Bonum Certa Men Certa

Microsoft “Defender” Pretender Attacks Random Software That Uses NSIS for installation; “Super Duper Secure Mode” for Edge is a Laugh

Guest post by Ryan, reprinted with permission from the original

Astronaut



Windows has for some time, apparently, attacked random software just because that software uses the Nullsoft Scriptable Installation System, a totally legitimate and Free and Open Source installation framework which has been around for decades.



Microsoft released an article about doing this years ago, but it appears they just randomly detect NSIS installers and assign some scary-sounding but bogus Trojan name to them.



In reality, just having a powerful scripting system doesn’t make your software a Trojan horse, and if Windows had proper software management, tools like NSIS would never have been necessary.



The developers I’ve heard from consider this just one more frustration to expect when developing software for Windows, and keep submitting their particular installer package to Microsoft to get on some kind of an exclusion list, but that doesn’t solve the bigger problem.



There’s nothing wrong with NSIS, and “Microsoft Pretender” is either just guessing and pulling random trojan names out of its proverbial ass or this is another attack on competitors and things that the “MAFIAA” doesn’t like and sometimes remove them without permission from the user or even a warning.



They’ve been caught doing this with LibreOffice, QBittorrent, PeaZip and other perfectly legitimate things.



Going after NSIS, which is what many Free Software programs prefer to use to install themselves on Windows because NSIS is also Free Software and doesn’t cost an exorbitant license fee, seems to me to be worthy of intense scrutiny, as it would be a great way to harass the Free Software community and blame it on “suspected malware”.



It seems, in my experience, that “False Positives” on Windows antivirus products are the most serious problem when you use Microsoft’s own, and it almost always “oopses” in really suspicious ways. Like, ways you’ll never have them dead to rights on, but very interesting nonetheless.



In fact, whenever I would ask VirusTotal for another opinion, it was rare that even a single antivirus program out of dozens of others agreed with Microsoft’s “False Positives”.



Like, you can just about count on “Microsoft Pretender” to miss RATS and ransomware, and removing QBittorrent without asking. (There’s also mention here of it attacking Ardour, a Free Software Digital Audio Workstation, and quarantining it.)



It’s a dark joke among Reddit users. Everyone knows how bad this thing is.



SJVN of ZDNet, which is a total spam farm now, for corporate PR releases, was talking about the “rich investigative experiences” of “Microsoft Pretender” for GNU/Linux, but considering that it’s by far the most incompetent and corrupt antivirus solution on the market for Windows, and it’s known to transmit lots of information about you back to Microsoft, there’s absolutely no reason to use it.



SJVN should write another article about the comforts of Rich Corinthian Leather seats. There’s nothing sadder than a so-called “independent journalist” who writes absolute drivel like this.



If Microsoft hadn’t made installing and removing software on Windows an unholy mess from its inception, and then told developers to go license a third party solution to deal with it, we probably wouldn’t be dealing with half the problems we have over the years, but NSIS is so good that it’s all but relegated the InstallShield Wizard and other expensive and error-prone methods of dealing with software programs on Windows to the ash heap of history.



Another thing Microsoft stands to gain from creating the perception that legitimate software (and might as well be FOSS while they’re attacking something) is overflowing with viruses, is it puts pressure on software developers to use Microsoft’s crummy Windows Store and agree to a litany of abuses that don’t apply if you “sideload” (the newspeak term for installing programs on your own computer).



Apple, for their part, pulls no punches when they make wild accusations that people who “sideload” are probably criminals.



Sure, yeah, okay…. I want to use Infinity for Reddit and NewPipe for Youtube on my phone because the real things have gotten so annoying that I can’t stand them and otherwise wouldn’t use a phone, but sure….



Most of the software in the F-Droid (for Android) store is of much higher technical quality and far less annoying to the user than in the Google Play or Apple App Store, because the author is writing it to be useful, not like these companies that have given up on anything except 27 tracking libraries and ads every 2 minutes.



Since Apple has warred against “sideloading”, anyone who wants software on their phone that’s not an annoying piece of shit designed to spy on them, shovel ads onto their screen, and drain their bank accounts with micro-transactions is now a “child molester”. Whoa, that escalated quickly. Thanks Apple!



Microsoft’s “liberalized” terms of use, which are still awful, for their Windows Store, are a desperate move ten years too late, and years after their Windows Mobile division failed.



Had they done these then, it may have saved that division.



