Badcaps.net Forum
Go Back   Badcaps Forums > Troubleshooting Hardware & Devices and Electronics Theory > Troubleshooting Laptops, Tablets, and Mobile Devices > BIOS Requests ONLY!
Register FAQ Calendar Search Today's Posts Mark Forums Read

 
Thread Tools Display Modes
Old 02-24-2020, 11:24 AM   #1
superhansi
New Member
 
Join Date: Dec 2019
City & State: Dubai
My Country: VAE
I'm a: Knowledge Seeker
Posts: 4
Default mec 16xx dump with info block

Hi,

anyone can share a (256kb) MEC dump with info block? (containing SER#,CON#,USR#...) or share the SVP offset (e.g. for DXE mapped its 0x1F400)? With SVP would be great.
thanks
superhansi is offline   Reply With Quote
Old 02-24-2020, 02:23 PM   #2
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,255
Default Re: mec 16xx dump with info block

If you want to unlock lenovo, use the patch method instead.
RethoricalCheese is offline   Reply With Quote
Old 02-25-2020, 01:15 AM   #3
superhansi
New Member
 
Join Date: Dec 2019
City & State: Dubai
My Country: VAE
I'm a: Knowledge Seeker
Posts: 4
Default Re: mec 16xx dump with info block

doesnt work on t490 and above
superhansi is offline   Reply With Quote
Old 02-25-2020, 02:37 AM   #4
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,255
Default Re: mec 16xx dump with info block

Okay, thats where you should have started sadly I have no information on what you asked.

I think there is a checksum aswell. So if you want to delete SVP, got to consider that aswell. But since I have not modified mec-s, I am not sure if it is important or even true

Anyway, good luck with trying and let us know how it goes.
RethoricalCheese is offline   Reply With Quote
Old 02-25-2020, 02:51 AM   #5
superhansi
New Member
 
Join Date: Dec 2019
City & State: Dubai
My Country: VAE
I'm a: Knowledge Seeker
Posts: 4
Default Re: mec 16xx dump with info block

i only need a dump with this block, e.g. v**fix has but i dont wanna buy it...

FYI: erasing+rewriting MEC to get rid of SVP works like a charm, unfortunately UUID,SN and such are "lost" due to the fact that this info block seems to be read protected in mec1663, with the offsets avail i could skip this block during erase/write and then I wouldnt need to rewrite it... so any dump should do thus i didnt mention T490 and later

Last edited by superhansi; 02-25-2020 at 02:53 AM.. Reason: typo
superhansi is offline   Reply With Quote
Old 05-29-2020, 09:51 AM   #6
xmasterboss
Member
 
Join Date: Apr 2014
City & State: Bucharest
My Country: Romania
I'm a: Knowledge Seeker
Posts: 23
Default Re: mec 16xx dump with info block

Hy. I also have a T490s. Did you remove the chip or connected the programmer via wires to the motherboard? I can't find schematic or where the pins are. Also, did you succeed in removing SVP ?
xmasterboss is offline   Reply With Quote
Old 07-04-2020, 01:17 PM   #7
Aditya11ttt
Adi
 
Join Date: Feb 2019
City & State: Kolkata
My Country: India
I'm a: Knowledge Seeker
Posts: 71
Default Re: mec 16xx dump with info block

Quote:
Originally Posted by xmasterboss View Post
Hy. I also have a T490s. Did you remove the chip or connected the programmer via wires to the motherboard? I can't find schematic or where the pins are. Also, did you succeed in removing SVP ?
try this try to find jtag1 connector name on the board only space will be there without connector !!
Attached Images
File Type: jpg photo_2020-07-05_00-45-19.jpg (177.0 KB, 692 views)
Aditya11ttt is online now   Reply With Quote
Old 07-07-2020, 02:36 AM   #8
xmasterboss
Member
 
Join Date: Apr 2014
City & State: Bucharest
My Country: Romania
I'm a: Knowledge Seeker
Posts: 23
Default Re: mec 16xx dump with info block

Quote:
Originally Posted by Aditya11ttt View Post
try this try to find jtag1 connector name on the board only space will be there without connector !!
Thanks. Did you find the MEC Dump you were looking for? even if it's for sale i will buy and share it with you.
xmasterboss is offline   Reply With Quote
Old 11-24-2020, 05:23 PM   #9
zomi
Badcaps Veteran
 
Join Date: Nov 2011
Posts: 374
Default Re: mec 16xx dump with info block

On these if you replace the mec ic will that solve the password ?
remove ic and put another one in ?
Is that confirmed solution ?
zomi is offline   Reply With Quote
Old 11-25-2020, 07:10 AM   #10
iTec
New Member
 
Join Date: Oct 2017
City & State: Houston Texas
My Country: USA
I'm a: Knowledge Seeker
Posts: 14
Default Re: mec 16xx dump with info block

Quote:
Originally Posted by Aditya11ttt View Post
try this try to find jtag1 connector name on the board only space will be there without connector !!
Do you know which or where is the RST#? It's a T490 with the MEC1663
Any help is really appreciated.
iTec is offline   Reply With Quote
Old 02-28-2021, 12:43 AM   #11
black0hackers
Badcaps Veteran
 
Join Date: Jul 2020
City & State: oregon
My Country: USA
I'm a: Knowledge Seeker
Posts: 236
Default Re: mec 16xx dump with info block

