Take a look at our
ThinkPads.com HOME PAGE
For those who might want to contribute to the blog, start here: Editors Alley Topic
Then contact Bill with a Private Message

x220 Issues after IME update

X200, X201, X220 (including equivalent tablet models) and X300, X301 series specific matters only.
Post Reply
Message
Author
plasturion
Posts: 5
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

x220 Issues after IME update

#1 Post by plasturion » Sat Nov 09, 2019 2:40 am

Hi, I'm using win7 x64 and have an issues with my x220 right after I updated IME to recent one(7.1.91.3272), bios (1.46):

Most issues are related to bugy temporary delay/freeze at bios level when system is in shutdown/reboot/sleep procedure:

- often there's no beep sound when system is shutdown, battery led is turn on and fan is still working. After 10-15 seconds battery led blink for a seccond and then everything is off, sometimes it won't turn off even after that time, sometimes works ok
- system reboot makes some extra delay, it looks like there's shutdown procedure for a few seconds (all leds are turn off, beep, no fan spin)
- when alt+ctrl+del is pressed in bios screen is freezed for 10 seconds (curror keys doesn't work).
- im not sure it's related but two times happend: after 30minutes system istantly powered off. (doesn't found IME signature?)
- often sleep mode doesn't work (no beep, two leds: power and sleep led are lid till 10-15 sec or sometimes longer and fan is spinning, then system is instantly powered off. and it's system independed, is acting the same with linux and windows), sometimes works ok
- when ac is connected beep sounds like is cutted, sounds different.

Downgrade to previous IME fix some of this issues (bios screen not freeze, beep always when go into sleep mode) but most of them not, rarely I guess they still appear. I did downgrade using UPD files given by lenovo so now my configuration looks like that, I think that no all numbers are downgraded, especialy UNS, LMS and MEI. So I guess my downgrade wasn't fully succesful right?

Code: Select all

Intel(R) MEInfo Version: 7.1.50.1166
Copyright(C) 2005 - 2011, Intel Corporation. All rights reserved.

Intel(R) Manageability and Security Application code versions:

BIOS Version:                           8DET76WW (1.46 )
MEBx Version:                           7.0.0.63
Gbe Version:                            1.3
VendorID:                               8086
PCH Version:                            4
FW Version:                             7.1.52.1176
UNS Version:                            7.1.80.1213
LMS Version:                            7.1.80.1213
MEI Driver Version:                     7.1.70.1198
Wireless Hardware Version:              1.1.225
Wireless Driver Version:                14.3.0.6

FW Capabilities:                        234249317

    Intel(R) Active Management Technology - PRESENT/ENABLED
    Intel(R) Anti-Theft Technology - PRESENT/ENABLED
    Intel(R) Capability Licensing Service - PRESENT/ENABLED
    Protect Audio Video Path - PRESENT/ENABLED
    Intel(R) Dynamic Application Loader - PRESENT/ENABLED

Intel(R) AMT State:                     Enabled
CPU Upgrade State:                      Upgrade Capable
Cryptography Support:                   Enabled
Last ME reset reason:                   Power up
Local FWUpdate:                         Enabled
BIOS and GbE Config Lock:               Enabled
Host Read Access to ME:                 Disabled
Host Write Access to ME:                Disabled
...
BIOS boot State:                        Post Boot
OEM Id:                                 ********-****-0000-0000-000000000000
Link Status:                            Link down
....
IPv6 Enablement:                        Disabled
Wireless IPv6 Enablement:               Disabled
Privacy Level:                          Default
Configuration state:                    Not started
Provisioning Mode:                      PKI
Capability Licensing Service:           Enabled
Capability Licensing Service Status:    Permit info not available
OEM Tag:                                0x00000000

I think that's very similar issue describing some more:
https://www.reddit.com/r/thinkpad/comme ... rom_sleep/

Anyone have actual bios and IME firmware and everything works ok? How?
What is nature of that problem, is it connected to bios patches to isolate core and user level due the "Spectre" risk?
Is it possible to fix all the issues with me_cleaner?
Now what can I do to just make my laptop work as before?
Last edited by plasturion on Sat Nov 09, 2019 2:53 pm, edited 1 time in total.

RealBlackStuff
Admin Emeritus
Admin Emeritus
Posts: 20344
Joined: Mon Sep 18, 2006 5:17 am
Location: Dublin, Éire
Contact:

Re: x220 Issues after IME update

#2 Post by RealBlackStuff » Sat Nov 09, 2019 3:21 am

I never touched IME and when I had an X220 I used this BIOS: http://www.mcdonnelltech.com/X220_v1.46 ... d_BIOS.zip
More info here: http://x220.mcdonnelltech.com/resources/
Lovely day for a Guinness! (the Real Black Stuff). And pigs CAN fly!
Check out The Boardroom for Parts, Mods and Other Services.

skx
Sophomore Member
Posts: 148
Joined: Mon Jul 09, 2018 6:25 pm
Location: Colombia

Re: x220 Issues after IME update

#3 Post by skx » Sat Nov 09, 2019 12:17 pm

https://github.com/corna/me_cleaner

me_clean your X220 and release your machine from the evilness (flash with lowercase s). there is no need to update the malicious Intel ME as the latest version provided by Lenovo has plenty of security vulnerabilities as well. just remove it and never look back
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian - ME_cleaned
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian - ME_cleaned

plasturion
Posts: 5
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

Re: x220 Issues after IME update

#4 Post by plasturion » Sat Nov 09, 2019 1:43 pm

RealBlackStuff wrote:
Sat Nov 09, 2019 3:21 am
I never touched IME and when I had an X220 I used this BIOS: http://www.mcdonnelltech.com/X220_v1.46 ... d_BIOS.zip
More info here: http://x220.mcdonnelltech.com/resources/
I tried that bios but I had some issues in flashing so I tried only 1.45 the one with withelist remove and then I flashed stock 1.46 again.
skx wrote:
Sat Nov 09, 2019 12:17 pm
https://github.com/corna/me_cleaner

me_clean your X220 and release your machine from the evilness (flash with lowercase s). there is no need to update the malicious Intel ME as the latest version provided by Lenovo has plenty of security vulnerabilities as well. just remove it and never look back
Thanks, I'd love too but procedure is too advanced for me, I don't have rpi and stuff. Better is give to someone who can do it.

I traced this topic to find some conclusion - https://forums.lenovo.com/t5/ThinkPad-T ... 89#M117415
and I tried now the latest version before 7.1.91.3272:
https://download.lenovo.com/ibmdl/pub/p ... rf45ww.exe - 7.1.86.1221
so what exactly I did:
1. Unistalled windows management inteface driver
2. rebooted
3. Installed IME driver again.
4. Installed IME firmware 7.1.86.1221.
5. rebooted and right after I set bios defaults.

Now everything works promising, i can go into sleep mode 10 times in a row and nothing hangs. Sometimes beep is missing, but always I can wake up easly. There's no issues with shutdown. No bios freeze. There's only long time reboot, Great! :] I wonder if I can do the same with the 7.1.91.3272.
----
No, it was too early to say everything is ok... just now the worst happened - Instant off. Why? Intel why are you doing to us? at least sleep mode not hangs.

dr_st
Moderator
Moderator
Posts: 8089
Joined: Sat Oct 29, 2005 6:20 am
Location: Israel

Re: x220 Issues after IME update

#5 Post by dr_st » Sat Nov 09, 2019 2:11 pm

The lesson to learn from this is not to update BIOS/FW components when everything is working well, especially on old systems, where such very late, out-of-cycle updates are frequently released basically without any meaningful testing.
Thinkpad 25 (20K7), X1 Carbon (20HQ), Yoga 14 (20FY), T430s (IPS FHD + Classic Keyboard), X220 4291-4BG
X61 7673-V2V, T60 2007-QPG, T42 2373-F7G, X32 (IPS Screen), A31p w/ Ultrabay Numpad, A21m 2628-GXU

plasturion
Posts: 5
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

Re: x220 Issues after IME update

#6 Post by plasturion » Sat Nov 09, 2019 2:39 pm

dr_st wrote:
Sat Nov 09, 2019 2:11 pm
The lesson to learn from this is not to update BIOS/FW components when everything is working well, especially on old systems, where such very late, out-of-cycle updates are frequently released basically without any meaningful testing.
Thanks, I will remember now, If the update didn't show up as critical for CVE-2017-5689 I could completely ignore it, but now I see how things are going.

skx
Sophomore Member
Posts: 148
Joined: Mon Jul 09, 2018 6:25 pm
Location: Colombia

Re: x220 Issues after IME update

#7 Post by skx » Sun Nov 10, 2019 7:54 am

plasturion wrote:
Sat Nov 09, 2019 1:43 pm
Thanks, I'd love too but procedure is too advanced for me, I don't have rpi and stuff. Better is give to someone who can do it.
you do not need to follow the complicated RPi procedure. just buy a 5USD usb SPI CH341A programmer on ebay. it is a 5minute job on a X220 with the chip below the palm rest

Image
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian - ME_cleaned
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian - ME_cleaned

plasturion
Posts: 5
Joined: Thu Nov 07, 2019 11:59 am
Location: Jaworzyna Slaska, Poland

Re: x220 Issues after IME update

#8 Post by plasturion » Sun Nov 10, 2019 1:24 pm

skx wrote:
Sun Nov 10, 2019 7:54 am
plasturion wrote:
Sat Nov 09, 2019 1:43 pm
Thanks, I'd love too but procedure is too advanced for me, I don't have rpi and stuff. Better is give to someone who can do it.
you do not need to follow the complicated RPi procedure. just buy a 5USD usb SPI CH341A programmer on ebay. it is a 5minute job on a X220 with the chip below the palm rest

Image
That's definitely the thing I want to mess with and make sure I don't have that spyware anymore, however I'm really curious just for now if I can do something whithout external flasher.
Sleep mode and shutdown just started to be bugy again at my current configuration so I repeated actions above with the reccomended firmware for my system.(7.1.80.1214)
And at first I was scared, because after reboot, disabled atm, reboot again to see "IME unconfiguration..." and remove battery for a minute I had 5 times boot loops and I thought that's over. So i removed battery for a while again and connected to AC and after that, fortunally I could see the boot screen again. Sleep mode and shutdown works again I'm not sure how long.
And i think maybe my data/settings region of IME is responsible for all the failures, so maybe I want to clear that region.
Here's some advice from plutomaniac about similar thread.
I suggest to:

1) Update the BIOS to the latest version from Lenovo's website
2) Update the ME to the latest version from Lenovo's website (they definitely have 7.1.91.3272 for all their affected machines)
3) If the problems re-appears, try a "fpt -greset" or a manual one if the former fails.
4) If the problem persists, we have ruled out BIOS/MEBx incompatibility so the issue is almost certainly a corrupted ME region (its code or settings).
5) In such case, the only way is to unlock the FD and reflash the ME region manually after following the CleanUp Guide.
6) The reflashed firmware will be 7.1.80.1214 (last RGN), after which you can use FWUpdate to go to 7.1.91.3272.

If everything above fails, I suggest you downgrade to the last working ME firmware (7.1.85 maybe, whatever you want) and unprovision+disable AMT from MEBx. Maybe contacting Lenovo could help at such point.
so I tried 3rd step and...

Code: Select all

D:\x>fptw64 -GRESET

Intel (R) Flash Programming Tool. Version: 7.1.50.1166
Copyright (c) 2007-2011, Intel Corporation. All rights reserved.

Platform: Intel(R) QM67 Express Chipset Revision: B2
Reading HSFSTS register... Flash Descriptor: Valid

    --- Flash Devices Found ---
    W25Q64FV    ID:0xEF4017    Size: 8192KB (65536Kb)

Could not set the GlobalReset bit

Error 205: Failure. Unexpected error occurred.
Just for now everything works ok, so If the things start happen again I have to unlock Flash Descriptor
https://www.win-raid.com/t3553f39-Guide ... icing.html
and things starts to getting too complicated... but I'm not sure that I need to go trough all of this, MEinfoWin doesn't show up any errors.
Maybe my bios is the reason too, I don't really know.
------
Good news, since the last update I don't have any issues now. Everything works perfectly fine. There's beep every time i go into sleep mode. Nice. Thanks guys.

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “ThinkPad X200/201/220 and X300/301 Series”

Who is online

Users browsing this forum: No registered users and 12 guests