Link to home
Start Free TrialLog in
Avatar of cfourkays
cfourkaysFlag for United States of America

asked on

Intel Anti-Theft System Lock -Platform Attack

I have a Dell Inspiron N7010 for repair.
Boots to:
"Intel Anti-Theft system lock due to "Platform Attack Detected"
Time left to enter password: 3594 second (This never changes) (Different figure on every boot)
Please select one of following for platform recovery:
1 User Password
2 Server Token Password

Select one of the above......
Intel Anti-Theft service provider Id: 2000"
----------------------------------------------------------------
Bios shows under Security: Computrace Status:   Activated
Failsafe Status: Deactivated
--------------------------------------------------------------------------
My customer has no knowledge of service on the PC.
Does not recall ever setting a password for this.
This is not a business PC, just used for owner;s email, web surfing, etc.
-----------------------------------------------------------------------------------------
I cannot boot past this, only to F2 and F12.
Cannot boot to CD/DVD or USB.
Have HDD removed with same status.
Avatar of David
David
Flag of United States of America image

This isn't dell software.   It is McAfee's software.  This link tells you how to get them to override the lock.  
http://service.mcafee.com/FAQDocument.aspx?lc=1033&id=TS101587
Avatar of btan
btan

Based on the provider id (I.e. 2000) reported - it appears to be Absolute Software Computrace instead of McAfee (ie supposedly having Id of 5000), see this for provider ID number to the provider listed http://www.intel.com/support/software/services/sb/CS-034450.htm

See if this can help to cover the recover scenario
- http://www.intel.com/support/services/anti-theft-svc/sb/CS-034444.htm

Overall, the triggers are due typically to hard drive and/or motherboard was replaced. Supposed to be able to deactivate from Intel-AT service online (https://atservice.intel.com/login.action)
- see more steps in (assuming you are aware of the account for this), this is old one but sharing for info
 http://www.intel.com/support/services/anti-theft-svc/sb/CS-033585.htm

Note that there is incompatibility if the running OS has Intel-AT from Mcafee as well as the below co-existing installed in Win7 /8
•Absolute Software*: Lojack for Laptops
•Norton AntiTheft*
•Prey*
•Snuko*
•Symantec PGP*
•WinMagic SecureDoc*
•Laptop Cop*
•McAfee Anti-Theft* 1.5 - TS101371
•Intel® Anti-Theft 1.5
http://www.intel.com/support/software/services/sb/CS-033942.htm

Unless the customer can get back the original HDD and replaced back. Otherwise the online activation will be the route. If it is Intel-AT v2.0 then dlethe has already shared the scenario. Importantly that end of Jan 2015, Intel-AT has discontinued (http://www.intel.com/support/performancetools/sb/CS-034630.htm), doubt you can get any support from Intel, worst case has to go direct to Computrace  (Global contact - http://lojack.absolute.com/en/support/global-telephone-support_

The full Intel-AT troubleshooting listed available in http://www.intel.com/p/en_US/support/category/sftwr-prod/anti-theft-service/trblsht
You ought to be able to go to the Maintenance section of the BIOS (F2) and clear the flag there.

A caution; though, have you checked to see if his hard disk drive is not encrypted on another PC?  If it is and you clear the BIOS, you may lose everything that is on it!
SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of cfourkays

ASKER

I'm working on it, not neglecting. (It's Sunday).
Intel and McAfee are out of the picture. McAfee wants the login information. Was never activated.
I submitted a support case to Absolute Computrace with the serial number and owner's ID.
Came back with no Lojack activation.
Contacted owner who said he never paid or activated anything like Lojack.

Removed the HDD and found the "Reserved" partition OK but the main has "Incorrect parameters".
I'm running a "chkdsk /F /R /X N:" on it but it will take a while.
Even if I clear the drive, I still have the Anti-Theft.
Nothing in the BIOS to deactivate.

CHKDSK just finished and I have the customer's data.
Any final words about resurrecting the PC?

All
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
That's a no-win solution but I really appreciate the replies.
Already informed the customer.
Thanks to all.
Pete
in fact, if customer know nothing and see no changes or lost (have been out of sight) the laptop before then it is probably the spolit hw or corrupted hdd triggering this. as prev shared, this cannot be deactivated and note that it is activated meaning someone has done that before, I suspect the HDD is reused. Customer should know unless it is not original and is probably second hand ... backup is advocated.

