I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-04-10T18:02:08+00:00

    Thanks for the report, Houndsong.

    Ads are targeted so you're more likely to get it once it happens. When you see it next time, please send a piece of feedback on the same page the offending ad happen and write: "ad scam - trojan virus found on this page". I'll be able to mine the requests to find the offending ad and why that and hopefully narrow down a culprit to the Adobe scam. I think there is a good chance I can find something out of your report.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-04-10T18:05:08+00:00

    Hi Bhavesh,

    When you do get the .hta, does it redirect the whole page or are you still within the MSN article? Next time, could you please send a piece of feedback? I can collect some metadata around it to try to find the offending ad. This is more widespread than the feedback I've received so far so I really want to narrow it down, but it's so targeted that's been difficult to nail.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-04-10T18:05:49+00:00

    Will do. Whatever this is, it's definitely something ad-related. With ad-blocking turned off, this page was just peaking at ~1500 MB (80%) and ~35% CPU (within 15 minutes) – when I got hit with another fake Adobe Flash Player update:

    https://www.msn.com/en-us/news/world/with-syria-in-focus-trump-cancels-trip-to-latin-america/ar-AAvIqg3?ocid=spartandhp

    I paged-back to the news article; and within 3 minutes, I was seeing ~1780 MB and ~30% CPU. The baseline for this news page, with ad-blocking turned on, is ~0.5% CPU and ~242 MB.

    GreginMich

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-04-10T18:06:10+00:00

    Btw, please write "adobe scam - ad with virus" in the feedback so I can find your entry in my backend.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-04-10T18:43:45+00:00

    Oh wow...so it seems you're off the context of the page as soon as the ad loads. I'll see if I can get something out of the URL you're showing that it's trying to load the hta. Please still submit an entry for feedback so I can try to find the exact culprit.

    Was this answer helpful?

    0 comments No comments