mec 16xx dump with info block

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • corona100
    Senior Member
    • Mar 2020
    • 145
    • U.S.A

    #381
    Re: mec 16xx dump with info block

    any idea about Lenovo X13 gen 10 jtag pin

    Comment

    • Bravetech
      New Member
      • Jul 2023
      • 5
      • Nigeria

      #382
      Re: mec 16xx dump with info block

      Originally posted by 69d0b913
      After a lot of persistence I managed to remove the T14 bios password! I believe that few here know how to do it and no one shares it, I understand that certain types of information are not shared and are sold! But I persisted, and I come to inform you that the (Thinkpad T14 1st 20S1) was unlocked by an RT809H the only programmer I have, as I don't have access to a vertyanov. Here are the photos in the attachment, now I just need to invert the bios information, but I had taken a photo before.

      Please how did manage to solve the T14 problem

      Comment

      • mmccomputer
        Senior Member
        • Jan 2018
        • 71
        • France

        #383
        I have a Lenovo X13 Gen 1 (i5 10th gen) with Supervisor Password and a Mec1663 that I was able to read it with my SVOD3 and I followed the usual steps to unlock it (I have already done it on other models) but this time the password does not remove​, every time he comes back
        MB : NM-C891 Rev 1.0
        SN: PC-1Y3HPX

        Comment

        • x16
          Senior Member
          • May 2015
          • 81
          • Germany

          #384
          Hello,

          I finally managed to unlock my T590 using the JTAC method with SVOD4. Unfortunately I did not choose eeprom but main. So now I have to add the dmi information.
          I have now tried various maintenace tools, but it keeps giving me the error: "error: drive not found to format". What can I do? And what dmi information do I have to enter, just the serial number?

          Thank you​

          Comment

          • monolith-2001
            Member
            • Aug 2021
            • 25
            • Japan

            #385
            I have read the EEPROM area of MEC1663.
            Where and how should I edit the BIN file to remove only the BIOS password?"
            Thank you in advance.

            X1 Carbon Gen8 20UA
            Attached Files

            Comment

          • Maxpower3
            Bad Veteran
            • Feb 2018
            • 1155
            • France

            #386
            Originally posted by monolith-2001
            I have read the EEPROM area of MEC1663.
            Where and how should I edit the BIN file to remove only the BIOS password?"
            Thank you in advance.

            X1 Carbon Gen8 20UA
            try
            Attached Files

            Comment


            • monolith-2001
              monolith-2001 commented
              Editing a comment
              I apologize for forgetting to provide the serial number.
              The serial number is PF-2BA1AW.

              Thank you for creating the 00.bin and FF.bin files.
              I will report the results at a later date.
          • Maxpower3
            Bad Veteran
            • Feb 2018
            • 1155
            • France

            #387
            Mec16 translated
            Click image for larger version  Name:	386453902_1041202147221888_1671781784116666234_n.jpg Views:	5 Size:	746.3 KB ID:	3162076
            Last edited by Maxpower3; 12-13-2023, 11:29 AM.

            Comment


            • monolith-2001
              monolith-2001 commented
              Editing a comment
              Thanks to your support, the unlocking was successful.
              I tried using FF.bin, and I was able to erase only the password without losing information such as the model number.
              I truly appreciate your assistance.
              ***Although you kindly created 00.bin for me, I did not try it.

              By the way, I'm amazed that you can translate Mec16—it's truly a divine skill.
          • nimbus12
            New Member
            • Feb 2015
            • 4
            • CZECH REPUBLIC

            #388
            Originally posted by Maxpower3
            Mec16 translated
            Click image for larger version Name:	386453902_1041202147221888_1671781784116666234_n.jpg Views:	5 Size:	746.3 KB ID:	3162076
            Amazing, how you pls translate this hex?

            Comment


            • AAAC
              AAAC commented
              Editing a comment
              Just XOR the original file with FF(h), use an Hex editor that perform that operation.
              What's the value that repeats most? It's FF, so that's the value we use for the XOR operation.
          • monolith-2001
            Member
            • Aug 2021
            • 25
            • Japan

            #389
            Attempting to read MEC1663 blocks JTAG and prevents the read operation.
            s there a way to unblock JTAG and continue reading?

            Programmer:SUCCESSOR BASE2
            X1 Carbon Gen8
            20UA
            PF-1SJ5XP
            Click image for larger version  Name:	MEC1663.jpg Views:	0 Size:	52.1 KB ID:	3170421
            Last edited by monolith-2001; 12-30-2023, 09:32 AM.

            Comment

            • monolith-2001
              Member
              • Aug 2021
              • 25
              • Japan

              #390
              When tested with RT809H, all read data was zero.
              What is the difference between MEC1663 devices that are unlocked and those that are locked, even if they are the same model?

              Comment

              • Ariu
                Senior Member
                • Dec 2020
                • 133
                • Germany

                #391
                Hello everybody, i successfully flashed the mec1663 chip of a lenovo thinkpad x390 (20Q1 Model) after the notebook wasn't turning on at all.
                So far all good but i realised that the product number is missing(is showing invalid).
                i was able to get bios DMI information back via Lenovo Maintenance Utility v1.10 . However product number on windows or Lenovo Vantage is invalid.
                Had someone the same problem and how can i resolve it ?
                Thank you.






                Attached Files

                Comment

                • elbostan
                  EL.BOSTAN TEAM
                  • Apr 2012
                  • 30
                  • egypt

                  #392
                  i need the rom file for this mec 1663 nm-c881

                  Comment

                • PTMQ
                  New Member
                  • Aug 2023
                  • 7
                  • United Kingdom

                  #393
                  Hey there,

                  While attempting to relocate the 10k resistor in order to enable jtag, I lost the resisor.
                  Does anyone know the specifications of the resistor so that I can order a new one?
                  Also do I have any other options instead of adding the resistor?
                  I have read somewhere that you can enable jtag by adding a certain amount of voltage so a specific part of the board.
                  Any ideas about how to do this?

                  Many thanks in advance, PT.

                  Comment

                  • noktabiz
                    New Member
                    • Aug 2016
                    • 8
                    • türkiye

                    #394
                    RT809F The process is complete. This is how it is done.

                    Comment

                    • vuquanghoanh
                      Member
                      • Feb 2023
                      • 45
                      • US

                      #395
                      Originally posted by volinakis
                      Re: mec 16xx dump with info block

                      I want to share my 1st experience with MEC1663 from Yoga X1 4th gen.

                      Many thanks to AAAC, RethoricalCheese, EvilBzyk, their shared knowledge helped me a lot.

                      1. Connected jtag pins as in picture, no pull up resistor needed. Moved 10k resistor from pull-down to pull-up. Chose MEC1633#ISP. power on motherboard.
                      2. Got message "Chip may be damaged or encrypted, the data is not valid" I did try other options, MEC1653#ISP, MEC1633_256k, same result.
                      3. I hit "Erase" and laptop stops working, no power on/charge led lit.
                      4. I took EC file from bios update and trim 32bytes, the same version it was in bios (I took a photo of info in bios before pulling off the motherboard) wrote the file into EC then power off motherboard. Waited few minutes an power on motherboard, power on/charge led lit. Moved the 10k resistor to pull down.
                      5. schematics IS WRONG! TP1 IS REVERSED WITH TP5.
                      I did it your way. For Thinkpad X1 Carbon Gen 7th "FX90 NM-B861 Rev: 1.0". I can read the EC dump but it's only 192 Kb
                      Unluckily, I blew out this resistor. I re-soldered it but the laptop couldn't boot up.
                      Does anyone know the value of this resistor?
                      Thank you​
                      Attached Files

                      Comment

                      • volinakis
                        Badcaps Legend
                        • Jan 2021
                        • 2615
                        • N/A

                        #396
                        R86151 1/20W_0_5%_0201 schematic and boardview:
                        https://www.badcaps.net/forum/troubl...32#post1680232

                        Chose MEC1633_256k if you have RT809H
                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                        https://www.badcaps.net/donate/
                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                        Comment

                        • vuquanghoanh
                          Member
                          • Feb 2023
                          • 45
                          • US

                          #397
                          Originally posted by volinakis
                          R86151 1/20W_0_5%_0201 schematic and boardview:
                          https://www.badcaps.net/forum/troubl...32#post1680232

                          Chose MEC1633_256k if you have RT809H
                          Thank you so much. I have successfully removed the password

                          Comment

                          • wangbreeze
                            Member
                            • Jan 2024
                            • 19
                            • USA

                            #398
                            Sharing my experience. I have two t490 that need svp removal. I have the rt809f programmer.

                            the first one did not give me problems. Read erase write and svp is gone.

                            however, the second one I cannot even recognize the mec chip. The programmer reported 0xCDCDCDCD as the mec chip id. This is the same as if the chip is disconnected from the programmer (i actually tried it with out any pins attached to the programmer, it also reported this chip id).

                            I wonder what could be the cause of this discrepancy in the chips response. The one without problem has it’s BIOS dated back to 2021 while the one giving me problems has BIOS dating back to 2022 (so it’s newer).

                            anyone can help? Thanks.

                            Comment

                            • vuquanghoanh
                              Member
                              • Feb 2023
                              • 45
                              • US

                              #399
                              I have successfully removed EC password. The system has received complete information. But when starting the laptop there is still message 2202: Product name is invalid.
                              I used the Gold key to re-enter the information but the problem was not resolved.
                              Has anyone solved this problem yet?​
                              Thanks,
                              Attached Files

                              Comment

                              • wangbreeze
                                Member
                                • Jan 2024
                                • 19
                                • USA

                                #400
                                Originally posted by vuquanghoanh
                                I have successfully removed EC password. The system has received complete information. But when starting the laptop there is still message 2202: Product name is invalid.
                                I used the Gold key to re-enter the information but the problem was not resolved.
                                Has anyone solved this problem yet?​
                                Thanks,
                                did you update the product brand to thinkpad T**?

                                Comment

                                Related Topics

                                Collapse

                                • Habble7
                                  I need a BIOS dump for the Samsung S49CG934SU monitor
                                  by Habble7
                                  The Samsung S49CG934SU monitor does not power on - no LED indicator activity and no response to power button. However, when 21V power is connected, it immediately draws 0.8A of current with no display output. The motherboard processor gets warm, and there is continuous reading activity from the W25Q128BV BIOS chip.

                                  Suspected Cause:
                                  I suspect the BIOS may have been corrupted during a power interruption while updating the firmware. The official website provides firmware updates, but they can only be installed via USB flash drive.

                                  Troubleshooting Attempts:
                                  ...
                                  05-22-2025, 07:28 AM
                                • Mephysis
                                  DUMP DVR HIKVISION DS-7208HGHI-K1 (80389 Rev 1.3 Firmware)
                                  by Mephysis
                                  Hello guys i really need help, i recently updated my DS-7208HGHI-K1 and it somehow got bricked, I've got it up and working now by flashing a new dump file i found but the serial number is really wrong and the uploader of the dump file probably intentionally did it.

                                  I still have the bricked dump file is it possible to transfer the serial number of the "bricked dump" to the "working dump"?
                                  03-27-2025, 02:34 AM
                                • Andreas_de
                                  Power supply Manson NTP-5561 (5661) LCD controller dead - PIC18F87K90 HEX dump required
                                  by Andreas_de
                                  Hello!

                                  i got a damaged Manson NTP-5561 (60V, 1,6A DC output) and and the main issue is that the controler IC for the LCD display has a short. The controler IC PIC18F87K90 is mounted on the back of the back of the LCD. Vss-Vdd = 3 Ohm. The 5V and 3,3V power line was killed as well, but that is not a problem. A new LDO 3,3V and 5V 7805 is already ordered.
                                  Replacing the PIC18F87K90 is necessary but that makes no sense without having the HEX dump of the new controler.

                                  Does anybody have such a power supply and could do a HEX dump of the Flash and EEPROM memory?
                                  ...
                                  04-12-2025, 10:38 AM
                                • re-atari
                                  Anycubic Photon 5.5 3D printer 25Q32 flashrom dump needed
                                  by re-atari
                                  Hello all, as the title says, I'm very much in need of a valid firmware dump of a Anycubic Photon 5.5 3D resin printer. It's stored in a Winbond 25Q32, so it's 4Mbyte.

                                  Here's a little background for my request. A few weeks ago I bought this 3D printer from a guy who had moved on to a PLA printer. I got it at a vey reasonable price, as it was in a defective state. The seller told me that he had experienced a power failure during a firmware upgrade, after which the printer appeared to be dead. He thought the firmware was corrupted in such a way that the printer was now bricked. As he...
                                  02-03-2025, 06:49 PM
                                • Buzzfuzz2k
                                  Bios password removal on a Unowhy dump
                                  by Buzzfuzz2k
                                  Hi Everyone,

                                  I'm facing a problem with a locked bios with a password and i can't find how to remove it...

                                  The small computer is only booting on a M2 ssd Windows partition and i get a "signed partition error" if i try to boot on the same SSD with another Os (linux for example).

                                  the Computer is a Unowhy small pc
                                  N° UYM6524702229


                                  After failling trying to boot on other "none Windows" partition, i wanted to try to remove the bios password.

                                  My first attempt was to get the bios dump from windows...
                                  11-13-2023, 07:37 AM
                                • Loading...
                                • No more items.
                                Working...