I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Anonymous
    2018-04-15T16:09:56+00:00

    please help me my protection is turned off.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-04-14T17:15:01+00:00

    I am seeing...............

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-04-10T04:28:42+00:00

    I just got this issue just now 8 pm Central time 4/9/2018 on a Windows 10 machine viewing the article from the Edge MSN home page: "Tommy Lee's son won't be charged for allegedly assaulting him".  It showed me the fake Adobe Flash update warning and then Defender warned me that it Quarantined: Trojan:JS/Flafisi.D.

    This is the 2nd time in a week this same virus hit me from an article from the Edge default page.

    It's happening to me every day for a week or two, several times a day.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-03-12T21:40:18+00:00

    Nothing new if you keep your eyes closed. Otherwise we have a malvertising issue on MSN webpages, and one that doesn’t leverage exploits according to the latest available analysis. And also a totally bizzare blocking behavior by both Windows Defender Antivirus and Windows Defender SmartScreen.

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-12T21:18:57+00:00

    OK, that's something I didn't see you state in your testing above, but I suspect that since SmartScreen is now integrated within Windows 10 it may not truly be possible to fully disable it's operation, though I don't really care either.

    Breaking a malvertising chain has always been done by a major operation like Microsoft in cooperation with others, typically including international law enforcement.  With Microsoft providing the data required to identify the true perpetrators, as well as any C&C or other server resources when those are involved.  That's what Microsoft always does in these cases, while many run around dealing with peripheral effects as the investigation and data collection continues.

    That's why I always take the workaround direction and ignore the noise, since those who don't know how to protect themselves might actually get successfully attacked during the typical delay that occurs.

    As I stated above, nothing new other than a different type of detection for a new snippet of JavaScript likely relating to a new vulnerability.  We may learn something more about this tomorrow when the updates release.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments