From what I understand of Superfish, Mozilla (and other browser vendors) can't just blacklist the certificate. That would make all HTTPS connections error out. A message notifying users of the issue is all they can do.
They have the choice of having HTTPS effectively useless (by leaving the certificate there), or making HTTPS not work (by removing it, thus prompting action from the user to fix it -- perhaps by calling their tech savvy nephew).
Browser vendors should (and usually do) err on the side of security.
https://twitter.com/matthew_d_green/status/56843703790644428...
Probably not a proxy; probably low-level socket interception in Windows.
So there isn't much the browsers can do to help the user.
At least the technical side of Lenovo's response is all the way to "We are writing a program to remove the certificates", which is probably the thing that is going to impact the most people.