Post #2153254
2026-03-21 00:38 UTC
I've been twitchy about Lenova since they got caught [selling computers with a rootkit that reinstalled crap-ware that users had uninstalled](https://www.zdnet.com/article/lenovo-rootkit-ensured-its-software-could-not-be-deleted/). A user would uninstall useless software from their computer, and when they rebooted, the rootkit would kick in and reinstall the bloatware.
>The "rootkit"-style covert installer, dubbed the Lenovo Service Engine (LSE), works by installing an additional program that updates drivers, firmware, and other pre-installed apps. The engine also "sends non-personally identifiable system data to Lenovo servers," according to the company. The engine, which resides in the computer's BIOS, replaces a core Windows system file with its own, allowing files to be downloaded once the device is connected to the internet.
>But that service engine also put users at risk.
>In a July 31 security bulletin, the company warned the engine could be exploited by hackers to install malware. The company issued a security update that removed the engine's functionality, but users must install the patch manually.
They had previously been caught selling computers with adware installed on them.
>Earlier this year, the computer maker was forced to admit it had installed Superfish adware over a three-month period on new machines sold through retail channels. The adware had the capability to intercept and hijack internet traffic flowing over secure connections, including online stores, banks, among others.
>Users were told they should "not use their laptop for any kind of secure transactions until they are able to confirm [the adware] has been removed," security researcher Marc Rogers told ZDNet at the time.
>It was thought as many as 16 million consumers and bring-your-own-device users were affected by the preinstalled adware.
Replies (1)
-
@MonkderVierte@lemmy.zip 2026-03-21 11:31
> since they got caught selling computers with a rootkit Is there any large computer/phone vendor that didn't? Tuxedo maybe, but they aren't large. No excuse, but preinstalled malware is more "common" than you think, and sometimes one of them is a rootkit/bootkit. (paid-for) bloatware is often not quality-checked; it's handled similiarly to ad platforms.