I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2018-05-13T05:02:54+00:00

    Hi, PaulSey. As far as I know, there has never been any report (or reason to believe) that these Trojan:JS/Flafisi.D detections are “false detections” – and the general consensus heretofore has been that these are authentic detections being prompted by malware-site redirects that are carried in on an MSN advertizing channel – and that these malvertising redirects would need to be eliminated at their source by cleaning up the compromised ad supplier. And I think that this is also the understanding of RodrigoLode(MSFT)"). So can you please tell us whether rechanneling the reports for this issue signals a change in the status of the MSN investigation – and can you also please clarify whether or not this is based on some kind of reinterpretation of the circumstances surrounding these Trojan:JS/Flafisi.D detections.

    Thanks,

    GreginMich

    +1

    This is confusing for the home user and the Feedback Hub option is likely a deterrent for reporting.

    If there is a question of the detection being false positive it should have been resolved some time ago.

    Hoping Rodrigo will respond.

    ~bhringer

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-05-13T02:01:06+00:00

    I agree ! Microsoft is just checking everyone's patience and wasting everyone's time by asking each individual to provide some data which they can gather if they get 5-6 laptops. Microsoft have tons of employees and I am pretty sure they might be getting same issue but not willing to do anything for it. This is the reason Internet Explorer losing its market share.

    I lost my patience and switched to Chrome and it stopped all popups for me.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-05-12T02:12:05+00:00

    Hi, PaulSey. As far as I know, there has never been any report (or reason to believe) that these Trojan:JS/Flafisi.D detections are “false detections” – and the general consensus heretofore has been that these are authentic detections being prompted by malware-site redirects that are carried in on an MSN advertizing channel – and that these malvertising redirects would need to be eliminated at their source by cleaning up the compromised ad supplier. And I think that this is also the understanding of RodrigoLode(MSFT)"). So can you please tell us whether rechanneling the reports for this issue signals a change in the status of the MSN investigation – and can you also please clarify whether or not this is based on some kind of reinterpretation of the circumstances surrounding these Trojan:JS/Flafisi.D detections.

    Thanks,

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-05-02T19:44:35+00:00

    we understand your frustration as we are having to "control alt delete" to stop our pc's from screaming "YOUR PC IS INFECTED! Alert, Call this number, this site is stealing your info"...  I know its not infecting the PC but it locks up Edge.

    You shouldn't be trying to hunt down these sites, the Edge team should be fixing this and it should be a #1 priority so it can't happen like with Chrome/Firefox...  You should be banging on the door of the Edge team going FIX THIS NOW.

    This is why hundreds of thousands of people leave Edge and get firefox/Chrome everyday.

    If MS doesn't care about Edge then seriously cancel it and bundle Windows with Chrome.

    It doesn't even look like MS uses Edge... its sad really.

    I've downloaded uBlock Origin to both my PC and then it automatically (SYNC?????) puts a blocker into your phone!!!!!!  (Yes, I know!!!) There are different downloads for Google, Opera, Firefox, IE etc.  They were suggested by several participants in this thread as well as the "experts" at Malwarebytes.  Biggest problem is I can't find a guide or figure out how to utilize uBlock.  I think I've adjusted some things-accidently on purpose-but basically have no clue.  I don't know what's up at Mbytes!!  They used to be very responsive.  But, like MS they have also had "personnel" adjustments.  Maybe even new owners??????   

    So I'm just going to keep doing what I usually do with my PC.  Or actually, what my PC lets me do!!!!!  I foresee that it eventually will go out the window, followed by my "smartphone."

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-04-16T12:16:20+00:00

    Hi...I selected a James Comey headline from the msn.com startup page on Apr 16, 2018. Then I received a  msg saying that Windows Defender detected Trojan:JS/Flafisi.D. I immediately closed Microsoft Edge and opened Defender to see about removing Trojan:JS/Flafisi.D. However, I don't see any instructions on removing it. So I started a full scan of my computer. Unfortunately some 5hrs later, it was still running and only appears to half way thru. However, I have mistakenly closed the scan. I will run it again later. How do I ensure that Trojan:JS/Flafisi.D is removed?

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments