ThinkPad x395 attempt at password removal

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • volinakis
    Badcaps Legend
    • Jan 2021
    • 2607
    • N/A

    #21
    Originally posted by 3mz3t
    volinakis I also have a t495s laptop with a supervisor password set (I know this thread is for X395, but it's the same motherboard).

    Can you please patch the attached bios dump for me so that I can try your method? S/N PC-1HF898

    Thanks.
    try
    Attached Files
    ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
    https://www.badcaps.net/donate/
    ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

    Comment

    • franklinogot
      Super Member
      • Oct 2023
      • 27
      • Philippines

      #22
      Originally posted by 3mz3t
      volinakis I also have a t495s laptop with a supervisor password set (I know this thread is for X395, but it's the same motherboard).

      Can you please patch the attached bios dump for me so that I can try your method? S/N PC-1HF898

      Thanks.
      Here you go
      Attached Files

      Comment

      • 3mz3t
        Member
        • Sep 2023
        • 13
        • Slovakia

        #23
        volinakis franklinogot The patched bios worked like a charm, I did not even have to remove the winbond chip (I used clips), clean & quick method. Thank you very much! :-)

        Comment

        • volinakis
          Badcaps Legend
          • Jan 2021
          • 2607
          • N/A

          #24
          Originally posted by 3mz3t
          volinakis franklinogot The patched bios worked like a charm, I did not even have to remove the winbond chip (I used clips), clean & quick method. Thank you very much! :-)
          which patch did you use? mine or the other one? because they are different.
          ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
          https://www.badcaps.net/donate/
          ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

          Comment

          • 3mz3t
            Member
            • Sep 2023
            • 13
            • Slovakia

            #25
            volinakis I used yours (I assumed the other one uses the same mechanism).

            Comment

            • volinakis
              Badcaps Legend
              • Jan 2021
              • 2607
              • N/A

              #26
              Originally posted by 3mz3t
              volinakis I used yours (I assumed the other one uses the same mechanism).
              nope, the other one doesn't even have NVRAM volume cleaned. I am sure it will not work.
              Attached Files
              ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
              https://www.badcaps.net/donate/
              ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

              Comment

              • tazertest
                New Member
                • Dec 2024
                • 2
                • Pakistan

                #27
                Hi, I also have recently bough a x395. Can you please help me volinakis?

                Comment

                • volinakis
                  Badcaps Legend
                  • Jan 2021
                  • 2607
                  • N/A

                  #28
                  Originally posted by tazertest
                  Hi, I also have recently bough a x395. Can you please help me volinakis?
                  post bios backup
                  ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                  https://www.badcaps.net/donate/
                  ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                  Comment

                  • tazertest
                    New Member
                    • Dec 2024
                    • 2
                    • Pakistan

                    #29
                    Originally posted by volinakis

                    post bios backup
                    How do I do that? Sorry I'm a noob.

                    Comment

                    • volinakis
                      Badcaps Legend
                      • Jan 2021
                      • 2607
                      • N/A

                      #30
                      Originally posted by tazertest

                      How do I do that? Sorry I'm a noob.
                      Read Bios Guides ...

                      https://www.badcaps.net/forum/troubl...t=phoenix+bios
                      ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                      https://www.badcaps.net/donate/
                      ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                      Comment

                      • mshone
                        Senior Member
                        • Jan 2014
                        • 50
                        • serbia

                        #31
                        Originally posted by volinakis
                        Re: ThinkPad x395 attempt at password removal



                        What programmer did you use to erase IT8186VG?


                        Hi file,
                        I have 2 laptops of model thinkpad x390. One is witg Gigadevice 1,8V BIOS chip, another is with winbond. Please to unlock.
                        1. Lenovo thinkpad X390, model 20NM-S0GM01 20/04, s/n PC-1GK33V. BIOS chip gigadevice 25LB128DSIG 1.8 V, original file name is "x395 GD orig 1.zip"
                        2.
                        Lenovo thinkpad X390, model 20NM-S0GM01 19/12, s/n PC-1CMMX8, BIOS chip is WINBOND 25Q128FWSQ 1.8 V, original file name is "x395 wb orig 1.zip"

                        Thanks in advance.

