Announcement

Collapse
No announcement yet.

Legion Y540 Bios Password Reset

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Legion Y540 Bios Password Reset

    I created a supervisor password for my laptop a while back and I forgot it. It can't be reset by resetting CMOS. Can I extract it from a BIOS dump or through another method without a bios/eeprom programmer?

    #2
    Originally posted by NootABoot View Post
    I created a supervisor password for my laptop a while back and I forgot it. It can't be reset by resetting CMOS. Can I extract it from a BIOS dump or through another method without a bios/eeprom programmer?
    NO..you need an SPI programmer to extract the contents of the bios chip...
    Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests all donations are welcome, click:

    >>>>> https://www.badcaps.net/index.php?pageid=donate1 <<<<<

    Every donation made will go towards server fees and maintenance costs.

    Comment


      #3
      Originally posted by peste View Post

      NO..you need an SPI programmer to extract the contents of the bios chip...
      I don't know if this is insufficient (I don't anything about bios programming) but I got this image from ME tools. Is it possible to reset the password in it and reflash the bios using an all-software solution (by modifying the original bios update exe, for example)?
      Attached Files

      Comment


        #4
        Originally posted by NootABoot View Post

        I don't know if this is insufficient (I don't anything about bios programming) but I got this image from ME tools. Is it possible to reset the password in it and reflash the bios using an all-software solution (by modifying the original bios update exe, for example)?
        RULES UPDATE for BIOS requests/offers AVOID BANNING, READ BEFORE POSTING
        https://www.badcaps.net/forum/troubl...before-posting

        You MUST:
        • Provide the full machine model number, serial number (or Service tag, SNID) and the board model number (see https://www.badcaps.net/forum/showthread.php?t=88758 ) ,The serial number, make, full model number, motherboard model and revision (except QR codes) must be written/typed at your request as per the rules. Not as a picture, part of the file name and so on.
        All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

        Comment


          #5
          Sorry for that.

          Laptop: Lenovo Legion Y540-15IRH
          Model: 81SX
          S/N: PF1YVPN7
          MTM: 81SX005TAD
          Motherboard model: Lenovo LNVNB161216
          Version: SD0K11763
          Chipset: Intel HM370
          BIOS version: Lenovo (but bios update utility says Insyde H20) BHCN44WW

          Can the password be reset/extracted? If so, and if you don't mind, can you tell me how you do it?

          Comment


            #6
            Edit: full bios image instead of bios region only
            Attached Files

            Comment


              #7
              Originally posted by NootABoot View Post
              Edit: full bios image instead of bios region only
              Try
              Attached Files

              Comment


                #8
                Originally posted by qayyum786 View Post

                Try
                Sorry for the noob question, but how can I flash without a programmer? FPT says something about range protection registers. Can I flash in dos from a usb flash drive? (Keeping in mind I'm in efi mode with secure boot enabled and can't change that because I don't have the password.)

                I was also reading on winraid and found a tool called RU Shell which, as I understand, allows one to directly modify the bios on board. Could it be useful here?

                Comment


                  #9
                  Here's a thought. I was fiddling around and I was able to disable FPRR and BIOS lock through H2OUVE by reading the variables from IFR extractor. I also found the prompt asking for the supervisor password. However, the offset doesn't even exist in H2OUVE. Can this be exploited in some way?

                  I can flash the image you sent me but I'm worried about bricking especially since I don't have a programmer.

                  Comment


                    #10
                    Originally posted by NootABoot View Post

                    I don't know if this is insufficient (I don't anything about bios programming) but I got this image from ME tools. Is it possible to reset the password in it and reflash the bios using an all-software solution (by modifying the original bios update exe, for example)?
                    The password is "am2431121"

                    Comment


                      #11
                      Originally posted by fire1234 View Post

                      The password is "am2431121"
                      Thank you so much!!! Mind telling me how you were able to find it? If not, I have a friend with the same laptop, can I give you his dump to find out the password?

                      Comment


                        #12
                        Originally posted by NootABoot View Post

                        Thank you so much!!! Mind telling me how you were able to find it? If not, I have a friend with the same laptop, can I give you his dump to find out the password?
                        Share your bios with a friend and we'll see what we can do.

                        Comment


                          #13
                          Originally posted by fire1234 View Post

                          The password is "am2431121"
                          Wow, how were you able to do this? I was under impression the password is stored in EC.
                          I would appreciate it greatly if you could take a look at my Y540 15IRH dump, others have done so and concluded that the fix is more complex. Has BIOS administrator password applied (boots into Windows, just cannot configure BIOS) and previous owner has forgotten it, much to my frustration.

                          S/N: PF1X715
                          Board: NM-C221 Rev 2.0

                          Can provide any other details if necessary
                          Attached Files

                          Comment


                            #14
                            Originally posted by pickledegg View Post

                            Wow, how were you able to do this? I was under impression the password is stored in EC.
                            I would appreciate it greatly if you could take a look at my Y540 15IRH dump, others have done so and concluded that the fix is more complex. Has BIOS administrator password applied (boots into Windows, just cannot configure BIOS) and previous owner has forgotten it, much to my frustration.

                            S/N: PF1X715
                            Board: NM-C221 Rev 2.0

                            Can provide any other details if necessary
                            Pass : 5545


                            ----------------------------------------------------------------------------------------------------------------------------------------------------------
                            All donations to Badcaps are welcome.
                            Become a Badcaps supporter
                            >>>>> click on this link to donate <<<<<
                            Thanks to all supporters.
                            ----------------------------------------------------------------------------------------------------------------------------------------------------------​

                            Comment


                              #15
                              Originally posted by hoaca388 View Post

                              Pass : 5545
                              Outstanding! thank you, this worked.

                              I know how you got it so quickly as well, I had considered that method but every person I spoke to about it assured me the password was stored in EC on this model! A little annoyed by that... should have come here first!

                              Thank you.

                              Comment


                                #16
                                Originally posted by pickledegg View Post

                                Outstanding! thank you, this worked.

                                I know how you got it so quickly as well, I had considered that method but every person I spoke to about it assured me the password was stored in EC on this model! A little annoyed by that... should have come here first!

                                Thank you.
                                how to find ? can you shar ?
                                ************************************************** ***********************************
                                Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests
                                all donations are welcome,
                                see the donate button at the bottom of the page, or
                                >>>>> click on this link to donate via PayPal. <<<<<
                                Every donation made will go towards server fees and maintenance costs.
                                ************************************************** ***********************************

                                Comment


                                  #17
                                  привет ребята купил ноутбук в нерабочем состоянии для восстановления , проблема оказалась в чипе RTX3060 , заменив высветился код 43 первым делом хочется использовать Mats Mods для проверки чипов памяти , но вот проблема BIOS под паролем ,помогите снять пароль ,програмная часть не самая сильная у меня . Дамп снят SVOD 4 платформа Nm-c211 rev 2.0 (legion y540 15IRH)

                                  Hi guys, I bought a non-working laptop for recovery, the problem turned out to be in the RTX3060 chip, after replacing it, code 43 appeared, the first thing I want to do is use Mats Mods to check the memory chips, but here is the problem with the BIOS password, help me remove the password, the software part is not the strongest for me. The dump was taken SVOD 4 platform Nm-c211 rev 2.0 (legion y540 15IRH)

                                  in English please..
                                  Attached Files

                                  Comment


                                    #18
                                    Originally posted by alexeyb43 View Post
                                    привет ребята купил ноутбук в нерабочем состоянии для восстановления , проблема оказалась в чипе RTX3060 , заменив высветился код 43 первым делом хочется использовать Mats Mods для проверки чипов памяти , но вот проблема BIOS под паролем ,помогите снять пароль ,програмная часть не самая сильная у меня . Дамп снят SVOD 4 платформа Nm-c211 rev 2.0 (legion y540 15IRH)

                                    Hi guys, I bought a non-working laptop for recovery, the problem turned out to be in the RTX3060 chip, after replacing it, code 43 appeared, the first thing I want to do is use Mats Mods to check the memory chips, but here is the problem with the BIOS password, help me remove the password, the software part is not the strongest for me. The dump was taken SVOD 4 platform Nm-c211 rev 2.0 (legion y540 15IRH)

                                    in English please..
                                    post S/N,TYPE,etc..
                                    Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests all donations are welcome, click:

                                    >>>>> https://www.badcaps.net/index.php?pageid=donate1 <<<<<

                                    Every donation made will go towards server fees and maintenance costs.

                                    Comment


                                      #19
                                      Originally posted by alexeyb43 View Post
                                      привет ребята купил ноутбук в нерабочем состоянии для восстановления , проблема оказалась в чипе RTX3060 , заменив высветился код 43 первым делом хочется использовать Mats Mods для проверки чипов памяти , но вот проблема BIOS под паролем ,помогите снять пароль ,програмная часть не самая сильная у меня . Дамп снят SVOD 4 платформа Nm-c211 rev 2.0 (legion y540 15IRH)

                                      Hi guys, I bought a non-working laptop for recovery, the problem turned out to be in the RTX3060 chip, after replacing it, code 43 appeared, the first thing I want to do is use Mats Mods to check the memory chips, but here is the problem with the BIOS password, help me remove the password, the software part is not the strongest for me. The dump was taken SVOD 4 platform Nm-c211 rev 2.0 (legion y540 15IRH)

                                      in English please..
                                      Hi guys, I bought a non-working laptop for recovery, the problem turned out to be in the RTX3060 chip, after replacing it, code 43 appeared, the first thing I want to do is use Mats Mods to check the memory chips, but there is a problem with the BIOS password, help remove the password, the software part is not the strongest for me. Dump taken SVOD 4 platform Nm-c211 rev 2.0 (legion y540 15IRH)

                                      Hi guys, I bought a non-working laptop for recovery, the problem turned out to be in the RTX3060 chip, after replacing it, code 43 appeared, the first thing I want to do is use Mats Mods to check the memory chips, but there is a problem with the BIOS password, help remove the password, the software part is not the strongest for me. Dump taken SVOD 4 platform Nm-c211 rev 2.0 (legion y540 15IRH)
                                      S/N PF22SBQW
                                      TYPE 81SX
                                      MTM 81SX016GPB
                                      FACTORY ID JVHFC1

                                      Comment


                                        #20
                                        Originally posted by alexeyb43 View Post

                                        Hi guys, I bought a non-working laptop for recovery, the problem turned out to be in the RTX3060 chip, after replacing it, code 43 appeared, the first thing I want to do is use Mats Mods to check the memory chips, but there is a problem with the BIOS password, help remove the password, the software part is not the strongest for me. Dump taken SVOD 4 platform Nm-c211 rev 2.0 (legion y540 15IRH)

                                        Hi guys, I bought a non-working laptop for recovery, the problem turned out to be in the RTX3060 chip, after replacing it, code 43 appeared, the first thing I want to do is use Mats Mods to check the memory chips, but there is a problem with the BIOS password, help remove the password, the software part is not the strongest for me. Dump taken SVOD 4 platform Nm-c211 rev 2.0 (legion y540 15IRH)
                                        S/N PF22SBQW
                                        TYPE 81SX
                                        MTM 81SX016GPB
                                        FACTORY ID JVHFC1
                                        try pass: 2014
                                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                                        https://www.badcaps.net/donate/
                                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                                        Comment

                                        Working...
                                        X