I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Newest
  1. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-02-28T22:25:16+00:00

    I didn't say anyone was passing the buck here, though it's obviously possible in this scenario, it's just not possible to truly manage the security of these advertisements when such a convoluted, layered set of systems exists.

    I don't think Microsoft is ignoring this or they'd be spewing far grater numbers of these similar to the issues that Le Boule mentioned Yahoo has been generating lately.  I've personally never seen a single such popup generated by any Microsoft website and only one single popup in all my years of normal browsing.

    On the other hand, I can experience dozens of these in a single session of purposefully risky browsing behavior, most generated directly by the websites being browsed.  This is most likely where many of the reports we see here daily come from, though some number are also clearly experienced via advertising on news pages and the like.

    I think that Microsoft is more focused on the future of Windows itself, including not only Windows 10 S, but also the Windows Core OS including the Polaris version targeted at consumers and other light-duty users.  I suspect that this is where they'll actually solve these types of problems, since many of these problems exist due to legacy components more often used in business.

    Rob

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-02-28T20:52:45+00:00

    But passing the buck won’t help protect the people who use the Microsoft Start page, or solve the issue of trust. Sites that host malware like this are considered “compromised” – and since this is a Microsoft site, they’re ultimately responsible for doing whatever it takes to break the supply chain and clean things up. It’s not just about protecting their bottom line – it’s about protecting their reputation and their customers.

    GreginMich

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-02-28T19:06:18+00:00

    I understand what you're saying and from what I've personally seen, Microsoft's pages receive less of these than most others.  However, the design of the advertising structure itself is the real problem here and always has been.

    As I understand it, the ad networks contract to provide advertising to the page owners like Microsoft, which they then use to supply access to particular demographic groups to the advertisers, who buy these by blocks of ads.  With this isolation between advertiser and page owner, it's the ad networks that are responsible for vetting and with the margins they make, there's little interest by them in performing this action.

    I believe I've seen mention of yet another layer in these transactions, but even without this it's easy to see why the problem exists.  The page owner simply wants revenue, as does the ad network and the advertiser just wants their ad to reach lots of potentially valuable eyes.  In the case of popup purveyors, the demographics are only partially important, since what they're truly after is simply potential targets who might be prone to responding to their scams, which could be anyone.

    With the trends towards more targeted systems and apps, the interest in general web pages is declining, so this makes any additional effort to protect and maintain this avenue of less concern at all levels as well.  I think we're simply seeing a symptom of this decline as the more knowledgeable user moves away from the browser to devices with apps, which by their nature are less susceptible to such simplistic forms of attack.

    Just think back about the typical type of user we've seen here over time, with the more knowledgeable mostly disappearing as those still holding onto the older technology appear to be most common now.  It might seem that this is due to the better protection provided by Windows 10 and current security it includes, which to an extent may be true, but I feel it's more a reflection of this migration to modern devices and apps within the consumer market.

    Rob

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-02-28T18:18:03+00:00

    I’m certainly not surprised to see something like this while I’m using the Edge browser – but I’ve never seen anything like this on a Microsoft site before, and I’ve been browsing from the Start page every day since Edge was launched – first multiple detections for Trojan:JS/Flafisi.D last week, and now this. Since Microsoft's home page is a big source of advertizing dollars these days, I would expect Microsoft to show a little interest in cleaning up its act – just to keep users from switching over to another startup page (or another browser), or from installing an ad-blocker. But I sure appreciate the feedback here, because I wasn’t fully aware of the scope of this issue.

    GreginMich

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-02-28T17:39:21+00:00

    I’ve seen that specific popup numerous times using Edge, using Chrome, using Internet Explorer, using Win 7, using Win 10, using a Vista, using Windows Defender, using Emsisoft Antimalware, using Kaspersky Free and with one common denominator…Yahoo webpage.  Have received complaints from acquaintances about the same popup –  also on Yahoo.

    Yahoo says there is nothing wrong on their webpage and that the issue must be on all of the computers I’m using.  Uh Huh!  Yeah!  Sure!

    No problems closing down the browser when I see the popup though once I had to use Task Manager.  No suspect browser extensions found and "Quick Scans" after restart found nothing either.

    Have not seen in a couple of weeks on any computers I'm using though there’ve been more reports of it on the forum.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments