logo elektroda
logo elektroda
X
logo elektroda

Lenovo T470 BIOS Password Bypass: Seeking Solution for NM-A931 REV 2.0, SSD Drive Password

gold-game 6618 19
Best answers

How can I remove the BIOS password on a Lenovo T470 NM-A931 Rev. 2.0 when a normal BIOS dump does not help and there is also an SSD drive password?

The BIOS password is not stored in the main BIOS image; it is stored in the MEC/KBC, so you need a MEC dump rather than a 1 MB BIOS file [#17517135] For this platform, the relevant dump should be much smaller, around 100–200 kB, and you should check the exact layout ID and programmer because a 1 MB file from the MEC is likely wrong [#17516642][#17516697] If your TL866 cannot read the MEC and it is covered with black epoxy, the suggested tools are SVOD3 or Vertyanov JIG V3 [#17516713][#17516968] One reply also points out that the NM-A931 platform uses MEC1653L on some variants, so matching the exact board revision matters [#17515686][#17516697]
Generated by the language model.
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 17515121
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    Hello. I have a problem with bypassing the bios password on the T470 lenovo, the CD: CT470 NM-A931 REV 2.0. I was looking for a bios feed, but I did not find one. There is also a password on the SSD drive, but rather I write it down. Please help. In the attachment, a bios droplet with a password.
    Attachments:
    • org dump haslo.BIN (16 MB) You must be logged in to download this attachment.
  • ADVERTISEMENT
  • #2 17515341
    boro1234567
    IT specialist
    Posts: 26420
    Help: 2772
    Rate: 1534
    The password in this album is probably in the MEC.
  • #3 17515566
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    Tomorrow I will do another MEC dump and send. In total, I could take both discharges. Excuse me.
  • ADVERTISEMENT
  • #4 17515686
    lisek
    Service technician RTV
    Posts: 39712
    Help: 6307
    Rate: 6802
    After registration (maybe a light fee ... currently?) Link
    ideapad 310-14IKB, 310-15IKB, 310 Touch-15IKB, 510-15IKB
    - MB CT470 NM-A931 REV 2.0
    BIOS Version 3JCN20WW U49
    kbc MEC1653L
    cpu Intel 7th gen

    Similarly Link
    :idea: Similarly Link

    Lenovo T470 BIOS Password Bypass: Seeking Solution for NM-A931 REV 2.0, SSD Drive Password


    ps
    Other ver. NM-A981 Rev 1.0
    see Elvikom NM-A981 Rev 1.0 Link

    The NM-A681 platform is IT8586E-FXA kbc
  • ADVERTISEMENT
  • #5 17516628
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    I'm putting on a tight MEC.
    Attachments:
    • MEC org dump.BIN (1 MB) You must be logged in to download this attachment.
  • Helpful post
    #6 17516642
    boro1234567
    IT specialist
    Posts: 26420
    Help: 2772
    Rate: 1534
    Where does the 1MB file from Meca come from?
    Something's wrong.
    What is your layout ID, what programmer?
  • #7 17516672
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    Maybe I misunderstood something here. I've done a second bios dump called 25Q80JV
  • Helpful post
    #8 17516697
    lisek
    Service technician RTV
    Posts: 39712
    Help: 6307
    Rate: 6802
    Your model
    Lenovo T470 BIOS Password Bypass: Seeking Solution for NM-A931 REV 2.0, SSD Drive Password

    This kbc MEC -... was used on NM-A931 rev.1.0
    * NM-A931 CT470; Intel Core i5 6200U ... i7-7500U
    * depends on the description of lenovo, eg 5B20M31195 (i7-)

    The batch should be in the order of 100-200kB

    ps

    Also on NM-B071 (kabylake_H)
    Bios in 25Q128JVSQ 128Mb
    Lenovo T470 BIOS Password Bypass: Seeking Solution for NM-A931 REV 2.0, SSD Drive Password
  • #9 17516713
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    So there is a problem. My TL866 can not read it. In addition, the MEC is rather dense with black epoxy.
  • #10 17516815
    lisek
    Service technician RTV
    Posts: 39712
    Help: 6307
    Rate: 6802
    Quote:
    In addition, MEC is rather
    Quote:
    black epoxy.

    Again, "black clouds" over servicing lenovo!
  • #11 17516968
    boro1234567
    IT specialist
    Posts: 26420
    Help: 2772
    Rate: 1534
    gold-game wrote:
    My TL866 can not read it.

    SVOD3 or Vertyanov JIG V3 give them advice.
  • #12 17517008
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    I do not think I will buy a programmer especially for this occasion. The laptop is my private one, purchased for part by this slogan, but I was hoping that another bios feed would be enough.
  • #13 17517023
    boro1234567
    IT specialist
    Posts: 26420
    Help: 2772
    Rate: 1534
    gold-game wrote:
    I think I will not buy a programmer especially for this occasion.

    I thought you had.
  • #14 17517034
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    Unfortunately, I do not have access anymore.
  • ADVERTISEMENT
  • #15 17517053
    lisek
    Service technician RTV
    Posts: 39712
    Help: 6307
    Rate: 6802
    I gave links, send a mail to them with the question about the possibility of: sending a programmed Bios bone.
    They were usually "kind"

    I have not seen the last ebay offers.
  • #16 17517135
    boro1234567
    IT specialist
    Posts: 26420
    Help: 2772
    Rate: 1534
    lisek wrote:
    I
    lisek wrote:
    given links, send a mail to them asking if they can: send a programmed Bios bone.

