The bloatware problem is not only still present on modern computers, but it has become much more "sneaky", so to speak. A large number of users took to Lenovo's official forums to report the activities of Superfish, a preinstalled software on their computers that not only injects advertisements into browsing sessions, but does so using fake HTTPS certificates, a resource that places it in the category of malware.
The discussion about Superfish began to gain momentum a few months ago. In essence, any Lenovo computer purchased in the second half of 2014 likely has Superfish preinstalled. Superfish's main function is to inject advertisements, analyzing images and offers on each page to show the user something supposedly better. The injection of ads by itself is a concerning action, as it can generate different security issues and/or "break" the loading of the page in question.
Last January, Lenovo confirmed that Superfish's server system had been deactivated, and that its installation would be temporarily suspended until the sharp edges of the adware are corrected. However, Superfish will no longer be present on future Lenovo computers. Superfish may aim to increase the company's earnings per computer, but its method clearly fits under the description of malware.
A Serious Security Risk
Why? Because Superfish works with a fake HTTPS certificate, which allows it to intercept data on secure connections and sites. This is the definition of "man-in-the-middle", and one of the biggest security risks a user can be exposed to. Superfish was caught red-handed, delivering "secure certificates" to portals like Bank of America, Nordea Bank, and even Google itself, when that role belongs to a trusted entity, such as VeriSign. Lenovo's first official response was nothing short of lamentable, stating that they found "no evidence" to support doubts about Superfish's security.
We are talking about a fake HTTPS certificate that uses the same private key on "all" Lenovo computers where it was installed. If someone with malicious intentions were to discover that private key, they would have a real feast. Well... guess what? The private key of Superfish was cracked. It is "komodia", the name of a company that among other things offers an "SSL decoder". Apparently, Komodia's technology is available in several products, so there is a possibility that the fake certificates are not exclusive to Superfish.
Removing Superfish
Lenovo has stated that computers with Superfish preinstalled hit the market between October and December 2014, but there are also reports from September, so it is recommended that any user of a Lenovo system acquired in the second half of 2014 perform the necessary checks. The first step to eliminate Superfish is its formal uninstallation through "Programs and Features" in the Control Panel, and the second is the manual purge of the certificate. This requires going to the "Content" tab within "Internet Options", clicking "Certificates", going to the "Trusted Root Certification Authorities" tab, selecting and deleting all entries that reference Superfish Inc. The process must be repeated for precaution in the other browsers, including Firefox and Chrome. The nuclear option is a complete reinstallation of the operating system, without using the factory restore, because those emergency images have Superfish inside.
Lenovo's CTO, Peter Hortensius, confirmed that the company will release in the coming days a dedicated tool for the complete elimination of Superfish. Meanwhile, if you want to check the presence of Superfish on your system, you can click this link.