Take a look at our
ThinkPads.com HOME PAGE
For those who might want to contribute to the blog, start here: Editors Alley Topic
Then contact Bill with a Private Message

x220 Issues after IME update

X200, X201, X220 (including equivalent tablet models) and X300, X301 series specific matters only.
Post Reply
Message
Author
plasturion
Posts: 6
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

x220 Issues after IME update

#1 Post by plasturion » Sat Nov 09, 2019 2:40 am

Hi, I'm using win7 x64 and have an issues with my x220 right after I updated IME to recent one(7.1.91.3272), bios (1.46):

Most issues are related to bugy temporary delay/freeze at bios level when system is in shutdown/reboot/sleep procedure:

- often there's no beep sound when system is shutdown, battery led is turn on and fan is still working. After 10-15 seconds battery led blink for a seccond and then everything is off, sometimes it won't turn off even after that time, sometimes works ok
- system reboot makes some extra delay, it looks like there's shutdown procedure for a few seconds (all leds are turn off, beep, no fan spin)
- when alt+ctrl+del is pressed in bios screen is freezed for 10 seconds (curror keys doesn't work).
- im not sure it's related but two times happend: after 30minutes system istantly powered off. (doesn't found IME signature?)
- often sleep mode doesn't work (no beep, two leds: power and sleep led are lid till 10-15 sec or sometimes longer and fan is spinning, then system is instantly powered off. and it's system independed, is acting the same with linux and windows), sometimes works ok
- when ac is connected beep sounds like is cutted, sounds different.

Downgrade to previous IME fix some of this issues (bios screen not freeze, beep always when go into sleep mode) but most of them not, rarely I guess they still appear. I did downgrade using UPD files given by lenovo so now my configuration looks like that, I think that no all numbers are downgraded, especialy UNS, LMS and MEI. So I guess my downgrade wasn't fully succesful right?

Code: Select all

Intel(R) MEInfo Version: 7.1.50.1166
Copyright(C) 2005 - 2011, Intel Corporation. All rights reserved.

Intel(R) Manageability and Security Application code versions:

BIOS Version:                           8DET76WW (1.46 )
MEBx Version:                           7.0.0.63
Gbe Version:                            1.3
VendorID:                               8086
PCH Version:                            4
FW Version:                             7.1.52.1176
UNS Version:                            7.1.80.1213
LMS Version:                            7.1.80.1213
MEI Driver Version:                     7.1.70.1198
Wireless Hardware Version:              1.1.225
Wireless Driver Version:                14.3.0.6

FW Capabilities:                        234249317

    Intel(R) Active Management Technology - PRESENT/ENABLED
    Intel(R) Anti-Theft Technology - PRESENT/ENABLED
    Intel(R) Capability Licensing Service - PRESENT/ENABLED
    Protect Audio Video Path - PRESENT/ENABLED
    Intel(R) Dynamic Application Loader - PRESENT/ENABLED

Intel(R) AMT State:                     Enabled
CPU Upgrade State:                      Upgrade Capable
Cryptography Support:                   Enabled
Last ME reset reason:                   Power up
Local FWUpdate:                         Enabled
BIOS and GbE Config Lock:               Enabled
Host Read Access to ME:                 Disabled
Host Write Access to ME:                Disabled
...
BIOS boot State:                        Post Boot
OEM Id:                                 ********-****-0000-0000-000000000000
Link Status:                            Link down
....
IPv6 Enablement:                        Disabled
Wireless IPv6 Enablement:               Disabled
Privacy Level:                          Default
Configuration state:                    Not started
Provisioning Mode:                      PKI
Capability Licensing Service:           Enabled
Capability Licensing Service Status:    Permit info not available
OEM Tag:                                0x00000000

I think that's very similar issue describing some more:
https://www.reddit.com/r/thinkpad/comme ... rom_sleep/

Anyone have actual bios and IME firmware and everything works ok? How?
What is nature of that problem, is it connected to bios patches to isolate core and user level due the "Spectre" risk?
Is it possible to fix all the issues with me_cleaner?
Now what can I do to just make my laptop work as before?
Last edited by plasturion on Sat Nov 09, 2019 2:53 pm, edited 1 time in total.

RealBlackStuff
Admin Emeritus
Admin Emeritus
Posts: 20993
Joined: Mon Sep 18, 2006 5:17 am
Location: Dublin, Éire
Contact:

Re: x220 Issues after IME update

#2 Post by RealBlackStuff » Sat Nov 09, 2019 3:21 am

I never touched IME and when I had an X220 I used this BIOS: http://www.mcdonnelltech.com/X220_v1.46 ... d_BIOS.zip
More info here: http://x220.mcdonnelltech.com/resources/
Lovely day for a Guinness! (the Real Black Stuff). And pigs CAN fly!
Check out The Boardroom for Parts, Mods and Other Services.