    The password is not saved in the BIOS only in MECU.
  • #17 17517292
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    And how does this method of downloading a password work for you? Have they mastered something for this platform?
  • #18 17517339
    lisek
    Service technician RTV
    Posts: 39712
    Help: 6307
    Rate: 6802
    The latter Link (vinafix.com) (with a mug of beer) seems to have both batches.
  • #19 17517367
    gold-game
    Level 21  
    Posts: 841
    Help: 64
    Rate: 153
    I have a friend who has an account on vinafix. I will ask him, he will download and check me. All in all, it's a good site, they only count. I think PLN 50 a month.
  • #20 17518648
    Stani12
    Level 28  
    Posts: 1180
    Help: 134
    Rate: 107
    Vinfix $ 10 per week. Ripples are not everything. Besides, they do not have to NM-A931.

Topic summary

✨ The discussion revolves around bypassing the BIOS password on a Lenovo T470 laptop, specifically the NM-A931 REV 2.0 motherboard. Users suggest that the password is likely stored in the MEC (Microcontroller Embedded Controller) rather than the BIOS itself. Several users discuss the challenges of extracting the MEC data due to its dense epoxy coating, which complicates reading with standard programmers like the TL866. There are mentions of alternative programming tools and services that may assist in obtaining the necessary BIOS files or MEC dumps. The conversation also touches on the potential costs associated with these services and the availability of BIOS feeds for the specific model.
Generated by the language model.

FAQ

TL;DR: MEC/EC dump size is 100–200 kB; “The batch should be in the order of 100–200 kB.” This T470 CT470 NM-A931 FAQ helps technicians and owners choose safe, effective unlock paths and tools. [Elektroda, lisek, post #17516697]

Why it matters: BIOS chip swaps alone often fail because the password typically resides in the MEC/EC, not the SPI BIOS.

Quick Facts

Where is the BIOS password stored on a Lenovo T470 CT470 NM-A931?

On this platform, the password resides in the MEC/EC, not the SPI BIOS. “The password is not saved in the BIOS only in MECU.” EC-level work is required to clear or change it. [Elektroda, boro1234567, post #17517135]

Will flashing or replacing the SPI BIOS chip remove the T470 password?

No. Reprogramming or swapping the SPI BIOS alone will not clear the password. It is stored in the MEC/EC, not the BIOS flash. [Elektroda, boro1234567, post #17517135]

What EC/KBC controller does the CT470 NM-A931 board use?

The CT470 NM-A931 board uses a MEC1653L KBC/EC. The platform pairs with Intel 7th‑generation processors. [Elektroda, lisek, post #17515686]

What size should a correct MEC/EC dump be on this platform?

Expect about 100–200 kB for a proper MEC dump. As one expert noted, “The batch should be in the order of 100–200 kB.” Larger reads suggest a setup issue. [Elektroda, lisek, post #17516697]

I got a 1 MB MEC dump—what went wrong?

A 1 MB MEC file indicates a wrong setup or selection. Verify the layout ID and confirm the programmer is configured correctly for the EC. [Elektroda, boro1234567, post #17516642]

Which programmer works for MEC1653L on the T470?

Use EC‑capable tools. Contributors recommend SVOD3 or Vertyanov JIG V3 for handling MEC operations on this board. [Elektroda, boro1234567, post #17516968]

Can a TL866 read the MEC/EC on this board?

A user reported the TL866 could not read the MEC on this unit. This highlights compatibility limits with generic SPI programmers for EC tasks. [Elektroda, gold-game, post #17516713]

Is the MEC sometimes covered with black epoxy on T470?

Yes. One report notes the MEC is covered with black epoxy, which complicates access and increases service risk. [Elektroda, gold-game, post #17516713]

Which SPI flash chip did users find on this T470?

In this case, the secondary SPI identified was a Winbond 25Q80JV. That was the chip the user successfully dumped. [Elektroda, gold-game, post #17516672]

What SPI size do related Lenovo boards use?

On the NM-B071 (Kaby Lake-H) platform, the BIOS resides in a 25Q128JVSQ, which is a 128 Mb part. [Elektroda, lisek, post #17516697]

I don't have EC tools—can someone send a pre-programmed chip?

Yes, you can email vendors or repositories and request a pre‑programmed BIOS chip. Contributors report they were often accommodating for such requests. [Elektroda, lisek, post #17517053]

Where can I download MEC and BIOS dumps for CT470 NM-A931?

A contributor pointed to Vinafix as hosting both required dumps for this board. Access may require registration and a fee. [Elektroda, lisek, post #17517339]

How much does Vinafix access cost, and do they have NM-A931?

Reported pricing is $10 per week. Availability is not guaranteed, and they may lack NM‑A931 at times. [Elektroda, Stani12, post #17518648]

How should a professional approach an EC-locked T470?

  1. Confirm board ID (CT470 NM‑A931) and EC model (MEC1653L).
  2. Use an EC programmer like SVOD3 or Vertyanov JIG V3 to back up the MEC.
  3. Proceed with authorized service actions or refer to a qualified lab if tools are unavailable. [Elektroda, boro1234567, post #17516968]
Generated by the language model.
ADVERTISEMENT