Bonum Certa Men Certa

Microsoft “Defender” Pretender Attacks Random Software That Uses NSIS for installation; “Super Duper Secure Mode” for Edge is a Laugh

Guest post by Ryan, reprinted with permission from the original

Astronaut



Windows has for some time, apparently, attacked random software just because that software uses the Nullsoft Scriptable Installation System, a totally legitimate and Free and Open Source installation framework which has been around for decades.



Microsoft released an article about doing this years ago, but it appears they just randomly detect NSIS installers and assign some scary-sounding but bogus Trojan name to them.



In reality, just having a powerful scripting system doesn’t make your software a Trojan horse, and if Windows had proper software management, tools like NSIS would never have been necessary.



The developers I’ve heard from consider this just one more frustration to expect when developing software for Windows, and keep submitting their particular installer package to Microsoft to get on some kind of an exclusion list, but that doesn’t solve the bigger problem.



There’s nothing wrong with NSIS, and “Microsoft Pretender” is either just guessing and pulling random trojan names out of its proverbial ass or this is another attack on competitors and things that the “MAFIAA” doesn’t like and sometimes remove them without permission from the user or even a warning.



They’ve been caught doing this with LibreOffice, QBittorrent, PeaZip and other perfectly legitimate things.



Going after NSIS, which is what many Free Software programs prefer to use to install themselves on Windows because NSIS is also Free Software and doesn’t cost an exorbitant license fee, seems to me to be worthy of intense scrutiny, as it would be a great way to harass the Free Software community and blame it on “suspected malware”.



It seems, in my experience, that “False Positives” on Windows antivirus products are the most serious problem when you use Microsoft’s own, and it almost always “oopses” in really suspicious ways. Like, ways you’ll never have them dead to rights on, but very interesting nonetheless.



In fact, whenever I would ask VirusTotal for another opinion, it was rare that even a single antivirus program out of dozens of others agreed with Microsoft’s “False Positives”.



Like, you can just about count on “Microsoft Pretender” to miss RATS and ransomware, and removing QBittorrent without asking. (There’s also mention here of it attacking Ardour, a Free Software Digital Audio Workstation, and quarantining it.)



It’s a dark joke among Reddit users. Everyone knows how bad this thing is.



SJVN of ZDNet, which is a total spam farm now, for corporate PR releases, was talking about the “rich investigative experiences” of “Microsoft Pretender” for GNU/Linux, but considering that it’s by far the most incompetent and corrupt antivirus solution on the market for Windows, and it’s known to transmit lots of information about you back to Microsoft, there’s absolutely no reason to use it.



SJVN should write another article about the comforts of Rich Corinthian Leather seats. There’s nothing sadder than a so-called “independent journalist” who writes absolute drivel like this.



If Microsoft hadn’t made installing and removing software on Windows an unholy mess from its inception, and then told developers to go license a third party solution to deal with it, we probably wouldn’t be dealing with half the problems we have over the years, but NSIS is so good that it’s all but relegated the InstallShield Wizard and other expensive and error-prone methods of dealing with software programs on Windows to the ash heap of history.



Another thing Microsoft stands to gain from creating the perception that legitimate software (and might as well be FOSS while they’re attacking something) is overflowing with viruses, is it puts pressure on software developers to use Microsoft’s crummy Windows Store and agree to a litany of abuses that don’t apply if you “sideload” (the newspeak term for installing programs on your own computer).



Apple, for their part, pulls no punches when they make wild accusations that people who “sideload” are probably criminals.



Sure, yeah, okay…. I want to use Infinity for Reddit and NewPipe for Youtube on my phone because the real things have gotten so annoying that I can’t stand them and otherwise wouldn’t use a phone, but sure….



Most of the software in the F-Droid (for Android) store is of much higher technical quality and far less annoying to the user than in the Google Play or Apple App Store, because the author is writing it to be useful, not like these companies that have given up on anything except 27 tracking libraries and ads every 2 minutes.



Since Apple has warred against “sideloading”, anyone who wants software on their phone that’s not an annoying piece of shit designed to spy on them, shovel ads onto their screen, and drain their bank accounts with micro-transactions is now a “child molester”. Whoa, that escalated quickly. Thanks Apple!



Microsoft’s “liberalized” terms of use, which are still awful, for their Windows Store, are a desperate move ten years too late, and years after their Windows Mobile division failed.



Had they done these then, it may have saved that division.



Who knows? The Windows brand is the operating system version of “Internet Explorer” at this point. There are those who look back and actually liked Windows Mobile and say “Oh why oh why did they have to call it Windows?”.



I have to wonder who would accept any restrictions on their creative vision and their rights as a software author when delivering software straight to the customer and being able to ship the full version without any meddling from Microsoft and delays in getting updates out is possible.



Whether there’s a conspiracy afoot at Microsoft or if you believe them that these really are “False Positives” that few or no other antivirus companies can ever seem to corroborate, or both, it’s definitely worth openly asking why we’d install this junk on GNU/Linux.



Even if it is just to make sure malicious Windows software isn’t being downloaded by Windows users from a server, it doesn’t appear to be doing a great job as part of Windows itself.



Of course, at this point, all antivirus boils down to is a short list (of millions) of prevalent malware samples and then a lot of guesswork, and that leaves plenty of room to be wrong. When the problem on Windows is so out of control that you have to resort to outright guessing, there’s going to be collateral damage.



We’ve never had a disaster of this magnitude on GNU/Linux, so Microsoft Googlebombs “Linux malware” to refer to something that runs in Windows Subsystem for Linux, and that’s a very important distinction, as they bungle WSL/WSL2 quite badly and manage to add an insurmountable amount of attack surface on their own OS.



A “WSL” is what a company does when they’re losing, or have already lost. It says, “We’re not important anymore, but we are compatible with the standard.”.



SCO did it with their “Linux Kernel Personality” on their way to bankruptcy court, and Microsoft is doing it while they bleed users.



But when we see “Linux” news sites talking about WSL viruses, we should err, “Blow the WSL.” on them. They’re Windows viruses that just so happen to exploit some dodgy compatibility hack that Microsoft tossed in there.



Microsoft has done things like leave WSL broken and inaccessible for weeks at a time before.



So, even if you manage to become productive somehow with a workflow that relies on WSL, remember Microsoft’s incompetent upgrade bungling. It’s only a matter of time before you’re doing negative work that wouldn’t have been necessary at all on a real computer running real GNU/Linux.



This virus mess and the ensuing disaster of malicious and randomly-guessing “security” software, some of which actually does cost a fortune, are more reasons to get out.



I about fell out of my chair laughing the other day that Microsoft actually put a thing in Edge called “Super Duper Secure Mode” (actual name), and all it does really is turn off the just-in-time compiler from the V8 JavaScript engine so that it can slowly interpret the scripts on the page.



When something is compiled by a JIT runtime, you do get extra potential for security vulnerabilities. The Medium Security mode on the Tor Browser (Firefox based) also turns off the JIT.



The thing is that if your browser really wants to have good “Web apps” performance, it can’t run in this mode, so the whole thing is a ruse put in there so Microsoft can Googlebomb the illusion of security in their products some more.



In fact, every day, more and more of our infrastructure is under attack, more identity theft happens, and more corporate and national secrets are spilled due to the fact that Windows is naked despite all of this rather bloated security theater that removes compatibility with older programs.



The only thing that makes sense for “national security” executive orders would be a plan to transition away from Microsoft entirely. They’ve proven time and time again that they can’t secure Windows, and they misconfigure their own networks and cause data breaches with it, and blame their customers for “using it wrong”.



Whether you choose to use Microsoft products or not, your data is subject to Windows malware because somewhere along the way, you will do business with people who do use Microsoft products.



Until we have some sort of national “cybersecurity” policy that makes sense, I think all we can do is ensure that our computing is as secure as possible on our end.



Microsoft pays for whitepapers and advertisement editorials, but will these fix the problem when you’re a victim of identity theft or ransomware and trying to clean up the mess?



How much will Microsoft pay you to help out with that? The whitepapers maybe? SJVN and the Rich Investigative Experiences of Corinthian Leather?



FDR famously said (or rather, usurped for his pitch for the New Deal) that he wanted a chicken in every pot and a car in every garage, however, when the ransomware went after JBS and the Colonial Pipeline recently, humorously there were regions of America where you couldn’t get gas to travel to the store and there wouldn’t be a chicken for your pot if you could.



Microsoft has thrown up more roadblocks to prosperity. Their crummy software has licensing costs and it costs the economy over and over when we have to stop and deal with the fallout from the latest attack.



These are problems that we didn’t even have before there were computers everywhere. Dealing with antivirus software that barely works and often “malfunctions” is just salt in the wound.



Thanks Microsoft!

Recent Techrights' Posts

Legal Attacks on Techrights Have Made Techrights More Popular and More Widely Read
The misogynists will have plenty of work to do this summer
 
Gemini Links 08/08/2026: Gigs, Poems, SREs, and Shared Passion
Links for the day
If GNU/Linux Rising is Just "Bots" (It's Not, Many Surveys Show the Same), Why Does Microsoft Rush to Lie About System Requirements of Vista 11?
The real reason is, GNU/Linux is rising
Kompromat Tactics in GNU and Linux
Kompromat as a concept was covered here in the past in relation to Microsoft
SLAPP Censorship - Part 143 Out of 200: After Nearly 10 Attempts to Settle With Us and Over a Million Pounds Spent on Lawyers and Barristers
We are in no particular hurry
20 Years and 43 Years
GNU/Linux is not just code, it's a philosophy, licence (copyleft), and community
GNU/Linux Turns 43 Next Month, Many Distros Actively Maintained
A lot of Debian-based distros are still actively maintained (we talk about this in IRC this evening), so the stability of the Debian Project is important
Links 08/08/2026: GAFAM Colonialism "Paved Over Protected Wetlands", Slop Companies Hoard Software Patents as Debt Soars to Trillions
Links for the day
Links 08/08/2026: "Palantir Paid No Federal Income Tax" and "Who's Responsible for This Mess?"
Links for the day
Retained: The Time IBM's Red Hat Tried to Hijack or Take Offline Site of Critics, Failed on All Grounds (Meritless Action Intended to Harass Critics)
Replicated from adrforum.com
IBM's 'Final Solution': Censor Sites Not Controlled by IBM, Sites Where Dissent is Expressed
IBM has no culture of free speech
More Mass Layoffs Coming IBM's Way (Ones IBM Cannot Hide, Cannot Convince Enough People to Leave or Unjustifiably PIP Them When They Say No)
The company that was like a "father of modern computing" is now stingy when it comes to travel. Not a good sign.
What Will it Take for Mainstream Media to Report Silent or Secret Layoffs at IBM?
"Silent" or "secret" sometimes because the media won't cover them
Is the Future of IBM Red Hat Temporary Staff, Contractors?
They want cheap, obedient lemmings
Gemini Links 08/08/2026: Tribute to Lloyd Center, Radio Amateurism, Homeworlds
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 07, 2026
IRC logs for Friday, August 07, 2026
Microsoft Uses Slop to Find Defects and Then Uses Slop to Replace Code, What Could Go Wrong?
Botspam is the problem, it's not a constructive approach in any shape or form
analytics.usa.gov: GNU/Linux Up Some More This Week
Days ago it said 6.4%, now it's up to 6.8%
RA-pocalypse: IBM Tells Workers "Taking a Hike" is Their "Next Step" ('Voluntary' Layoffs), Now It Prepares to Sack Lots of Contractors
There definitely is something going on
Kai Stephens (Barkley Walsh) & British Democrats in Clacton by-election hustings
Reprinted with permission from Daniel Pocock
Daniel Pocock 'Punching' Nazis in the UK
The so-called "cult" of so-called "Debianism" was left with nothing but massive legal bills
SLAPP Censorship - Part 142 Out of 200: GemText is Not a Webpage, Gemini Protocol is Not the Web, and Capsules Are Not Websites
our intention to appeal (escalate to the Court of Appeal)
Microsoft: Our August 2026 Layoffs Are Not Layoffs Because... Reasons
That's like IBM making "spin-offs", then pretending that no layoffs are happening
Links 07/08/2026: UMG and Anthropic in Trouble Over Copyright Infringements Sold as "Training" (Slop)
Links for the day
Links 07/08/2026: "BMW Is Showing Commercials On Their Car's Dash Screens And They Want You To Think It's A Treat", Software Patents on Drones
Links for the day
What We Said About Red Hat's Fate Under IBM Turned Out to be Right on the Money (That IBM Lacks)
There are no layoffs at IBM
IRC Networks Show No Signs of Going Away, IRC Enters Its 39th Year
That IRC daemons are still actively developed and patched in summer of 2026 (over 38 years after IRC was born) says a lot about IRC's importance
Social [Control] Media Needs to Die
I am a bit shocked to recall that I wasted a lot of time on it
Some Malware is Legal Because It's Made and Distributed by Politically-Connected GAFAM
In reality, the security non-experts 'championed' (and salaried) by GAFAM are anti-security people who advocate back doors
