Bonum Certa Men Certa

Microsoft “Defender” Pretender Attacks Random Software That Uses NSIS for installation; “Super Duper Secure Mode” for Edge is a Laugh

Guest post by Ryan, reprinted with permission from the original

Astronaut



Windows has for some time, apparently, attacked random software just because that software uses the Nullsoft Scriptable Installation System, a totally legitimate and Free and Open Source installation framework which has been around for decades.



Microsoft released an article about doing this years ago, but it appears they just randomly detect NSIS installers and assign some scary-sounding but bogus Trojan name to them.



In reality, just having a powerful scripting system doesn’t make your software a Trojan horse, and if Windows had proper software management, tools like NSIS would never have been necessary.



The developers I’ve heard from consider this just one more frustration to expect when developing software for Windows, and keep submitting their particular installer package to Microsoft to get on some kind of an exclusion list, but that doesn’t solve the bigger problem.



There’s nothing wrong with NSIS, and “Microsoft Pretender” is either just guessing and pulling random trojan names out of its proverbial ass or this is another attack on competitors and things that the “MAFIAA” doesn’t like and sometimes remove them without permission from the user or even a warning.



They’ve been caught doing this with LibreOffice, QBittorrent, PeaZip and other perfectly legitimate things.



Going after NSIS, which is what many Free Software programs prefer to use to install themselves on Windows because NSIS is also Free Software and doesn’t cost an exorbitant license fee, seems to me to be worthy of intense scrutiny, as it would be a great way to harass the Free Software community and blame it on “suspected malware”.



It seems, in my experience, that “False Positives” on Windows antivirus products are the most serious problem when you use Microsoft’s own, and it almost always “oopses” in really suspicious ways. Like, ways you’ll never have them dead to rights on, but very interesting nonetheless.



In fact, whenever I would ask VirusTotal for another opinion, it was rare that even a single antivirus program out of dozens of others agreed with Microsoft’s “False Positives”.



Like, you can just about count on “Microsoft Pretender” to miss RATS and ransomware, and removing QBittorrent without asking. (There’s also mention here of it attacking Ardour, a Free Software Digital Audio Workstation, and quarantining it.)



It’s a dark joke among Reddit users. Everyone knows how bad this thing is.



SJVN of ZDNet, which is a total spam farm now, for corporate PR releases, was talking about the “rich investigative experiences” of “Microsoft Pretender” for GNU/Linux, but considering that it’s by far the most incompetent and corrupt antivirus solution on the market for Windows, and it’s known to transmit lots of information about you back to Microsoft, there’s absolutely no reason to use it.



SJVN should write another article about the comforts of Rich Corinthian Leather seats. There’s nothing sadder than a so-called “independent journalist” who writes absolute drivel like this.



If Microsoft hadn’t made installing and removing software on Windows an unholy mess from its inception, and then told developers to go license a third party solution to deal with it, we probably wouldn’t be dealing with half the problems we have over the years, but NSIS is so good that it’s all but relegated the InstallShield Wizard and other expensive and error-prone methods of dealing with software programs on Windows to the ash heap of history.



Another thing Microsoft stands to gain from creating the perception that legitimate software (and might as well be FOSS while they’re attacking something) is overflowing with viruses, is it puts pressure on software developers to use Microsoft’s crummy Windows Store and agree to a litany of abuses that don’t apply if you “sideload” (the newspeak term for installing programs on your own computer).



Apple, for their part, pulls no punches when they make wild accusations that people who “sideload” are probably criminals.



Sure, yeah, okay…. I want to use Infinity for Reddit and NewPipe for Youtube on my phone because the real things have gotten so annoying that I can’t stand them and otherwise wouldn’t use a phone, but sure….



Most of the software in the F-Droid (for Android) store is of much higher technical quality and far less annoying to the user than in the Google Play or Apple App Store, because the author is writing it to be useful, not like these companies that have given up on anything except 27 tracking libraries and ads every 2 minutes.



Since Apple has warred against “sideloading”, anyone who wants software on their phone that’s not an annoying piece of shit designed to spy on them, shovel ads onto their screen, and drain their bank accounts with micro-transactions is now a “child molester”. Whoa, that escalated quickly. Thanks Apple!



Microsoft’s “liberalized” terms of use, which are still awful, for their Windows Store, are a desperate move ten years too late, and years after their Windows Mobile division failed.



Had they done these then, it may have saved that division.



Who knows? The Windows brand is the operating system version of “Internet Explorer” at this point. There are those who look back and actually liked Windows Mobile and say “Oh why oh why did they have to call it Windows?”.