Where is point to connect?
picture add of T490S
Attached Images
File Type: jpg da2d5d83f51605485c07.jpg (669.7 KB, 497 views)
black0hackers is offline   Reply With Quote
Old 02-28-2021, 06:45 PM   #12
AAAC
Badcaps Veteran
 
Join Date: Jan 2020
City & State: Zacatecas, Zacatecas.
My Country: Mexico
Line Voltage: 120VAC 60Hz
I'm a: Hobbyist Tech
Posts: 244
Default Re: mec 16xx dump with info block

@black0hackers
Upload another picture of complete motherboard, as most of the JTAG signals may be already in a connector pads.
  • So the JTAG signal wires will need to be soldered to this connector pads.
  • You will need to move a very tiny PULL-UP resistor and make it a PULL-DOWN resistor to enable JTAG interface.
  • Then you will need to locate RST# signal somewhere around MECxxxx chip by looking at schematic for this T490S, or by looking at another model schematic that uses the same MECxxxx chip part number (although I've read that this signal is not needed, someone with more JTAG experience may confirm/deny this).
AAAC is offline   Reply With Quote
Old 04-13-2021, 06:19 PM   #13
JOHNLAG7
New Member
 
Join Date: Nov 2014
City & State: megalopolis
My Country: Greece
I'm a: Knowledge Seeker
Posts: 8
Default Re: mec 16xx dump with info block

There is a photo t490 jtag1 and pins ,can someone draw the connection ?
Attached Images
File Type: jpg 20210414_030942.jpg (1.01 MB, 524 views)
File Type: jpg 20210414_031329.jpg (178.9 KB, 392 views)
File Type: jpg 20210414_031311.jpg (839.2 KB, 383 views)
JOHNLAG7 is offline   Reply With Quote
Old 04-15-2021, 07:55 AM   #14
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,255
Default Re: mec 16xx dump with info block

Looks like JTAG reset resistor is marked in red box. Move the resistor next to that capacitor on the empty pads.

I will test it tomorrow.
Attached Images
File Type: jpg T490_JTAG_RST.jpg (541.8 KB, 653 views)
RethoricalCheese is offline   Reply With Quote
Old 04-16-2021, 01:02 AM   #15
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,255
Default Re: mec 16xx dump with info block

The resistor in my last picture was indeed correct. I can read/write MEC now.

The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used?

Last edited by RethoricalCheese; 04-16-2021 at 01:04 AM..
RethoricalCheese is offline   Reply With Quote
Old 04-17-2021, 02:41 AM   #16
SMDFlea
Super Moderator
 
Join Date: Jan 2018
City & State: York
My Country: UK
I'm a: Knowledge Seeker
Posts: 10,461
Default Re: mec 16xx dump with info block

Quote:
Originally Posted by RethoricalCheese View Post
The resistor in my last picture was indeed correct. I can read/write MEC now.

The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used?
A Vertyanov jig or SVOD3
SMDFlea is online now   Reply With Quote
Old 04-17-2021, 07:27 AM   #17
AAAC
Badcaps Veteran
 
Join Date: Jan 2020
City & State: Zacatecas, Zacatecas.
My Country: Mexico
Line Voltage: 120VAC 60Hz
I'm a: Hobbyist Tech
Posts: 244
Default Re: mec 16xx dump with info block

@RethoricalCheese
In your last post you mention you can read/write MEC now, but you describe your problem as is not able to clear the write-only area... have you tried to disconnect all sources of energy for 2-3 minutes? seems like this area is temporarily copied to volatile memory too (ram), so removing energy for a couple of minutes will do the trick.
After this you will have to use Lenovo UEFI Maintenance utility to write Model Number, Serial Number, TYPE and other data for ThinkPad to be left as it was before programming MEC chip.

Last edited by AAAC; 04-17-2021 at 07:47 AM..
AAAC is offline   Reply With Quote
Old 04-17-2021, 11:03 AM   #18
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,255
Default Re: mec 16xx dump with info block

Thanks, will try. Did not try removing power for more than a few seconds.
RethoricalCheese is offline   Reply With Quote
Old 04-18-2021, 11:53 AM   #19
keczuk
Member
 
Join Date: Dec 2019
City & State: Internet
My Country: WWW
I'm a: Knowledge Seeker
Posts: 60
Default Re: mec 16xx dump with info block

Hi

I have question. I use svod3 for program this mec and when i read few times mec dump in hxd i see all dump are different. When i try write my clean ec dump i have error in veryfiication. Any idea how solve of my problem ?
keczuk is offline   Reply With Quote
Old 04-18-2021, 04:31 PM   #20
AAAC
Badcaps Veteran
 
Join Date: Jan 2020
City & State: Zacatecas, Zacatecas.
My Country: Mexico
Line Voltage: 120VAC 60Hz
I'm a: Hobbyist Tech
Posts: 244
Default Re: mec 16xx dump with info block

@keczuk
Upload a picture of your setup. Have you added PULL-UP resistors to JTAG signals.
At the time we did this one we couldn't find a schematic for T490, but X1 Carbon 6th Gen (T480s and others) have same MEC1663 EC/KBC chip so we used them as reference.

Attached Images
File Type: png JTAG-signals-resistors.png (97.4 KB, 1525 views)

Last edited by AAAC; 04-18-2021 at 04:33 PM..
AAAC is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



Badcaps.net Technical Forums 2003 - 2022
Powered by vBulletin ®
Copyright ©2000 - 2022, Jelsoft Enterprises Ltd.
All times are GMT -6. The time now is 08:44 AM.
Did you find this forum helpful?