support board & news
Joined: 07 Mar 2004
|Posted: Mon Oct 12, 2015 10:17 am Post subject: Unlocking T440..T480, T570, X1 C gen2/8, X270, W540,W541,etc
|These models listed below are using SMSC MEC1633L (or equivalents) to store the Supervisor password. Maybe Lenovo will come around with another chip for the next models, so we will update the list with all those we tested already.
Unlocked so far (All sub-models included. The list might be outdated, see a more detailed list in the next post):
A275, E450, E460, E470, E550, E560, L460, L560, T440, T450, T460, T470, T480, T540, T550, T560, T570, T580, X1 Yoga all gens, X1 carb gen2-gen6, X240, X250, X260, X270, X280, W540, W541, W550, Helix gen3, Thinkpad Yoga 11e, 12 and 15, Yoga260, Yoga 370, Yoga 460, P50, P40 Yoga, P51, P70. And more..
Unlocking solution is finally available and requires SPEG programmer to be able to flash the BIOS.
The process is:
1. Reading the BIOS and create a valid dump. In a Thinkpad, the BIOS is married to the internal TPM chip and contains a unique signature of it, so it is important that the original BIOS to be a correct read out for the success of the whole operation and to restore the BIOS afterwards.
2. Patching the BIOS binaries and inject a small allservice.ro UEFI program. This program will read the secure eeprom, reset TPM certificate and password, write secure eeprom and reconstruct all data.
3. Write the patched BIOS dump (this will only function in that TP btw), start the laptop and generate a Hardware ID. We will send you a unique key that will activate the Allservice BIOS, while the BIOS is loading it will execute the unlock routine and unlock the SVP and TPM.
4. Finally, write the original BIOS dump back for normal operations and enjoy the laptop.
We can also disable Computrace or change the SN/UUID and reset RFID checksum error by using our UEFI program in the same manner, if necessary
The unlock service price is per machine (like we do for the Macbook/iMac, HP, Acer, etc) For service price and availability please read the next post below. You may contact email@example.com for any inquiry.
We shall be able to also provide, for service shops only, a software solution that is able to dump/flash the MEC controller secure area from an USB device, and to have more control of the security operations, more like the usual way. Though this solution is still in progress..
ALLservice HQ, Romania.
Last edited by victor on Wed Oct 17, 2018 8:47 pm; edited 54 times in total
Joined: 07 Mar 2004
|Posted: Wed Oct 21, 2015 3:48 pm Post subject: Allservice unlock solution. UEFI DXE Driver
|UPDATED October 2018
The very final DXE driver version is finished and can do everything automatically: read MEC1633L secure eeprom, reset the SVP and certificate, write the secure eeprom, then reset TPM and de-activate Computrace (if active) and set the correct checksums. All in one step, you have to only load the patched BIOS and fire it up. All will be done in a few seconds.
We tested it with the follwing (all submodels included. The list might be outdated!):
A275, E450, E460, E470, E550, E560, L460, L560, T440, T440s, T440p, T450, T450s, T450p, T540, T540p, T550, W540, W541, W550s, X240, X250, X1 carbon gen2..gen6, Helix new gen, Thinkpad Yoga 11e, 12 and Yoga 15(with Compal Embedded Controller*), Lenovo 13, P40, P50, P51 and P70. We also unlocked the latest X1 Yoga gen 3, Yoga 260, Yoga 370, Yoga 460, X260, X270, X280, T460, T460s, T560, T470, T470s, T480, T480s, T570, T580, featuring the new ACM and BootGuard Key Manifest. Unlocked also Thinkpad P40 Yoga, P51 and Lenovo 13 and X1 carbon gen6.
Here is a X1 gen 6 booting our BIOS faster than the original. No beeping or other errors. Of course, this is a temporary boot on for the unlocking operation only. https://www.allservice.ro/forum/images/IMG_8535.MOV
*The solution will work in any new models including those with Compal EC.
Since Oct 2015, our service is also available "per machine", you can buy one unlock only, meaning the original patched BIOS will only work once and only on the locked laptop (naturally, the BIOS contains the unique TCG/TPM signature), based on a unique Hardware ID. Our support team will prepare the BIOS for you.
The unlock service price per 1 machine is US $65.
To order the unlock service:
1.a. If you have a SPI flash programmer then read the laptop's BIOS (8pin SOIC) and obtain a valid dump. Note that some models, i. e. T440p/T540p, have two BIOS chips so we need both of them.
1.b. If you don't have such device, then you may order SPEG in our store www.allservice.ro/store/utils/
This service is NOT INCLUDED with SPEG, therefore is not a bonus for buying SPEG programmer!
2. Send the payment for the service ($65) via PayPal to firstname.lastname@example.org then email the BIOS dump to the same email address, also email us the S/N and LAN MAC that is located on the RAM socket stickers.
Note: if you want us to email you a complete invoice for SPEG + service then contact us at email@example.com
3. We will verify the BIOS integrity, we will check the MAC and TCPA sig to see if they are genuine then patch the BIOS with our Allservice UEFI DXE (boot service driver) modules and send it to you along with the activation key for your laptop.
We professionally provide our unlocking/BIOS repair service for over 80 service centers worldwide, and we are the ONLY ONES selling OUR software or services online, here at allservice.ro. We do not have agreements and we do not allow third parties to resell our service over the Internet!
Therefore if you see some websites or individuals claiming that they can unlock latest Lenovo models and sell you an "Allservice" patched BIOS then they are scam or they send you a counterfeit or pirated Allservice BIOS file! And is a high risk that this will make your Thinkpad security chip inoperable!
If you think you're a victim of a counterfeit/scam then claim your money back!
Make sure you use PayPal whenever possible to be covered just in case..
You may contact us at firstname.lastname@example.org for any question or support.
Screenshot of the BIOS POST on T440s motherboard with initial release and X280 with latest version.
Also see below (scroll down more) the BIOS location for all mentioned models.
T440s motherboard with initial release.
Keep in mind that this list might be outdated as we service new models every day. Not all models we unlocked are in the list or pictured below. Email us at email@example.com if you have any question regarding your model.
Lenovo L460, L560*
*Both models may have only one 16Mbyte chip or 2x8Mbyte chips.
Helix new generations
X1 Carbon/X1 Yoga
Thinkpad Yoga 12 and Yoga 15
Yoga 260, Yoga 370, Yoga 470
All images are copyright www.allservice.ro
ALLservice HQ, Romania.
||All times are GMT + 2 Hours
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum