I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-03-20T01:42:27+00:00

    Here is an example of an offending domain i was redirected to from MSN (which attempted to malware me)... using edge...

    Cmon Microsoft... do something.

    hxxps://mai2olinkwissenschaft.org/2720392039203.... tons of numbers..

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-20T04:02:38+00:00

    "So the payload is really irrelevant, and the point (once again) is that there’s an open malware channel on the MSN news pages."

    You can sit around and pontificate about who's truly responsible to manage the security of the advertising distributed from websites until you're blue in the face.

    Or if you have a modicum of intelligence, you'll realize that the only one truly responsible for your security is yourself, so by simply using an ad blocker or Internet Explorer's Tracking lists for reputable websites that honor it, you can avoid this issue entirely.

    I prefer methods that work to wishful thinking.

    Rob

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-20T13:49:27+00:00

    "So the payload is really irrelevant, and the point (once again) is that there’s an open malware channel on the MSN news pages."

    You can sit around and pontificate about who's truly responsible to manage the security of the advertising distributed from websites until you're blue in the face.

    Or if you have a modicum of intelligence, you'll realize that the only one truly responsible for your security is yourself, so by simply using an ad blocker or Internet Explorer's Tracking lists for reputable websites that honor it, you can avoid this issue entirely.

    I prefer methods that work to wishful thinking.

    Rob

    Did you miss my repeated recommendations for using uBlock Origin for blocking this malvertising campaign; and the fact that I’m currently testing it on designated “blocker-on” days? But if you’re suggesting that I should personally just leave uBlock Origin turned on and forget about this issue, then you’ve misunderstood things pretty badly. I set up this thread in order to monitor the status of this month-long malvertising issue on the MSN news portal. From the standpoint of monitoring things, turning on an ad-blocker just masks the underlying issue. As of yesterday today, MSN viewers are still being exposed to this malvertising campaign, presumably including users on older versions of Windows and/or with third-party AV apps who are reporting this issue by filename, but not reporting any associated AV detection.

    Looking around the web, it’s pretty clear that no one else in the security sphere has ever suggested that hosting a malvertising campaign is a no-action-needed scenario for website owners and administrators, and I’m still hopeful that we won’t be setting a new precedent here. But in the long term, malvertising won’t be manageable without local website analytics of some kind, and I was merely suggesting that Microsoft could establish a more advanced in-house website analytics that leverages feedback from Windows Defender Advanced Threat Protection telemetry and analytics. But they could also work with a third-party website security analytics firm that's demonstrated the capability for rooting out these compromised domains (like Malwarebytes).

    Since this thread is now only serving to divert attention from the issue at hand, I’ll only be monitoring the high-traffic thread. I'd rather spend my time on prototyping a noiseless directional UHF antenna for spectrum analyzers and RF imagers.

    Gadzooks, it’s two-for-one Tuesday at both Wendy’s and the MSN news portal:

    GreginMich

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-03-29T14:31:30+00:00

    Thank you...I've been having both these issues for weeks now, and I was so puzzled because I've been using Windows Defender, and I never go to pages where I would expect something like this to happen...usually just MSN sites...I thought they were relatively "safe".  I'm old and not really tech savvy...your recommendation to use an Ad Blocker is what I'm going to try next, since I did every single thing that Windows Defender told me to, and it keeps happening.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-29T18:31:40+00:00

    Microsoft sites generally are safe, and Microsoft has responded to previous malvertising incidents in short order, at least from what I can gather. But this current malvertising incident is still posing a security risk for unsuspecting viewers; and eroding consumer confidence – and it will soon be taking a big bite out of the site’s advertizing revenues as viewers are forced to deploy ad-blockers in order to protect themselves. So this is a no-win situation for all parties concerned, and I can only hope that it does get resolved soon, and recommend using an ad-blocker extension in the interim.

    Installing an ad-blocker extension in Edge is safe and easy, because the Settings menu will take you directly to the Microsoft Store, where you’ll find a good selection to choose from. I’m very impressed with the effectiveness of uBlock Origin in mitigating this issue, and also with the way it gives us such a clear window into the extensive domain connection activity that’s going on behind the scenes at all of the high-profile sites. But others have reported success with AdBlocker Ultimate, which is also very well-reviewed. And of course, these extensions are all free, so if you’re unhappy with the first one you pick, you can just switch over to another one:

    For Microsoft Edge, find an ad-blocker extension in the Microsoft Store:

    Settings and more > Extensions > Get Extensions from the Store

    The documentation for uBlock Origin (and the instructions for installing it on other browsers) is available here:

    https://github.com/gorhill/uBlock

    GreginMich

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments