I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-20T04:02:38+00:00

    "So the payload is really irrelevant, and the point (once again) is that there’s an open malware channel on the MSN news pages."

    You can sit around and pontificate about who's truly responsible to manage the security of the advertising distributed from websites until you're blue in the face.

    Or if you have a modicum of intelligence, you'll realize that the only one truly responsible for your security is yourself, so by simply using an ad blocker or Internet Explorer's Tracking lists for reputable websites that honor it, you can avoid this issue entirely.

    I prefer methods that work to wishful thinking.

    Rob

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-07T21:43:48+00:00

    Ya, it was easy to get the impression that Microsoft was banning JavaScript with the development of Microsoft Edge when in fact they were just building it into the core of their new browser. The Chakra JavaScript engine was specially engineered for Edge by Microsoft, and then later open sourced as ChakraCore:

    https://github.com/microsoft/ChakraCore

    But I guess there’s really no getting around the need for a scripting engine of some sort, and the best we can do here is simply learn how to manage things when the JavaScript is being misused. With a little bit of luck, though, I think we’ll be able to manage this particular issue by just blocking the bad domain(s).

    GreginMich

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-03T20:31:03+00:00

    Thanks for that firsthand report, Charles. A firsthand experience is way more convincing than a thousand words. But with each of my 5 detections, this threat was actually blocked rather than quarantined – and since your detection sounds a little “anomalous”, you might want to run a Full Scan for a double-check, or maybe even check the current status of the threat with the Get-MpThreatDetection command, as I’ve illustrated here:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_start-windows_10/if-i-buy-a-new-computer-running-windows-10-do-i/49a25783-647e-48ec-9e06-dbc0e56b8798

    We have been seeing a few reports of issues with the removal of this threat:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/defenders-finds-and-stops-trojanjsflafisib/531a257f-4470-4275-87be-c249d0a47074

    While it looks like we’ve come out unscathed this time, we really do have to wonder if we’ll be so lucky with the next threat that gets delivered through this malware-site-redirect attack vector – which is why my original question was “what’s next”. Windows Defender is getting stronger every day, but no AV app is really capable of stopping everything out there. And we also have to wonder about how well people with weak or outdated AV protection (and/or unpatched vulnerabilities) will fare against these hit-and-run attacks. That’s why I’m not willing to accept the presence of these malware-site redirects as the “new normal” for trusted sites. Trusted sites shouldn’t pose any risk at all to their users.

    GreginMich

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-03-02T18:13:00+00:00

    In my case, the “Use Adobe Flash Player” switch was turned off – but that didn’t prevent this fake Adobe Flash Player update from just trying to install Trojan:JS/Flafisi.D while I was reading a news article on the Edge Start page (for the fifth time now). So the issue here is that the site with the "lurker at the threshold" is in this case the Microsoft Edge Start page – which means that this particular “trusted” site is now in jeopardy of losing my trust, and potentially the trust of others. That’s why I’m trying to call attention to this issue.

    GreginMich

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-01T08:16:45+00:00

    Hello. In January last year, there were a number of Fake News bulletins on Facebook that eg Kirk Douglas, Helen Mirren, HM Queen Elizabeth had died.

    I clicked on the first one thinking it was genuine. Up popped the pop-up and what was worse there was a voice telling me what I had to do to get rid of the "dreadful Trojan". It was a real beggar to get rid of, including switching off my laptop.

    I created this thread in the Community.  I was disgusted that (in public) Microsoft did absolutely nothing to do anything yet their reputation was being put at risk.

    https://answers.microsoft.com/en-us/windows/forum/windows_10-security-winpc/facebook-helping-scammers-attack-microsoft/d047f36c-a3d7-4648-9961-6b04408c5eb7

    I also emailed all of the USA stars/their agents to alert them to it but presumably they binned them, perhaps thinking the emails were from a madman. To see that pop-up appearing again is such a disappointment and I hope that you guys with your clout will be able to nudge Microsoft in the right direction

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments