unbrick HP m6-1000sg / bios dump

Discussion in 'BIOS Mods' started by nexus76, Oct 27, 2015.

  1. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #1 nexus76, Oct 27, 2015
    Last edited: Oct 27, 2015
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,381
    15,033
    340
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #3 nexus76, Oct 27, 2015
    Last edited: Oct 27, 2015
    (OP)
    Thanks Tito, indeed I followed the easier route first and tried the recovery mode, but now I'm not sure if this device
    even has a recovery option builtin.
    I tried it at least 30 times but holding windows + b while pluggin in the power cord, and pushed additionally the power-on button,
    it doesn't have any effect, the laptop doesn't start the recovery process.
    Tried even Fn+B and FN+ESC, nothing worked an I can see the usb stick isn't even accessed, nothing happens.
    The bios ^^ provided by HP can't be opened by Andy's Phoenix tool or using UEFI Tool, it looks like binary garbage in HxD.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,314
    1,433
    180
  5. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,381
    15,033
    340
    @nexus76 @LatinMcG

    sp66782.exe/018A4.FD is signed with new RSA signature so the hewprsa.exe bundled with Phoenix Tool can't decrypt it. Get the new one from here & replace it with the old one, then you will be able to decrypt it.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    thanks so much Tito, the dump (018A4.FD.DEC + RSA.SIG) looks like a valid uefi image now, it can be opened with coderush's UEFITool even,
    do you think it's enough to flash just this binary to the bios chip? Or will the EC binary be required with HP laptops?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,381
    15,033
    340
    #7 Tito, Oct 29, 2015
    Last edited: Jul 20, 2017
    @nexus76

    018A4.FD.DEC should contain both BIOS & EC dump; you need to read the EC chip content first & compare with the decrypted image to get the exact offset. LatinMcG or BDMaster can help you with this.

    On the other hand, the USB recovery should work - please try with the 018A4.FD.DEC (rename & rearrange properly). I've recovered many HPs, never faced any problem.

    :g:
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    ok, I'll try it once more before disassembling the device completely, but as I mentioned, the usb stick isn't even accessed, fat16 or fat32, what's the correct filesystem you used?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,381
    15,033
    340
    @nexus76

    4/8 GB pendrive + FAT32 works for me always.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #10 nexus76, Oct 29, 2015
    Last edited: Oct 29, 2015
    (OP)
    following this guide in every detail nothing happens at holding win + b + power, I'm holding it for one minute and
    the device doesn't turn on. as soon as I release the power button it turns on but the caps led blinks and there's no attempt to read from the stick. Tried all 4 usb ports.
    Either the recovery mode is bricked or this device has none.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  11. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,381
    15,033
    340
    #11 Tito, Oct 29, 2015
    Last edited by a moderator: Apr 20, 2017
    @nexus76

    Your naming convention is correct, but you need to put them in:
    Code:
    X:\Hewlett-Packard\Bios\Current
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  12. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,314
    1,433
    180
    the only problem ive had is bad chipset bga solder on some needing reflow.. would not light usb.
    research if this mobo is one of them.
     
  13. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    hey thanks LatinMcG, can I flash the decrypted bios binary directly via SPI or is there a special offset for EC code?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,314
    1,433
    180
    dump chip backup.bin compare it in hex editor
     
  15. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    this device really has at least 3 ROM chips:

    UH2: SPI Flash ROM (4MB) / MX25L6405DZNI-12G
    UH5: ??? (2MB) / ??? (besides UH2)
    SPI ROM (256KB) / MX25L2006EM1I-12G

    I guess EC binary is just for peripheral ROMs, let's see.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,314
    1,433
    180
    4mb likely is bios and other is likely Embeded controler and TP security or similar
     
  17. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #17 nexus76, Nov 2, 2015
    Last edited: Nov 2, 2015
    (OP)
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  18. jesusabc

    jesusabc MDL Novice

    Jul 20, 2017
    2
    0
    0
    any help, please?
     
  19. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,314
    1,433
    180
    CH341A and desolder chip if it cant be read on board with Pomona/3m test clip SOP8.

    make 3 backups and compare them if reading on board as sometimes it doesnt read right intermitent and has to be desoldered.

    make backups either way and compare with hexeditor like HxD and you will find what you need to flash.

    the Intel Management engine might need Cleaning.