Kaspersky Security Update

Superfish Adware Preinstalled on Lenovo Laptops

On February 19th of 2015, it became known that Lenovo's laptops had been shipped with an adware called Superfish preinstalled. There are two major problems with this issue.

The first one, being that the hardware maker had been shipping consumer laptops with an adware preinstalled for several months — starting in September 2014 up until February 2015.

Another problem is related to how Superfish behaves. Its ability to produce self-signed certificates possibly allows a malicious third person to intercept SSL/TLS connections or, to put it simply, web browser sessions to "https" links.

 

Remedy:

Users of Lenovo laptops with Superfish are strongly encouraged to delete both a software named "Superfish Inc. Visual Discovery" (from Windows Control Panel) and Superfish's certificate (from the list of Trusted Root Certification Authorities).

Kaspersky products can help you indentify if your laptop is affected. It can detect the adware as Not-a-virus:AdWare.Win32.Superfish.b.

Lenovo is also offering the Automatic Removal Tool for Superfish in their Security Advisory