Showing posts with label Lenovo Laptop. Show all posts
Showing posts with label Lenovo Laptop. Show all posts

Friday, 25 September 2015

Lenovo Again Accused Of Installing Dubious Software


Computer manufacturer Lenovo is again accused of installing dubious software on laptops. Previously, the company came under fire because the Superfish spyware bundled with laptops. Later it turned out that on some models a BIOS rootkit was installed to install the software on their own computers, even though Windows is installed from a clean DVD.

This time enables IT expert Michael Horowitz Lenovo tracking software to install so-called refurbished laptops. Horowitz had two such laptops purchased directly from IBM. The computers were provided with a clean installation of Windows 7 Professional. When analyzing the software on the computer expert saw that the program "Lenovo Customer Feedback Program 64" was performed daily.

According to the description of the program will send the data every day to Lenovo. In the configuration of the software he found a DLL file named Omniture, a company that deals with web analytics and online marketing. "While there appear no additional ads in the ThinkPads, there is something to monitor and track," said Horowitz. "On the one hand, it is surprising because the machines were refurbished and sold by IBM. On the other hand, it is in view of the past of Lenovo not at all surprising."

Lenovo has made ​​a separate page put on the software online. In it, the computer giant announced that Lenovo systems include programs that can communicate with servers on the Internet. It is non-personal and non-identifying information about using the Lenovo software are sent to the company. To avoid this, users with administrative privileges, the scheduled tasks of the Lenovo Customer Feedback Program off.

Wednesday, 12 August 2015

Lenovo BIOS Rootkit Installed On Laptops


Computer manufacturer Lenovo has a BIOS rootkit installed on many laptops, so that proprietary software was present on the system, even though Windows from a clean DVD reinstalled. This was reported by The Next Web by means of messages on the forum of Ars Technica and Hacker News .

A user discovered the rootkit in May when its new Lenovo laptop at every restart automatically writing a file system. Lenovo uses the Lenovo Service Engine, which downloads a program called OneKey Optimizer. The software should improve the performance of your computer and sends information about the system back to Lenovo. In the case of Windows 7 or 8 checks the BIOS of the laptop to the presence of a file called Autochk.exe, which then overwrites with its own version. Once the custom autochk file loads, two new files are created, which then additional files from the Internet.

In late July, there appeared an update to the Lenovo Service Engine. A vulnerability among other was discovered by the Dutch security researcher Roel Schouwenberg, would allow attackers to install via a malicious server malware on the system.The BIOS update was published for the Flex 2, Flex 3, G40-80 / G50-80 / G50-80 Touch / V3000, Yoga and several other models. Users need to install this update itself, as it is not automatically deployed.

Sunday, 31 May 2015

Advertising Company Superfish Closes Doors After Storm Of Criticism


Advertising company Superfish, early this year in the center was a storm of criticism, the doors closed.Superfish delivered to Lenovo a program that intercepted on all kinds of laptop models SSL connections to inject ads.

The adware used for this purpose its own root certificate. Researchers managed to crack the password using the private key of the Superfish certificate. This makes it possible in some cases to perform man-in-the-middle attacks against systems running Superfish and the certificate installed. Because of the incident Lenovo Superfish decided not to deliver laptops and offered a tool to remove. In addition, there were all kinds of lawsuits.

Co-founder Adi Pinhas has now decided to close Superfish and the company's technology through a new company, Visual Just to be used. Instead of injecting ads Visual works Just to smartphone apps that can recognize pictures and can search for similar images, without any text labels are required. According Pinhas was the move to this "visual search software" is already underway, but which was accelerated by all the criticism that erupted after the vulnerability.

That's not to say Just Visual nothing to do with the ads will have. The visual search engine is in fact focused on the search for specific objects by telephone. The search engine can then show ads of similar products. In addition, the company hopes to make money on licenses for the use of technology. Well Just Visual will follow industry standards for safety and privacy, as late as Chief Product Officer Keven Lee opposite the Associated Press know.

Wednesday, 29 April 2015

Lenovo Provides Free Recovery Media Without Superfish


Owners of a Lenovo laptop can now apply for recovery media to install Windows and additional software without even the Super Fish-adware is installed together, so has let the computer manufacturer on the private forum know. Super Fish is a program that intercepted SSL connections to inject ads. The adware used for this purpose its own root certificate. Researchers managed to crack the password using the private key of the Superfish certificate.

This makes it possible in certain cases to Man-in-the-middle attacks against systems that perform Superfish and the certificate installed. In total Superfish appeared on more than 40 different types of laptops to be installed. Because of the Superfish debacle Lenovo announced several measures. For example, published a removal tool and put the manufacturer's promise that it will provide cleaner machines with less pre-installed software in the future. Also followed a free subscription of six months on the McAfee virus scanner.

Current owners of a laptop sit with the problem on their recovery media, such as a special recovery partition, Superfish is still present. If the computer is reinstalled using the recovery media is also Superfish replaced. Last month, Lenovo's own forum know that they worked to restore clean media without Superfish which can be requested via the support department. An employee of Lenovo claims that the recovery media will not be sent in bulk. "But if you need due to specific circumstances recovery media, please contact the service desk." Whether the media via CD or USB stick will be offered the employee does not know. We have asked for clarification about Lenovo.

Tuesday, 10 March 2015

Lenovo Provides Customers With Superfish-Adware 6 Months McAfee


Customers of computer manufacturer Lenovo laptop with the Superfish-adware can receive from next week try a virus McAfee for a period of six months without charge, as the company has let know .Because of the Superfish debacle Lenovo announced several measures. Was published as a removal tool and put the manufacturer's promise that it will provide cleaner machines with less pre-installed software in the future.

In addition, the customers a free subscription offer of a half years at McAfee Live Safe. The security software can be used on multiple devices and to protect systems against malware and other online threats. Duped consumers can already download the trial version of the software, to activate it, then next week on 16 March. In case users the security itself already bought their existing subscription will be extended by six months.

In total, more than 40 different types of laptops that Superfish standard was installed qualify for the program. Super Fish is a program that intercepted SSL connections to inject ads. The adware used for this purpose its own root certificate.Researchers managed to crack the password using the private key of the Superfish certificate. This makes it possible in some cases to Man-in-the-middle attacks against systems that perform Superfish and the certificate installed.