Announcement

Collapse
No announcement yet.

T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

    Here is all the info you should need to remove bios password from your same model or one with an MEC-Chip and also write back the config data

    T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

    See Diagram for Wiring.

    Use MEC-1633#ISP on your RT809h
    This is same Jtag pinout and method for T490S/X390
    (But your R/W 10K Resistor Location May In a Different Location)


    MEC-Chips Store Bios Password In a Secure Un-Editable Area

    Following steps clear that secure area to re-initialize itself to default (Blank)
    Removing Bios Password Steps:
    -Read MEC Chip
    -Erase chip
    -Unplug power from board for 2 Min
    -Write dump back that we just read.-Password Is now Gone
    Remember to move R/W Resistor Back To Original Position For Normal Operation.

    After clearing bios password you have also wiped the serial and model number to restore them use the ThinkPad Config Information Update Utility.
    Serial/Model Info can usually be found on motherboard stickers and bottom cover.







    To set the Serial Number, Model Number, Etc back onto a Lenovo T14s:

    I Used "ThinkPad Config Information Update Utility v1.11" attached

    -Extract and run "usbfmtpw.exe" this will format your USB and copy the files over.
    (check that the files copied after format. if not manually copy them to the root of the USB).
    -Insert to laptop and boot to USB FDD it is EFI not Legacy (USB you just created).
    -Now go 1, then use 2 to read current keys. record any keys shown, take a photo of them they will be erased if there not already.
    -Now go back to main menu and choose initialize EEPROM, this clears all keys plus UUID and now the overflow error wont happen.
    -Now go 1, then use 1 again to add new info, enter C0 then Enter.
    -Now enter serial and model in long form will start with 1S so (1STTTTMMMMCCSSSSSSS)
    -Enter and Key is stored.
    -If you like can add more or go back and use option 3 for a few more config details. (I set my brand name there)
    -Once all info is set go to assign UUID, and say Yes.
    (once you generate the UUID you cannot edit the serials unless you initialize and do them all over again.
    -Reboot and check bios screen your info should be there no more beeps on boot.


    Product ID: TTTT-MMMMCC
    Serial#: SS-SSSSS

    TTTT = Machine Type
    MMMM = Model Type
    CC = Country Code
    SSSSSSS = Serial Number



    Coolshrimp
    Attached Files
    Last edited by SMDFlea; 10-24-2022, 05:01 AM.

    #2
    Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

    Add to a Sticky Guide?

    Comment


      #3
      Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

      I tried this on my x390 but it still booted up with a password after all the procedure.

      Comment


        #4
        Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

        Originally posted by mily.gawel View Post
        I tried this on my x390 but it still booted up with a password after all the procedure.
        Did the laptop die after erasing the chip? What Mec-16xx chip?

        Comment


          #5
          Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

          the laptop was dead after cleaning, after uploading the same charge again and moving the resistor to its place, it turned on correctly but still has the password. MEC1663-BA0

          Comment


            #6
            Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

            Originally posted by mily.gawel View Post
            the laptop was dead after cleaning, after uploading the same charge again and moving the resistor to its place, it turned on correctly but still has the password. MEC1663-BA0
            Did you try to remove the charger, bios and main battery after erasing chip.
            Let it sit for 5min then reflash and boot.

            Also it's the same chip but maybe this model the password is stored in the bios image. May have to manually edit it out or try the Lenovo bios unlock tool.

            Comment


              #7
              Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

              I used this procedure exactly as described to remove the BIOS password of a T490s (MEC1663). I think I succeeded, at least my RT809H only showed me success messages. After I soldered the resistor back to the old position, the laptop was dead and would not boot. No fan, no LED. Although the 3,3V and the 5V rail are working.
              I noticed the following irregularities: When connecting the charger, the RT809H program crashed. After restarting the program, it behaved normally.
              After I disconnected the charger for a few minutes and reconnected it, there was no fan and no LED. Still I was able to flash the original dump again, at least I got a success message.

              Does anyone have any ideas?

              Comment


                #8
                Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                I have nm-c891 when i read mec1663 the file is empty any help
                Last edited by didouche1200; 04-15-2023, 06:34 AM.

                Comment


                  #9
                  Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                  HI SIR
                  PLEASE TELL ME
                  LENOVO MEC 1663 BAO
                  Svod4 programmer WORK OR NOT

                  Comment


                    #10
                    Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                    Originally posted by ranajee7750 View Post
                    HI SIR
                    PLEASE TELL ME
                    LENOVO MEC 1663 BAO
                    Svod4 programmer WORK OR NOT
                    SVOD 3 and SVOD 4, 100% work.

                    Comment


                      #11
                      Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                      I tried a second time, this time with a T14s. Everything went fine, but after moving the resistor back the laptop wouldn't start: no fan, no LED, completely dead. Can anyone confirm that this really works?

                      Comment


                        #12
                        Question about EC Software for Lenovo

                        When flashing an EC on a Lenovo laptop, the software can be taken from any BIOS update package. For example, extracting the BIOS package for a T14s will result in a file C:\DRIVERS\FLASH\n2yuj14w\20231206.10111452\N2YET37W\$0AN2Y00.FL2 containing the EC image. Not exactly: the EC image is preceded by 16 bytes of other data and is much larger than the 192kB of the actual EC image. My question is, do I need to worry about the data after the 192kB?

                        Comment


                          #13
                          Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                          Originally posted by rumpumpel1 View Post
                          I tried a second time, this time with a T14s. Everything went fine, but after moving the resistor back the laptop wouldn't start: no fan, no LED, completely dead. Can anyone confirm that this really works?
                          It's working but I did chose MEC1633_256kB on RT809H
                          ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                          https://www.badcaps.net/donate/
                          ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                          Comment


                            #14
                            Re: Question about EC Software for Lenovo

                            EC for T14s is 256kb.
                            ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                            https://www.badcaps.net/donate/
                            ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                            Comment


                              #15
                              Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                              thanks, you made my day!
                              Now it works.
                              But that means, that the original description is just wrong: instead of MEC-1633#ISP it should read MEC1633_256K.

                              Comment


                                #16
                                Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                                Here are some more details in order to enjoy the laptop without password:

                                1. Using the ThinkPad Maintenance Utilities you need to set the brand name. Otherweise you get a beep concert during boot and the error message "Product Name is invalid":
                                - Update Configuration Area
                                - brand name
                                - Write brand name to EEPROM
                                - Special brand name
                                - T14s Gen 1

                                2. Probably you want to set the System board serial number:
                                - Add S/N data to EEPROM
                                - B0 - System board Serial Number
                                - enter 21 chars: Machine-Type-Model and System board serial number

                                Comment


                                  #17
                                  Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                                  hello
                                  where i find B0 system board serial number
                                  i cant find it
                                  i do every thing ok i charge the io bios and ok remove the password and enter serial number just i have one problem "Product Name is invalid" how can i solve it ??

                                  Comment


                                    #18
                                    Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                                    Originally posted by hamodeh View Post
                                    hello
                                    where i find B0 system board serial number
                                    i cant find it
                                    i do every thing ok i charge the io bios and ok remove the password and enter serial number just i have one problem "Product Name is invalid" how can i solve it ??
                                    use this tool and follow the instructions given in side and you are good to go
                                    Attached Files

                                    Comment


                                      #19
                                      Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                                      My board NM-B861. I use RT809H programmer, I follow the steps and the result is just empty bios file

                                      Comment


                                        #20
                                        Re: T14s - MEC-1663 - Jtag - Pinout - Bios Password Removal

                                        Originally posted by jacobk1508 View Post
                                        My board NM-B861. I use RT809H programmer, I follow the steps and the result is just empty bios file
                                        you have to power the board before reading EC
                                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                                        https://www.badcaps.net/donate/
                                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                                        Comment

                                        Working...
                                        X