{"id":6107,"date":"2016-06-17T12:19:55","date_gmt":"2016-06-17T12:19:55","guid":{"rendered":"http:\/\/www.macecraft.com\/?p=6107"},"modified":"2024-07-23T06:48:33","modified_gmt":"2024-07-23T06:48:33","slug":"lenovo-bloatware-haunts-oem-laptops","status":"publish","type":"post","link":"https:\/\/jv16powertools.com\/blog\/lenovo-bloatware-haunts-oem-laptops\/","title":{"rendered":"Lenovo Bloatware Haunts OEM Laptops"},"content":{"rendered":"<p>You might be at risk if you are using a brand computer and you haven&#8217;t uninstalled all the software that came already preinstalled on it, such as Lenovo bloatware. Not only can the preinstalled software slow down your computer,\u00a0but\u00a0it can also allow unauthorized access to your private data.<\/p>\n<h2>A security analysis of OEM updaters<\/h2>\n<p>Earlier this month, Lenovo issued a security advisory that advised\u00a0users to uninstall the <strong>Accelerator Application<\/strong> because of its insecure update mechanism. This discovery was\u00a0the result of research completed\u00a0by security company Duo Labs, which is responsible\u00a0for reporting this vulnerability.<\/p>\n<p>The same security research firm published a paper in 2015 entitled &#8220;<a href=\"\/\/duo.com\/assets\/pdf\/Dude,_You_Got_Dell_d.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Dude, You Got Dell\u2019d &#8211; Publishing Your Privates<\/a>&#8221; which\u00a0led to the discovery of potential man-in-the-middle attacks against Dell laptop computers shipped with insecure security certificates. For example, in\u00a0a real world scenario, if a user was using their <strong>Dell Inspiron 14<\/strong> laptop at a coffee shop, an attacker sitting in\u00a0the shop and utilizing the same Wi-Fi network could <strong>potentially intercept all <\/strong>of the\u00a0user&#8217;s<strong>\u00a0encrypted traffic<\/strong>, including sensitive data like bank passwords, emails, etc.<\/p>\n<p>This time, they took it a step further and tested OEM updaters for preinstalled software on 10 different laptop systems shipped with an out-of-box configuration, after any pending updates were applied. They also published the basic features from some of the updaters:<\/p>\n<h2><img loading=\"lazy\" decoding=\"async\" data-lity class=\"aligncenter wp-image-6123 size-full\" src=\"https:\/\/jv16powertools.com\/wordpress\/wp-content\/uploads\/2016\/06\/lenovo-bloatware-out-of-box-exploitation.jpg\" alt=\"lenovo bloatware OEM features\" width=\"576\" height=\"502\" srcset=\"https:\/\/jv16powertools.com\/blog\/wp-content\/uploads\/2016\/06\/lenovo-bloatware-out-of-box-exploitation.jpg 576w, https:\/\/jv16powertools.com\/blog\/wp-content\/uploads\/2016\/06\/lenovo-bloatware-out-of-box-exploitation-300x261.jpg 300w\" sizes=\"auto, (max-width: 576px) 100vw, 576px\" \/><\/h2>\n<p>While focusing on potential <a href=\"\/\/en.wikipedia.org\/wiki\/Man-in-the-middle_attack\" target=\"_blank\" rel=\"noopener noreferrer\">man-in-the-middle attacks<\/a>, which are considered to be the simplest and most common cyber attack methods, it was concluded that <strong>every vendor shipped with a vulnerable preinstalled updater<\/strong> that could allow for a complete compromise of the affected machine. High severity security holes were identified in preinstalled software shipped with laptops from the following manufacturers: Acer, Asus, Dell, Hewlett-Packard, and Lenovo.<\/p>\n<h2>Lenovo bloatware vulnerability: High severity<\/h2>\n<p>The most distressing of all have been the vulnerabilities discovered in Lenovo&#8217;s UpdateAgent, which &#8220;provides no security features whatsoever,&#8221;\u00a0according to researchers at Duo Labs. The Application Programmable Interface (API) calls made by Lenovo&#8217;s UpdateAgent can be intercepted and modified in order to obtain the necessary conditions for remote code execution by an attacker with local network access.<\/p>\n<p>Exploitation of this vulnerability may allow a remote attacker to take control of an affected system. As a result, it is recommended that users <strong>uninstall Lenovo UpdateAgent from more than 110 notebook and desktop models<\/strong> running Windows 10 OS. For a complete list of the affected Lenovo notebooks and desktops, please read the <a href=\"\/\/support.lenovo.com\/ro\/en\/product_security\/len_6718\" target=\"_blank\" rel=\"noopener noreferrer\">security advisory<\/a>. According to Lenovo, the vulnerable Accelerator Application was never installed on ThinkPad or ThinkStation devices.