Out of curiosity, I look at Absolute agreement
Things You Must Do.....
b. completely remove the Absolute Technology from a Customer Device prior to your sale or transfer of such Customer Device to another party;

Things You Must Not Do. .....
a. access the Service in respect of a Customer Device at any time other than during a valid Service Term for such Customer Device;
someone may have done it , it shd not be "magical" - in fact, once agent is installed, it will be activated for Computrace
How Persistence Technology Works
•OEMs embed Persistence technology into the firmware of devices at the factory
•Once the Computrace agent is installed, Persistence is activated
•Persistence triggers an automatic reinstallation if an Absolute software client is removed from a device
•The software client reinstalls even if the firmware is flashed, the device is reimaged, the hard drive is replaced, or if a tablet or smartphone is wiped clean to factory settings

What happens if the BIOS is flashed on a computer? Will the Computrace or Absolute Manage software
agent need to be reinstalled?
No. If the Persistence module has been enabled, the self-healing capability will repair the software agent and the
computer will still be protected. The enable/disable state of the Persistence module is stored in a part of the BIOS
that cannot be flashed to remove it.

A note is to remain customer as well Intel-AT is already EOL.  http://www.absolute.com/en/resources/matrices/absolute-computrace
btan,
Customer accepted PC is lost. All his data is recovered.
He told me a couple of months ago, a Security Co "CALLED HIM" and told him his computer had been compromised and was loaded with virus's. He let them take over his computer.

Here is what I think happened.
With customers permission, I checked a couple of documents on his Desktop.
What concerned me was a txt file for PC TECH SUPPORT:
---------------------------------------------------------------------------------------------------------------
"The charge on your credit card statement will appear as:
DALPORE.COM (PAYMENT GATEWAY) BASED IN TEXAS (USA)
                  OR
TECHKANGAROOS.COM (PAYMENT GATEWAY) BASED IN SINGAPORE

PRIMARY ISSUE:- getting unwanted pop-ups
+
UNLIMITED TECHNICAL SUPPORT FOR:-one time (30 days)
+
Security: one year Anti-virus + Malware security

Amount Paid: 129.99 USD "
-------------------------------------------------------------------------------------------------------------

Also found "Teamviewer" installed.
I don't know whether this was related but we're seeing an awful lot of this scamming.
thanks - then refurnished the laptop then, it cannot be trusted ever in compromised state and advice him to change or password and alert his credit card company asap
I get a call from scammers every few months telling me my computer is compromised.  Once, just for grins, I had nothing else better to to and kept him on the phone for maybe twenty minutes getting him to explain everything because i "wasn't very good with computers".  I kept him on the hook asking him if I could get a discount if I got my wife's computer and grandchildren's computers protected for next several years since they were living with me at the ranch   (Rambling on about the weather and their favorite TV shows and whatever else popped into my head that had nothing to do with computers).  

Finally I got tired of it and told him that i was just lonely and wanted to talk to somebody, and requested his home number so we could chat again.  

He hung up on me ;)
Accent and such phone scam attempt is "countered" :)

Teamviewer is remote assistance tool for going into the machine, they definitely did something to trigger this and probably the scam further tampering and trigger off the Intel-AT. Regardless, best also to report complaint @ https://www.ic3.gov/complaint/default.aspx

fyi on "Telephone Tech Support Scam" @ http://www.ic3.gov/media/2014/141113.aspx
Thanks, guys
Had already done the above.
Aware of Teamviewer, use it with most of my customers.

About 50% of my cases are Adware. I have mostly senior consumer uses.
Adware Removal Tool is a must for each call.
Thanks again, off to work.
The scammers are offshore organized crime groups who use VOIP lines.  It is a waste of time complaining.  The government isn't going to extradite them.
thanks all
Good day every one! I find the solution for me! I have HP Spectre 15-4000. I was replacing keyboard and after that get screen "Intel Anti-Theft system lock due to "Platform Attack Detected"... (Intel Anti-Theft service provider Id: 2000). I never use any Mcafee software
I tried to reinstall bios but cant
And just now i found solution here: https://communities.intel.com/thread/116374
So you need to choose variant 1 (1 User Password) and enter "123456". This passwordworked for me!!!
p/s: Intel support recommended to try password 12345678, but for me approached pass 123456
Good luck!!!