I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-03-07T04:05:38+00:00

    OK. Just got hit again while visiting the MSN homepage. Didn't even click on a story. The Trojan just appeared: 

    Microsoft is going to have to escalate this issue. Yes, Defender intercepted and quarantined it until I could remove it manually. But I am disinclined to get my news from MSN while this is happening.

    I mean...just how VULNERABLE IS this site, anyway?

    Yeah. It's gone. I am undamaged. But, as GreginMich has pointed out:

    It should NOT be there!

    Are the Techs at Microsoft actually DOING anything about this?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-07T04:49:54+00:00

    I'd be interested to know what is actually being detected and quarantined, as well as where it's being detected.

    If it's being detected in the browser cache, it's highly possible that this is the result of the Edge browser's default setting to Use page prediction..., since this may cause the detected file to be downloaded before the user actually clicks on anything.

    It's apparent that there's some sort of script or other vulnerability that's initially starting the process, but it's not clear if the next stage is still under user control or not.  We just seem to be assuming that the fact that Defender is activated means the file has made a successful intrusion.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-07T14:31:08+00:00

    I think this threat was being blocked in my case because I had Automatic Remediation disabled and Defender had to initially block the threat each time in order to provide the choice of actions that we have when Automatic Remediation is turned off:

    https://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning-windows_10/jsflafisid-malwarebytes/fa09a912-196f-40ab-bfd7-99c74d663fe8#LastReply

    Automatic Remediation is now turned on, and the Severe Threat Default Action is set to “Quarantine” – so we’ll see what happens now.

    The issue has been reported to be Microsoft-browser specific, so we need to determine whether or not these redirects can be effectively controlled by users in a much more general way - and the critical test here is to see whether or not these attacks can actually be eliminated on the MSN news pages by using an ad-blocker. Yesterday was a blocker-off day ,and I was hit with another fake Adobe Flash Player update (Trojan:JS/Flafisi.D):

    And also by this rather bizarre redirect:

    Today will be a blocker-on day.

    And I hope the day gets better as we go along, because I just went to the Start page, turned on uBlock Origen, clicked on a news article – and was greeted with this:

    Good grief. What's going on here?

    GreginMich

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-03-07T17:24:51+00:00

    Evil is going on here, that's what.

    Now, here's the part that I find particularly frustrating. Edge is supposed to block pop-ups as a matter of course. That's what I ASSUMED this setting was for, anyway: 

    Now, while I fully realize that won't block ads, as such, it should be blocking SOMETHING!!!

    And Trojans would be a confoundedly good place to start!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-07T18:02:02+00:00

    But Microsoft Edge blocks Java by default. So why am I still getting hit with this stupid thing?

    Was this answer helpful?

    0 comments No comments