I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-05-13T02:01:06+00:00

    I agree ! Microsoft is just checking everyone's patience and wasting everyone's time by asking each individual to provide some data which they can gather if they get 5-6 laptops. Microsoft have tons of employees and I am pretty sure they might be getting same issue but not willing to do anything for it. This is the reason Internet Explorer losing its market share.

    I lost my patience and switched to Chrome and it stopped all popups for me.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2018-05-13T05:02:54+00:00

    Hi, PaulSey. As far as I know, there has never been any report (or reason to believe) that these Trojan:JS/Flafisi.D detections are “false detections” – and the general consensus heretofore has been that these are authentic detections being prompted by malware-site redirects that are carried in on an MSN advertizing channel – and that these malvertising redirects would need to be eliminated at their source by cleaning up the compromised ad supplier. And I think that this is also the understanding of RodrigoLode(MSFT)"). So can you please tell us whether rechanneling the reports for this issue signals a change in the status of the MSN investigation – and can you also please clarify whether or not this is based on some kind of reinterpretation of the circumstances surrounding these Trojan:JS/Flafisi.D detections.

    Thanks,

    GreginMich

    +1

    This is confusing for the home user and the Feedback Hub option is likely a deterrent for reporting.

    If there is a question of the detection being false positive it should have been resolved some time ago.

    Hoping Rodrigo will respond.

    ~bhringer

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-05-13T13:56:28+00:00

    Thanks, bhringer. I’ve reported multiple issues along the way in this thread, and my guess here is that PaulSey... is responding to my reports about problems with the way that Windows Defender Antivirus and Windows Defender SmartScreen handle detections, and that the announcement at the Feedback Hub is actually announcing corrections for the issues that I previously described in this report:

    https://aka.ms/AA1abe5

    There might also have been some confusion regarding the inability to detect my submission of the FlashPlayer.hta file as malware, which in hindsight might also be related to the issue described by Catalin Cimpanu:

    Researchers noted a curious thing about this campaign. The downloaded files — the JavaScript and HTA files — wouldn't execute on a computer if the PC's IP address didn't pass the same ISP and geo filters. The purpose of this second check was to limit analysis from security researchers.

    https://www.bleepingcomputer.com/news/security/malvertising-group-spreading-kovter-malware-via-fake-browser-updates/

    But these issues are incidental to the malvertising issue that Rodrigo is trying to help us with here, and they’re also not being described accurately in the Feedback Hub announcement, so while I sincerely appreciate the efforts to fix Defender’s detections, the malvertising issue is the main topic of this thread, and it takes precedence over any other issues.

    My own experience with the MSN news pages has improved drastically in the last couple of days: The runaway resource utilization that I’ve been seeing on most news pages is gone, and I also haven’t seen any of the fake Adobe Flash Payer update screens or Tech Support Scam pages for a couple of days now – but of course it’s still too soon to say for sure that everything is “all better”.

    In fact, things are so quiet on the MSN news pages that in order to see the changes that PaulSey... is talking about, I had to click on my link to the Yahoo Home page. I just opened up the article on the Schneiderman case and waited for a couple of minutes – and sure enough, the fake Adobe Flash Player update screen popped up. But this time there wasn’t any immediate detection for Trojan:JS/Flafisi.D. So I proceeded to download the FlashPlayer.hta file to my desktop, and at that point the file was detected as a virus and deleted.

    In a second incident on another Yahoo news page, I noticed that the FlashPlayer.hta download tab is now persistent, and that the download is still active even when I page back and then forward, and the page can no longer be found. And then once the download is attempted, the file is detected as a virus and the "FlashPlayer.hta contained a virus and was deleted" message persists on subsequently visited pages:

    So it looks like the detection was "fixed" in the sense that the threat isn't detected until the download is actually attempted – but there's obviously still some more work to be done on the issues that I originally pointed out in this thread, and in my bug report. And once again, it's very important to understand that these issues with the way that Defender processes detections are in no way specific to Trojan:JS/Flafisi.D detections, and that they consequently don't have any direct relevance to the malvertising issue that we’re discussing here. Malvertising simply refers to the appearance of ad-delivered malware pages on a host site.

    Since the changes in Defender’s detection scheme apply generally, it’s easy to see how things have changed just by experimenting with the eicar.com test file; or with the test files provided on the AMTSO and Windows Defender Testground websites:

    http://www.eicar.org/85-0-Download.html

    https://www.amtso.org/security-features-check/

    https://demo.wd.microsoft.com/

    Also note that the test for Windows Defender’s Network Protection feature is now functional, even though the page doesn't display properly:

    https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection

    GreginMich

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-05-13T22:24:57+00:00

    Thanks, bhringer. I’ve reported multiple issues along the way in this thread, and my guess here is that PaulSey... is responding to my reports about problems with the way that Windows Defender Antivirus and Windows Defender SmartScreen handle detections, and that the announcement at the Feedback Hub is actually announcing corrections for the issues that I previously described in this report:

    https://aka.ms/AA1abe5

    There might also have been some confusion regarding the inability to detect my submission of the FlashPlayer.hta file as malware, which in hindsight might also be related to the issue described by Catalin Cimpanu:

    Researchers noted a curious thing about this campaign. The downloaded files — the JavaScript and HTA files — wouldn't execute on a computer if the PC's IP address didn't pass the same ISP and geo filters. The purpose of this second check was to limit analysis from security researchers.

    https://www.bleepingcomputer.com/news/security/malvertising-group-spreading-kovter-malware-via-fake-browser-updates/

    But these issues are incidental to the malvertising issue that Rodrigo is trying to help us with here, and they’re also not being described accurately in the Feedback Hub announcement, so while I sincerely appreciate the efforts to fix Defender’s detections, the malvertising issue is the main topic of this thread, and it takes precedence over any other issues.

    My own experience with the MSN news pages has improved drastically in the last couple of days: The runaway resource utilization that I’ve been seeing on most news pages is gone, and I also haven’t seen any of the fake Adobe Flash Payer update screens or Tech Support Scam pages for a couple of days now – but of course it’s still too soon to say for sure that everything is “all better”.

    In fact, in order to see the changes that PaulSey... is talking about, I had to click on my link to the Yahoo Home page. I just opened up the article on the Schneiderman case and waited for a couple of minutes – and sure enough, the fake Adobe Flash Player update screen popped up. But this time there wasn’t any immediate detection for Trojan:JS/Flafisi.D. So I proceeded to download the FlashPlayer.hta file to my desktop, and at that point it was detected as a virus and deleted – but with no notification of the detection by Windows Defender. When I looked in the Full History page, however, I saw that Defender had indeed make a silent detection for Trojan:JS/Flafisi.D.

    I didn’t have the time to do any detailed testing of this new detection scheme, but if these changes actually resolve the general issue with Windows Defender’s detections that I originally pointed out in this thread, and in my bug report, then I certainly do appreciate the efforts along that line – but once again, please note that these issues with the way that Defender processes detections were not specific to Trojan:JS/Flafisi.D detections, and therefore not directly relevant to the malvertising issue that we’re discussing here.

    GreginMich

    RICKCOE here.  I'm done-I quit.  MY problems really ramped up when I installed the latest POS upgrade to Windows 10 from Microsoft. (No offense meant Rolando).  I installed uBlock Origin which has basically ended EVERY pop-up that comes near my PC.  However, It's about as user friendly as the instructions to build an F-18.  I am going to uninstall it, go back to ADB if that works on windows (can't remember) and go from there.

    I don't know WHAT MS had in mind with the problems created by this latest upgrade to Windows 10.  Specifically the changes to the "sleep" procedures and why because I use Malwarebytes; I can no longer use a lot of Windows Defender items.  IE: Ransomware protection and folder access protection.  MBytes & Defender used to play very well together.  Not anymore!!!!  You rocket scientists make things SO f-ing difficult for those of us that aren't as brilliant as you are.  Thanks!!!!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-05-15T21:24:14+00:00

    I was initially taken aback by the announcement made by PaulSey... in this thread, and by Raluca H in the Feedback Hub, but since there isn’t really any doubt that these changes in Defender’s detection scheme were made by the Windows Defender team in response to some of the issues that we’ve experienced with the Trojan:JS/Flafisi malware, we need to understand the nature of these changes even though they don’t address the MSN malvertising issue per se. The changes in the detection scheme should actually help to dispel a lot of the confusion that was being generated by the way that Defender was detecting Trojan:JS/Flafisi in the browser cache as soon as the malware page popped up:

     

    This tended to give the false impression that the threat was being automatically downloaded to the user’s hard drive as soon as the page was loaded. And then when the threat was detected again later on, this made people wonder if the quarantine might have failed and if the threat might still be active on the system drive. So, as I understand it, the new detection scheme was designed help manage the concerns of users, as well as to resolve the technical issue where Defender was allowing the download of spurious malware files after making an initial detection in the browser cache:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/is-trojanjsflafisid-from-windows-10-defender-it/f0d42e70-7e7c-4d58-8941-6fd3ceb471d9

    In the revised detection scheme, Windows Defender will only detect and take action against a threat when a download is actually initiated by the user. And this change in behavior is reflected in a change in the detection path, which is now the download’s destination path, although the source of the detection is also being clearly identified as a web URL and file:

     

    This is a big change in Defender’s detection scheme, and it really should help allay a lot of the confusion and anxiety that users have been experiencing with respect to the repeating detections that we’ve seen previously in this MSN malvertising campaign – the only downside that I can see with this is that users will no longer have any advance warning that the download is a malware file.

    Defender’s new detection scheme is an important contribution from the Windows Defender team, and I didn’t mean to be dismissive of this contribution in my reply to PaulSey... – but we do need to be clear about the relevance of this contribution to the MSN malvertising issue: Although this change in the way that Defender handles threat detections was made in the context of the MSN malvertising issue, it doesn’t in any way represent a resolution for the underlying issue – malware-site redirects. The malvertising issue will only be resolved when the fake Adobe Flash Player update screens; and the Tech Support Scam pages; and the rogue ads; and the resource issues related to crypto mining have all completely disappeared from the MSN portal pages.

    And the MSN pages are actually looking a lot better on my own PC these days – but if anyone is still seeing these malvertising issues on the MSN web portal, then please report the issue here, and also please send feedback to Rodrigo via the MSN on-site feedback channel. If this malvertising issue has already been resolved, or if it gets resolved in the near future, then as far as I’m concerned, the credit rightfully goes to RodrigoLode(MSFT)") and his team at MSN. In any event, I have to say that I’m really overwhelmed to have seen such great responses from both the Windows Defender team and the MSN Engineering team. Both of these efforts are greatly appreciated.

    GreginMich

    Was this answer helpful?

    0 comments No comments