I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-03-01T17:29:37+00:00

    I didn’t have any problem removing the Tech Support Scam, Cyber; and I already know how to report bad websites. If you review my profile, you’ll see that I did all of the original groundwork on identifying the dialog loop as the underlying issue with these Tech Support Scams, and also the promotional work for the Microsoft Dialog Loop Protection patch for this issue.

    So that’s not really what this discussion is about – it’s really about the sudden appearance of malware and Tech Support Scams on the Edge Start page. I understand that my original title was impromptu and didn’t properly convey the content of the thread, so I agree that it should be changed. But I’m going to edit your edit in order to more accurately reflect the content of the discussion. 

    Thanks,

    GreginMich

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-01T17:48:12+00:00

    I tried to duplicate this problem myself using Edge after disabling all my more restrictive settings and enabling the newsfeed and top sites for both the start page and new tabs.  Have yet to see a single popup with only Windows Defender in real-time operation (MBAM free version only).

    I even tried browsing all over the various Yahoo News sites worldwide and clicking random, mostly politicl articles in both that and the MSN driven start page and still nothing.

    Any thoughts?

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-01T18:23:38+00:00

    There’s always the happy thought that they might have patched things up and made everything better by now. But I spend lots of time navigating on the Edge Start page (these attacks only occur after navigating to a specific article), and after a weeklong lull had me believing that everything was all better, I was hit again. So the highly intermittent and sporadic nature of these attacks makes them very hard to reproduce – and consequently the “observational data” will probably have to come mostly from the first-hand accounts of people who’ve been hit by one of these attacks. The upside is that this attack vector won’t be very effective if it’s limited to these occasional sniper shots.

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-01T19:38:26+00:00

    OK, that's helpful, since from past experience with the MSN home page I know that all of these articles are sourced from someone else, with Microsoft nothing but a façade that provides access to these and other MSN front ends.

    Yahoo, on the other hand, provides much of the news and other articles on their own sites.

    What this implies to me is that the attacks are likely coming from another site, through the advertising or other portions of the display that might be embedded within the supposed MSN sub-pages you're viewing.  It's still possible they're simply embedded within the ads delivered directly to the MSN generated pages, but that should result in them displaying on the main start page as well.

    It's also possible that the specific ads used to deliver these are tuned to the political affiliations or tendencies of those reading such articles.  As with phishing where the misspellings and other flaws are actually filters used by the spammers to weed out the more aware who'd be less likely to take the bait, displaying these popups only to those reading specific types of articles may provide a better response rate for the scammers.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-02T15:40:44+00:00

    I just walked away for about 20 minutes to check on a Windows 10 reinstallation that I’m doing for a friend – and this is what had replaced my news article upon my return:

     

    So now I’m wondering if the issue might be more easily reproducible if you just give the page some time to cycle through all of its ads. I’ll give that a try myself on another machine.

    GreginMich

    Was this answer helpful?

    0 comments No comments