Forum Home
Press F1
 
Thread ID: 146477 2018-08-11 09:17:00 Has anyone heard of the malware eDellRoot? mzee (3324) Press F1
Post ID Timestamp Content User
1452591 2018-08-11 09:17:00 eDellRoot was a bit of malware installed in certain Dell computers in 2015.
I have been trying to find out if current models still have it. I have done a search on the Dell website, but have found nothing useful.
mzee (3324)
1452592 2018-08-11 09:33:00 Never heard of it, but doing a google search, its not malware, its a root certificate that dell installed that's a possible source for attacks.

Couple of articles: HERE (krebsonsecurity.com) and HERE (www.symantec.com)
wainuitech (129)
1452593 2018-08-12 04:04:00 Never heard of it, but doing a google search, its not malware, its a root certificate that dell installed that's a possible source for attacks.

Couple of articles: HERE (krebsonsecurity.com) and HERE (www.symantec.com)

I saw those, but they were written in 2015. I have a new Del 17 5000 i7 computer coming from Singapore. It has a 280GB SSD and a 1T Seagate. Where would eDellRoot be in Windows 10 Pro be, if it is there? Dell have instructions for getting rid of it, but they do not say if it still exists. I doubt that it does as there was quite a fuss about it at the time. Lenovo had a similar thing called Superfish, prior to Dell.
mzee (3324)
1452594 2018-08-12 04:43:00 Yes they are dated 2015 -- But should you have searched google ( which is all I did) there are numerous articles about it, ALL dated 2015, AND a couple that show you how to check and remove.

Articles contain Links to a word document that describe how to check and remove.

techreport.com and threatpost.com


Dell have instructions for getting rid of it, but they do not say if it still exists. Yes they did -- in the articles:


Dell, meanwhile, late on Monday said that it was going to remove the eDellroot certificate from all Dell systems moving forward, and for existing affected customers, it has provided permanent removal instructions, and starting today will push a software update that checks for the eDellroot cert and removes it.
The company promises that it's removing the certificate from all new Dell systems from here on out, as well.


I have a new Del 17 5000 i7 computer coming from Singapore. That could be different, who knows what half these places put in the software. If it were me I'd be wiping the drives as soon as I got them, and reinstalling a fresh / clean copy of W10. = No Dell crap, "nothing extra" ;)
wainuitech (129)
1