<\/p>\n<h3>Notebook systems shipped with vulnerable Lenovo bloatware:<\/h3>\n<p>100\/100s\/110<br \/>\n305<br \/>\n700<br \/>\n300\/300S<br \/>\n310<br \/>\n500\/500S<br \/>\n700S<br \/>\nB40-30\/B40-45\/B40-45\/B40-80<br \/>\nB41-30\/B41-35\/B41-80<br \/>\nB50-10\/B50-30\/B50-30 Touch\/B50-45\/B50-50\/B50-80\/B51-30\/B51-35\/B51-80\/B70-80\/B71-80<br \/>\nE31-70\/E31-80\/E40-30\/E40-80\/E41-10\/E41-15\/E41-80\/E50-30\/E50-80\/E51-80<br \/>\nEdge 15<br \/>\nEdge 2-1580<br \/>\nErazer N40-30\/Erazer N40-45<br \/>\nErazer N50-45\/Erazer N50-45<br \/>\nErazer Z41-70<br \/>\nErazer Z51-70<br \/>\nFLEX 2 Pro<br \/>\nFLEX 3<br \/>\nFLEX 4<br \/>\nG40-45\/G40-80\/G40-80m<br \/>\nG41-35<br \/>\nG50\/G50-45\/G50-80\/G50-80m\/G50-80Touch<br \/>\nG51-35<br \/>\nG70-35\/G70-80<br \/>\nG50<br \/>\nK20-80<br \/>\nK21-80<br \/>\nK41-70\/K41-80<br \/>\nM41-70<br \/>\nM51-80<br \/>\nMIIX 3<br \/>\nMIIX 300\/MIIX310<br \/>\nMIIX 700<br \/>\nN22 Winbook<br \/>\nN41-35<br \/>\nN51-35<br \/>\nS21e-20<br \/>\nS41-35\/S41-70\/S41-75<br \/>\nTianYi 300<br \/>\nU31-70<br \/>\nU41-70<br \/>\nV4000<br \/>\nXiaoXin 700<br \/>\nXiaoXin Air 12<br \/>\nY50-70\/Y50-70 Touch<br \/>\nY50c<br \/>\nY700\/Y700 Touch<br \/>\nY70-70 Touch<br \/>\nY900<br \/>\nYoga 2<br \/>\nYOGA 3 14<br \/>\nYoga 3 Pro<br \/>\nYoga 300<br \/>\nYOGA 500\/YOGA 510<br \/>\nYOGA 700\/YOGA 710\/YOGA 900\/YOGA 900S<br \/>\nZ40-70\/Z40-75<br \/>\nZ50-70\/Z50-75<br \/>\nZ41-70<br \/>\nZ51-70<br \/>\nZ70-80<\/p>\n<h3>Desktop systems shipped with vulnerable Lenovo bloatware:<\/h3>\n<p>50050C\/50100E\/50550A\/50600I<br \/>\nA3300<br \/>\nA7300<br \/>\nA8150<br \/>\nB40<br \/>\nC20<br \/>\nC40<br \/>\nC50<br \/>\nC560<br \/>\nD3000<br \/>\nD5010\/ D5050\/ D5055<br \/>\nF5005\/ F5050\/ F5055<br \/>\nG5005\/ G5010\/ G5050\/ G5055<br \/>\nH3005<br \/>\nH30-50<br \/>\nH5005\/ H5055<br \/>\nH50-50<br \/>\nIdeaCentre 200<br \/>\nIdeaCentre 300\/300S<br \/>\nIdeaCentre 510\/510S<br \/>\nIdeaCentre 700<br \/>\nM7300z<br \/>\nM8300z\/M8350z<br \/>\nM9550z<br \/>\nYoga Home 500<\/p>\n<p>Found Lenovo bloatware on a laptop or desktop model not listed in the security advisory? <a href=\"\/\/macecraft.zendesk.com\/hc\/en-us\/requests\/new\" target=\"_blank\" rel=\"noopener noreferrer\">Open a support ticket<\/a> with our support team and we will be glad to assist you in determining if you should remove it or not.<\/p>\n<h2>What you should do to protect yourself<\/h2>\n<p>Based on the Lenovo Security Advisory: LEN-6718, there are three official ways to uninstall Lenovo Accelerator Application, as described here:<\/p>\n<ol>\n<li>In Lenovo System Update, click on \u201cGet new updates\u201d and follow the prompts to uninstall Lenovo Accelerator Application. This update will also run automatically if a user has not disabled the \u201cAutomatically download and install updates\u201d option.<\/li>\n<li>Download and run the <a href=\"\/\/support.lenovo.com\/us\/en\/olddownloads\/ds113158\" target=\"_blank\" rel=\"noopener noreferrer\">Lenovo Accelerator Application removal tool<\/a> available here. Using this verified\u00a0removal tool, you should be able to remove vulnerable Lenovo bloatware without leaving any software traces behind.<\/li>\n<li>Go to the \u201cApps and Features\u201d application in Windows 10, select Lenovo Accelerator Application and click on \u201cUninstall.&#8221;<\/li>\n<\/ol>\n<h2>Better bloatware-free than sorry<\/h2>\n<p>As was recently concluded in our own research &#8220;<a href=\"https:\/\/jv16powertools.com\/blog\/tests-determine-best-product-to-uninstall-quicktime\/\">Software Uninstaller Comparison<\/a> &#8211; How to fully remove QuickTime from Windows,&#8221; popular software does not always fully uninstall itself using its own uninstaller. After using the software&#8217;s\u00a0own uninstaller to remove the vulnerable QuickTime software, we have concluded that there were plenty of QuickTime software traces (<strong>more than 1500 different file system and registry elements<\/strong>) left behind in our test system.<\/p>\n<p>In some cases,\u00a0<strong>removing QuickTime using its own uninstaller left behind its registry entries as well as its executables<\/strong>. Most likely this leaves the computer vulnerable to the security issues identified in the software. Luckily, jv16 PowerTools is known for its improved ability to detect software leftovers.<\/p>\n<p>We recommend everyone to follow these steps to ensure the safety of their computer due to the possible security issues related with Lenovo bloatware:<\/p>\n<p>1. <a href=\"https:\/\/jv16powertools.com\/download\/\" target=\"_blank\" rel=\"noopener\">Download and install jv16 PowerTools<\/a><\/p>\n<p>2. Open jv16 PowerTools &#8211; <strong>Software Uninstaller<\/strong> and see if it finds Lenovo Accelerator Application in your system. Notice that it may be under Installed Software or under Possible Leftover Traces.<\/p>\n<p>3. If Lenovo Accelerator Application or its leftovers are found, allow jv16 PowerTools to remove them from your system.<\/p>\n<h2>Further tests yet to be performed<\/h2>\n<p>For analyzing QuickTime, the Windows 10 based tests were performed using a virtual computer running Windows 10 build 1511 (64 bit) with a base memory of 4096 MB (RAM), with two logical CPU cores and 50 GB of hard disk space. Windows updates were disabled for the test environment to ensure the system was not changed during the testing period.<\/p>\n<p>The Lenovo Accelerator Application (part of Lenovo QuickOptimizer program) is used to speed up the launch of Lenovo applications and it was installed in some notebook and desktop systems preloaded with Windows 10. Obviously, doing a similar test such as the one we did for QuickTime requires <strong>select Lenovo computers<\/strong>:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-lity class=\"aligncenter wp-image-6120 size-full\" src=\"https:\/\/jv16powertools.com\/wordpress\/wp-content\/uploads\/2016\/06\/lenovo-bloatware-quickoptimizer-info.png\" alt=\"lenovo bloatware quickoptimizer info\" width=\"499\" height=\"387\" srcset=\"https:\/\/jv16powertools.com\/blog\/wp-content\/uploads\/2016\/06\/lenovo-bloatware-quickoptimizer-info.png 499w, https:\/\/jv16powertools.com\/blog\/wp-content\/uploads\/2016\/06\/lenovo-bloatware-quickoptimizer-info-300x233.png 300w\" sizes=\"auto, (max-width: 499px) 100vw, 499px\" \/><\/p>\n<p>In a follow-up blog entry, our intention is to outline the test results for <strong>Lenovo IdeaPad 300<\/strong> (one of the affected systems) and find out if there are any software leftovers remaining on the system after Lenovo Accelerator Application has been uninstalled using its own uninstaller.<\/p>\n<h2>Lenovo bloatware\u00a0in summary<\/h2>\n<p>Learning more about Lenovo bloatware or other OEM bloatware existing in your system is easy with jv16 PowerTools as the Software Uninstaller tool and has been greatly improved to detect and remove software leftovers. <a href=\"https:\/\/jv16powertools.com\/download\/\">Download<\/a> our product and activate a free, fully functional 60-day trial license to clean and speed up your computer.<\/p>\n<p><em>Note: jv16 PowerTools X is a commercial software product. The above link will download the free trial version which can be fully used to uninstall Lenovo bloatware or other OEM bloatware residing in your system. There is no bundled software, no adware, no spyware, and no hidden surprises. Always backup your computer before using jv16 PowerTools or any other similar software.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You might be at risk if you are using a brand computer and you haven&#8217;t uninstalled all the software that came already preinstalled on it, such as Lenovo bloatware. Not only can the preinstalled software slow down your computer,\u00a0but\u00a0it can also allow unauthorized access to your private data. A security analysis of OEM updaters Earlier [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":34831,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[],"class_list":["post-6107","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/posts\/6107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/comments?post=6107"}],"version-history":[{"count":2,"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/posts\/6107\/revisions"}],"predecessor-version":[{"id":236091,"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/posts\/6107\/revisions\/236091"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/media\/34831"}],"wp:attachment":[{"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/media?parent=6107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/categories?post=6107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jv16powertools.com\/blog\/wp-json\/wp\/v2\/tags?post=6107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}