Lenovo Covertly Downloading, Installing Software on Its Windows PCs: Reports

Advertisement
By Manish Singh | Updated: 12 August 2015 19:26 IST

Lenovo has reportedly been caught using a "rootkit-like" technique to forcefully install a bunch of software on its Windows-powered machines. The largest PC vendor is said to be using the BIOS to track a certain application in Windows' system files and overwrite it on boot up with its own programs. Furthermore, the mechanism the company utilises to tweak the BIOS is vulnerable and can be used to install malicious code. Lenovo has issued a patch to remove the vulnerability, but users will have to download and install it manually.

Multiple users report that the Chinese computer manufacturer is covertly installing its software on Windows-powered computers. One person who goes by the username 'chuckup' on Hacker News, notes that a Lenovo service gets installed on the machine even after performing a clean OS install on a new SSD using a Windows 8 DVD.The company is installing an application called "Lenovo Updater" using a mechanism that appears to resemble a rootkit, an unauthorised way to gain access, on its computers using something called Lenovo Service Engine (LSE) to download a program called OneKey Optimiser (OKO).

Advertisement

Here's how the company describes this application, it "is powerful, next-generation system optimization software designed specifically for Lenovo computers. It can enhance your PC's performance by updating firmware, drivers, and pre-installed apps. It also provides power management schemes that can extend the life of your battery."But that's not all. As The Next Web, points out the application also sends data to Lenovo server to help them "understand how customers use [their] products." A predefined setting made to the BIOS forces it to verify a program called "autochk.exe" (found here: Windows\system32) to see whether it is signed by Microsoft or Lenovo. In case of the former, it seemingly overwrites the file with its own.

This application then creates LenovoUpdate.exe and LenovoCheck.exe programs which further download more files when the computer establishes a connection with the Internet.

Advertisement

If that wasn't dubious enough, a vulnerability was found in the way Lenovo uses Lenovo Service Engine to download files. The company issued a patch to remove the functionality on July 31, but it will have to be downloaded and installed manually. An advisory on Lenovo's official support site notes that a number of laptops and desktops including Yoga 3 14 and Z70-80 / G70-80 are vulnerable to the attack.

The vulnerability once again raises concerns about an OEM's authority over the software it loads on its systems. Lenovo was widely criticised earlier this year over the Superfish fiasco wherein one of the apps it preloaded was categorised as adware.

Advertisement

Microsoft allows manufacturers to make changes to BIOS and even allows them to push software for installation from BIOS. However, a manufacturer ideally needs to update the mechanism if a vulnerability is detected in it.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Sony 1000X The Collexion Launched With DSEE Ultimate, Up to 24 Hours Battery Life
  2. Google IO 2026: Here's Everything That Was Announced During the Event
  3. Fortnite Returns to App Store for iPhone, iPad Globally
  4. Redmi Turbo 5 India Launch Timeline, Key Features Leaked
  5. Airtel's Priority Postpaid Becomes India's First 5G Network Slicing Service
  6. Samsung Galaxy S27 Pro Tipped to Launch With Compact Design, Ultra Features
  7. Google Is Rebuilding Search Around AI, Agents, and Gemini
  8. Google I/O 2026: Docs Live Brings Gemini Voice AI to Gmail, Docs and Keep
  9. Lenovo Legion Y70 (2026) With 8,000mAh Battery Arrives at This Price
  10. Who Is Andrej Karpathy, the Renowned AI Researcher Who Joined Anthropic?
  1. Motorola Razr Fold Goes on Sale in India With Snapdragon 8 Gen 5 SoC, Triple 50-Megapixel Cameras: Price, Offers
  2. Xbox Launches Player Voice Feedback Portal, Fans Say Bring Back Xbox Exclusives
  3. Fortnite Returns to App Store for iPhone, iPad Globally After Apple-Epic Legal Battle
  4. WhatsApp for iOS Gets Redesigned Media Share Sheet to Make Sharing Photos Easier: Report
  5. Lenovo Legion Y70 (2026) Launched With 8,000mAh Battery, 50-Megapixel Camera: Price, Specifications
  6. Google I/O 2026: Ask YouTube Brings Conversational Search for AI-Powered Video Discovery
  7. Who Is Andrej Karpathy, the Renowned AI Researcher Who Joined Anthropic?
  8. Satan: The Dark Locks Now Streaming Online: Everything You Need to Know About Plot, Cast, and More
  9. Sony 1000X The Collexion Launched With DSEE Ultimate, Up to 24 Hours Battery Life as 1000X 10-Year Anniversary Headphones
  10. Google I/O 2026: AI Agents in Search to Deliver Smarter Personalised Results
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.