Microsoft updates Windows Defender, its onboard anti-virus software, to remove the Superfish software that was pre-installed on many Lenovo computers
Microsoft has updated Windows Defender to root out the Superfish bug — Microsoft just took a major step towards rooting out the Superfish bug …
Context & Ripple Effects
Lenovo had been under fire for shipping Superfish, an adware component that intercepts web traffic, pre-installed on consumer laptops — and for a response Wired called astonishingly clueless. Lenovo first tried to contain the damage with its own automatic Superfish removal tool, but that only reached users who ran it.
Microsoft's Windows Defender update changes the cleanup math: the antivirus already present on most Windows machines now strips Superfish without any action from Lenovo or its customers. By early March, Microsoft's malware removal tools had scrubbed Superfish from 250K Lenovo PCs — scale no vendor-issued uninstaller could match.
First-order effects
- Lenovo customers with Defender enabled get Superfish removed automatically, closing the gap left by Lenovo's opt-in tool.
- Superfish loses its installed base at platform-owner speed rather than OEM-cleanup speed, effectively ending the product's distribution on affected machines.
Second-order effects
- Other PC makers bundling traffic-intercepting or certificate-injecting software face a new risk model: their preinstalls can be unilaterally classified as malware by Microsoft.
- OEM adware economics weaken — if Microsoft will remove it anyway, vendors lose the revenue case for preinstalled software that carries security liability.
Third-order effects
- The episode hardened into policy: Microsoft committed to detecting and removing adware that uses man-in-the-middle techniques like Superfish as a class starting in March, shifting adware enforcement onto the OS vendor permanently.
The trend: OS vendors are asserting gatekeeping power over OEM-shipped software, reclassifying bundled adware as removable malware whenever it compromises security.