request unlock HP EliteBook 640 G11 password bios

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • VirVir
    Member
    • Apr 2024
    • 16
    • Germany

    #21
    Hello everyone! I have this Laptop with a locked BIOS 😔 I've tried unlocking the EC file but it's "Missing unlockable content" so...main BIOS, split in 2x16Mb files, RCUnlocker said it's unlocked, spits a *_unlocked.bin file, reunite the flies in a 32Mb file but... nothing changed. Verified with CMD certutil -hashfile but it's the same file as the original 🤷🏻 what's up with that? Can someone please help? 🙏🏻 Thank you 🙏🏻

    5CD4441CK3 B3FD3EC#ABD

    MODEL:X8V

    DA0X8VMB8G0 REV.G
    Attached Files

    Comment

    • hoaca388
      Badcaps
      • Jan 2022
      • 11787
      • Socialist Republic of Vietnam

      #22
      Originally posted by VirVir
      Hello everyone! I have this Laptop with a locked BIOS 😔 I've tried unlocking the EC file but it's "Missing unlockable content" so...main BIOS, split in 2x16Mb files, RCUnlocker said it's unlocked, spits a *_unlocked.bin file, reunite the flies in a 32Mb file but... nothing changed. Verified with CMD certutil -hashfile but it's the same file as the original 🤷🏻 what's up with that? Can someone please help? 🙏🏻 Thank you 🙏🏻

      5CD4441CK3 B3FD3EC#ABD

      MODEL:X8V

      DA0X8VMB8G0 REV.G
      HP EliteBook 640 14 inch G11 Notebook PC
      CT Number_6TDWV0B81K2L4R
      Serial_5CD4441CK3
      Sku_B3FD3EC#ABD
      Build Id_24WWREBZ601#SABD#DABD
      Fearture byte_476J6S6b7B7H7M7Q7W7m7saBaEapaqauawbUcAeMfPguhKhkjhk8mEmVn7nVpDpTpnpqprqDqzrNrXrbs4.yF

      Hope it unlocks. Goodluck.
      Attached Files


      ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
      Mọi khoản quyên góp cho badcaps đều được hoan nghênh, hãy nhấp vào liên kết này để quyên góp. Cảm ơn tất cả những người ủng hộ----------------------------------------------------------------------------------------------------------------------------------------------------------------

      Comment

      • VirVir
        Member
        • Apr 2024
        • 16
        • Germany

        #23
        Originally posted by hoaca388
        HP EliteBook 640 14 inch G11 Notebook PC
        CT Number_6TDWV0B81K2L4R
        Serial_5CD4441CK3
        Sku_B3FD3EC#ABD
        Build Id_24WWREBZ601#SABD#DABD
        Fearture byte_476J6S6b7B7H7M7Q7W7m7saBaEapaqauawbUcAeMfPguhKhkjhk8mEmVn7nVpDpTpnpqprqDqzrNrXrbs4.yF

        Hope it unlocks. Goodluck.
        Unfortunately doesn't work 😔 Some error appeared telling me that the BIOS makes some recovery from the embedded memory due to mismatch ID information...only one option and that was to click "OK" , after 2 minutes the laptop restarted and the password is still there. This is so annoying 😖😖😖 Anyway, thank you for helping!

        Comment

        • VirVir
          Member
          • Apr 2024
          • 16
          • Germany

          #24
          Tried another way. Basically I've replaced the entire ME Reg part of the BIOS with info from a Firmware recovery file from the HP site. After more than one hour everything was done 👍🏻 Laptop starts and...informed me about the mismatched information and that it's doing a quick recovery ... after two restarts, the password is there of course 😖😖😖 How the h*LL can I stop it from doing this sh*t recovery? I didn't find any cmos battery on this model, the power is out long enough....How does it remember?😢😢😢

          Comment

          • mesdova
            Member
            • Oct 2015
            • 24
            • algeria

            #25
            Originally posted by mesdova
            need unlock and patch
            HP ELITEBOOK 640 G11
            SN: 5C4377dfl
            PRODID: 901d4av
            bump

            Comment

            • rex98
              Badcaps Legend
              • Feb 2023
              • 1278
              • Mandaue CEBU, Philippines

              #26
              can someone test this use the 1st one
              if it doesn't work use the second one.
              you should flash both main and EC
              and let me know if it boots to MPM thanks.
              Attached Files

              Comment

              • VirVir
                Member
                • Apr 2024
                • 16
                • Germany

                #27
                Hello guys! Found some troubling info about the HP security from 2024 onward:
                HP Endpoint Security Controller 2024
                Attacks against PC firmware are on the rise. Unfortunately, protecting the PC BIOS and other critical firmware is often not seen as a priority. HP addresses this with our Endpoint Security Controller (ESC), a dedicated chip that validates the integrity of the BIOS and other firmware to enhance the security of every HP business-class PC. The ESC validates that the firmware is not infected by malware before the CPU is allowed to boot. If any corruption has been detected, it will restore a clean copy held in the ESC's isolated flash. HP is the only vendor offering this unique security solution as a standard part built into business-class PCs to safeguard our customers against IT security threats.