I have to wonder who would accept any restrictions on their creative vision and their rights as a software author when delivering software straight to the customer and being able to ship the full version without any meddling from Microsoft and delays in getting updates out is possible.



Whether there’s a conspiracy afoot at Microsoft or if you believe them that these really are “False Positives” that few or no other antivirus companies can ever seem to corroborate, or both, it’s definitely worth openly asking why we’d install this junk on GNU/Linux.



Even if it is just to make sure malicious Windows software isn’t being downloaded by Windows users from a server, it doesn’t appear to be doing a great job as part of Windows itself.



Of course, at this point, all antivirus boils down to is a short list (of millions) of prevalent malware samples and then a lot of guesswork, and that leaves plenty of room to be wrong. When the problem on Windows is so out of control that you have to resort to outright guessing, there’s going to be collateral damage.



We’ve never had a disaster of this magnitude on GNU/Linux, so Microsoft Googlebombs “Linux malware” to refer to something that runs in Windows Subsystem for Linux, and that’s a very important distinction, as they bungle WSL/WSL2 quite badly and manage to add an insurmountable amount of attack surface on their own OS.



A “WSL” is what a company does when they’re losing, or have already lost. It says, “We’re not important anymore, but we are compatible with the standard.”.



SCO did it with their “Linux Kernel Personality” on their way to bankruptcy court, and Microsoft is doing it while they bleed users.



But when we see “Linux” news sites talking about WSL viruses, we should err, “Blow the WSL.” on them. They’re Windows viruses that just so happen to exploit some dodgy compatibility hack that Microsoft tossed in there.



Microsoft has done things like leave WSL broken and inaccessible for weeks at a time before.



So, even if you manage to become productive somehow with a workflow that relies on WSL, remember Microsoft’s incompetent upgrade bungling. It’s only a matter of time before you’re doing negative work that wouldn’t have been necessary at all on a real computer running real GNU/Linux.



This virus mess and the ensuing disaster of malicious and randomly-guessing “security” software, some of which actually does cost a fortune, are more reasons to get out.



I about fell out of my chair laughing the other day that Microsoft actually put a thing in Edge called “Super Duper Secure Mode” (actual name), and all it does really is turn off the just-in-time compiler from the V8 JavaScript engine so that it can slowly interpret the scripts on the page.



When something is compiled by a JIT runtime, you do get extra potential for security vulnerabilities. The Medium Security mode on the Tor Browser (Firefox based) also turns off the JIT.



The thing is that if your browser really wants to have good “Web apps” performance, it can’t run in this mode, so the whole thing is a ruse put in there so Microsoft can Googlebomb the illusion of security in their products some more.



In fact, every day, more and more of our infrastructure is under attack, more identity theft happens, and more corporate and national secrets are spilled due to the fact that Windows is naked despite all of this rather bloated security theater that removes compatibility with older programs.



The only thing that makes sense for “national security” executive orders would be a plan to transition away from Microsoft entirely. They’ve proven time and time again that they can’t secure Windows, and they misconfigure their own networks and cause data breaches with it, and blame their customers for “using it wrong”.



Whether you choose to use Microsoft products or not, your data is subject to Windows malware because somewhere along the way, you will do business with people who do use Microsoft products.



Until we have some sort of national “cybersecurity” policy that makes sense, I think all we can do is ensure that our computing is as secure as possible on our end.



Microsoft pays for whitepapers and advertisement editorials, but will these fix the problem when you’re a victim of identity theft or ransomware and trying to clean up the mess?



How much will Microsoft pay you to help out with that? The whitepapers maybe? SJVN and the Rich Investigative Experiences of Corinthian Leather?



FDR famously said (or rather, usurped for his pitch for the New Deal) that he wanted a chicken in every pot and a car in every garage, however, when the ransomware went after JBS and the Colonial Pipeline recently, humorously there were regions of America where you couldn’t get gas to travel to the store and there wouldn’t be a chicken for your pot if you could.



Microsoft has thrown up more roadblocks to prosperity. Their crummy software has licensing costs and it costs the economy over and over when we have to stop and deal with the fallout from the latest attack.



These are problems that we didn’t even have before there were computers everywhere. Dealing with antivirus software that barely works and often “malfunctions” is just salt in the wound.



Thanks Microsoft!

Recent Techrights' Posts

EPO Union Leaders in Rijswijk Explain Where EPO Strikes Stand and How to Prepare for Next Week's
We have some revelations to share in a few days
Microsoft's "AI CEO" (Slop Propagandist) is Projecting, Many Microsoft "Jobs to be Replaced With All-Indian Low-Paid Staff in 12 Months"
Windows is perishing
 
Gemini Links 19/02/2026: "Towards a Gemini Famicom Resource" and Dumping Microsoft
Links for the day
IBM Behaves Like a Company Looking for Loose Change Between Sofa Cushions
Chasing laid-off workers for dollars and even pennies, making excuses and devising loopholes (such as PIPs) to flout severance obligations
Microsoft Found Another Bailout Opportunity: Killing People
Good thing that Nadella is not racist!
No "Smart Mobs" (Social Control Media) in BRIC?
It looks like the "Social" "Media" sites tracked by statCounter see little from (or of) BRIC, and moreover it is declining fast
The Few Slopfarms We Saw Today
The sentiment has changed a lot
Links 19/02/2026: Protecting Framework Laptop 13, Hardware Drive Shortages
Links for the day
In Africa's Second-Largest Nation, Democratic Republic of the Congo (DRC), Opera 10 Times Bigger Than Firefox (and GNU/Linux Now at 5%)
This will become an accessibility problem
Links 19/02/2026: "A.I.pocalypse" Inevitable and "Butlers to LLMs"
Links for the day
An Inherently Royal (Monarchs') Legal System Where Size Matters (Big Capital Eats the Small)
This reinforces the notion that justice is only for those who can afford it
These Statistics Should Keep Microsoft Shareholders Awake at Night
Windows is, in general (all versions collectively), declining over time
Economic Failure and Other Harsh Realities Have Nothing to Do With Slop 'Innovation'
Advanced propaganda, not advanced 'AI' [...] They attack workers while insulting their intelligence
Spaniards Shutting Down MElon's Digital Weapon of "Smart Mobs"
Are the Spanish people already acting based on gut feeling and shunning/shutting out the provocation vector?
Bitcoin: government engagement contradictions
Reprinted with permission from Daniel Pocock
Richard Stallman in the United States - Part II - "Haters Gonna Hate"
we shall carry on with this series at the right pace
Typical! Solicitors Regulation Authority (SRA) Tells Victims of Fraud to Wait 10 Weeks
justice delayed is justice denied
statCounter: Only One in 350 Iranians Would Use Microsoft for Web Search
Microsoft is trying to fake "demand"
Slides Shown a Week Ago by the EPO's Staff Committee Ahead of the Second Very Large Strike
This coming weekend we'll drop a 'bombshell' of sorts
EPO "Cocaine Communication Manager" - Part II - Illegal Drug Addicts Mobbing the Wrong People, This Will Definitely Backfire
This year may well be the last year of Team Campinos. Nobody will hire them after that.
Mass Layoffs (But Silent Layoffs) Still Happening in IBM, You Need Only Look Closely (There Are NDAs, PIPs, 'Early Retirement' Sweeteners and IBM - Like Microsoft - Skirts the WARN Act)
the layoffs are definitely happening
Very Little Slop
We are not finding much slop anymore
Links 19/02/2026: Illegal Kangaroo Court for Patents Attracts Aggressive Firms, Public Domain Review Grows
Links for the day
Gemini Links 19/02/2026: Taxing the Rich, Raspberry Pi 4 Tinkering
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 18, 2026
IRC logs for Wednesday, February 18, 2026
Links 18/02/2026: DMCA Weakened, Anna’s Archive Still Thriving
Links for the day
Links 18/02/2026: Gig 'Economy' Condemned, Microsoft Insulting/Stressing People With False Slop Predictions
Links for the day
Twitter Falling to 1% in Africa's Largest Nation (Algeria)
About 15 years ago the regime in Egypt got toppled (and others had been too) partly because of social control media such as Twitter
"How Many Friends Do You Have?"
"Do bots count?" "Friends in Facebook?" "Does a girlfriend chatbot count as a friend?"
Solicitors Regulation Authority (SRA) Responds to Crises Only After It's Way Too Late
The SRA does not do its job. The new chief's job is face-saving PR in the media.
The Techrights Team Makes the Platform Faster
The infrastructure is already fast
Mozilla Firefox Died in Afghanistan
Mozilla has been a complete disaster
Gemini Links 18/02/2026: Astronomy and Texinfo
Links for the day
Are IBM CEO and IBM CFO Ready for Financial Audit That Topples the Shares by 50% in One Day?
The same "chefs" that cooked up Kyndryl Holdings Inc are still in charge of the IBM kitchen
France Does Not Need Digital Weapons Disguised as Social and as Media
French people lost interest in Social Control 'Media' (or Networks)
"Senior AI Reporter" at Slop Technica/Ars Sloppica Has Written Nothing in Nearly a Week, Did Conde Nast Suspend Him for Fake Articles With Fake Quotes?
Slop Technica/Ars Sloppica is having a serious credibility issue right now
Linux Foundation Puts Slop Images, Not Just Slop Text, in Linux.com
More of the same then
The Register MS Paid-for 'Articles' (Ads) Seem to be LLM Slop Again
If it's true that The Register MS is resorting to these marketing tactics, will they later delete the evidence (as they did months ago)?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, February 17, 2026
IRC logs for Tuesday, February 17, 2026
Microsoft Had Mass Layoffs Every Month Last Year, This Year It's Delaying a Lot to "Prove" Rumours That Crashed Its Stock... 'Wrong'
Building a bigger snowball for later
Red Hat Is Not a Company Anymore, Amid Bluewashing and Mass Layoffs It's Merely IBM "Division" or "Brand" or "Product"
systemd at this point is sort of like IBM/Microsoft thing
IBM suffers "worst weekly drop in six years", Microsoft's MSN calls it "buying opportunity"
Ask Cramer what to do
Still Some Slopfarms in View, Sometimes Targetting "Linux"
That's a total of at least 4 in Google News today, coming from 3 sources
Gemini Links 17/02/2026: 3D-Printed Stainless Steel Smartwatch and Gopher Bay Offline
Links for the day
Links 17/02/2026: Machine Rage and Microsoft Kills XBox Social Clubs
Links for the day
EPO "Productivity" Will Fall Off a Cliff If Examiners Stick to the European Patent Convention (EPC) and Follow the Real Rules
The EPO's "Cocaine Communication Manager" would hate to see the next "productivity" metrics
The Problem is Not Technology, the Problem is Really Bad Things Sold or Imposed as "Tech" (Like a Religion Built Around Technology)
Don't hate technology, hate the corporations that abuse it to promote coercion, exploitation etc.
Resisting IBM and EPO Corruption
Rise up against EPO dictatorship next week
Where Slop Meets Ghostwriting: It's a False Analogy
It's a false analogy
Links 17/02/2026: Why OpenClaw is Very Sleazy and Ars Technica Exposed as Hub of LLM Slop (Credibility Destroyed Overnight)
Links for the day
Benj Edwards (Ars Technica) Used Fake Articles to Promote Ponzi Scheme for Conde Nast and Its Client (Marketing)
What Ars Technica and Conde Nast do here helps defraud the general public
Slop Technica: Ars Technica Seems Like Repeat Offender, a Part-Time Slopfarm
The culprits are repeat offenders, but the publisher will never admit this in public
Only One in 50 Saudis Would Use Microsoft for Search, Almost Same as Would Use Russia's Yandex
If statCounter is to be trusted
Microsoft's "AI" Concerns Are All Indian (or Low-Paid Workers Who Work Extra Hours Unpaid)
portraying charlatans and frauds like they're some kind of visionaries and luminaries
Microsoft Turned Bing Into Censorship Machine of China, But Bing Is Pegged at a Mere 2% in Asia, Yandex is Bigger
Expect many Bing layoffs some time soon (like in past years)
Just Like The Register MS, Conde Nast's Ars Technica Has Just Publicly Admitted That It Published Fake Articles (Slop) Made by LLMs About Serious Subjects
Conde Nast might shut Ars Technica down to escape the bad publicity/association
Solicitors Regulation Authority (SRA) Way Too Slow to Respond to Financial Fraud at Law Firms, in Effect Helping Those Law Firms Defraud Many More People (Fleecing Clients)
Who will hold the SRA accountable for this?
Techrights Became a Hub for News That IBM/Red Hat Doesn't Want You to See (and Pays Mainstream Media to Distract From)
the more viciously the notorious organisation attacks the reporter, the greater the interest in what the reporter has to say
EPO's Central Staff Committee on Fourth Technical Meeting, Two Days Before First of (At Least) 4 Winter Strikes at the Second-Largest European Institution
“future orientations on the salary adjustment procedure”
IBM's Collapse Continues, Half of EU Countries to Have Mass Layoffs, "IBM Clearly Disinvests From Europe" Says IBM European Works Council
Recent publication
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, February 16, 2026
IRC logs for Monday, February 16, 2026
Gemini Links 17/02/2026: Alpenglow Industries' Closure and Gemini Server Issues
Links for the day