Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Earth Bound Misfit

(3,554 posts)
Sat Feb 21, 2015, 07:33 AM Feb 2015

Lenovo caught installing adware on new computers

Another company trying to pilfer as much user data as possible & sell it to the highest bidder... all while potentially putting users at risk & patently denying it.

http://thenextweb.com/insider/2015/02/19/lenovo-caught-installing-adware-new-computers/

Other users are reporting that the adware actually installs its own self-signed certificate authority which effectively allows the software to snoop on secure connections, like banking websites as pictured...

This is a malicious technique commonly known as a man-in-the middle attack, where the certificate allows the software to decrypt secure requests, ...


http://www.theregister.co.uk/2015/02/19/superfish_lenovo_analysis/

Superfish reportedly intercepted users' traffic to sling ads at them even when they were visiting banking websites.

The adware-on-steroids installs its own self-signed root CA certificate in Windows before generating certificates on the fly for each attempted SSL connection. Superfish even served fake certs in order to MiTM banking websites, it has been reported.


http://www.pcworld.com/article/2886278/how-to-remove-the-dangerous-superfish-adware-presintalled-on-lenovo-pcs.html

Browsing to this website will quickly let you know if you have Superfish installed. Thanks, Filippo Valsorda! Lastpass also tossed up a website that can check for Superfish.

http://systemexplorer.net/file-database/file/visualdiscovery-exe

What is the "visualdiscovery.exe" ?

This was bundled with my new Lenovo...It injects itself into your browser session, offering "deals" similar to pictures you're looking at, and also suggests ads. To remove this, navigate to %programfiles%LenovoVisualDiscovery and run Uninstall.exe. Very shady.

https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-Pre-instaling-adware-spam-Superfish-powerd-by/td-p/1726839

First thing i done was download chrome and already noticed when i google search, adware adverts appear into the search results.

These are cleverly designed to fit into the search results to make them appear to look normal.

21 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Lenovo caught installing adware on new computers (Original Post) Earth Bound Misfit Feb 2015 OP
WOW! marym625 Feb 2015 #1
You're welcome. Earth Bound Misfit Feb 2015 #2
Thanks again marym625 Feb 2015 #5
Your Mileage May Vary... Earth Bound Misfit Feb 2015 #15
Ah! Thanks yet again! marym625 Feb 2015 #17
UPDATE: Lenovo admits security issues with Superfish, releases removal tool Earth Bound Misfit Feb 2015 #3
I call bullshit... Earth Bound Misfit Feb 2015 #19
Not on my ASUS or on the new Acer sitting here. hobbit709 Feb 2015 #4
How did you check? marym625 Feb 2015 #6
Both the links above and then a Search on the hard drive for visualexplorer.exe. hobbit709 Feb 2015 #7
But he said it only works with Lenovo marym625 Feb 2015 #8
It shows up on other computers too. hobbit709 Feb 2015 #9
Thanks! marym625 Feb 2015 #10
Best of the free versions. hobbit709 Feb 2015 #11
Thanks! marym625 Feb 2015 #13
I said... Earth Bound Misfit Feb 2015 #12
I'm sorry marym625 Feb 2015 #14
No worries! Earth Bound Misfit Feb 2015 #16
I can honestly say marym625 Feb 2015 #18
I found this way to clean install Windows 47of74 Feb 2015 #20
I just received my new Lenovo laptop yesterday and cntrygrl Mar 2015 #21

marym625

(17,997 posts)
1. WOW!
Sat Feb 21, 2015, 07:39 AM
Feb 2015

Thank you so much for this. I highly suspect my computer has something like this. I have had issues since I got it and Norton has been in there multiple times, always thinking they fixed the problem, only for it to reappear.

It's not a lenovo, it's a Asus. I am going to check as soon as I turn it on this morning.

Thanks again

Earth Bound Misfit

(3,554 posts)
2. You're welcome.
Sat Feb 21, 2015, 08:26 AM
Feb 2015

This particular instance applies to Lenovo consumer comps only... (ThinkPads not affected AFAICT). You may have other issues... not the least of which (IMHO) is running Norton... not a fan to say the least. YMMV.

marym625

(17,997 posts)
5. Thanks again
Sat Feb 21, 2015, 08:35 AM
Feb 2015

Well, it's better than McAfee. And it has caught more than a few viruses. It also keeps me from clicking on unsafe sites.

Sorry, what's YMMV?

Earth Bound Misfit

(3,554 posts)
3. UPDATE: Lenovo admits security issues with Superfish, releases removal tool
Sat Feb 21, 2015, 08:33 AM
Feb 2015
http://www.zdnet.com/article/lenovo-admits-security-issues-with-superfish-releases-removal-tool/

After playing a dead bat and attempting to push the perception that Superfish was not a security concern, Lenovo has admitted that it was caught napping on the security implications of preloading a piece of adware that installed its own self-signing man-in-the-middle proxy service that hijacked SSL/TLS connections.

"We did not know about this potential security vulnerability until yesterday," Lenovo said in a statement released Saturday, Sydney time. "We recognise that this was our miss, and we will do better in the future. Now we are focused on fixing it."

To that end, Lenovo has joined Microsoft in offering a removal tool to fix the Superfish issue


Lenovo Security advisory: http://support.lenovo.com/us/en/product_security/superfish

hobbit709

(41,694 posts)
9. It shows up on other computers too.
Sat Feb 21, 2015, 08:48 AM
Feb 2015

Usually comes bundled with some crapware "helper" application.
Lenovo got caught putting it in brand new computers.
Malwarebytes Antimalware will also find and remove it.
And I agree with EBM, Norton is garbage. I consider it about as useful as a screen door on a submarine.
Over half the infected computers that are brought in for me to fix have Norton on them and it didn't do diddly squat for protection.

marym625

(17,997 posts)
10. Thanks!
Sat Feb 21, 2015, 08:50 AM
Feb 2015

I will check when I get on my computer this morning.

What do you recommend? A screen door on a submarine isn't what I want

hobbit709

(41,694 posts)
11. Best of the free versions.
Sat Feb 21, 2015, 09:01 AM
Feb 2015

AVG, Avast, Bit Defender. Hell, even MSE or Windows Defender is better than Norton in my book. Norton was pretty good until they were bought out by Symantec-then it turned into crappy bloatware.
I just use MSE in conjunction with the paid for version of Malwarebytes on my computers.

Earth Bound Misfit

(3,554 posts)
12. I said...
Sat Feb 21, 2015, 09:06 AM
Feb 2015

This particular instance applies to Lenovo... links worked on my Dell/Gateway boxes.



EDIT: hobbitt709's replies #9 & #11 about covers it.

 

47of74

(18,470 posts)
20. I found this way to clean install Windows
Wed Feb 25, 2015, 01:57 AM
Feb 2015
http://arstechnica.com/gadgets/2015/02/save-yourself-from-your-oems-bad-decisions-with-a-clean-install-of-windows-8-1/

It's not perfect and takes some work. If I ever were to buy a PC and use Windows on it I think going forward I would wipe a computer and put a vanilla install of Windows on it before using it on a regular basis.

I use Mac Air for most of my daily stuff. I am thinking of getting a PC to use as a media server here at home. I'm thinking of going with a local company that does custom builds since they're willing to not install Windows (or any other OS). That's a big plus not having to pay for a copy of Windows that I wouldn't use anyways since I'd immediately put Ubuntu on it.

cntrygrl

(356 posts)
21. I just received my new Lenovo laptop yesterday and
Thu Mar 5, 2015, 09:10 AM
Mar 2015

want to thank you for these links. It appears I don't have the invading adware mentioned. Thank you again.

Latest Discussions»Help & Search»Computer Help and Support»Lenovo caught installing ...