Lenovo to Stop Pre-Installing 'Adware' on Consumer PCs

Advertisement
By Reuters | Updated: 21 February 2015 12:25 IST

China's Lenovo Group Ltd, the world's largest PC maker, said on Thursday it will no longer pre-install software that cybersecurity experts said was malicious and made devices vulnerable to hacking.

Lenovo had come under fire from security researchers who said earlier on Thursday the company pre-installed a virus-like software from a company called Superfish on consumer laptops that hijacked web connections and allowed them to be spied upon.

Users reported as early as last June that a programme, also called Superfish, was 'adware', or software that automatically displays adverts.

Advertisement

Superfish will no longer be pre-installed and has been disabled on all products in the market since January, when Lenovo also stopped pre-installing the software, said a Lenovo spokesman in an email to Reuters on Thursday. Superfish was included on some consumer notebooks shipped between October and December, he said.

Advertisement

"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns," the spokesman said. Superfish "does not profile nor monitor user behaviour. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted... The relationship with Superfish is not financially significant."

On Friday, the Lenovo United States Twitter handle provided instructions on how to remove the Superfish software and root certificate, guiding users to its support forums page.

Advertisement

Robert Graham, CEO of U.S.-based security research firm Errata Security, said Superfish was malicious software that hijacks and throws open encrypted connections, paving the way for hackers to also commandeer these connections and eavesdrop, in what is known as a man-in-the-middle attack.

"This hurts (Lenovo's) reputation," Graham told Reuters. "It demonstrates the deep flaw that the company neither knows nor cares what it bundles on their laptops."

Advertisement

Graham and other experts said Lenovo was negligent, and that computers could still be vulnerable even after uninstalling Superfish. The software throws open encryptions by giving itself authority to take over connections and declare them as trusted and secure, even when they are not.

Graham added that Lenovo's method of removing the root certificate doesn't do so for users utilising the Firefox browser, and provides instructions on how to do it: " For Firefox, click on the main menu "Options", "Advanced", "Certificates". The Certificate Manager pops up. Scroll down, select "Superfish, Inc.", then "Delete or Detrust"."

"The way the Superfish functionality appears to work means that they must be intercepting traffic in order to insert the ads," said Eric Rand, a researcher at Brown Hat Security. "This amounts to a wiretap."

Concerns about cybersecurity have dogged Chinese firms, including telecoms equipment maker Huawei Technologies Ltdn over ties to China's government and smartphone maker Xiaomi Inc over data privacy.

Lenovo commanded one-fifth of the global PC market in the third quarter of 2014, according to data research firm IDC. 

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Adware, Apps, Laptops, Lenovo, PC, Superfish
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  2. Motorola Edge 70 Fusion India Launch Teased; Might Launch With This Chip
  3. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  4. Realme P4 Lite With 6,300mAh Battery Launched at This Price in India
  5. Here's When Xiaomi Will Launch the Xiaomi 17 and Xiaomi 17 Ultra Globally
  6. Tipster Leaks Details of the Oppo Find X9 Ultra, Vivo X300 Ultra Cameras
  1. Google Pixel Call Recording Reportedly Available in Additional Regions Ahead of Global Expansion
  2. Oppo Find X9 Ultra, Vivo X300 Ultra Leak: Tipster Shares Details of Anticipated 200-Megapixel Cameras
  3. Redmi A7 Could Launch Soon as Handset Bags Thailand’s NBTC Certification
  4. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  5. Hello Bachhon OTT Release Date: When and Where to Watch Vineet Kumar Singh Starrer Online?
  6. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  7. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  8. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
  9. Google Blocked 266 Million Risky App Installs, Prevented 1.75 Million Policy-Violating Apps in 2025
  10. Motorola Edge 70 Fusion India Launch Teased on Flipkart; Leaked Marketing Image Hints at Snapdragon 7s Gen 4 SoC
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.