"Computers don't lie, but liars can compute." (Terry Hayes's I Am Pilgrim)

skx
Sophomore Member
Posts: 171
Joined: Mon Jul 09, 2018 6:25 pm
Location: Colombia

Re: x220 Issues after IME update

#3 Post by skx » Sat Nov 09, 2019 12:17 pm

https://github.com/corna/me_cleaner

me_clean your X220 and release your machine from the evilness (flash with lowercase s). there is no need to update the malicious Intel ME as the latest version provided by Lenovo has plenty of security vulnerabilities as well. just remove it and never look back
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian - ME_cleaned
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian - ME_cleaned

plasturion
Posts: 6
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

Re: x220 Issues after IME update

#4 Post by plasturion » Sat Nov 09, 2019 1:43 pm

RealBlackStuff wrote:
Sat Nov 09, 2019 3:21 am
I never touched IME and when I had an X220 I used this BIOS: http://www.mcdonnelltech.com/X220_v1.46 ... d_BIOS.zip
More info here: http://x220.mcdonnelltech.com/resources/
I tried that bios but I had some issues in flashing so I tried only 1.45 the one with withelist remove and then I flashed stock 1.46 again.
skx wrote:
Sat Nov 09, 2019 12:17 pm
https://github.com/corna/me_cleaner

me_clean your X220 and release your machine from the evilness (flash with lowercase s). there is no need to update the malicious Intel ME as the latest version provided by Lenovo has plenty of security vulnerabilities as well. just remove it and never look back
Thanks, I'd love too but procedure is too advanced for me, I don't have rpi and stuff. Better is give to someone who can do it.

I traced this topic to find some conclusion - https://forums.lenovo.com/t5/ThinkPad-T ... 89#M117415
and I tried now the latest version before 7.1.91.3272:
https://download.lenovo.com/ibmdl/pub/p ... rf45ww.exe - 7.1.86.1221
so what exactly I did:
1. Unistalled windows management inteface driver
2. rebooted
3. Installed IME driver again.
4. Installed IME firmware 7.1.86.1221.
5. rebooted and right after I set bios defaults.

Now everything works promising, i can go into sleep mode 10 times in a row and nothing hangs. Sometimes beep is missing, but always I can wake up easly. There's no issues with shutdown. No bios freeze. There's only long time reboot, Great! :] I wonder if I can do the same with the 7.1.91.3272.
----
No, it was too early to say everything is ok... just now the worst happened - Instant off. Why? Intel why are you doing to us? at least sleep mode not hangs.

dr_st
Moderator
Moderator
Posts: 8347
Joined: Sat Oct 29, 2005 6:20 am
Location: Israel

Re: x220 Issues after IME update

#5 Post by dr_st » Sat Nov 09, 2019 2:11 pm

The lesson to learn from this is not to update BIOS/FW components when everything is working well, especially on old systems, where such very late, out-of-cycle updates are frequently released basically without any meaningful testing.
Thinkpad 25 (20K7), X1 Carbon (20HQ), Yoga 14 (20FY), T430s (IPS FHD + Classic Keyboard), X220 4291-4BG
X61 7673-V2V, T60 2007-QPG, T42 2373-F7G, X32 (IPS Screen), A31p w/ Ultrabay Numpad, A21m 2628-GXU

plasturion
Posts: 6
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

Re: x220 Issues after IME update

#6 Post by plasturion » Sat Nov 09, 2019 2:39 pm

dr_st wrote:
Sat Nov 09, 2019 2:11 pm
The lesson to learn from this is not to update BIOS/FW components when everything is working well, especially on old systems, where such very late, out-of-cycle updates are frequently released basically without any meaningful testing.
Thanks, I will remember now, If the update didn't show up as critical for CVE-2017-5689 I could completely ignore it, but now I see how things are going.

skx
Sophomore Member
Posts: 171
Joined: Mon Jul 09, 2018 6:25 pm
Location: Colombia

Re: x220 Issues after IME update

#7 Post by skx » Sun Nov 10, 2019 7:54 am

plasturion wrote:
Sat Nov 09, 2019 1:43 pm
Thanks, I'd love too but procedure is too advanced for me, I don't have rpi and stuff. Better is give to someone who can do it.
you do not need to follow the complicated RPi procedure. just buy a 5USD usb SPI CH341A programmer on ebay. it is a 5minute job on a X220 with the chip below the palm rest

Image
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian - ME_cleaned
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian - ME_cleaned

plasturion
Posts: 6
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

Re: x220 Issues after IME update

#8 Post by plasturion » Sun Nov 10, 2019 1:24 pm

skx wrote:
Sun Nov 10, 2019 7:54 am
plasturion wrote:
Sat Nov 09, 2019 1:43 pm
Thanks, I'd love too but procedure is too advanced for me, I don't have rpi and stuff. Better is give to someone who can do it.
you do not need to follow the complicated RPi procedure. just buy a 5USD usb SPI CH341A programmer on ebay. it is a 5minute job on a X220 with the chip below the palm rest

Image
That's definitely the thing I want to mess with and make sure I don't have that spyware anymore, however I'm really curious just for now if I can do something whithout external flasher.
Sleep mode and shutdown just started to be bugy again at my current configuration so I repeated actions above with the reccomended firmware for my system.(7.1.80.1214)
And at first I was scared, because after reboot, disabled atm, reboot again to see "IME unconfiguration..." and remove battery for a minute I had 5 times boot loops and I thought that's over. So i removed battery for a while again and connected to AC and after that, fortunally I could see the boot screen again. Sleep mode and shutdown works again I'm not sure how long.
And i think maybe my data/settings region of IME is responsible for all the failures, so maybe I want to clear that region.
Here's some advice from plutomaniac about similar thread.
I suggest to:

1) Update the BIOS to the latest version from Lenovo's website
2) Update the ME to the latest version from Lenovo's website (they definitely have 7.1.91.3272 for all their affected machines)
3) If the problems re-appears, try a "fpt -greset" or a manual one if the former fails.
4) If the problem persists, we have ruled out BIOS/MEBx incompatibility so the issue is almost certainly a corrupted ME region (its code or settings).
5) In such case, the only way is to unlock the FD and reflash the ME region manually after following the CleanUp Guide.
6) The reflashed firmware will be 7.1.80.1214 (last RGN), after which you can use FWUpdate to go to 7.1.91.3272.

If everything above fails, I suggest you downgrade to the last working ME firmware (7.1.85 maybe, whatever you want) and unprovision+disable AMT from MEBx. Maybe contacting Lenovo could help at such point.
so I tried 3rd step and...

Code: Select all

D:\x>fptw64 -GRESET

Intel (R) Flash Programming Tool. Version: 7.1.50.1166
Copyright (c) 2007-2011, Intel Corporation. All rights reserved.

Platform: Intel(R) QM67 Express Chipset Revision: B2
Reading HSFSTS register... Flash Descriptor: Valid

    --- Flash Devices Found ---
    W25Q64FV    ID:0xEF4017    Size: 8192KB (65536Kb)

Could not set the GlobalReset bit

Error 205: Failure. Unexpected error occurred.
Just for now everything works ok, so If the things start happen again I have to unlock Flash Descriptor
https://www.win-raid.com/t3553f39-Guide ... icing.html
and things starts to getting too complicated... but I'm not sure that I need to go trough all of this, MEinfoWin doesn't show up any errors.
Maybe my bios is the reason too, I don't really know.
------
Good news, since the last update I don't have any issues now. Everything works perfectly fine. There's beep every time i go into sleep mode.
------
after few days - sometimes sleep mode works faulty as before. It happen only few times when i closed a laptop screen. I noticed overall system slowdown too.
there was a freeze for 15 seconds in the second screen(the one with resume when your system wasn't colse properly) right after I used reboot command (alt+ctrl+del)

this time I tried to do something with bios... so I tried to roll back to 1.45 (the one without withelist) i flashed just like that (even if I should flash stock first but I can't), normally there's no way to downgrade, but if anyone know other way how to rollback bios without external flasher, let me know.
So after bios downgrade my system speed up, start-up noticely faster. I can use sleep mode again, everything works again ok, time for testing...
I've used similar procedure:
- opened cmd as admin, downgraded bios to 1.45 (modified with whitelist removal only)
- reboot
- right after I set bios defaults and disable AMT
No, there's still failure when i close screen down to enter sleep mode...

skx
Sophomore Member
Posts: 171
Joined: Mon Jul 09, 2018 6:25 pm
Location: Colombia

Re: x220 Issues after IME update

#9 Post by skx » Wed Nov 13, 2019 9:18 pm

You are really confused and should take a break. It is just perfectly possible to flash a lower bios version. You make it yourself so difficult by just trying to do each time the opposite. Use usb stick, copy the image on it and flash it. If the version is 1.0 it will even flash. Only flashing from within windows is blocked to prevent newbies messing up their computers, but who is using windows anyways in 2019 :mrgreen: Just remove your malicious intel me and move on or keep posting long posts :wink:
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian - ME_cleaned
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian - ME_cleaned

plasturion
Posts: 6
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

Re: x220 Issues after IME update

#10 Post by plasturion » Thu Nov 14, 2019 1:50 am

Thank you for telling me i had prepared 1.43 bootable iso on usb already but i thought it's pointless because thats from lenovo and it will be restricted to not allow me but you are right. This really works, thanks! I have 1.43 stock now

I have few new failures (uncommon strange scraches sounds when boot up, or simetimes i can't use f1 f12 to enter bios ) and old (sleep mode works faulty) that appeared before bios change and still present, afer bios downgrade and there's no difference. Maybe they were but i didn't notice it. I'll post when everything will be fixed or me_cleaned, just now I need a break from all the tweeks.
----
Bacause of random happening and instant off i thought maybe that's a hardware issue, or might be caused by wan card. So I made a small cleanup with my hardware, reconnected all the cables inside use an vaccum cleaner, and reconected wan card and for now it works ok.

I have request can anyone make a test using HW_Monitor(I've got 1.37) how looks some values after go into sleep mode and wake up?
because after I woke up from sleep mode I've got >21000W(Packages, IA Cores, GT) recorded max value.
Maybe that's normal because like a light bulb, i takes most power at the moment when it's switched on. But I woudl like to compare are that high values ok?

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “ThinkPad X200/201/220 and X300/301 Series”

Who is online

Users browsing this forum: SPONSZ and 14 guests