![]() |
|
|
Thread Tools | Display Modes |
![]() |
#1 |
New Member
Join Date: Dec 2019
City & State: Dubai
My Country: VAE
I'm a: Knowledge Seeker
Posts: 4
|
![]() Hi,
anyone can share a (256kb) MEC dump with info block? (containing SER#,CON#,USR#...) or share the SVP offset (e.g. for DXE mapped its 0x1F400)? With SVP would be great. thanks |
![]() |
![]() |
![]() |
#2 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,286
|
![]() If you want to unlock lenovo, use the patch method instead.
|
![]() |
![]() |
![]() |
#3 |
New Member
Join Date: Dec 2019
City & State: Dubai
My Country: VAE
I'm a: Knowledge Seeker
Posts: 4
|
![]() doesnt work on t490 and above
|
![]() |
![]() |
![]() |
#4 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,286
|
![]() Okay, thats where you should have started
![]() I think there is a checksum aswell. So if you want to delete SVP, got to consider that aswell. But since I have not modified mec-s, I am not sure if it is important or even true ![]() Anyway, good luck with trying and let us know how it goes. |
![]() |
![]() |
![]() |
#5 |
New Member
Join Date: Dec 2019
City & State: Dubai
My Country: VAE
I'm a: Knowledge Seeker
Posts: 4
|
![]() i only need a dump with this block, e.g. v**fix has but i dont wanna buy it...
FYI: erasing+rewriting MEC to get rid of SVP works like a charm, unfortunately UUID,SN and such are "lost" due to the fact that this info block seems to be read protected in mec1663, with the offsets avail i could skip this block during erase/write and then I wouldnt need to rewrite it... so any dump should do thus i didnt mention T490 and later Last edited by superhansi; 02-25-2020 at 02:53 AM.. Reason: typo |
![]() |
![]() |
![]() |
#6 |
Member
Join Date: Apr 2014
City & State: Bucharest
My Country: Romania
I'm a: Knowledge Seeker
Posts: 23
|
![]() Hy. I also have a T490s. Did you remove the chip or connected the programmer via wires to the motherboard? I can't find schematic or where the pins are. Also, did you succeed in removing SVP ?
|
![]() |
![]() |
![]() |
#7 |
Adi
Join Date: Feb 2019
City & State: Kolkata
My Country: India
Line Voltage: 220V
I'm a: Knowledge Seeker
Posts: 110
|
![]() try this try to find jtag1 connector name on the board only space will be there without connector !!
|
![]() |
![]() |
![]() |
#8 |
Member
Join Date: Apr 2014
City & State: Bucharest
My Country: Romania
I'm a: Knowledge Seeker
Posts: 23
|
![]() |
![]() |
![]() |
![]() |
#9 |
Badcaps Veteran
Join Date: Nov 2011
Posts: 374
|
![]() On these if you replace the mec ic will that solve the password ?
remove ic and put another one in ? Is that confirmed solution ? |
![]() |
![]() |
![]() |
#10 |
New Member
Join Date: Oct 2017
City & State: Houston Texas
My Country: USA
I'm a: Knowledge Seeker
Posts: 14
|
![]() |
![]() |
![]() |
![]() |
#11 |
Badcaps Veteran
Join Date: Jul 2020
City & State: oregon
My Country: USA
I'm a: Knowledge Seeker
Posts: 236
|
![]() Where is point to connect?
picture add of T490S |
![]() |
![]() |
![]() |
#12 |
Badcaps Veteran
Join Date: Jan 2020
City & State: Zacatecas, Zacatecas.
My Country: Mexico
Line Voltage: 120VAC 60Hz
I'm a: Hobbyist Tech
Posts: 291
|
![]() @black0hackers
Upload another picture of complete motherboard, as most of the JTAG signals may be already in a connector pads.
|
![]() |
![]() |
![]() |
#13 |
New Member
Join Date: Nov 2014
City & State: megalopolis
My Country: Greece
I'm a: Knowledge Seeker
Posts: 8
|
![]() There is a photo t490 jtag1 and pins ,can someone draw the connection ?
|
![]() |
![]() |
![]() |
#14 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,286
|
![]() Looks like JTAG reset resistor is marked in red box. Move the resistor next to that capacitor on the empty pads.
I will test it tomorrow. |
![]() |
![]() |
![]() |
#15 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,286
|
![]() The resistor in my last picture was indeed correct. I can read/write MEC now.
The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used? Last edited by RethoricalCheese; 04-16-2021 at 01:04 AM.. |
![]() |
![]() |
![]() |
#16 |
Super Moderator
Join Date: Jan 2018
City & State: York
My Country: UK
I'm a: Knowledge Seeker
Posts: 10,787
|
![]() A Vertyanov jig or SVOD3
|
![]() |
![]() |
![]() |
#17 |
Badcaps Veteran
Join Date: Jan 2020
City & State: Zacatecas, Zacatecas.
My Country: Mexico
Line Voltage: 120VAC 60Hz
I'm a: Hobbyist Tech
Posts: 291
|
![]() @RethoricalCheese
In your last post you mention you can read/write MEC now, but you describe your problem as is not able to clear the write-only area... have you tried to disconnect all sources of energy for 2-3 minutes? seems like this area is temporarily copied to volatile memory too (ram), so removing energy for a couple of minutes will do the trick. After this you will have to use Lenovo UEFI Maintenance utility to write Model Number, Serial Number, TYPE and other data for ThinkPad to be left as it was before programming MEC chip. Last edited by AAAC; 04-17-2021 at 07:47 AM.. |
![]() |
![]() |
![]() |
#18 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,286
|
![]() Thanks, will try. Did not try removing power for more than a few seconds.
|
![]() |
![]() |
![]() |
#19 |
Member
Join Date: Dec 2019
City & State: Internet
My Country: WWW
I'm a: Knowledge Seeker
Posts: 60
|
![]() Hi
I have question. I use svod3 for program this mec and when i read few times mec dump in hxd i see all dump are different. When i try write my clean ec dump i have error in veryfiication. Any idea how solve of my problem ? |
![]() |
![]() |
![]() |
#20 |
Badcaps Veteran
Join Date: Jan 2020
City & State: Zacatecas, Zacatecas.
My Country: Mexico
Line Voltage: 120VAC 60Hz
I'm a: Hobbyist Tech
Posts: 291
|
![]() @keczuk
Upload a picture of your setup. Have you added PULL-UP resistors to JTAG signals. At the time we did this one we couldn't find a schematic for T490, but X1 Carbon 6th Gen (T480s and others) have same MEC1663 EC/KBC chip so we used them as reference. Last edited by AAAC; 04-18-2021 at 04:33 PM.. |
![]() |
![]() |
![]() |
Thread Tools | |
Display Modes | |
|
|