Who knows? The Windows brand is the operating system version of “Internet Explorer” at this point. There are those who look back and actually liked Windows Mobile and say “Oh why oh why did they have to call it Windows?”.



I have to wonder who would accept any restrictions on their creative vision and their rights as a software author when delivering software straight to the customer and being able to ship the full version without any meddling from Microsoft and delays in getting updates out is possible.



Whether there’s a conspiracy afoot at Microsoft or if you believe them that these really are “False Positives” that few or no other antivirus companies can ever seem to corroborate, or both, it’s definitely worth openly asking why we’d install this junk on GNU/Linux.



Even if it is just to make sure malicious Windows software isn’t being downloaded by Windows users from a server, it doesn’t appear to be doing a great job as part of Windows itself.



Of course, at this point, all antivirus boils down to is a short list (of millions) of prevalent malware samples and then a lot of guesswork, and that leaves plenty of room to be wrong. When the problem on Windows is so out of control that you have to resort to outright guessing, there’s going to be collateral damage.



We’ve never had a disaster of this magnitude on GNU/Linux, so Microsoft Googlebombs “Linux malware” to refer to something that runs in Windows Subsystem for Linux, and that’s a very important distinction, as they bungle WSL/WSL2 quite badly and manage to add an insurmountable amount of attack surface on their own OS.



A “WSL” is what a company does when they’re losing, or have already lost. It says, “We’re not important anymore, but we are compatible with the standard.”.



SCO did it with their “Linux Kernel Personality” on their way to bankruptcy court, and Microsoft is doing it while they bleed users.



But when we see “Linux” news sites talking about WSL viruses, we should err, “Blow the WSL.” on them. They’re Windows viruses that just so happen to exploit some dodgy compatibility hack that Microsoft tossed in there.



Microsoft has done things like leave WSL broken and inaccessible for weeks at a time before.



So, even if you manage to become productive somehow with a workflow that relies on WSL, remember Microsoft’s incompetent upgrade bungling. It’s only a matter of time before you’re doing negative work that wouldn’t have been necessary at all on a real computer running real GNU/Linux.



This virus mess and the ensuing disaster of malicious and randomly-guessing “security” software, some of which actually does cost a fortune, are more reasons to get out.



I about fell out of my chair laughing the other day that Microsoft actually put a thing in Edge called “Super Duper Secure Mode” (actual name), and all it does really is turn off the just-in-time compiler from the V8 JavaScript engine so that it can slowly interpret the scripts on the page.



When something is compiled by a JIT runtime, you do get extra potential for security vulnerabilities. The Medium Security mode on the Tor Browser (Firefox based) also turns off the JIT.



The thing is that if your browser really wants to have good “Web apps” performance, it can’t run in this mode, so the whole thing is a ruse put in there so Microsoft can Googlebomb the illusion of security in their products some more.



In fact, every day, more and more of our infrastructure is under attack, more identity theft happens, and more corporate and national secrets are spilled due to the fact that Windows is naked despite all of this rather bloated security theater that removes compatibility with older programs.



The only thing that makes sense for “national security” executive orders would be a plan to transition away from Microsoft entirely. They’ve proven time and time again that they can’t secure Windows, and they misconfigure their own networks and cause data breaches with it, and blame their customers for “using it wrong”.



Whether you choose to use Microsoft products or not, your data is subject to Windows malware because somewhere along the way, you will do business with people who do use Microsoft products.



Until we have some sort of national “cybersecurity” policy that makes sense, I think all we can do is ensure that our computing is as secure as possible on our end.



Microsoft pays for whitepapers and advertisement editorials, but will these fix the problem when you’re a victim of identity theft or ransomware and trying to clean up the mess?



How much will Microsoft pay you to help out with that? The whitepapers maybe? SJVN and the Rich Investigative Experiences of Corinthian Leather?



FDR famously said (or rather, usurped for his pitch for the New Deal) that he wanted a chicken in every pot and a car in every garage, however, when the ransomware went after JBS and the Colonial Pipeline recently, humorously there were regions of America where you couldn’t get gas to travel to the store and there wouldn’t be a chicken for your pot if you could.



Microsoft has thrown up more roadblocks to prosperity. Their crummy software has licensing costs and it costs the economy over and over when we have to stop and deal with the fallout from the latest attack.



These are problems that we didn’t even have before there were computers everywhere. Dealing with antivirus software that barely works and often “malfunctions” is just salt in the wound.



