* Posts by Panum

2 publicly visible posts • joined 5 Mar 2015

Superfish: Lenovo ditches adware, but that doesn't fix SSL megavuln – researcher

Panum

Re: Removing it

I had to take my business laptop to a security expert. He told me it was a rather difficult task to remove all the convoluted crap Lenovo thoughtfully installed on my machine. (He likes this kind of stuff)

I am fortunate he is a friend and it didn't cost me much. There was re-spawning code hidden in innocuous looking sections of the root directory.

I will NEVER buy a Lenovo again.

$250K: That's what Lenovo earned to rat you out with Superfish

Panum

Re: Heads will roll?

I think Lenovo's involvement goes deeper. I custom ordered a new Think Pad laptop for my business. When I received it in the mail, it came with software installation CD's yet no CD/DVD player, and the software not installed. My bad for not realizing this configuration, I just assumed all laptops had DVD players. I called customer service to complain about the not so obvious omission and was told "No problem, I'll pass you over to our tech department and they will install the software remotely." So I did the dumb thing being trusting and all and gave their "tech" remote access. The first thing the "tech" did was scan the computer and tell me that I had all kinds of malware and spyware on the laptop and offer to remove it for a fee. I informed them that they were the literal first person to have any access to the computer, so if there was crap on the computer, they must have installed it themselves.

In the ensuing conversation I got rather angry by the obvious obfuscation and attempts to convince me to sign up for regular 'virus removal services'. I tried to end the conversation and the "tech" kept hijacking the cursor so I could not end the session. I had to pull the power on the machine to break the techs control. Turns out the Lenovo "tech" was an outside company, not Lenovo at all.

I will never buy a Lenovo again.