The GNU/Linux Anniversary is Next Month, Not This Month
It'll turn 43
At Clacton by-election Hustings Event Daniel Pocock Says "Social [Control] Media Has Contributed to Some of the Anti Social Behaviour."
No doubt many problems in society are caused or at least amplified/accentuated by this horrible phenomenon
IBM Insiders Explain Why IBM is in Very Serious Trouble
Will IBM last long enough for any "quantum" deliverables to become a reality?
The Register MS Took Money From Broadcom to Publish Fake 'News' With "AI" Mentioned 35 Times
not legitimate or authentic journalism.
GNU/Linux Approaching 20% in Georgia (the Country)
Usage of GNU/Linux was near 0%, as measured by statCounter, several years ago
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 06, 2026
IRC logs for Thursday, August 06, 2026
Gemini Links 07/08/2026: Radio Amateurism, Summer Updates, and Programming "Taste"
Links for the day
Links 06/08/2026: Billboard Chart Contaminated by Slop Plagiarists, Sheinbaum Blasts Social Control Media
Links for the day
A Long Break and What's Coming Next Year
Some time next year we definitely plan to show how the EFF failed women, failed bloggers, and basically prioritised GAFAM
Daniel Pocock on a "metre-long ballot paper"
The Debian "cult" (as he calls them collectively) is simply jealous of him
Links 06/08/2026: Disney and Fentanylware (TikTok) Deal, "Hearing Aids Shenanigans"
Links for the day
IBM Mass Layoffs Began Yesterday, They're Sold as "Voluntary", the "Offer" Runs for Two Weeks (Last Day August 19th 2026)
IBM will self-detonate while using contractual agreements to force people to smile
Start of September 2026 'Voluntary' Mass Layoffs at IBM, Start of October Red Hat Employees Forced Into the 'Bloodbath' (After Collapse of IBM's Shares)
Red Hat is in trouble
Many GNU/Linux PCs Are Not Connected to the Net or Don't Use the Web
Saying GNU/Linux user-agents are just "bots" (Microsoft Lunduke and other Microsofters say this) is like asserting that the Twin Towers fell not because of two giant planes but because of explosives
They Call Occupations "Professions" Because the "Pro" Means Something
If you want to find tech news online
New Conference Paper (Science of Cyber Security) Credits RMS With Delaying Passwords
When it comes to passwords, RMS was "right"
Removing Gender Barriers in Computer Science
It is not that "women aren't good at maths"
In Brunei, GNU/Linux Approaches International Average of 8.5%
a sharp rise from 0% to about 7.5% happened in a few years
15% of IBM Staff Marked for Layoffs ("RAs"), the Workers' Objective is to Find Another Employer and Leave
"That's not a workforce, that's a waiting room."
Maintenance to be Completed Tonight (IPv6)
Notice how, after 25+ years, we're still not fully adopting IPv6, we're only about 50% there
A Data Centres Hub Puts Everyone at Risk, Especially People Who Live Near Them at Times of War/s
Spoiler: Datacentres are military targets, they attract missiles, some with nuclear warheads
GAFAM Mass Layoffs and Mountains (Trillions of Dollars in 'Secret' or 'Off-the-Ledger') Debt
GAFAM is having layoffs this month
August 2026 Microsoft Layoffs Confirmed by Staff This Week
It's hard to assess how many are impacted but signed an NDA, preventing them from speaking about what really happened
analytics.usa.gov Says 7% of Sessions Come From GNU/Linux and ChromeOS. If ~40% (Mobile) Get Omitted, It's More Like 11%.
In desktops and in laptops GNU/Linux has become a big player
IBM Cannot Survive for Much Longer, There Are Limits to RAs and Offshoring, IBM Now Asks Workers to Quit
IBM is in very serious trouble
SLAPP Censorship - Part 141 Out of 200: Brett Wilson LLP Failed to Learn From the Mistakes of the European Patent Office (EPO)
my solicitor, David Allen Green, put them in their place
Texts of the Claims From Balabhadra (Alex) Graveley and Matthew J. Garrett Almost Identical, I am Suing for Abuse of Process
Half a decade ago Balabhadra (Alex) Graveley from Microsoft and GNOME was arrested for strangulation in Texas
Gemini Links 06/08/2026: "Eat That Frog", Mutt Terminal Email Guide, and BASICODE
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 05, 2026
IRC logs for Wednesday, August 05, 2026