Lenovo shipped laptops with an “anti-theft” rootkit that reinstalled unwanted software, has issued manual, optional patch to remove the functionality
Owen Williams / The Next Web :
Context & Ripple Effects
This is the second act of a bad year for Lenovo's software practices: in February the SSL-busting Superfish code put every affected laptop's users at risk of interception, and Lenovo's initial handling was widely panned as astonishingly clueless before it promised to stop bundling crapware. Now the company confirms some machines shipped with an 'anti-theft' rootkit that reinstalls unwanted software even after removal — and its fix is a manual patch users must opt into and apply themselves.
First-order effects
- Affected laptop owners must find and manually run an optional patch; anyone who doesn't keeps software they deleted coming back from below the OS level.
- Lenovo's February promise to stop bundling crapware is directly undercut by the revelation that preinstalled code persisted on shipped machines after that commitment.
Second-order effects
- Security researchers now have a template for auditing what else ships in vendor images — the same dynamic that later led Duo Labs to flag insecure bloatware across Lenovo, Acer, HP, Dell, and Asus laptops and forced Lenovo to tell users to uninstall its Accelerator app over MITM risk.
- Rival PC vendors face pressure to publish what their own factory images install and how to remove it, since 'bloatware' is no longer just a performance complaint but an attack surface.
Third-order effects
- If vendors keep treating preinstalled persistence as acceptable, buyers will increasingly demand clean-image options or wipe machines themselves — pushing OEMs toward verifiable software manifests the way Hacking Team's UEFI-surviving malware pushed the industry to treat firmware-level persistence as a threat class rather than a feature.
The trend: PC vendors are being dragged from treating bundled software as a revenue line to defending it as a security liability, with each disclosure narrowing what manufacturers can quietly ship.