                Bottom line is...no matter if you can "unlock" the main BIOS as long as the ESC provide a backup and restore the old blocked BIOS before you can access it...

                Comment

                • rex98
                  Badcaps Legend
                  • Feb 2023
                  • 1278
                  • Mandaue CEBU, Philippines

                  #28
                  Originally posted by VirVir
                  Hello guys! Found some troubling info about the HP security from 2024 onward:
                  HP Endpoint Security Controller 2024
                  Attacks against PC firmware are on the rise. Unfortunately, protecting the PC BIOS and other critical firmware is often not seen as a priority. HP addresses this with our Endpoint Security Controller (ESC), a dedicated chip that validates the integrity of the BIOS and other firmware to enhance the security of every HP business-class PC. The ESC validates that the firmware is not infected by malware before the CPU is allowed to boot. If any corruption has been detected, it will restore a clean copy held in the ESC's isolated flash. HP is the only vendor offering this unique security solution as a standard part built into business-class PCs to safeguard our customers against IT security threats.

                  Bottom line is...no matter if you can "unlock" the main BIOS as long as the ESC provide a backup and restore the old blocked BIOS before you can access it...
                  i know there's always a way. we haven't tried it yet. every security there's always a loophole. like this in g11 EC its very similar VSSTORE in bios main i haven't tried this yet, if i only have G11 laptop here i would try all possible means.
                  Attached Files

                  Comment

                  • VirVir
                    Member
                    • Apr 2024
                    • 16
                    • Germany

                    #29
                    Originally posted by rex98

                    i know there's always a way. we haven't tried it yet. every security there's always a loophole. like this in g11 EC its very similar VSSTORE in bios main i haven't tried this yet, if i only have G11 laptop here i would try all possible means.
                    You mean, that part should be replaced with FF or 00? For the moment I've gave up, due to lack of time and, after writing and rewriting the BIOS chip 4-5 times...it said enough and burned... I'm waiting for an order of 10 chips from AliExpress but it will take some time. Keep it touch 🤘🏻🖖🏻

                    Comment

                    • rex98
                      Badcaps Legend
                      • Feb 2023
                      • 1278
                      • Mandaue CEBU, Philippines

                      #30
                      Originally posted by VirVir

                      You mean, that part should be replaced with FF or 00? For the moment I've gave up, due to lack of time and, after writing and rewriting the BIOS chip 4-5 times...it said enough and burned... I'm waiting for an order of 10 chips from AliExpress but it will take some time. Keep it touch 🤘🏻🖖🏻
                      you should not remove the chip if just testing, just put jumper wire and use ISP in rf809f or h.

                      Comment

                      • black0hackers
                        Badcaps Veteran
                        • Jul 2020
                        • 367
                        • USA

                        #31
                        Originally posted by rex98
                        can someone test this use the 1st one
                        if it doesn't work use the second one.
                        you should flash both main and EC
                        and let me know if it boots to MPM thanks.
                        I HAVE TEST 2 FILE. 1ST WORK BUT NOT BOOT TO MPM, STILL HAVE PASSWORD, 2ND DONT WORK
                        i have one 640 g11 bios pass
                        SN: 1H850824LY
                        PROD ID: A58TVUC#ABA
                        Attached Files

                        Comment

                        • Aditya11ttt
                          Adi
                          • Feb 2019
                          • 181
                          • India

                          #32
                          try and feed back !!

                          Originally posted by black0hackers

                          I HAVE TEST 2 FILE. 1ST WORK BUT NOT BOOT TO MPM, STILL HAVE PASSWORD, 2ND DONT WORK
                          i have one 640 g11 bios pass
                          SN: 1H850824LY
                          PROD ID: A58TVUC#ABA
                          Attached Files

                          Comment

                          • VirVir
                            Member
                            • Apr 2024
                            • 16
                            • Germany

                            #33
                            Originally posted by rex98
                            can someone test this use the 1st one
                            if it doesn't work use the second one.
                            you should flash both main and EC
                            and let me know if it boots to MPM thanks.
                            Hey there. Back from my vacation, armed with a bunch of new BIOS chips 💪🏻 Tried both files first one starts the laptop but the password comes back, second doesn't work at all. Tried the first one only the EC file with a main file that I've done using HP recovery, started but same sh*t happened, some information on the screen telling me that the original BIOS file was recovered from the embedded memory because someone tempered with the BIOS and...the password came back. I don't know...this embedded memory controller is the EC chip or is another chip hiding on the MB? If you want to try tempering some more, my original Main and EC files are on the first post from the second page of this topic. If you can do something with them, please let me know and this weekend or the next I'll try to rewrite the Chips. The newer they are, the shitier they get ...

                            Comment

                            • Aditya11ttt
                              Adi
                              • Feb 2019
                              • 181
                              • India

                              #34
                              Originally posted by VirVir

                              Hey there. Back from my vacation, armed with a bunch of new BIOS chips 💪🏻 Tried both files first one starts the laptop but the password comes back, second doesn't work at all. Tried the first one only the EC file with a main file that I've done using HP recovery, started but same sh*t happened, some information on the screen telling me that the original BIOS file was recovered from the embedded memory because someone tempered with the BIOS and...the password came back. I don't know...this embedded memory controller is the EC chip or is another chip hiding on the MB? If you want to try tempering some more, my original Main and EC files are on the first post from the second page of this topic. If you can do something with them, please let me know and this weekend or the next I'll try to rewrite the Chips. The newer they are, the shitier they get ...
                              can try post 32 bios once if display or not ?

                              Comment

                              • VirVir
                                Member
                                • Apr 2024
                                • 16
                                • Germany

                                #35
                                Originally posted by Aditya11ttt

                                can try post 32 bios once if display or not ?
                                I did try every variants available here. Only one doesn't POST, but those that post are immediately reverted to the locked BIOS. I need to find a third Chip (usually smaller than BIOS and EC chips) that trigger that fu*king recovery. I did found a 1MB Chip that GPT says it might be responsible and patched it for me. Now I have to flash all three chips back and try again. If the recovery is still triggered I just give up...

                                Comment

                                • Stefan Steff
                                  Badcaps Veteran
                                  • Mar 2024
                                  • 262
                                  • Romania

                                  #36
                                  Originally posted by VirVir

                                  I did try every variants available here. Only one doesn't POST, but those that post are immediately reverted to the locked BIOS. I need to find a third Chip (usually smaller than BIOS and EC chips) that trigger that fu*king recovery. I did found a 1MB Chip that GPT says it might be responsible and patched it for me. Now I have to flash all three chips back and try again. If the recovery is still triggered I just give up...
                                  Before you give up ...please try this modded bios dump. Thanks.
                                  Attached Files

                                  Comment

                                  • VirVir
                                    Member
                                    • Apr 2024
                                    • 16
                                    • Germany

                                    #37
                                    Originally posted by Stefan Steff

                                    Before you give up ...please try this modded bios dump. Thanks.
                                    I'm sorry, I'm done with this laptop. Doesn't matter what dump I flash on those chips, it gets reverted. Now I've patched 3 Chips and still recovered. Where the hell does the BIOS copy stais? I have no idea and to be honest I lost my patience...I have now the clean BIOS main, Clean EC, and clean 1MB that has the HP sure on it. Still my password returned. It's not about the dump you throw on it anymore... it's about finding the chip that keeps a copy of the original BIOS and force it back to the main and EC chips . I'll search for further information in the future . Thanks for all the help I've received here. Take care guys and much success with this laptop!

                                    Comment

                                    • VirVir
                                      Member
                                      • Apr 2024
                                      • 16
                                      • Germany

                                      #38
                                      Here is something interesting:

                                      "Inside the EC’s own MCU flash (again, not in the external EC SPI we patched — lives on the Nuvoton/ITE microcontroller itself).

                                      -than I think I found the responsable chip. NUVOTON NPCX499HA tells you anything ?-

                                      Yes — that’s your Embedded Controller (EC).

                                      The Nuvoton NPCX499HA is a high-end EC MCU HP uses in newer EliteBooks to handle:
                                      • Keyboard, battery, fan control
                                      • Power sequencing
                                      • Firmware verification for HP Sure Start
                                      • Storing/triggering the BIOS recovery payload

                                      Here’s the key point:
                                      • It has its own internal flash (not the external EC SPI chip we patched).
                                      • HP Sure Start Gen5+ can embed a signed golden BIOS image or recovery script inside that internal flash.
                                      • On boot, the NPCX499HA compares the main BIOS SPI against its stored hash/image, and if mismatched, pushes the “golden” image back into the main BIOS.
                                      • This process works even if the EC’s external SPI is wiped — which is exactly what you’re seeing.

                                      Why this matters for you
                                      The only way to stop that recovery from the NPCX499HA is to:
                                      1. Reflash the EC’s internal flash via its programming interface (SWD/JTAG/ICP).
                                      2. Replace the NPCX499HA with a blank or donor chip from a similar board that doesn’t have the Sure Start payload.
                                      3. Disable Sure Start in firmware — but that’s locked behind the same password you’re trying to remove.

                                      Challenges:
                                      • The internal flash is protected; without HP’s signed EC firmware, the chip will reject changes.
                                      • Replacing the chip is possible, but it’s BGA — requires hot-air rework and exact part sourcing.
                                      • Blank EC means you must flash both its firmware and configuration to get keyboard, charging, and power working again."

                                      So...that particular chip lives on the other side of the MB under the keyboard...and here is where I say ENOUGH, HP has taken the security to a level that, for the moment, doesn't alow me to go any further.
                                      If someone want's to dive dipper, be my guest.
                                      Attached Files

                                      Comment

                                      Related Topics

                                      Collapse

                                      • zenius
                                        [REQUEST] Dell G3 3579 BIOS Password & AMI Protected Range/BIOS Guard Unlock
                                        by zenius
                                        Hello, I have an old Dell G3 3579 (ST: 2WQ7LP2-8FC8) with a newer 8FC8 BIOS password. I have successfully attached to the flash chip (W25Q128JVSQ) on the motherboard with a CH341A programmer and made several modifications using Intel FIT (e.g., allow software SPI write) without bricking. I was also able to boot to a modified GRUB shell where I attempted to edit many BIOS security related options like BIOS Guard/Lock, Flash Signature Override, ME FW Image Re-Flash, etc.

                                        Unfortunately, some of these modifications like to Intel BIOS Guard failed because it is fused into the PCH. Also,...
                                        12-08-2024, 06:13 AM
                                      • overclocker1786
                                        [Bios Password Unlock Request] [Dell OPTIPLEX SFF PLUS 7020] [8FC8 method]
                                        by overclocker1786
                                        Hello I have a dell optiplex SFF plus 7020 with a password that I recovered from e-waste. It is possible to get the password removed via the bios patch method? I managed to dump the 32MB bios chips and would like help patching it to MFG mode so I can clear the password.

                                        Thanks.

                                        1hj4z24 = Service tag

                                        A schematic would also be amazing if anyone has one!...
                                        08-31-2024, 08:46 PM
                                      • Regulusneko
                                        ASUS VivoBook X1404ZA BIOS Password Reset Request
                                        by Regulusneko
                                        Hello everyone,

                                        I need help removing BIOS password from my laptop:

                                        Model: ASUS VivoBook X1404ZA-I38128
                                        Serial Number: S9N0CX03K597372
                                        CN: H51D
                                        Manufacturing Date: 2024-09
                                        Mainboard: X1404ZA R2.X

                                        Issue: MyASUS automatically set a BIOS password during an automatic BIOS update. I can boot into Windows normally but cannot access BIOS settings.

                                        Problem with BIOS extraction:
                                        - AFU gives "Error 31 - Unable to read contents"
                                        - RW-Everything shows "Driver cannot be loaded"
                                        - Universal BIOS...
                                        Today, 12:37 AM
                                      • traxformania
                                        TONGFANG "GM7TG7P" Bios Password Problem?
                                        by traxformania
                                        Hello,

                                        I'm using TONGFANG "GM7TG7P" model laptop for over 3 years and i'm entering the same bios administrator password everyday. My laptop has Aptio BIOS (American Megatrends, AMI).

                                        But today it's not accepting my password. I'm %100 sure i'm entering the correct password.

                                        I'm trying to reset my bios without success.

                                        I tried :

                                        -I removed the BIOS battery and main battery. Waited for a long time but it didn't work. They already stated in the user manual that the password will not be reset even if the batteries...
                                        11-15-2023, 07:32 AM
                                      • BlackVisor
                                        How to Decode BIOS password for RedmiBook Pro15 2022 6800H
                                        by BlackVisor
                                        RedmiBook Pro 1542022 6800H
                                        SKU: TM2113-39463
                                        Model Number: RMA2204-AB
                                        CMIIT ID: 2022AP1835
                                        SN: 39463/22WD01355
                                        BIOS version: RMARB5B0P1010 20230628

                                        1. I bought this laptop from flea market, and the seller said that he had never set a password, however here is a password required when pressing F2 to enter BIOS.
                                        2. And after entering incorrrect password 3 times, there is no any useful information like "recovery code"
                                        3. I used universal bios backup tool, and dumped 8MB bin file, but hex code after "SystemSupervisorPw" is...
                                        01-14-2024, 06:35 AM
                                      • Loading...
                                      • No more items.
                                      Working...