Thanks Microsoft!

Recent Techrights' Posts

openai.com Traffic Said to Have Fallen 50% in the Past Three Months, Reports Say It Nearly Ran Out of Money to Borrow
After the slop frenzy all we'll have left is environmental destruction
Rudeness and Vulgarity Won't Stop Journalism About Free Software
we seem to be on the right path
IBM Plans for Layoffs Becoming Clearer With "Employee Reviews"
Of course this impacts Red Hat as well
If You Don't Want "Linux" to Become "Windows", Then Follow GNU
GAFAM isn't a friend of Linux; it's only a user in the same sense clients are "users" of a brothel
 
LLM Slop Not Dead Yet, Examples of Slop About "Linux"
We wish to see the totals down to zero
Links 20/01/2026: Cheeto Blackmails France Into 'Peace' While Looking to Annex EU, Mass Layoffs in Capgemini (Microsoft Reseller/Promoter) in France
Links for the day
Gemini Links 20/01/2026: Boxing and "Inbox Zero" Success
Links for the day
Windows and Slop Declining While Microsoft Silences Critics
Microsoft tries to suppress facts while faking 'demand' by imposing slop on everybody, everywhere
IBM Kills OzLabs, Signalling An Attack on Free Software (a Sign for Red Hat)
ibiblio also appears to have died (or experiences critical issues)
Red Hat Vice President Leaving After Nearly Two Decades
IBM's culture of secrecy is not compatible with Free software
Links 20/01/2026: "ChatGPT Health" (Latest Distraction From Being Insolvent) Flops and Raises Concerns, "The U.S. Military Faces a Reckoning on Greenland"
Links for the day
Readers Pleased With Layout Changes
Two days ago we began improving clarity and accessibility in the site
IBM is Outsourcing Red Hat's Fedora to Slop to 'Save Money'
If IBM cared about quality rather than alleged "cost savings" (cutting corners), it would assign more IBM staff to Fedora, but instead the exact opposite happened, with the likes of Cotton and Miller removed from the project
European Patent Office (EPO) Industrial Actions Formally Start in Two Hours
As per the latest (revised) action plan, today workers will slow down their work and limit patent grants
Microsoft Under Fresh Investigation by the Italian Competition Authority
In 2025 we kept a running tally of 30,000+ Microsoft layoffs, so 40k this year would not be unthinkable
The "Alicante Mafia" - Part VI - More Strikes Planned at the EPO, Starting This Month
Yesterday we said that friends of Berenguer or inside Berenguer's circle may have left
Gemini Links 20/01/2026: New Tea, Using a Roku at a Hotel, and "Voltage-Based Power Management for Any Raspberry Pi"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, January 19, 2026
IRC logs for Monday, January 19, 2026
Links 19/01/2026: National Broadcasters on World or Local Affairs Up to a Week Ago
Links for the day
Gemini Links 19/01/2026: Game Boy and "The Lounge" (IRC) for the Elderly
Links for the day
Slopfarms in Google News (at Least Three Today) With Fake 'Articles' About "Linux"
Google itself is trying to promote its own slop ("Overview") at the expense of original and credible sources
Links 19/01/2026: ChatGPT’s Defects and The Guardian on Why So-called "AI Companies Will Fail"
Links for the day
This is What the Slop Bubble Popping Can Look Like
Maybe not an overnight collapse, but getting there gradually
IBM Quiet About Its Plan for Red Hat Amid Accelerated Bluewashing
Something is going on at Red Hat
The "Alicante Mafia" - Part V - It Seems Like Some People Are Already Leaving "The Mafia"
they have a rough idea of what's coming
Microsoft Means War, Microsoft is on the Side of ICE
Microsoft, people-ready
More Confirmatory Rumours Regarding "Massive" Red Hat Layoffs
Ecosystem and sales said to be targeted
Proprietary UNIX is What We'll Have If IBM Red Hat Gets Its Way
IBM Red Hat wants to control everything, even if that means killing everybody
Free Software in Times of Peace (and Times of War, Too)
GAFAM and IBM are war companies
Founder of GNU/Linux (RMS) Speaks in US University (College) This Week
The auditorium has very high capacity and this is his "college comeback" talk in the United States
Office Meetings Are Most Useful to the Least Productive Workers
In my "office life" days I really didn't like meetings
LinuxSecurity and Linuxiac Are Still Slopfarms, Even Anthony Pell Does It
