All 5 Lenovo Laptops we had (replaced since then) had a BIOS Rootkit by Lenovo.
NO clean Os, no fancy AV will be of any use. If your not in the mood to rewrite your bios Lenovo will (has proven to)use this backdoor to secretly install malware again and again as they have done again since superfish.
Furthermore it'll leave a big backdoor for everyone right to the core since they abused one of Microsofts Bios features.
Contrary to Lenovos statement: "(ThinkPad, ThinkCentre, Lenovo Desktop, ThinkStation, ThinkServer and System x products are not impacted.) "
The ARE infected, just not every single one.
The lesson they took from Superfish was to secretly install more spy/ad/crapware a couple months later.
I think it's safe to say that no Lenovo product can be trusted.
Parent is probably referring to Lenovo's use of the Windows Platform Binary Table, which allows OEMs to put a Windows program in the firmware. Recent versions of Windows will then automatically run this program on each boot. This is apparently intended to allow persistent remote management/anti-theft software.
Trust is earned not given, and they did a hell of a job to make sure it's lost. I don't have the time (why should i waste time with this in the first place) nor the patience to check every Lenovo product down to the bios.
My first expierience was with a customers laptop about 3 month before Superfish hit the media. Remote location no inet access ... so removing all the malware by hand took about 6 hours and a mental breakdown since some pieces just came back again and again.
I suspected a hidden system recovery partition that would reload some malware functions... don't ask how much time was wasted all in all.
Edit: If you used a Lenovo PC and did any sensitive stuff like online banking, thanks to their MiM attack, they phished your logins and other data or you are willing to believe they put in all this work - compromitting https/hiding in Bios (maybe HDD Firmware, too) to just replace an ad here and there and suuuurely delete anything of ... real value.... that gets cought by accident/technical impossibility to filter.
There are other operating systems besides Windows, you know? And if you insist on running Windows, Dell snooping on you is your last concern - Microsoft is already doing a much more thorough job.
It's true i haven't tested it yet on my DELLs, but these machines sit in a separated Vlan behind a big black blinking box and cannot communicate with anything outside.
But these HP machines could as well run DOS or TempleOS, since the culprit is in the BIOS - you don't even have to boot a kernel to have access your Fujitsu machine from the outside.
Dell, Windows and Abit snooping my habbits is still different than a shady third-party from NewPanama phishing my bank logins, reloading new malware.
All 5 Lenovo Laptops we had (replaced since then) had a BIOS Rootkit by Lenovo.
NO clean Os, no fancy AV will be of any use. If your not in the mood to rewrite your bios Lenovo will (has proven to)use this backdoor to secretly install malware again and again as they have done again since superfish.
Furthermore it'll leave a big backdoor for everyone right to the core since they abused one of Microsofts Bios features.
Contrary to Lenovos statement: "(ThinkPad, ThinkCentre, Lenovo Desktop, ThinkStation, ThinkServer and System x products are not impacted.) "
The ARE infected, just not every single one. The lesson they took from Superfish was to secretly install more spy/ad/crapware a couple months later.
I think it's safe to say that no Lenovo product can be trusted.