{"id":96,"date":"2015-03-01T01:56:47","date_gmt":"2015-03-01T01:56:47","guid":{"rendered":"https:\/\/carlosthomas.net\/blog\/?p=96"},"modified":"2015-03-01T01:56:47","modified_gmt":"2015-03-01T01:56:47","slug":"alert-superfish-on-lenovo","status":"publish","type":"post","link":"https:\/\/carlosthomas.net\/blog\/2015\/03\/alert-superfish-on-lenovo\/","title":{"rendered":"ALERT &#8211; Superfish On Lenovo"},"content":{"rendered":"<p>SOURCE: <a href=\"http:\/\/www.avg.com\/campaign-landing-pages\/ww-en\/lenovo-superfish\">http:\/\/www.avg.com\/campaign-landing-pages\/ww-en\/lenovo-superfish<\/a><\/p>\n<p>Based on the information on that link you should remove this software immediately if you own a Lenovo PC.<\/p>\n<p><a href=\"http:\/\/en.wikipedia.org\/wiki\/Lenovo\">Something to note &#8211; Lenovo and IBM are not the same company. IBM sold their PC business to Lenovo some time ago.<\/a><\/p>\n<p>A copy of the information from the AVG website is below for your convenience.<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<div class=\"wrapper section\">\n<div class=\" background-none none full-top-wrapper\">\n<div>\n<div class=\" full-width-content-wrapper\">\n<div class=\"full-width-inner\">\n<div>\n<div class=\"avgparsys wrapperParsys\">\n<div class=\"textComponent section\">\n<div>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-1'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/carlosthomas.net\/blog\/2015\/03\/alert-superfish-on-lenovo\/#How_to_remove_Superfish_and_its_certificate_from_your_Lenovo%C2%AE_PC\" >How to remove Superfish \nand its certificate from your Lenovo\u00ae PC<\/a><ul class='ez-toc-list-level-2' ><li class='ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/carlosthomas.net\/blog\/2015\/03\/alert-superfish-on-lenovo\/#What_is_Superfish\" >What is Superfish?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/carlosthomas.net\/blog\/2015\/03\/alert-superfish-on-lenovo\/#Why_is_Superfish_so_dangerous\" >Why is Superfish so dangerous?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/carlosthomas.net\/blog\/2015\/03\/alert-superfish-on-lenovo\/#Which_computers_are_affected\" >Which computers are affected?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/carlosthomas.net\/blog\/2015\/03\/alert-superfish-on-lenovo\/#Will_restoring_from_a_backup_help\" >Will restoring from a backup help?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h1><span class=\"ez-toc-section\" id=\"How_to_remove_Superfish_and_its_certificate_from_your_Lenovo%C2%AE_PC\"><\/span>How to remove Superfish<br \/>\n<span class=\"hd-medium nevada-text\">and its certificate from your Lenovo<sup>\u00ae<\/sup> PC<\/span><span class=\"ez-toc-section-end\"><\/span><\/h1>\n<\/div>\n<\/div>\n<div class=\"avgimage section\">\n<div><img decoding=\"async\" title=\"Superfish logo\" src=\"http:\/\/www.avg.com\/content\/dam\/other\/superfish-220x169.png\" alt=\"Superfish logo\" \/><\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"wrapper section\">\n<div class=\" background-none none full-top-wrapper\">\n<div>\n<div class=\" full-width-content-wrapper\">\n<div class=\"clear\"><\/div>\n<div class=\"full-width-inner\">\n<div>\n<div class=\"clear\"><\/div>\n<div class=\"avgparsys wrapperParsys\">\n<div class=\"textComponent section\">\n<div>\n<h2><span class=\"ez-toc-section\" id=\"What_is_Superfish\"><\/span>What is Superfish?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>Superfish is a piece of software that <a href=\"http:\/\/news.lenovo.com\/article_display.cfm?article_id=1929\">Lenovo has admitted to pre-installing<\/a> on many of its laptops to &#8220;enhance the\u00a0shopping experience&#8221; of its users. However, the <a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA15-051A\">U.S. Computer Emergency Readiness Team<\/a> calls Superfish\u00a0a &#8220;man-in-the-middle attack&#8221; because of how it &#8220;intercepts users&#8217; web traffic to provide targeted advertisements.&#8221;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"separator2 section\"><\/div>\n<div class=\"wrapper section\">\n<div class=\" background-none none full-top-wrapper\">\n<div>\n<div class=\" full-width-content-wrapper\">\n<div class=\"clear\"><\/div>\n<div class=\"full-width-inner\">\n<div>\n<div class=\"clear\"><\/div>\n<div class=\"avgparsys wrapperParsys\">\n<div class=\"textComponent section\">\n<div>\n<h2><span class=\"ez-toc-section\" id=\"Why_is_Superfish_so_dangerous\"><\/span>Why is Superfish so dangerous?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<\/div>\n<\/div>\n<div class=\"columns section\">\n<div class=\"columns-wrapper col-no-border\">\n<div class=\"table-wrapper\">\n<div class=\"table-row\">\n<div class=\"columns-cell column-index-0 \">\n<div class=\"avgparsys columnsParsys_0\">\n<div class=\"textComponent section\">\n<div>\n<p>Superfish snoops in on your web browsing and secretly slips ads into webpages. But the really dangerous part is that it&#8217;s pre-installed with root certificate authority, which allows it to impersonate any server&#8217;s security certificate.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"columns-cell column-index-1 \"><\/div>\n<div class=\"columns-cell column-index-2 last\">\n<div class=\"columnsParsys_2 avgparsys\">\n<div class=\"textComponent section\">\n<div>\n<p>If this certificate is compromised by hackers, you could\u00a0be tricked into logging in to a fake website and giving\u00a0hackers your password. Because of Superfish, any of\u00a0your accounts\u2014including encrypted bank accounts\u2014could be easily compromised.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"separator2 section\"><\/div>\n<div class=\"wrapper section\">\n<div class=\" background-white none full-top-wrapper\">\n<div>\n<div class=\" full-width-content-wrapper\">\n<div class=\"clear\"><\/div>\n<div class=\"full-width-inner\">\n<div>\n<div class=\"clear\"><\/div>\n<div class=\"avgparsys wrapperParsys\">\n<div class=\"textComponent section\">\n<div>\n<h2><span class=\"ez-toc-section\" id=\"Which_computers_are_affected\"><\/span>Which computers are affected?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><span class=\"h2-subheading\">According to Lenovo, Superfish may have been pre-installed<br \/>\non the following models:<\/span><\/p>\n<\/div>\n<\/div>\n<div class=\"columns section\">\n<div class=\"columns-wrapper col-no-border\">\n<div class=\"table-wrapper\">\n<div class=\"table-row\">\n<div class=\"columns-cell column-index-0 \">\n<div class=\"avgparsys columnsParsys_0\">\n<div class=\"avgimage section\">\n<div><img decoding=\"async\" title=\"Lenovo laptop\" src=\"http:\/\/www.avg.com\/content\/dam\/uis\/lenovo-laptop-317x211.png\" alt=\"Lenovo laptop\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"columns-cell column-index-1 last\">\n<div class=\"avgparsys columnsParsys_1\">\n<div class=\"columns section\">\n<div class=\"columns-wrapper col-no-border\">\n<div class=\"table-wrapper\">\n<div class=\"table-row\">\n<div class=\"columns-cell column-index-0 \">\n<div class=\"avgparsys columnsParsys_0\">\n<div class=\"textComponent section\">\n<div>\n<p><strong>E Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>G Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>S Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>U Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>Y Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>Z Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>Edge Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>Flex Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>MIIX\u00a0Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><strong>YOGA\u00a0Series:<\/strong><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"columns-cell column-index-1 last\">\n<div class=\"avgparsys columnsParsys_1\">\n<div class=\"textComponent section\">\n<div>\n<p>E10-30<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>G410, G510, G710, G40-70, G50-70, G40-30, G50-30, G40-45, G50-45, G40-80<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>S310, S410, S40-70, S415, S415Touch, S435, S20-30, S20-30Touch<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>U330P, U430P, U330Touch, U430Touch, U530Touch<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>Y430P, Y40-70, Y50-70, Y40-80, Y70-70<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>Z40-75, Z50-75, Z40-70, Z50-70, Z70-80<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>Edge 15<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>Flex2 14D, Flex2 15D, Flex2 14, Flex2 15, Flex2 Pro, Flex 10<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>MIIX2-8, MIIX2-10, MIIX2-11, MIIX 3 1030<\/p>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p>YOGA2Pro-13, YOGA2-13, YOGA2-11, YOGA3 Pro<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<p><a href=\"http:\/\/news.lenovo.com\/article_display.cfm?article_id=1929\">Source: Lenovo<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"separator2 section\"><\/div>\n<div class=\"wrapper section\">\n<div class=\"  none full-top-wrapper\">\n<div>\n<div class=\" full-width-content-wrapper\">\n<div class=\"clear\"><\/div>\n<div class=\"full-width-inner\">\n<div>\n<div class=\"clear\"><\/div>\n<div class=\"avgparsys wrapperParsys\">\n<div class=\"avgimage section\">\n<div><img decoding=\"async\" title=\"\" src=\"http:\/\/www.avg.com\/content\/dam\/feature-icons\/feature-icon-with-arrows-in-circle-representing-restore-101x101.png\" alt=\"\" \/><\/div>\n<\/div>\n<div class=\"textComponent section\">\n<div>\n<h2><span class=\"ez-toc-section\" id=\"Will_restoring_from_a_backup_help\"><\/span>Will restoring from a backup help?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Superfish has been pre-installed by Lenovo. Therefore, restoring your computer to factory condition from either a backup partition or a backup DVD will not solve the problem if Superfish is also part of your backup. Superfish would only be reinstalled, too.<\/p>\n<p>So if you ever use a backup to restore your system, you may need to again remove Superfish and its root security certificate from your system.<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>SOURCE: http:\/\/www.avg.com\/campaign-landing-pages\/ww-en\/lenovo-superfish Based on the information on that link you should remove this software immediately if you own a Lenovo PC. Something to note &#8211; Lenovo and IBM are not the same company. IBM sold their PC business to Lenovo some time ago. A copy of the information from the AVG website is below for &hellip; <a href=\"https:\/\/carlosthomas.net\/blog\/2015\/03\/alert-superfish-on-lenovo\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">ALERT &#8211; Superfish On Lenovo<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"pagelayer_contact_templates":[],"_pagelayer_content":"","_eb_attr":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1],"tags":[],"class_list":["post-96","post","type-post","status-publish","format-standard","hentry","category-info"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4XHmQ-1y","_links":{"self":[{"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/posts\/96","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/comments?post=96"}],"version-history":[{"count":3,"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/posts\/96\/revisions"}],"predecessor-version":[{"id":99,"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/posts\/96\/revisions\/99"}],"wp:attachment":[{"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/media?parent=96"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/categories?post=96"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/carlosthomas.net\/blog\/wp-json\/wp\/v2\/tags?post=96"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}