I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Anonymous
    2018-03-17T19:44:11+00:00

    I’m just adding this link:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/trojanjsflafisid/b70661cc-5b98-4e9b-9db4-f76d5b1bb69c

    Since this is the thread that appears at the top of the Bing search list for “Trojan:JS/Flafisi.D”, and it’s consequently getting most of the hits for this issue with malvertising on the MSN news pages.

    GreginMich

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-03-12T20:30:53+00:00

    Windows Defender SmartScreen is always turned off for this kind of testing, since it would otherwise block access to the eicar download. Could it have caused this issue had it been turned on? Most likely not.

    I don’t have time to argue that it’s possible to break a malvertising supply chain, but it happens quite frequently; and it should be a major concern for any website that wants a “safe site” reputation.

    OK, I just turned Windows Defender SmartScreen back on and retested; and now I have to correct myself. SmartScreen doesn’t block the eicar.com download – it merely allows the download of a 0 bytes eicar.com file:

    And then it leaves its message in place when I switch back to the forum site:

    GreginMich

    Was this answer helpful?

    0 comments No comments
  5. Rob Koch 26,080 Reputation points Volunteer Moderator
    2018-03-12T19:06:09+00:00

    You sure that issue with the apparent inconsistent operation of Defender during download isn't just the obvious race condition that's always existed when using SmartScreen along with Defender?

    This situation has always created interesting anomalies when the automatic operations performed by SmartScreen that hand off malicious file detection processes to Defender interact with those which happen seconds later as either the user's actions or Defender's automated filing system operations cause a potential second trigger.

    This means that in some cases, the earlier events related to SmartScreen have already snatched the file itself from the user or Defender before it can actually be seen, often leaving a zero-filled file placeholder that's either locked (quarantine) or empty (corrupted).

    This is nothing new and hasn't changed significantly since the early days of MSE, though there's likely been minor changes in the way these errors are displayed due to either filing system or other process changes to either SmartScreen or Defender themselves.  Since Defender has always seemed to be unaware that it's already processing the same file, I assume that's because it's specifically performing these operations in isolated processes, possibly to allow the most effective and fastest process to "win" regardless which one this might be.

    As for the compromised domains, we already knew (which that article confirms) that the creation and so pace of change for these had exceeded that for any existing manual system to keep up with a few years ago.  This implies that protection needs to be either proactive (ad blocking) or handle this by blocking the false pages within the browser itself, before the malware content can become an issue.

    How to identify a good page from a bad page is the problem with the latter, since it's typically a matter of the content, which is what this particular detection appears to be focused on as relates to the malicious JavaScript it contains.

    Rob

    Was this answer helpful?

    0 comments No comments