We suppose waiting another month or another year won't change a thing
Claim That the Board of Directors at IBM Isn't Happy With How the Company is Run
IBM tries to project an image of strength to the whole world, especially to its clients
Links 18/01/2026: Legal Trouble for xAI, Climate Concerns, Data Breaches and More
Links for the day
'Vibe Coding', Chatbots, and Other Bots (e.g. "Agents" Disguised as "Superintelligence") Aren't Saving You Time
False marketing, FOMO marketing tactics
Gemini Links 19/01/2026: Analog Cameras and Plucker in 2026, US Losing Acceptability in Europe
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, January 18, 2026
IRC logs for Sunday, January 18, 2026
Links 18/01/2026: The "Deepfake Porn Site Formerly Known as Twitter" and Turkey to Block Kids' Access to Social Control Media
Links for the day
Gemini Links 18/01/2026: Against English as Language of the Net, "Symposium of Destruction"
Links for the day
You Would Expect This Kind of Misleading Narrative Shortly Before Microsoft (or GAFAM) Mass Layoffs
misleading PR
FOSDEM 2026: democracy panel, GNOME & Sonny Piers modern slavery experiment
Reprinted with permission from Daniel Pocock
Pump-and-Dump With IBM Shares, Courtesy of People Who Stand to Gain From the 'Pump'
"3 Reasons to Buy IBM Stock Right Now"
IBM: Spying on Staff Like Never Before and Implementing Silent Layoffs This Month, Say Insiders
what we heard from whistleblowers seems to corroborate
'Cancel Culture' Doesn't Work (in the Long Run)
Despite all the attacks, I'm enjoying life, I'm keeping productive, and our audience continues to grow
IBM is Not a Free Software Company (It Never Was)
Red Hat's main product, RHEL, is full of secret sauce and has 'secret recipes' (it is basically proprietary)
IBM Turning Up the 'RTO' (Stress) and 'PIP' (Fear) Heat on Workers, Rebellion May be Brewing
Sometimes it feels like today's executives at IBM view IBM workers as a liability
Links 18/01/2026: Indonesia Against Comedy, Media-Hostile (Censors Comedians) Convicted Felon in White House Defecting to Opponents of NATO
Links for the day
GNU/Linux Still up (statCounter Says to 6%) in Bosnia And Herzegovina
Let's see where it is at year's end
Making Layout Changes
Feedback can be sent to us
Behind an Economy of Fake 'Worths' and Fictional 'Valuations' or 'Market Caps'
They normalise white-collar crime and say "everyone is doing it!"
Links 18/01/2026: "South Africa is Running Out of Software Developers", Companies Spooked to Find Slop is a Major Liability
Links for the day
Eventually the Joke (and Financial Fraud) is on Microsoft, Stigmatised for Slop
Is Microsoft trying to commit suicide?
GNU/Linux Leaps to All-time Highs in Virgin Islands
it seems to have started around the "end of 10"
Place Your Bets: Who Will Die First? Microsoft or IBM?
Not even joking; make a guess
Making and Keeping the Sites Accessible
Sometimes less does mean "more" (or "MOAR")
The "Alicante Mafia" - Part IV - How Europe's Largest Patent Office Recruited Drug Addicts, Antisemites, and People Who Absolutely Cannot Do the Job (But Know the 'Right' People)
To better overlap industrial actions we might delay/postpone/pause this series for a bit
Restoring Professional Pride in the Tech Sector
Rejecting slop isn't being a Luddite
Benefiting by Adding Presence in Geminispace
As the Web gets worse, not limited to bloat as a factor, people seek alternatives
Google News Recently Started Syndicating Another Slopfarm, Linuxiac
Even if Google is aware that there is slop there, it's hard to believe that Google will mind
Slop Bubble "Is Worse Than The Dot Com Bubble"
Edward Zitron Says It like it is
Software Patents and USMCA (or NAFTA)
We recently pondered going back to issuing 2-3 articles per day about patents and common issues with them
IBM Sued Over PIPs
PIPs are "performance improvement plans"
Sites With "Linux" in Their Name That Are in Effect Slopfarms and Issue Fake Articles
We try to name some of the prolific culprits
Gemini Links 18/01/2026: Raising Notifications From Terminal and Environmental Sanity
Links for the day
IRC Proceedings: Saturday, January 17, 2026
IRC logs for Saturday, January 17, 2026
Over at Tux Machines...
GNU/Linux news for the past day