I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-05-08T21:20:25+00:00

    Hello, I have been using the UBlock since 4/28. The good I have not gotten any flash popups since then. The bad I use MSN as my home page and had a practice of reading or browsing the 12 or so articles daily. Now they no longer appeasr and I just have a white empty box.

     I would gladly uninstall Ublock if Microsoft ever gets around to improving Edge and stop the Flash popup. Any Financial work or deep browsing I now use Chrome.     

    Received the following information the other day.  Have not had time to verify.  Except that I've been using MBytes for years.

    Larry (Malwarebytes Support)

    May 1, 09:48 PDT

    See if this helps with uBlock

    https://www.dailywoke.com/how-to-use-ublock-origin-to-block-all-ads-complete-guide/

    Larry Tate - "LDT"

    Senior Malware Removal Specialist

    Technical Support Specialist

    support.malwarebytes.com

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-05-11T01:40:49+00:00

    Hi Mary,

    Could you please submit a piece of feedback saying "trojan threat - please help"? I'll use this as a seed to investigate your cases together with all others. You're definitely getting the offending ad that downloads the virus as a targeted advertisement. 

    To submit feedback - just go to www.msn.com. Scroll the page just a tad bit to see the "Feedback" button at the bottom right corner of the page; click to open the dialog and write the message above. It would help me a ton!!

    Thank you!

    -Rodrigo 

    MSN Engineering.

    HI Rodrigo-NEED HELP PLEASE:

     rule of patching.

    1. never install a Windows 10 feature update the same week it comes out.  I don't care that you get a pop saying CLICK ME it's the April update, you never want to be part of the first round of updaters.
    2. Early patching means that antivirus is often not ready.  I personally feel that windows defender is just fine on Windows 10.  Per my read you have hitman and cleaner and malware bytes and that's way way way too many antivirus on any platform.
    3. Do you know if you have HOme sku or Pro sku?

     I got this email the other day and 2 phone calls with caller ID 1 800 Service  800-642-7676.  I did talk in general terms with the person who called tonight.  He is supposed to call me back to work on case. I blew off Malwarebytes because I couldn't understand what they wanted me to do!!!!

    When someone calls-what is the best way to be sure you are talking to a legitimate representative?????

    Microsoft Technical Support <******@css.one.microsoft.com>

    |

    Yesterday, 10:38 PM

    You

    Dear Rick,

    We tried to call you, but weren’t able to contact you.

    If you’d like us to call you again, please reply to this email with the best time and number to contact you.

    Thank you for visiting Answer Desk. We’re here if you need us.

    The Microsoft Answer Desk team

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-05-12T00:17:21+00:00

    Hi,

    We are making adjustments on identification of Flafisi.D malware. If you are still getting reports of ‘false detections’, please use this Feedback Link and provide us the steps you follow to reproduce the detection, including the URL from the browser.

    If you would like to report **** ‘false detections” other than Flafisi.D, you can use this Feedback Link or submit the detected file here.

    Thanks,

    Paul...

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-05-12T02:12:05+00:00

    Hi, PaulSey. As far as I know, there has never been any report (or reason to believe) that these Trojan:JS/Flafisi.D detections are “false detections” – and the general consensus heretofore has been that these are authentic detections being prompted by malware-site redirects that are carried in on an MSN advertizing channel – and that these malvertising redirects would need to be eliminated at their source by cleaning up the compromised ad supplier. And I think that this is also the understanding of RodrigoLode(MSFT)"). So can you please tell us whether rechanneling the reports for this issue signals a change in the status of the MSN investigation – and can you also please clarify whether or not this is based on some kind of reinterpretation of the circumstances surrounding these Trojan:JS/Flafisi.D detections.

    Thanks,

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more