Lenovo Slipped Superfish Malware Into Laptops (Windows 8.1)

Lenovo Slipped Superfish Malware Into Laptops (Windows 8.1)

If you have missed the security furor over Lenovo pre-installing adware (antispyware catagory of antimalware products) you may want to check out these news links for information, degree of danger, and most importantly removal instructions (easy).

It is absolutely recommended to remove this immediately by all. Lenovo has been caught and publicly apologized. Just about all new computers come with what they used to call “bloatware” which is a handful of extra softwares which some may find useful. They take up space and may even slow down performance. But this is a big no-no Lenovo has done. It became as infamous as the Sony Rootkit malware they bundled in downloads, of music I believe it was, a good while ago.

A snippet…. (Removal help/instructions below)

“…The furor blew up because Lenovo installed Superfish adware on consumer laptops sold between September 2014 and January 2015. All these laptops were running Microsoft Windows 8.1. Your laptop fits the time frame, but you may have escaped for two reasons. First, Superfish was not installed on Lenovo’s business machines, such as ThinkPads. Second, it was not installed on laptops running Windows 7, which is still the business standard…..”
SOURCE: http://www.theguardian.com/technology/2015/feb/26/how-can-i-find-and-remove-superfish-and-similar-malware


US-CERT: Lenovo Superfish Adware Vulnerable to HTTPS Spoofing

Lenovo Slipped ‘Superfish’ Malware Into Laptops
LenovoComputer maker Lenovo has been shipping laptops prepackaged with malware that makes you more vulnerable to hackers — all for the sake …

Lenovo computers come with pre-installed adware and MITM proxy
Posted on Feb 19, 2015 10:45 am
If you have recently bought a new Lenovo computer, you’re in for a nasty surprise: the company has been shipping them with pre-installed adware. And, what’s even worse, the software in question is…
Read in browser »

Lenovo apologises for preinstalling malware on its PCs that can snoop on
its customers’ bank …
The preinstalled malware, known as Superfish, intercepts and decrypts
secured HTTPS connections, which are used to send sensitive information …

US cyber-cops declare WAR on Superfish ad-spewing malware lurking in Lenovo laptops
The Register
The US government’s Computer Emergency Readiness Team (US-CERT) today said the Superfish ad-injecting malware installed by Lenovo on its …


Superfish Uninstall Instructions (Lenovo Website)
NOTE: Please download and run the Automatic Removal tool executable to ensure complete removal of Superfish and Certificates for all major browsers.

Superfish malware: how do you know if your computer is affected? And how do you get rid of it?
Belfast Telegraph
The Superfish malware that was revealed last week to have been installed onto Lenovo laptops could allow hackers to watch your internet activity and …

How to wipe Superfish adware and offending cert from your Lenovo laptop
Posted on Feb 20, 2015 12:38 pm
After the recent revelation that Lenovo has been shipping some of it laptops with pre-installed adware that’s also breaking the security of secure connections by using self-signed MITM SSL certificate…
Read in browser »

How to remove the dangerous Superfish adware preinstalled on Lenovo PCs
You can revoke that certificate manually, however. Here’s how, as told to PCWorld by Chris Boyd, a malware intelligence analyst at Malwarebytes. ….

Internet Explorer continual long running script error – malware or fix available ?

Internet Explorer continual long running script error – malware or fix available ?

This has been edited from an actual help question/answer I made here: Re: [Windows_Vista] in Internet explorer 9 http://tech.groups.yahoo.com/group/Windows_Vista/message/3879 Mon Apr 1, 2013 1:20 pm

The symptoms were that the user was getting the ‘long running script error’ (or similar) error messages at multiple websites – not just one….

One common cause can be this…..

Stack buffer overflow http://en.wikipedia.org/wiki/Stack_buffer_overflow From Wikipedia, the free encyclopedia

“In software, a stack buffer overflow (also known as stack smashing) occurs when a program writes to a memory address on the program’s call stack outside of the intended data structure; usually a fixed length buffer.[1][2] Stack buffer overflow bugs are caused when a program writes more data to a buffer located on the stack than there was actually allocated for that buffer. This almost always results in corruption of adjacent data on the stack, and in cases where the overflow was triggered by mistake, will often cause the program to crash or operate incorrectly. This type of overflow is part of the more general class of programming bugs known as buffer overflows.[1]…..” FULL http://en.wikipedia.org/wiki/Stack_buffer_overflow

That is somewhat to the opposite what a crafted malware can do – flooding, injecting lengthy nonsense to the point it starts overwriting in the memory and overtakes or destroys, whatever the malicious intent.

INFO LINKS Error message: “A script on this page is causing Internet Explorer to … http://support.microsoft.com/kb/175500 Some tests and benchmarks may use scripts that take a long time to run and may want to increase the amount of time before the message box appears.

How to troubleshoot script errors in Internet Explorer http://support.microsoft.com/kb/308260 Describes how to troubleshoot the following script error: “Problems with this Web … FIX: You may receive a script error when you try to run a script on a computer …

There are many types of scripts for various content on a website. There is also like Java script. Check out this simple short information…. How is JavaScript different from Java? http://www.java.com/en/download/faq/java_javascript.xml

Since you are saying the symptoms are “dang near every page” – it seems this certainly is not just some bug at any website that has some new content they uploaded but was flawed in language causing a bug or two and they were not aware of it yet to fix it. So, to me, it seems it leans toward the internet connected browser – Internet Explorer.

Many times you get that message and there also would be a pop up to click to “Stop the script” and end of story, you go on with what you were doing. Apparently this is not happening.

QUICK FIX….. For a quick fix you can use the “magic” in Internet Explorer many users are unaware of. Lots of Firefox users say they like it more because it does not allow Active X to run and you an install plug ins to stop scripts from running at every website and give temporary permission etc etc etc. Seems to run faster. (You can click not to allow Active X to run in IE too) THAT is very messy and not necessary in Internet Explorer. You simply shove the Security setting all the way to HIGH…..

So that you do not encounter the error first change your Homepage in IE (Internet Explorer nic) to a known good site (you can change back later anytime). A good fast loader is Google.com (white page, not full of graphics etc). GO TO…. Start > Control Panel > click Classic View ( upper left) > Internet Options > panel opens and change the Homepage to http://www.google.com/ ….. click > Apply

NEXT click the Security Tab in the same panel, Internet Options. It is probably at Default settings – ‘Medium High’. If it says “Custom” then first click Default and Apply. NOW slide that Settings bar all the way up to “High” and click Apply / OK  / close the Internet Options panel.

Okay, open Internet Explorer and you are now going to experience Internet Explorer running even safer and faster than the similar Firefox set up without having to click nothing for each individual site. HIGH Security settings in Internet Explorer stops all kinds of website add ons and scripts and java and auto runs and embedded players and on and on and on. It stops all the crap kind of like Plain Text email does. This setting should stop whatever was running and try going to a few familiar sites to see how it performs. (Don’t forget after all said and done to click Default again in Internet Options IE for normal browsing).

NEXT if IE is browsing okay I would absolutely want to run a good scan with a quality antimalware program. I am assuming you probably have one installed as a veteran Windows user. There is possibly a malware that is failing in attempt to rifle the Internet Explorer browser – hijack it – but is a flawed malware and can not execute properly for its nefarious intents.

A common attack at rigged websites is…..

Cross-site scripting Wikipedia, the free encyclopedia http://en.wikipedia.org/wiki/Cross-site_scripting Cross-site scripting (XSS) is a type of computer security vulnerability typically found in Web applications. XSS enables attackers to inject client-side script into …

….BUT again you are saying it is not an individual website but is occurring everywhere. So if there is no malware present – ruled out by full scan by quality amtimalware as Symantec, Trend Micro, Emsisoft, Bit Defender, NOD32 etc etc – I would move to a more advanced solution.



Most users are oblivious to Java exploits and zero days in security news. This is a REAL worldwide event and many entities are completely disabling Java. As recommended and as I do ( I am in pc security since 2005 anyway) – I uninstalled Java from my computers and have disabled ALL Java plug ins in ALL browsers.

READ UP  / Seeing is believing…. (my security blog)   Catch Up With Java Malware Information March 3, 2013 — bluecollarpc https://bluecollarpcwebs.wordpress.com/2013/03/03/catch-up-with-java-malware-information/

You can now see the horrific extent and nightmarish ongoing continual cyber crime attacks to circumvent Java and security to take over computers worldwide. I don’t remember ANY such event in this magnitude since I have been online from 1999. For users unaware, the only possible defense was quality Real Time Protection antimalware. Additionally, this does not apply in your case – the recent Internet Explorer Zero Day….

US-CERT – Microsoft Releases Security Advisory for Internet Explorer http://tech.groups.yahoo.com/group/BlueCollarPCSecurity/message/2539 Microsoft has released Security Advisory 2794220 to address a vulnerability in Microsoft Internet Explorer 6, 7, and 8.

RECAP…. (my advice) ….

# Regain control of navigation of the system by placing Internet Explorer in ultimate High Security Settings. Note, Internet Explorer is not a separate software but is part of the Windows OS (operating system) – Unix Certified.

# Perform a complete full scan of the system and files with a quality antimalware product and have installed same with Real Time Protection activated. Quarantine any malware found, should be automatic. Try installing ….. / run it…. (clean scan will also rule out botnet activity) BitDefender Launches Free 60-Second Virus Scanner http://www.bitdefender.com/solutions/60-second-virus-scanner.html

# Restart the computer and perform a quick scan by quality antimalware program without internet connection.

# Uninstall Java from the computer at Control Panel > Programs/Features. (Optional, I would). As well, disable Java in ALL browsers in their Tools/Settings.

# Clean ? Connect to the internet and run Windows Updates and apply ALL security and Important Updates.

# Upgrade ALL browsers to their latest versions. Firefox > Click About Firefox… will scan instantly to see if latest version is installed. Same/similar in Google Chrome browser, others. (Little known fact, Opera and Firefox along with a handful of other softwares received the ultimate disgrace as being rated “Riskware” in 2009 or 2010 by respected institutes worldwide ! )

# If still experiencing trouble, I would reconsider an informed choice as to “quality” antimalware. Many users believe hype and paid advertising good reviews by like magazine type destinations rather than the real world truth from independent labs and word of mouth from experienced advanced users. For instance, you may have heard raves over free MalwareBytes. This product has not even achieved the simplest certifications yet…..

VB100 Award = Perfect scores ! (Top AntiVirus World Prize) http://www.virusbtn.com/vb100/index http://en.wikipedia.org/wiki/Virus_Bulletin

West Coast Labs http://www.westcoastlabs.org/

AV-Test.org http://www.av-test.org/

Malware Research Group http://malwareresearchgroup.com/

Welcome to the independent and renowned ProtectStar Test Lab http://www.protectstar-testlab.org/

Welcome to AV-Comparatives.org http://www.av-comparatives.org/


HiJackFree (Genuine Freeware) [wrkx w/ Netbooks] Freeware! HiJackFree helps advanced users to detect and remove Malware manually. With HiJackFree you can manage all active processes, services, drivers, autoruns, open ports, hosts file entries and many more. For your full control over your system. http://www.hijackfree.com/en/

Alternatively you may want to install…. HiJackThis http://sourceforge.net/projects/hjt Description. HijackThis is a free utility that generates an in depth report of registry and file settings from your computer. HijackThis – Wikipedia, the free encyclopedia http://en.wikipedia.org/wiki/Hijackthis HijackThis (also HiJackThis or HJT) is an open source enumerating tool for Microsoft Windows originally created by Merijn Bellekom, and later sold to Trend Micro. ….. and post the HiJackThis Log for analysis. IN THESE DIAGNOSTICS DO NOT CLICK “FIX” ANYWHERE ! Generally for advanced use or may render software or even Windows itself inoperable with a wrong removal or fix !

# Last resort, if this continues as mentioned, I would have to consider reinstalling Windows and bring ALL things up to speed security-wise as mentioned…. Run Windows Updates apply all, upgrade all browsers, uninstall Java and disable Java plug ins in all browsers, install quality antimalware with Real Time Protection enabled.

— Gerald309-> (for reference) HOME: https://sites.google.com/site/pcsecurityhelper/ (webmaster bluecollarpc.us, down for the moment)

Additional Follow Up (these are just my opinions, suggestions I am no expert LOL) http://tech.groups.yahoo.com/group/Windows_Vista/message/3880

In the one Microsoft Information/Help link, Microsoft suggests diminshing the time out time so that in these events it would not seem to be an endless looping hung application or frozen scenario or crashing abrubtly intermittingly.

To do this, they give the Windows Registry keys to edit or insert – writing into the Windows Registry. …..jv16 PowerTools http://www.macecraft.com/ and http://en.wikipedia.org/wiki/Jv16_powertools is about best in world for well over 10 years. The free version (registry clean up) does not have the registry write in / modification features. You can do this manually but the paid version just makes it easier to do. Apparently, Microsoft is instructing to cut short the time-out to avoid the hung application scenario (meaning the browser in this case) or frozen browser. Apparently the fix will cut short the script etc running and then with in seconds or whatever the browser is normal again without these running. The FIX there is for versions 8 down though.

In other words look at…. “Let me fix it myself” http://support.microsoft.com/kb/175500

This would be a high tech solution as the average user has never even opened the Windows Registry or even know that user access exists. Of course this is where all the warnings come in to “NEVER touch anything in the Windows Registry unless you know what you are doing or you may damage Windows and/or other softwares. ”

I am not suggesting you alter your registry. I am offering the information to read between the lines as to what the problem actually is. Then to go from there in any possible solution as easy as possible.


Internet Timeout Virus http://www.ehow.com/facts_7559067_internet-timeout-virus.html


“Timeout Virus Sends Different Messages Web Scanners Bundled with certain Anti-Virus Packages can cause Time out

The Internet Time Out Virus sends out varying messages. Some include:”A Run time error has occurred. Do you want to debug? Line 34 Error: Permission denied” or “Runtime Error! Program:E\Program Files\Internet Explorer\iexplore.exe. This application has requested the Runtime to terminate it in an unusual way”. Microsoft Support offers a fix for this you can download. Some Causes Viruses are a fact of life online.

A family of programs called Vundo Trojan can cause some Web browsers to have problems loading certain high traffic sites such as search engines and social media. It spreads through network drives and uses different methods to reside on your computer. It is not easy to detect. Firewalls Selectively block Internet Access Run a full system spyware scan daily.

Sometime the problem occurs because a timeout limit to return data has been imposed on the server by your Web browser. The default timeout limit could be five minutes to 60 minutes. In case of server problems, the browser will keep waiting. A solution is to reset or change the default time out setting. Incorrect firewall settings may also give a timeout message.”


I added this to maybe help identify what I suggested as problems and how to fix easily.

The bottom line here would be that reinstalling Windows is such the overkill and unnecessary if a simple registry edit was the cure. I am going to look for this for IE version 9 to see if they posted a fix.

Addditionally if you want to skim over some Windows Registry information help to get a little familiar to what is being said you can look at a help page I have \up here form my web (Google Sites) https://sites.google.com/site/pcsecurityhelper/windows-registry-help

I would just review things mentioned in the several help answers and wait a little for maybe more and keep posting, hang in there to get it fixed.

gerald philly pa usa Home https://sites.google.com/site/pcsecurityhelper/PCSecurityHelper

PS….TIP: If you move towards editing the registry, a paid software with registry Back Up features is not necessary. Simply open the Windows Registry and click Export and then Save to like My Documents with any File name you want to give it like “Registry Back Up Jan 2013” example.

Click Start > Run > type in “regedit” without the parenthesis > click OK > … the Windows Registry Opens…. > click File > Export

Note that this takes about 10 to 20 seconds to complete before ready to save it as a file. NOW if there has be any mistake made then you simply close everything running (browsers, email, software program, etc etc) and Go To the back up file you saved in like My Documents. YOU SIMPLY DOUBLE CLICK THE BACK UP FILE AND WINDOWS REGISTRY REINSTALLS TO THAT SAVED FILE WHEN IT WAS WORKING. It will over write the entire registry and write in the registry as it was saved. Of course you do not do other things as install new softwares, Windows Updates, etc in between time while working on the registry. You do your fix task and confirm it is okay by navigating the pc a bit and maybe open afew softwares one at at time and close them. things working ? try a reboot and try again to confirm the registry edit is okay and everything is working.

The reinstallation of the Windows Registry is like System Restore. The System Restore Point is a snaphot of the entire system at that instant. Same thing in the Windows Registry back up file. It can only rewrite that “snapshot’ in time of what was in it. If you were to make changes (as installations and updates/upgrades) before checking the edit was okay – then these new registry keys from the changes would NOT be in the back up and would not then work no doubt until uninstalled and reinstalled if possible. A manual uninstall may be necessary of these as would be “corrupted” due to missing registry keys and entries.

CLEAN UP TIPS……. http://tech.groups.yahoo.com/group/Windows_Vista/message/3881?l=1

As Microsoft mentioned to clean up Temporary Internet Files, the easiest wy to do this is with a very popular safe durable software called CCleaner (nic crap cleaner) used by millions and millions of Windows users. It is Genuine Freeware meaning NO ads, ad pop ups, etc etc.

CCleaner http://www.ccleaner.com/ http://en.wikipedia.org/wiki/CCleaner

Here is the normal settings used in it for entire safe clean up of junk temporary internte files etc….

Recommended Settings and use of CCleaner – Temporary Internet Files Clean Up Browsers, Applications January 14, 2012 — bluecollarpc https://bluecollarpcwebs.wordpress.com/2012/01/14/recommended-settings-and-use-of-ccleaner-temparary-internet-files-clean-up-browsers-applications/

NOTE it is recommended NOT to keep any cookies stored on the PC as malware now can break into a PC and take it over through stored cookies. This was happening at Facebook users. SEE:

Delete ALL cookies ALL the time EVERY time Facebook malware reminds us December 27, 2011 — bluecollarpc https://bluecollarpcwebs.wordpress.com/2011/12/27/236/

TIP: You rarely hear about cleaning up Java temporary files. Malware tries to reside and hide here from detection and removal. You can achieve this by opening the Java Panel…..

Start > Control Panel > Java …. double click the Java panel icon to open it.

In settings there, go to the Temporary Files and click delete all. This affects nothing and is safe to perform anytime. There can be age old files there and a mini malware payload. It is better to even choose “Do Not Store Java Temporary Files On This Computer”. This blocks Java based malware from executing a payload from these files. This is a safe setting or they would not offer it. May slow navigation a nanon second if that. I did this 5 years ago or more before actually uninstalling Java due to current ongoing crisis with it.

gerald philly pa usa https://sites.google.com/site/pcsecurityhelper

%d bloggers like this: