Saturday, February 28, 2015

The Superfish Trojan, Lenovo "recall", and the AVG warning

I use AVG as one of my spyware tools.  "It" popped a warning that the "Superfish Trojan" might need to be removed from my computer.  I heard from others who have had the same thing happen.  When it occurred I was suspicious- could this be ransomware?  It turns out that, at least in my case, it wasn't.  But the way it occurred makes it a target for reengineering:  ransomware could easily spoof that warning.

So, the rest of the story is that the Superfish Trojan does exist and worse, Lenovo installed it on its computers as part of the ship image.  How bad is that!  They felt it was helpful in some way plus they made a little money from the developer.

Oh, don't try to reinstall your operating system- since it was shipped with the computer, going back to the original will only reinstall it.

Now I'm stuck with a problem.  If I start giving links, where you might be suspicious about where those links would go.  One of my former IBM friends called me to task for warning about links and then giving links to information.  So, for this blog entry, let me give you an web link without the underlying hyperlink.  Go there for an explanation of the issue and how to remove Superfish:  http://www.cnet.com/news/lenovos-superfish-screwup-highlights-biggest-problem-in-software/.   Copy this link into your address bar.

Lenovo offers a removal tool.  Go to this web page:

 http://support.lenovo.com/en/product_security/superfish 

What's next?!

No comments:

Post a Comment

Printfriendly

Print Friendly and PDF