Bonum Certa Men Certa

Microsoft “Defender” Pretender Attacks Random Software That Uses NSIS for installation; “Super Duper Secure Mode” for Edge is a Laugh

Guest post by Ryan, reprinted with permission from the original

Astronaut



Windows has for some time, apparently, attacked random software just because that software uses the Nullsoft Scriptable Installation System, a totally legitimate and Free and Open Source installation framework which has been around for decades.



Microsoft released an article about doing this years ago, but it appears they just randomly detect NSIS installers and assign some scary-sounding but bogus Trojan name to them.



In reality, just having a powerful scripting system doesn’t make your software a Trojan horse, and if Windows had proper software management, tools like NSIS would never have been necessary.



The developers I’ve heard from consider this just one more frustration to expect when developing software for Windows, and keep submitting their particular installer package to Microsoft to get on some kind of an exclusion list, but that doesn’t solve the bigger problem.



There’s nothing wrong with NSIS, and “Microsoft Pretender” is either just guessing and pulling random trojan names out of its proverbial ass or this is another attack on competitors and things that the “MAFIAA” doesn’t like and sometimes remove them without permission from the user or even a warning.



They’ve been caught doing this with LibreOffice, QBittorrent, PeaZip and other perfectly legitimate things.



Going after NSIS, which is what many Free Software programs prefer to use to install themselves on Windows because NSIS is also Free Software and doesn’t cost an exorbitant license fee, seems to me to be worthy of intense scrutiny, as it would be a great way to harass the Free Software community and blame it on “suspected malware”.



It seems, in my experience, that “False Positives” on Windows antivirus products are the most serious problem when you use Microsoft’s own, and it almost always “oopses” in really suspicious ways. Like, ways you’ll never have them dead to rights on, but very interesting nonetheless.



In fact, whenever I would ask VirusTotal for another opinion, it was rare that even a single antivirus program out of dozens of others agreed with Microsoft’s “False Positives”.



Like, you can just about count on “Microsoft Pretender” to miss RATS and ransomware, and removing QBittorrent without asking. (There’s also mention here of it attacking Ardour, a Free Software Digital Audio Workstation, and quarantining it.)



It’s a dark joke among Reddit users. Everyone knows how bad this thing is.



SJVN of ZDNet, which is a total spam farm now, for corporate PR releases, was talking about the “rich investigative experiences” of “Microsoft Pretender” for GNU/Linux, but considering that it’s by far the most incompetent and corrupt antivirus solution on the market for Windows, and it’s known to transmit lots of information about you back to Microsoft, there’s absolutely no reason to use it.



SJVN should write another article about the comforts of Rich Corinthian Leather seats. There’s nothing sadder than a so-called “independent journalist” who writes absolute drivel like this.



If Microsoft hadn’t made installing and removing software on Windows an unholy mess from its inception, and then told developers to go license a third party solution to deal with it, we probably wouldn’t be dealing with half the problems we have over the years, but NSIS is so good that it’s all but relegated the InstallShield Wizard and other expensive and error-prone methods of dealing with software programs on Windows to the ash heap of history.



Another thing Microsoft stands to gain from creating the perception that legitimate software (and might as well be FOSS while they’re attacking something) is overflowing with viruses, is it puts pressure on software developers to use Microsoft’s crummy Windows Store and agree to a litany of abuses that don’t apply if you “sideload” (the newspeak term for installing programs on your own computer).



Apple, for their part, pulls no punches when they make wild accusations that people who “sideload” are probably criminals.



Sure, yeah, okay…. I want to use Infinity for Reddit and NewPipe for Youtube on my phone because the real things have gotten so annoying that I can’t stand them and otherwise wouldn’t use a phone, but sure….



Most of the software in the F-Droid (for Android) store is of much higher technical quality and far less annoying to the user than in the Google Play or Apple App Store, because the author is writing it to be useful, not like these companies that have given up on anything except 27 tracking libraries and ads every 2 minutes.



Since Apple has warred against “sideloading”, anyone who wants software on their phone that’s not an annoying piece of shit designed to spy on them, shovel ads onto their screen, and drain their bank accounts with micro-transactions is now a “child molester”. Whoa, that escalated quickly. Thanks Apple!



Microsoft’s “liberalized” terms of use, which are still awful, for their Windows Store, are a desperate move ten years too late, and years after their Windows Mobile division failed.



Had they done these then, it may have saved that division.



Who knows? The Windows brand is the operating system version of “Internet Explorer” at this point. There are those who look back and actually liked Windows Mobile and say “Oh why oh why did they have to call it Windows?”.



I have to wonder who would accept any restrictions on their creative vision and their rights as a software author when delivering software straight to the customer and being able to ship the full version without any meddling from Microsoft and delays in getting updates out is possible.



Whether there’s a conspiracy afoot at Microsoft or if you believe them that these really are “False Positives” that few or no other antivirus companies can ever seem to corroborate, or both, it’s definitely worth openly asking why we’d install this junk on GNU/Linux.



Even if it is just to make sure malicious Windows software isn’t being downloaded by Windows users from a server, it doesn’t appear to be doing a great job as part of Windows itself.



Of course, at this point, all antivirus boils down to is a short list (of millions) of prevalent malware samples and then a lot of guesswork, and that leaves plenty of room to be wrong. When the problem on Windows is so out of control that you have to resort to outright guessing, there’s going to be collateral damage.



We’ve never had a disaster of this magnitude on GNU/Linux, so Microsoft Googlebombs “Linux malware” to refer to something that runs in Windows Subsystem for Linux, and that’s a very important distinction, as they bungle WSL/WSL2 quite badly and manage to add an insurmountable amount of attack surface on their own OS.



A “WSL” is what a company does when they’re losing, or have already lost. It says, “We’re not important anymore, but we are compatible with the standard.”.



SCO did it with their “Linux Kernel Personality” on their way to bankruptcy court, and Microsoft is doing it while they bleed users.



But when we see “Linux” news sites talking about WSL viruses, we should err, “Blow the WSL.” on them. They’re Windows viruses that just so happen to exploit some dodgy compatibility hack that Microsoft tossed in there.



Microsoft has done things like leave WSL broken and inaccessible for weeks at a time before.



So, even if you manage to become productive somehow with a workflow that relies on WSL, remember Microsoft’s incompetent upgrade bungling. It’s only a matter of time before you’re doing negative work that wouldn’t have been necessary at all on a real computer running real GNU/Linux.



This virus mess and the ensuing disaster of malicious and randomly-guessing “security” software, some of which actually does cost a fortune, are more reasons to get out.



I about fell out of my chair laughing the other day that Microsoft actually put a thing in Edge called “Super Duper Secure Mode” (actual name), and all it does really is turn off the just-in-time compiler from the V8 JavaScript engine so that it can slowly interpret the scripts on the page.



When something is compiled by a JIT runtime, you do get extra potential for security vulnerabilities. The Medium Security mode on the Tor Browser (Firefox based) also turns off the JIT.



The thing is that if your browser really wants to have good “Web apps” performance, it can’t run in this mode, so the whole thing is a ruse put in there so Microsoft can Googlebomb the illusion of security in their products some more.



In fact, every day, more and more of our infrastructure is under attack, more identity theft happens, and more corporate and national secrets are spilled due to the fact that Windows is naked despite all of this rather bloated security theater that removes compatibility with older programs.



The only thing that makes sense for “national security” executive orders would be a plan to transition away from Microsoft entirely. They’ve proven time and time again that they can’t secure Windows, and they misconfigure their own networks and cause data breaches with it, and blame their customers for “using it wrong”.



Whether you choose to use Microsoft products or not, your data is subject to Windows malware because somewhere along the way, you will do business with people who do use Microsoft products.



Until we have some sort of national “cybersecurity” policy that makes sense, I think all we can do is ensure that our computing is as secure as possible on our end.



Microsoft pays for whitepapers and advertisement editorials, but will these fix the problem when you’re a victim of identity theft or ransomware and trying to clean up the mess?



How much will Microsoft pay you to help out with that? The whitepapers maybe? SJVN and the Rich Investigative Experiences of Corinthian Leather?



FDR famously said (or rather, usurped for his pitch for the New Deal) that he wanted a chicken in every pot and a car in every garage, however, when the ransomware went after JBS and the Colonial Pipeline recently, humorously there were regions of America where you couldn’t get gas to travel to the store and there wouldn’t be a chicken for your pot if you could.



Microsoft has thrown up more roadblocks to prosperity. Their crummy software has licensing costs and it costs the economy over and over when we have to stop and deal with the fallout from the latest attack.



These are problems that we didn’t even have before there were computers everywhere. Dealing with antivirus software that barely works and often “malfunctions” is just salt in the wound.



Thanks Microsoft!

Recent Techrights' Posts

SLAPP Censorship - Part 29 Out of 200: Violent Language Won't Go Away When You Use It in Your Site, Blog, and Social Control Media
abuse began in 2012 because I had politely and accurately criticised Red Hat
Lacking Business Model, Bluesky Has Become Slop and Gravitates Towards Plagiarism, Bots
LLM slop/plagiarism under the guise of "Artificial Intelligence" (AI)
 
IBM "Headcount Reductions" by Early Retirement and Death
The tragedy at IBM started 33 years ago on the first of April
Red Hat: Latin-1 character set under threat from Bishop Michael Martin, North Carolina
Reprinted with permission from Daniel Pocock
Links 01/04/2026: Microsoft GitHub Now Pushing Ads Into People's Code/Commits, Earth Overshoot Day Draws Nearer
Links for the day
What IBM and EPO Workers Have in Common: European Media Not Covering Very Major News (Press Became Dysfunctional)
Are IBM operatives working to scuttle the process of investigative journalism?
Free Speech in the United Kingdom When "Chilling Effect" is Increasingly Prevalent
If politicians cannot even use a term like "parasitic behaviour", then where do we as a society end up?
Oracle Lays Off Because of Debt and Commercial Issues, Not Slop
Like Scam Altman, Larry Ellison hangs around Cheeto King because he could use some bailouts in the form of government contracts or phony money with an incredible name like "Stargate"
The Real Reason Many Sites and Forums Shun Microsoft Lunduke
When forums say that they banned Microsoft Lunduke or don't want him mentioned it's probably because they are familiar with the "stench" that follows him around
Gemini Links 01/04/2026: Hallucinations, Stitching, and Type Systems
Links for the day
Lots of Layoffs at IBM, "Media Blackout" About Mass Layoffs at IBM's HashiCorp and Confluent Last Month
IBM is a dying company circling down the drain while manipulating or paying the media to pretend everything is fine
Microsoft Under Investigation by the UK's Competition and Markets Authority (CMA) for Abusive Tactics
What's noteworthy is that this is "set to begin in May"
Sounds Like Red Hat (IBM) Layoffs in Slop Clothing
This is an IBM policy. They try to justify staff cuts.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, March 31, 2026
IRC logs for Tuesday, March 31, 2026
In Time for April Fools (and Easter), 30,000 Oracle 'Pink Slips' While People Are Asleep
Oracle probably has no choice but to fire a ton of people
Gemini Links 31/03/2026: Five Years on Gemini (Rob's Gemini Capsule), OFFLIFIRSOCH 2026, and More
Links for the day
Slopfarms Persist, But Google Seems to Have Delisted Many
We are still checking
Links 31/03/2026: More Energy Shortages Noted, Taylor Swift Faces Trademark Infringement Suit
Links for the day
Chaff, Slop and Spam Help Distract From Parallel Crises at IBM
IBM seems very eager to undermine discussion about what goes on inside
IBM-Spawned Lexmark Sold, Then Came Mass Layoffs, Now the CEO Who Did This is Leaving
IBM is really not a magnet for talent at this point
Not April Fools But April First: Red Hat Staff Becoming "IBM"
claims of mass layoffs set to kick off at IBM some time soon
Gemini Links 31/03/2026: Antenna Packed Up, AuraGem and AuraSearch Maintenance
Links for the day
Links 31/03/2026: More Social Control Media Bans, BBC Now Run by GAFAM (US) Executive
Links for the day
'Broligarchs' Don't Want Science, They Want Entertainers to Entertain Them (and Make Them Richer)
Of course this will result in things getting worse in the sciences and everyone who relies on the sciences
When Republics Turn From Democratic Governments Into Imperialistic Dictatorships
What goes on in the US would require talking about politics
Companies That Have Nothing Except Buzzwords and Promises Will Perish
Dishonest media will perish along with the companies it is covering up for
The Solicitors Regulation Authority (SRA) to be Grilled in Two Weeks' Time by the British Government for "Recent Regulatory Failures"
we escalated to our politicians
GNU/Linux Will Thrive as Long as It's Modular, Not Monolithic
To IBM, it's all about money. Nothing else matters.
EPO "Cocaine Communication Manager" - Part X - People Are Leaving
"I was happy to be at the EPO in the beginning, but since I realized it's all a big mafia"
IBM's 33 Years as a "Financial Engineering" (Accounting Tricks) Company
In relation to Red Hat, this "financial engineering" involves culling many workers and trying to replace them with slop
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 30, 2026
IRC logs for Monday, March 30, 2026
Links 31/03/2026: Rising Costs, Cyberattacks, Novo Patent Expiry
Links for the day
Gemini Links 31/03/2026: American Spring, Distributed Systems Simulator, and Calculus for Electronics
Links for the day
SUEPO Central Made a Strike (or Striking) Success
Europe has more than enough qualified patent officials
IBM Layoffs and Their Expected Scope in April 2026
Such layoffs impact not only IBM "proper"
SLAPP Censorship - Part 28 Out of 200: Facing Consequences for Impersonation and Worse
It's not "funny". It is moreover libellous.
Links 30/03/2026: South Korea Next to Curb Social Control Media Addiction and Manipulation, Notorious Patents in the US Challenged
Links for the day
Gemini Links 30/03/2026: Going Back to Wrist Watches and Why LLMs in Programming Suck
Links for the day
Did IBM Pay thestreet.com for Puff Pieces? (Like It Did With Forbes)
If so, there is no disclosure
Wikipedia - Funded by Slop-pushing Companies and 'Broligarchs' - Gave Benefit of the Doubt to Slop, Then Regretted It
Wikipedia sucks. Without slop it'll suck a little less.
Payoffs of Lifelong Commitments
"The Lifelong Activist"
Links 30/03/2026: "We Can’t Income-Tax Ultra-Elites"; "The Pirate Bay’s Oldest Torrent Turned 22"
Links for the day
Today, Europe's Second-Largest Institution (EPO) Goes on Strike That Can Last Until 2027. Nobody in the Media Covers This!
"We stand with the protesters"
When the Cost (or Time) of Maintenance Exceeds the Value
In recent years it seems like more people learn to remove things from their lives, not add more things
Passage of Wealth Upwards, Blaming the Victims
Tim Sweeney's net worth is 5.1 billion USD according to Forbes
More Media Needs to Tell the Public Slop is a Giant Bubble, It Should Stop Taking "Sponsorship" Money to Inflate This Bubble
If enough of (what's left of) the media changes its tune and quits being a parrot of GAFAM, then we can debate slop like grown-ups
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 29, 2026
IRC logs for Sunday, March 29, 2026
Trying to Hide One's Abuses by Imposing Silence on Critics ("My Profile Was Private")
With enough daylight, sooner or later everyone knows you are a vampire
Fedora Badges System Shows the Demise of Fedora Under IBM
IBM isn't good at keeping what it buys
IBM is Sunsetting Red Hat, It Only Uses the Brand and the Shell
IBM buys or spins off companies as containers for "toxic assets" and debt
Cisco Systems is a Still Weak Spot With Bug Doors
nothing to offer except storytelling
EPO Strike Begins Today and It's the Longest One Yet (Can Last a Year)
Where's the media?
Gemini Links 30/03/2026: Approaching April and Arvelie Calendar
Links for the day