Mostrando los resultados de 
Buscar en lugar de 
Querías decir 
Responder
Mensajes publicados: 2.226
Temas: 83
Kudos: 281
Soluciones: 142
Registrado: ‎05-01-2008
Location: MY
Mensaje 11 de 23 (6.137 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloader

[ Editado ]

Hi All,

 

We suspect the issue caused by the unusual extra code in html pages. However, we can not confirm yet but we are looking for a quick fix and iron out the root cause asap with server team now.

 

Users of Firefox and Chrome will be able to see the virus alert, however, IE users won't. Regardless of the type of browsers, like Mark has advised, please postpone downloads for a day or so to allow us time to fully investigate and take appropriate action.

 

FYI, it currently only impacts html files hosted on download.lenovo.com , and the general lenovo.com domain is unaffected. That means you can still look for info such as drivers EXE, PDF, warranty status, IWS, system service parts, etc.


Thanks to everyone here who reported the issue especially Mornsgrans’ sharing. He is right at the attacking website which may steal private information etc.


Sorry for any inconvenience caused and thanks, again.

 

Regards,

Cleo

 


T410, x240

Did someone help you today? Press the star on the left to thank them with a Kudo!
If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!

How to send a private message? --> Check out this article.


English Community   Deutsche Community   Comunidad en Español   Русскоязычное Сообщество
SCSI Port
Mensajes publicados: 37
Registrado: ‎06-13-2010
Location: Delhi(India)
Mensaje 12 de 23 (6.110 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloader

[ Editado ]

Too big picture converted to Link:


Warning Message in Chrome:

 

http://img138.imageshack.us/img138/9076/lenovok.jpg

Guru
Mensajes publicados: 1.407
Registrado: ‎05-29-2010
Location: SG
Mensaje 13 de 23 (6.023 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloader

Oh My God! I have downloaded the BIOS and flash it on 19 June, no wonder my laptop is experiencing some startup problem now.

 

http://forum.lenovo.com/t5/W-Series-ThinkPad-Laptops/W510-hangs-at-POST-randomly/td-p/242028

Guru
Mensajes publicados: 2.523
Registrado: ‎03-19-2009
Location: DE
Mensaje 14 de 23 (5.950 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloader

[ Editado ]

I've got the information - but not tested - that the server from which the trojan downloader gets fetched, is up again.

 

 

heise.de wrote:

 

Update:
There is now solid evidence that the dropper was the "Phoenix kit" and reloaded at the pest to the "Bredolab Trojan". 

Info about the trojan: http://www.malwaredomainlist.com/mdl.php?search=volgo-marun.cn&colsearch=All&quantity=50

 

Heise.de  also wrote that the iframe meanwhile has been removed but please wait until the moderators confirm it.

 

--------------------------------
My home-forum: http://www.thinkpad-forum.de
Wiki: Deutsches ThinkPad-Wiki English ThinkWiki
My ThinkPad-Collection
Coffee must be like women's eyes: deep black & shiny. ThinkPads have to be like men's feet: deep black & matte!
Mensajes publicados: 8.592
Temas: 428
Kudos: 1.600
Soluciones: 348
Registrado: ‎11-19-2007
Location: US
Mensaje 15 de 23 (5.706 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloaded

All,

 

Our e-support teams have been actively investigating and working to correct this issue.   An initial round of clean up has been completed, and a secondary re-validation is in progress to ensure all infected files have been remediated.

 

Investigation of the source of the infection is also underway, and I feel confident that preventative measures will be undertaken to prevent a similar future recurrence.

 

It may take up to 24 hours for our site to be fully reviewed and cleared by many of these 3rd party alerts.

 

We appreciate your patience as we work through this, and will provide further updates once the work is completed.

 

Best regards,

 

Mark

Guru
Mensajes publicados: 2.523
Registrado: ‎03-19-2009
Location: DE
Mensaje 16 de 23 (5.602 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloaded

[ Editado ]

I hope, that Lenovo will establish an internal emergency system over week-ends and banking holidays to prevent the distribution of malware in a similar case by turning off the infected server immediatelly.

 

I read the "experiences" of a german business man whos Thinkpad got infected by this trojan, so that he had to buy annother laptop for a very important presentation because he had no time to fix it.

--------------------------------
My home-forum: http://www.thinkpad-forum.de
Wiki: Deutsches ThinkPad-Wiki English ThinkWiki
My ThinkPad-Collection
Coffee must be like women's eyes: deep black & shiny. ThinkPads have to be like men's feet: deep black & matte!
Mensajes publicados: 1.605
Registrado: ‎05-01-2010
Location: US
Mensaje 17 de 23 (5.590 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloaded

[ Editado ]

Thank you for the update, Mark.

When the alert was first issued, I noticed that a few of the anti-virus and webpage scanners did not see this.

If anyone thinks that he may be having issues as a result of possibly downloading the malware in question, please feel free to post a diagnostic log at SpywareHammer or at one of the other help forums listed HERE. The security forums listed here are staffed by trained volunteers, and help is always free.

You will find instructions for posting the required logs at each forum. Please post at only one. It would be helpful to include a link to this topic or to the H-Security article.











English    Deutsche     Español     Português     Русскоязычное

If you find a post helpful and it answers your question, please click the "Accept As Solution" button.

I am not employed by Lenovo or Microsoft. I am a volunteer.

SpywareHammer





Punch Card
Mensajes publicados: 11
Registrado: ‎02-08-2010
Location: Vienna, Austria (EU)
Mensaje 18 de 23 (5.291 Visitas)

Re: Warning - Lenovo download-site is infected by trojan downloader

Please, I'd appreciate it if you edited the first post with clarifications, e.g.

 - current status

 - extent of infection (only webserver IFrames?)

 - available alternatives.

 

E.g. are users downloading drivers & updates through Thinkvantage System Update safe?

 

Thanks!

Mensajes publicados: 8.592
Temas: 428
Kudos: 1.600
Soluciones: 348
Registrado: ‎11-19-2007
Location: US
Mensaje 19 de 23 (5.280 Visitas)

Support Site Cleared - Malware Free

[ Editado ]

All,

 

The site has been confirmed cleared of Malware, and Google has rescanned and cleared the ban / warnings.

 

You should be able to access the site with confidence now.    If you accessed the download section between late 6/18/2010 and 6/21/2010, I would recommend that you run an antivirus scan on your system.  I would also suggest ensuring that the AV that you are using is up to date.

 

Additional updates to follow.

 

Mark

Token Ring
Mensajes publicados: 219
Registrado: ‎10-18-2008
Location: Amsterdam
Mensaje 20 de 23 (5.261 Visitas)

Re: Support Site Cleared - Malware Free

Hi Mark,

 

So far, I've not seen a message from Lenovo on its website (in particular not in the support section) that informs about the incident. Or if there is a message, then it's not very prominent. Wouldn't it be good if there were such a notice?

Miembros con mas kudos recibidos
Usuario Recuento de kudos
1
1
1