Winstep Nexus, Nexus Ultimate and Winstep Xtreme v26.9 Released!
Version 26.9 is now available across the complete Winstep product line.
https://www.winstep.net
|
|||||||||||||||||||||||||||||||||||||||
Version 26.9 is now available across the complete Winstep product line.
https://www.winstep.net
|
|||||||||||||||||||||||||||||||||||||||
|
|
Is great, Carl. Getting into gridstacks now.
Thanks guys...
Oh, with the number of false positives going around because of Windows Defender "reputation racket", this might be useful: When Antivirus Software Becomes the Problem
Thanks guys...
Oh, with the number of false positives going around because of Windows Defender "reputation racket", this might be useful: When Antivirus Software Becomes the Problem
Make your font darker in Winstep forums. I know you're familiar with the owner over there, Seu preguiçoso! Older eyes like contrast. So do younger ones, for that matter.
"When Antivirus Software Becomes the Problem
The latest Winstep release has turned into a perfect demonstration of how badly antivirus false positives are getting out of hand.
Shortly after release, several completely legitimate Winstep files began being reported as malware:
* Malwarebytes classified the Ultimate installer as **Malware.Ransom.Agent.Generic**.
* Microsoft Defender quarantined **Nexus-Ultimate.exe** as **Trojan:Win32/Wacatac.H!ml**.
* Microsoft Defender detected **WsxService.exe** as **Trojan:Script/Wacatac.H!ml**.
* On VirusTotal, Microsoft alone classified **NextSTART.exe** as **Trojan:Win32/Wacatac.B!ml**, while the other 69 antivirus engines reported it as clean.
I submitted the affected executables directly to Microsoft for analysis. Microsoft’s analysts have now returned the same verdict for all three submissions:
> At this time, the submitted files do not meet our criteria for malware or potentially unwanted applications. The detection has been removed.
In other words, Microsoft has confirmed that **NextSTART.exe, Nexus-Ultimate.exe and WsxService.exe were all false positives**.
This appears to be a recurring problem involving automated reputation and machine-learning systems rather than the identification of specific malicious code. Newly released executables have little or no established reputation, particularly when they are not digitally signed. Instead of treating that as “unknown”, these systems increasingly seem willing to jump directly to “Trojan” or even “ransomware”.
A lack of reputation is not evidence of malware. An unsigned executable is not evidence of malware either.
Digital signing can establish who published a file and whether it was altered after signing. It does not magically prove that the program itself is harmless. Nevertheless, independent developers are increasingly being pressured into purchasing expensive code-signing certificates merely to reduce the chances of their perfectly legitimate software being blocked.
The most absurd part of this experience came when I attempted to use Microsoft’s own file-submission system. Its authentication page identified the **Windows Defender Security Intelligence** application as **“unverified”**, while asking for access to my profile, email address and previously supplied data. There was no option to skip authentication.
So Microsoft’s security system warns users about software whose reputation it does not recognize, while Microsoft’s own security submission application is presented to users as unverified. The irony is difficult to miss.
False positives will always happen occasionally. That is understandable. What is not acceptable is repeatedly labeling legitimate applications as severe Trojans or ransomware merely because a new version has not yet accumulated enough reputation.
This has serious consequences:
* Legitimate applications are quarantined or deleted without justification.
* Installed software can suddenly stop working.
* Users are frightened into believing that trusted developers have infected their computers.
* Small developers lose time, money and credibility repeatedly submitting every new build to antivirus vendors.
* Developers are placed under pressure to pay for certificates simply to avoid being treated as suspicious by default.
* Most dangerously, users may eventually stop believing genuine security warnings.
That final point should concern antivirus vendors most of all. If people repeatedly discover that dramatic declarations such as “Trojan”, “ransomware” and “severe threat” were wrong, they will learn to ignore those declarations. A security product that cries wolf too often eventually makes everyone less safe.
This is not an argument against antivirus software. It is an argument for antivirus products to distinguish clearly between **confirmed malicious behavior**, **suspicious behavior**, and simply **an unknown or low-reputation file**.
Calling everything unfamiliar a Trojan is not security. It is automated guesswork presented as certainty.
Microsoft has now examined the three affected Winstep executables, confirmed that they do not meet its malware or potentially unwanted application criteria, and removed the detections. Users may need to update Defender’s security intelligence before the corrected definitions take effect."
LOL if you create an account there - or you already have one, as is your case - you can simply turn dark mode on by clicking on the sun/moon icons at the top right of the forum page.
Make your font darker in Winstep forums. I know you're familiar with the owner over there, Seu preguiçoso! Older eyes like contrast. So do younger ones, for that matter.
LOL if you create an account there - or you already have one, as is your case - you can simply turn dark mode on by clicking on the sun/moon icons at the top right of the forum page.
Welcome Guest! Please take the time to register with us.
Select a reason for giving karma:
You're about to visit an external site:
Sign up here to get the latest news, updates, and special offers delivered directly to your inbox.