                        Attached Files

                        Comment

                        • mshone
                          Senior Member
                          • Jan 2014
                          • 50
                          • serbia

                          #32
                          Originally posted by mshone


                          Hi file,
                          I have 2 laptops of model thinkpad x390. One is witg Gigadevice 1,8V BIOS chip, another is with winbond. Please to unlock.
                          1. Lenovo thinkpad X390, model 20NM-S0GM01 20/04, s/n PC-1GK33V. BIOS chip gigadevice 25LB128DSIG 1.8 V, original file name is "x395 GD orig 1.zip"
                          2.
                          Lenovo thinkpad X390, model 20NM-S0GM01 19/12, s/n PC-1CMMX8, BIOS chip is WINBOND 25Q128FWSQ 1.8 V, original file name is "x395 wb orig 1.zip"

                          Thanks in advance.
                          It is model X395, not x390

                          Comment

                          • volinakis
                            Badcaps Legend
                            • Jan 2021
                            • 2607
                            • N/A

                            #33
                            Originally posted by mshone


                            Hi file,
                            I have 2 laptops of model thinkpad x390. One is witg Gigadevice 1,8V BIOS chip, another is with winbond. Please to unlock.
                            1. Lenovo thinkpad X390, model 20NM-S0GM01 20/04, s/n PC-1GK33V. BIOS chip gigadevice 25LB128DSIG 1.8 V, original file name is "x395 GD orig 1.zip"
                            2.
                            Lenovo thinkpad X390, model 20NM-S0GM01 19/12, s/n PC-1CMMX8, BIOS chip is WINBOND 25Q128FWSQ 1.8 V, original file name is "x395 wb orig 1.zip"

                            Thanks in advance.
                            follow steps from autopatcher
                            Attached Files
                            ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                            https://www.badcaps.net/donate/
                            ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                            Comment

                            • mshone
                              Senior Member
                              • Jan 2014
                              • 50
                              • serbia

                              #34
                              Originally posted by volinakis

                              follow steps from autopatcher
                              IT WORKS !!!! THANKS A LOT !!!!! EYHARISTW FILE !!!

                              Comment

                              • volinakis
                                Badcaps Legend
                                • Jan 2021
                                • 2607
                                • N/A

                                #35
                                Originally posted by mshone

                                IT WORKS !!!! THANKS A LOT !!!!! EYHARISTW FILE !!!
                                you are welcome but i'm not Greek!
                                ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                                https://www.badcaps.net/donate/
                                ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                                Comment

                                • mshone
                                  Senior Member
                                  • Jan 2014
                                  • 50
                                  • serbia

                                  #36
                                  Originally posted by volinakis

                                  you are welcome but i'm not Greek!
                                  You are good man, it is important 😀

                                  Comment

                                  • rumpumpel1
                                    Senior Member
                                    • Jul 2019
                                    • 134
                                    • germany

                                    #37
                                    I have a X395 with a BIOS password. Could someone please help me to remove the password?

                                    MTM: 20NMS1U800
                                    unit SN: PC1KRHEL
                                    board SN: L1HF07L02H5

                                    X395_704.zip

                                    In case of an E14 Gen3 the password is stored in the EC, so I attach also the EC dump of the X395:

                                    X395_704_IT818641_192KB_CRC32_0x142F96D8.zip

                                    Comment

                                    • rumpumpel1
                                      Senior Member
                                      • Jul 2019
                                      • 134
                                      • germany

                                      #38
                                      Based on some other threads on this topic, I tried to overwrite 128 bytes with FF in the EC dump starting at 0x0002EF00.
                                      It looks like I found the right place, but just deleting everything seems not to be enough, I get the error: Post process stopped due to bad SVP data.

                                      Any help would be greatly appreciated.​

                                      Comment

                                      • Maxpower3
                                        Bad Veteran
                                        • Feb 2018
                                        • 1153
                                        • France

                                        #39
                                        try
                                        Attached Files
                                        Last edited by Maxpower3; 01-22-2025, 05:31 AM.

                                        Comment

                                        • rumpumpel1
                                          Senior Member
                                          • Jul 2019
                                          • 134
                                          • germany

                                          #40
                                          yes, the version 'unlock with 00 ...' works.
                                          thank you very much.

                                          Comment

                                          Related Topics

                                          Collapse

                                          • AppleLover123
                                            Lenovo Yoga X380 22LH Supervisor Password removal
                                            by AppleLover123
                                            Hey guys,

                                            have a laptop here that has a supervisor Password (dump in Attachements).
                                            Before i write the Serial NR.etc i wanted to say that strangely after flashing with 3 different Bios dumps and one from lenovos site
                                            the laptop works but everytime it wants me to type a supervisor password i never set.
                                            I thought the supervisor password is stuck in the ec bios but no it isn't either because after replacing the ec chip from one of another board it still has the supervisor password.
                                            Anyway i wanted to ask what of the two chips is the ec bios because on the left...
                                            04-17-2025, 03:42 PM
                                          • mferna14
                                            Password removal on MacBook Pro A2159
                                            by mferna14
                                            Hi friends., I am working on MacBook Pro A2159 touchbar 2019. The old logic board was liquid spilled so I ordered another logic board from AE. Received it & all worked fine till I got to the Chinese login screen where the login screen password tobe entered. I tried to reset the password but it again gave me options which I do not know about the Apple ID. I formatted the onboard SSD. & wanted to change the startup boot sequence but in order to change it, again the password is needed for that too. Is there a way to get rid of this password?? The seller has not replied back past 2 days, how...
                                            05-13-2025, 04:16 PM
                                          • Badpatch02
                                            Thinkpad X380 Yoga supervisor password removal + Intel ME removal question
                                            by Badpatch02
                                            Hi all, I'm new here, a few words about myself: CS student, interested in hardware stuff too - tinkering my whole life but with practically no experience when it comes to firmware "hacking".

                                            So I have this X380 Yoga with a supervisor password in place and before doing anything stupid I figured I'd rather ask.
                                            I plan on using the tool from this thread: https://www.badcaps.net/forum/troubl...password-remov...
                                            11-30-2024, 05:22 AM
                                          • Johnny h
                                            Asus M7600R BIOS Password request/removal
                                            by Johnny h
                                            Hello,

                                            I'm hoping someone can assist me.
                                            I have an Asus Vivobook 16x Pro OLED laptop which has a BIOS password, and I can't seem to find it.
                                            It still boots into Windows (boots from whatever SSD is installed but not from USB).

                                            The model number is M7600R and serial number is N8N0CX03H71131C.

                                            I tried AMITSESetup Decryptor but the password I got doesn't make sense (it's got a line break and special characters).
                                            I also tried to use *************** MOD EDIT ,redacted************** and it also gave me the funny password of
                                            Code:
                                            tmNx\'=QJQ
                                            ...
                                            04-10-2024, 06:13 AM
                                          • coolshrimp
                                            T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal
                                            by coolshrimp
                                            Here is all the info you should need to remove bios password from your same model or one with an MEC-Chip and also write back the config data

                                            T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                                            See Diagram for Wiring.

                                            Use MEC-1633#ISP on your RT809h
                                            This is same Jtag pinout and method for T490S/X390
                                            (But your R/W 10K Resistor Location May In a Different Location)


                                            MEC-Chips Store Bios Password In a Secure Un-Editable Area

                                            Following steps clear that secure area to re-initialize itself to default (Blank)
                                            ...
                                            10-24-2022, 12:18 AM
                                          • Loading...
                                          • No more items.
                                          Working...