unbrick HP m6-1000sg / bios dump

Discussion in 'BIOS Mods' started by nexus76, Oct 27, 2015.

  1. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #1 nexus76, Oct 27, 2015
    Last edited: Oct 27, 2015
    Hi,

    I bricked my m6-1000sg and altough I have a hardware flasher I guess I'll need a bios binary dump cause the
    original HP file looks scramled:

    http://whp-hou4.cold.extweb.hp.com/pub/softpaq/sp66501-67000/sp66782.exe

    after this update the laptop don't start, no beep, black screen, only the caps led flashes constantly.
    Andy's Tool doesn't even detect this one as a bios file.

    edit: I found a site with a binary dump
    http://pcdeb.pl/viewtopic.php?t=135
    but unfortunately I don't speak polish, so I'm not able to register to show
    the download.


    edit2: okay, now I got the files, there are 3 files:

    HP Pavilion M6-1000sg LA-8711P BIOS_25Q16BV_UH5.bin (2048KB)
    HP Pavilion M6-1000sg la-8711P EC.bin (256KB)
    HP Pavilion M6-1000sg la-8711pBIOS_25Q32BV_UH2.bin (4096KB)

    what does it mean and why 3 files?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,215
    14,777
    340
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #3 nexus76, Oct 27, 2015
    Last edited: Oct 27, 2015
    (OP)
    Thanks Tito, indeed I followed the easier route first and tried the recovery mode, but now I'm not sure if this device
    even has a recovery option builtin.
    I tried it at least 30 times but holding windows + b while pluggin in the power cord, and pushed additionally the power-on button,
    it doesn't have any effect, the laptop doesn't start the recovery process.
    Tried even Fn+B and FN+ESC, nothing worked an I can see the usb stick isn't even accessed, nothing happens.
    The bios ^^ provided by HP can't be opened by Andy's Phoenix tool or using UEFI Tool, it looks like binary garbage in HxD.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,267
    1,422
    180
    #4 LatinMcG, Oct 28, 2015
    Last edited: Oct 28, 2015
    seems it uses 018A4.bin and .sig but cant decrypt from dloads.. needs original hd and use findandmount to recover the file if partition was deleted... or find a dload for it.

    edit: i found it in previous versions F.03 works with phoenixmodtool sp57291.exe

    create diagnostics usb first with
    http://ftp.hp.com/pub/softpaq/sp63001-63500/sp63259.exe

    then use these files to recover old bios F.03

    http://www.mediafire.com/view/gtxf6mdcb4ma3am/sp57291_18A4_DECrypted.zip

    follow steps for win7.. but also place files in win 8 location as im not sure which location this pc use
     
  5. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,215
    14,777
    340
    @nexus76 @LatinMcG

    sp66782.exe/018A4.FD is signed with new RSA signature so the hewprsa.exe bundled with Phoenix Tool can't decrypt it. Get the new one from here & replace it with the old one, then you will be able to decrypt it.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    thanks so much Tito, the dump (018A4.FD.DEC + RSA.SIG) looks like a valid uefi image now, it can be opened with coderush's UEFITool even,
    do you think it's enough to flash just this binary to the bios chip? Or will the EC binary be required with HP laptops?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,215
    14,777
    340
    #7 Tito, Oct 29, 2015
    Last edited: Jul 20, 2017
    @nexus76

    018A4.FD.DEC should contain both BIOS & EC dump; you need to read the EC chip content first & compare with the decrypted image to get the exact offset. LatinMcG or BDMaster can help you with this.

    On the other hand, the USB recovery should work - please try with the 018A4.FD.DEC (rename & rearrange properly). I've recovered many HPs, never faced any problem.

    :g:
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    ok, I'll try it once more before disassembling the device completely, but as I mentioned, the usb stick isn't even accessed, fat16 or fat32, what's the correct filesystem you used?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,215
    14,777
    340
    @nexus76

    4/8 GB pendrive + FAT32 works for me always.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #10 nexus76, Oct 29, 2015
    Last edited: Oct 29, 2015
    (OP)
    following this guide in every detail nothing happens at holding win + b + power, I'm holding it for one minute and
    the device doesn't turn on. as soon as I release the power button it turns on but the caps led blinks and there's no attempt to read from the stick. Tried all 4 usb ports.
    Either the recovery mode is bricked or this device has none.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  11. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    17,215
    14,777
    340
    #11 Tito, Oct 29, 2015
    Last edited by a moderator: Apr 20, 2017
    @nexus76

    Your naming convention is correct, but you need to put them in:
    Code:
    X:\Hewlett-Packard\Bios\Current
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  12. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,267
    1,422
    180
    the only problem ive had is bad chipset bga solder on some needing reflow.. would not light usb.
    research if this mobo is one of them.
     
  13. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    hey thanks LatinMcG, can I flash the decrypted bios binary directly via SPI or is there a special offset for EC code?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,267
    1,422
    180
    dump chip backup.bin compare it in hex editor
     
  15. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    this device really has at least 3 ROM chips:

    UH2: SPI Flash ROM (4MB) / MX25L6405DZNI-12G
    UH5: ??? (2MB) / ??? (besides UH2)
    SPI ROM (256KB) / MX25L2006EM1I-12G

    I guess EC binary is just for peripheral ROMs, let's see.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,267
    1,422
    180
    4mb likely is bios and other is likely Embeded controler and TP security or similar
     
  17. nexus76

    nexus76 MDL Addicted

    Jan 25, 2009
    783
    296
    30
    #17 nexus76, Nov 2, 2015
    Last edited: Nov 2, 2015
    (OP)
    I already revived the device :clap: flashing just UH2 and UH5, linked at my first post.
    Regarding the 2MB (UH5) part, is it maybe the Intel Management Engine code seperated from bios?
    UH2 starts like the bios binary.

    edit: looks like ME descriptor but starts at offset:

    [​IMG]

    in decoded 6MB original bios binary same code starts at offset 004F0000.

    after 4MB and before this part starts there's only a 960KB (EFFF0h) FFh pattern.

    so, if you jump 400000h + EFFF0h in the decoded ROM you'll land at this position.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  18. jesusabc

    jesusabc MDL Novice

    Jul 20, 2017
    2
    0
    0
    Hi


    I would like to request some help about my case [​IMG]

    I installed from Windows 10 bios F.27 Rev.A in my laptop (I bought it in Spain, it is HP PAVILLION M6 1000SS)


    All was OK, then the Windows HP program told me to reboot...


    After booting: Blank screen, only the power button lights...then the HDD sounds, and it powers off...

    It was an official BIOS!!!!!! [​IMG] [​IMG]

    So... I think I need a BIOS DUMP 4MB Insyde bios for my laptop, f. ex F.26 (the last one which it had and was working perfectly!!!)

    http://ftp.hp.com/pub/softpaq/sp66501-67000/sp66782.exe


    I saw that NEXUS76's laptop was M6 1000SG... and the firmware file IS THE SAME...


    Could anyone help me with this dump? Do I need some special "bios writing machine" to reflash it or from an USB pendrive could be done?????

    Thanks in advance for all your possible help!!! I am a bit desperate... [​IMG]
     
  19. jesusabc

    jesusabc MDL Novice

    Jul 20, 2017
    2
    0
    0
    any help, please?
     
  20. LatinMcG

    LatinMcG Bios Borker

    Feb 27, 2011
    5,267
    1,422
    180
    CH341A and desolder chip if it cant be read on board with Pomona/3m test clip SOP8.

    make 3 backups and compare them if reading on board as sometimes it doesnt read right intermitent and has to be desoldered.

    make backups either way and compare with hexeditor like HxD and you will find what you need to flash.

    the Intel Management engine might need Cleaning.