mec 16xx dump with info block

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • superhansi
    New Member
    • Dec 2019
    • 4
    • VAE

    #1

    mec 16xx dump with info block

    Hi,

    anyone can share a (256kb) MEC dump with info block? (containing SER#,CON#,USR#...) or share the SVP offset (e.g. for DXE mapped its 0x1F400)? With SVP would be great.
    thanks
  • RethoricalCheese
    Badcaps Legend
    • Mar 2013
    • 1514
    • Estonia

    #2
    Re: mec 16xx dump with info block

    If you want to unlock lenovo, use the patch method instead.

    Comment

    • superhansi
      New Member
      • Dec 2019
      • 4
      • VAE

      #3
      Re: mec 16xx dump with info block

      doesnt work on t490 and above

      Comment

      • RethoricalCheese
        Badcaps Legend
        • Mar 2013
        • 1514
        • Estonia

        #4
        Re: mec 16xx dump with info block

        Okay, thats where you should have started sadly I have no information on what you asked.

        I think there is a checksum aswell. So if you want to delete SVP, got to consider that aswell. But since I have not modified mec-s, I am not sure if it is important or even true

        Anyway, good luck with trying and let us know how it goes.

        Comment

        • superhansi
          New Member
          • Dec 2019
          • 4
          • VAE

          #5
          Re: mec 16xx dump with info block

          i only need a dump with this block, e.g. v**fix has but i dont wanna buy it...

          FYI: erasing+rewriting MEC to get rid of SVP works like a charm, unfortunately UUID,SN and such are "lost" due to the fact that this info block seems to be read protected in mec1663, with the offsets avail i could skip this block during erase/write and then I wouldnt need to rewrite it... so any dump should do thus i didnt mention T490 and later
          Last edited by superhansi; 02-25-2020, 02:53 AM. Reason: typo

          Comment

          • xmasterboss
            Member
            • Apr 2014
            • 34
            • Romania

            #6
            Re: mec 16xx dump with info block

            Hy. I also have a T490s. Did you remove the chip or connected the programmer via wires to the motherboard? I can't find schematic or where the pins are. Also, did you succeed in removing SVP ?

            Comment

            • Aditya11ttt
              Adi
              • Feb 2019
              • 176
              • India

              #7
              Re: mec 16xx dump with info block

              Originally posted by xmasterboss
              Hy. I also have a T490s. Did you remove the chip or connected the programmer via wires to the motherboard? I can't find schematic or where the pins are. Also, did you succeed in removing SVP ?
              try this try to find jtag1 connector name on the board only space will be there without connector !!
              Attached Files

              Comment

              • xmasterboss
                Member
                • Apr 2014
                • 34
                • Romania

                #8
                Re: mec 16xx dump with info block

                Originally posted by Aditya11ttt
                try this try to find jtag1 connector name on the board only space will be there without connector !!
                Thanks. Did you find the MEC Dump you were looking for? even if it's for sale i will buy and share it with you.

                Comment

                • zomi
                  Badcaps Veteran
                  • Nov 2011
                  • 505

                  #9
                  Re: mec 16xx dump with info block

                  On these if you replace the mec ic will that solve the password ?
                  remove ic and put another one in ?
                  Is that confirmed solution ?

                  Comment

                  • iTec
                    Member
                    • Oct 2017
                    • 17
                    • USA

                    #10
                    Re: mec 16xx dump with info block

                    Originally posted by Aditya11ttt
                    try this try to find jtag1 connector name on the board only space will be there without connector !!
                    Do you know which or where is the RST#? It's a T490 with the MEC1663
                    Any help is really appreciated.

                    Comment

                    • black0hackers
                      Badcaps Veteran
                      • Jul 2020
                      • 365
                      • USA

                      #11
                      Re: mec 16xx dump with info block

                      Where is point to connect?
                      picture add of T490S
                      Attached Files

                      Comment

                      • AAAC
                        Badcaps Veteran
                        • Jan 2020
                        • 457
                        • Mexico

                        #12
                        Re: mec 16xx dump with info block

                        @black0hackers
                        Upload another picture of complete motherboard, as most of the JTAG signals may be already in a connector pads.
                        • So the JTAG signal wires will need to be soldered to this connector pads.
                        • You will need to move a very tiny PULL-UP resistor and make it a PULL-DOWN resistor to enable JTAG interface.
                        • Then you will need to locate RST# signal somewhere around MECxxxx chip by looking at schematic for this T490S, or by looking at another model schematic that uses the same MECxxxx chip part number (although I've read that this signal is not needed, someone with more JTAG experience may confirm/deny this).

                        Comment

                        • JOHNLAG7
                          Member
                          • Nov 2014
                          • 19
                          • Greece

                          #13
                          Re: mec 16xx dump with info block

                          There is a photo t490 jtag1 and pins ,can someone draw the connection ?
                          Attached Files

                          Comment

                          • RethoricalCheese
                            Badcaps Legend
                            • Mar 2013
                            • 1514
                            • Estonia

                            #14
                            Re: mec 16xx dump with info block

                            Looks like JTAG reset resistor is marked in red box. Move the resistor next to that capacitor on the empty pads.

                            I will test it tomorrow.
                            Attached Files

                            Comment

                            • RethoricalCheese
                              Badcaps Legend
                              • Mar 2013
                              • 1514
                              • Estonia

                              #15
                              Re: mec 16xx dump with info block

                              The resistor in my last picture was indeed correct. I can read/write MEC now.

                              The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used?
                              Last edited by RethoricalCheese; 04-16-2021, 01:04 AM.

                              Comment

                              • SMDFlea
                                Super Moderator
                                • Jan 2018
                                • 20279
                                • UK

                                #16
                                Re: mec 16xx dump with info block

                                Originally posted by RethoricalCheese
                                The resistor in my last picture was indeed correct. I can read/write MEC now.

                                The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used?
                                A Vertyanov jig or SVOD3
                                All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

                                Comment

                                • AAAC
                                  Badcaps Veteran
                                  • Jan 2020
                                  • 457
                                  • Mexico

                                  #17
                                  Re: mec 16xx dump with info block

                                  @RethoricalCheese
                                  In your last post you mention you can read/write MEC now, but you describe your problem as is not able to clear the write-only area... have you tried to disconnect all sources of energy for 2-3 minutes? seems like this area is temporarily copied to volatile memory too (ram), so removing energy for a couple of minutes will do the trick.
                                  After this you will have to use Lenovo UEFI Maintenance utility to write Model Number, Serial Number, TYPE and other data for ThinkPad to be left as it was before programming MEC chip.
                                  Last edited by AAAC; 04-17-2021, 07:47 AM.

                                  Comment

                                  • RethoricalCheese
                                    Badcaps Legend
                                    • Mar 2013
                                    • 1514
                                    • Estonia

                                    #18
                                    Re: mec 16xx dump with info block

                                    Thanks, will try. Did not try removing power for more than a few seconds.

                                    Comment

                                    • keczuk
                                      Senior Member
                                      • Dec 2019
                                      • 83
                                      • WWW

                                      #19
                                      Re: mec 16xx dump with info block

                                      Hi

                                      I have question. I use svod3 for program this mec and when i read few times mec dump in hxd i see all dump are different. When i try write my clean ec dump i have error in veryfiication. Any idea how solve of my problem ?

                                      Comment

                                      • AAAC
                                        Badcaps Veteran
                                        • Jan 2020
                                        • 457
                                        • Mexico

                                        #20
                                        Re: mec 16xx dump with info block

                                        @keczuk
                                        Upload a picture of your setup. Have you added PULL-UP resistors to JTAG signals.
                                        At the time we did this one we couldn't find a schematic for T490, but X1 Carbon 6th Gen (T480s and others) have same MEC1663 EC/KBC chip so we used them as reference.

                                        Attached Files
                                        Last edited by AAAC; 04-18-2021, 04:33 PM.

                                        Comment

                                        Related Topics

                                        Collapse

                                        • Habble7
                                          I need a BIOS dump for the Samsung S49CG934SU monitor
                                          by Habble7
                                          The Samsung S49CG934SU monitor does not power on - no LED indicator activity and no response to power button. However, when 21V power is connected, it immediately draws 0.8A of current with no display output. The motherboard processor gets warm, and there is continuous reading activity from the W25Q128BV BIOS chip.

                                          Suspected Cause:
                                          I suspect the BIOS may have been corrupted during a power interruption while updating the firmware. The official website provides firmware updates, but they can only be installed via USB flash drive.

                                          Troubleshooting Attempts:
                                          ...
                                          05-22-2025, 07:28 AM
                                        • Mephysis
                                          DUMP DVR HIKVISION DS-7208HGHI-K1 (80389 Rev 1.3 Firmware)
                                          by Mephysis
                                          Hello guys i really need help, i recently updated my DS-7208HGHI-K1 and it somehow got bricked, I've got it up and working now by flashing a new dump file i found but the serial number is really wrong and the uploader of the dump file probably intentionally did it.

                                          I still have the bricked dump file is it possible to transfer the serial number of the "bricked dump" to the "working dump"?
                                          03-27-2025, 02:34 AM
                                        • Andreas_de
                                          Power supply Manson NTP-5561 (5661) LCD controller dead - PIC18F87K90 HEX dump required
                                          by Andreas_de
                                          Hello!

                                          i got a damaged Manson NTP-5561 (60V, 1,6A DC output) and and the main issue is that the controler IC for the LCD display has a short. The controler IC PIC18F87K90 is mounted on the back of the back of the LCD. Vss-Vdd = 3 Ohm. The 5V and 3,3V power line was killed as well, but that is not a problem. A new LDO 3,3V and 5V 7805 is already ordered.
                                          Replacing the PIC18F87K90 is necessary but that makes no sense without having the HEX dump of the new controler.

                                          Does anybody have such a power supply and could do a HEX dump of the Flash and EEPROM memory?
                                          ...
                                          04-12-2025, 10:38 AM
                                        • re-atari
                                          Anycubic Photon 5.5 3D printer 25Q32 flashrom dump needed
                                          by re-atari
                                          Hello all, as the title says, I'm very much in need of a valid firmware dump of a Anycubic Photon 5.5 3D resin printer. It's stored in a Winbond 25Q32, so it's 4Mbyte.

                                          Here's a little background for my request. A few weeks ago I bought this 3D printer from a guy who had moved on to a PLA printer. I got it at a vey reasonable price, as it was in a defective state. The seller told me that he had experienced a power failure during a firmware upgrade, after which the printer appeared to be dead. He thought the firmware was corrupted in such a way that the printer was now bricked. As he...
                                          02-03-2025, 06:49 PM
                                        • Buzzfuzz2k
                                          Bios password removal on a Unowhy dump
                                          by Buzzfuzz2k
                                          Hi Everyone,

                                          I'm facing a problem with a locked bios with a password and i can't find how to remove it...

                                          The small computer is only booting on a M2 ssd Windows partition and i get a "signed partition error" if i try to boot on the same SSD with another Os (linux for example).

                                          the Computer is a Unowhy small pc
                                          N° UYM6524702229


                                          After failling trying to boot on other "none Windows" partition, i wanted to try to remove the bios password.

                                          My first attempt was to get the bios dump from windows...
                                          11-13-2023, 07:37 AM
                                        • Loading...
                                        • No more items.
                                        Working...