable of stopping everything out there. And we also have to wonder about how well people with weak or outdated AV protection (and/or unpatched vulnerabilities) will fare against these hit-and-run attacks. That’s why I’m not willing to accept the presence of these malware-site redirects as the “new normal” for trusted sites. Trusted sites shouldn’t pose any risk at all to their users.

    GreginMich

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-03T01:10:04+00:00

    WUPS! I spoke too soon. Let me update this a little.

    Yes, it has now been quarantined just since the Restart:

    and you can see it there. But remember, neither MSN nor Bing are the "Edge" Homepage. 

    The Edge Homepage doesn't actually have news articles. The Edge Homepage actually looks like this:

    Anyway, the Trojan was still never a real threat. The Windows Defender Security Center caught and quarantined it without my having to do anything except (in a minute) go and remove it.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-03-03T00:59:39+00:00

    Hello, Greg. I DO humbly apologize. I have now seen the problem you are talking about. At least, I believe so. I am not sure which page is the "Edge" homepage, You mentioned "News Articles" so I brought up MSN...the usual default homepage for Microsoft and found myself reading about Alec and Alex Baldwin when you're favorite Flash Player Alert appeared.

    I was further informed that "Smart Screen" had been turned off and that that very Trojan required attention from my Windows Defender Security Center.

    Yet, when I opened the Security Center (as you do) I found no trace of this thing downloading, installing, having been installed, OR having been quarantined (which it would have been had it gotten in).

    Also, oddly, my Smart Screen was actually ON---not OFF as my "Notifications" would have it.

    ALL of which tells me that someone has written a pretty clever bot designed to panic us the hell out by making us think they've broken through all our security but, in all actuality, they had done nothing of the sort.

    To make certain I restarted my device, updated my antivirus re-ran the scan, and even checked my Security Screen (still on).

    So, no danger. BUT I AGREE Microsoft needs to jump on this ASAP and kudos to you, mate, for bringing attention to it!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  5. Anonymous
    2018-03-02T18:13:00+00:00

    In my case, the “Use Adobe Flash Player” switch was turned off – but that didn’t prevent this fake Adobe Flash Player update from just trying to install Trojan:JS/Flafisi.D while I was reading a news article on the Edge Start page (for the fifth time now). So the issue here is that the site with the "lurker at the threshold" is in this case the Microsoft Edge Start page – which means that this particular “trusted” site is now in jeopardy of losing my trust, and potentially the trust of others. That’s why I’m trying to call attention to this issue.

    GreginMich

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments