Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 11 Vote(s) - 4.64 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
Lenovo IdeaPad Gaming 3 15IAH7 BIOS unlo...
Last Post: yigmayo
Today 03:07 PM
» Replies: 0
» Views: 39
[REQUEST] Lenovo ThinkPad Edge E330 (H3E...
Last Post: kolnew
Today 08:48 AM
» Replies: 653
» Views: 424257
Dell Optiplex 5070 SFF i9 9900K
Last Post: DeathBringer
Today 01:43 AM
» Replies: 4
» Views: 3568
Extracting BIOS - Samsung Galaxy Book 3 ...
Last Post: mirroreduser
10-02-2026 09:12 AM
» Replies: 0
» Views: 233
[REQUEST] HP Pavilion g6-1b87cl WiFi Whi...
Last Post: AkiNakano6055
10-02-2026 12:32 AM
» Replies: 0
» Views: 168
Asrock Z890-C Bios Mod
Last Post: xul8tr
10-01-2026 12:51 PM
» Replies: 0
» Views: 261
[REQUEST] Lenovo G580 (5ECNxxWW) Whiteli...
Last Post: frozik1990
10-01-2026 11:55 AM
» Replies: 1735
» Views: 1224010
[REQUEST] Acer Aspire VN7-791(G) BIOS Un...
Last Post: Whiter
10-01-2026 06:19 AM
» Replies: 92
» Views: 119117
Modifying Aptio V BIOS to disable non-fa...
Last Post: KappaDev
09-30-2026 09:16 PM
» Replies: 0
» Views: 242
[Unlocked] Acer Aspire One D255E
Last Post: ananinami
09-29-2026 01:26 PM
» Replies: 3
» Views: 6750
FANPEEC S210 i9-10980HK
Last Post: geometryczny@tlen.pl
09-29-2026 07:14 AM
» Replies: 0
» Views: 364
[REQUEST] Lenovo Z410 & Z510 (8DCNxxWW) ...
Last Post: anntoxx
09-28-2026 02:28 PM
» Replies: 504
» Views: 309584
[REQUEST] Lenovo Y70-70 (9ECNxxWW) White...
Last Post: Dooglas
09-27-2026 11:31 AM
» Replies: 92
» Views: 61916
[REQUEST] Lenovo E31-70 (AFCNxxWW) BIOS ...
Last Post: kristian6237455372
09-27-2026 11:04 AM
» Replies: 2
» Views: 579
[REQUEST] HP dv6-6c51ca whitelist remova...
Last Post: johnyn2005
09-26-2026 12:52 PM
» Replies: 20
» Views: 20232
[REQUEST] Lenovo B590 (H5ETxxWW) Whiteli...
Last Post: katri
09-26-2026 02:03 AM
» Replies: 281
» Views: 169182
[Request] Dell Optiplex 3040M 7th Gen CP...
Last Post: DeathBringer
09-25-2026 12:35 AM
» Replies: 10
» Views: 6284
[Untested] Dell OptiPlex 3040 H110 – Cof...
Last Post: gonza20889
09-23-2026 02:02 PM
» Replies: 0
» Views: 779
[REQUEST] Acer TravelMate B113-E BIOS Un...
Last Post: rt400
09-22-2026 07:39 AM
» Replies: 9
» Views: 5746
[REQUEST] Acer Aspire 8930(G) BIOS Unloc...
Last Post: xeper8x8
09-21-2026 10:04 PM
» Replies: 59
» Views: 61134

(UEFI) Dell XPS 15z L511z modded BIOS - and HOWTO
Happy new year kasar Smile I'm away from the laptop until mid-Jan, hence silence from my end for a while ^^

Unlocking 0x1AD MSR should be fairly easy, I had accomplished something similar to unlock the MSR for Speedstep to work correctly in OS X. Under my existing BIOS hack I have unlocked Bit 15 of MSR Register 0xE2 so a bit of hunting around in that region should do the trick.

For 0xE2 I had to look for the opcodes

"b9 e2 00 00 00" (mov $0xe2,%ecx)
...
"75 08" (jne next)
"0f ba e8 0f" (bts $0xf,%eax)

and make sure that the CPU did not execute the last instruction through an unconditional jump. So I replaced "75 08 0F BA E8 0F" with "EB 08 0F BA E8 0F". I don't have the specific module with me right now (only so many things I can take when off skiing) but I'd assume you can search for "75 xx 0F BA E8 28" (xx could be anything depending on next jump) immediately after "B9 AD 01 00 00".

Let me know if you need any help!
find
quote
thanks a lot for the info jkbuha Big Grin

Glad to know this still active Smile

I will give a look to the stuff at night when I arrive my grandspa home

should I look into any particular or specific modules?

Im looking for the MSR 0xCE bit 28 in particular

I will be away from my HW programmer this week, but I still have my old CD recovery, so I will still able to recover from BIOS region based bricks
find
quote
You're welcome mate Smile

Ok, now I understand, you want to set MSR_PLATFORM_INFO (0xCE) Bit 28, so this is (in theory) what needs to be done:

1) Open up the module I had modded to set MSR 0xE2. IIRC, most of the MSR read/writes are done from one module only, so this should be the correct one.

2) Find the byte sequence "B9 CE 00 00 00" which corresponds to the get MSR_PLATFORM_INFO register

3) Use a disassembler (IDA or equivalent) to dump the asm instructions around that area. We should be looking for an instruction to unset/reset Bit 28. Once found we force condition to set or else force jump away from the reset instruction.

4) Once successful, set 0x1AD to multiplier of choice from Intel XTU.
find
quote
I am stuck on step 3

well, I never used IDA or any other disassemblers before, so I feel a little noob here Big Grin

I'll try doing following

I picked of ida pro 6.1

and ran idaq64.exe

then loaded powermanagement2.efi

(the one for L502X I hex edited long time ago with your speedstep changes and also I found the "B9 CE 00 00 00" hex secuence on it)

then when I ask IDA to load the rom file, it ask to load with those settings.

[Image: DN31DRE.jpg]

then after I try to search the "B9 CE 00 00 00" part, it go to the selected zone


[Image: jTGAh7b.jpg]


///////////////////////////////////

then ..... well, I feel lost after that step :'D

I attached the powermanagement2.rom module

maybe you can point me into the right direction ^^


Attached Files
.rom   powermanagement2.ROM (Size: 16.09 KB / Downloads: 0)
find
quote
well it looks like you *have* found something... ^^

this is the procedure to call MSR 0xCE and then immediately after call MSR 0x1AD, both of which we know are key to unlocking multipliers - nice work =D

question is; I cannot see any instructions to read/lock specific bits (btr/bts), so I'm not sure how the BIOS is locking these specific bits in this module.

unfortunately I won't be back until week after next so won't be able to help you much for the next few days. in the meantime i'l try googling around to see if anyone has had a similar method of unlocking.
find
quote
Happy new year everyone!

@kasar , @jkbuha

I think you are using wrong cpu for disassembly - according to your screen you've loaded image for Z80 cpu , which has "a bit different" bytecode
I may be wrong if image loader , in this case it is PE64 , forces IDA to use correct processor, but I'm not sure
find
quote
@follow_me

yes, you are probably right, I never user IDA before or any other dissasembler app before, so I just loaded the efi module with default settings.

there are many of them, so I'm not sure wich one to pick

[Image: f5ec8cbdd0fe1393219baeb8049840af.png]

wich settings do you guys use to dissasembly your uefi bioses?
find
quote
Hi both - kasar's settings are correct. Even if the setting was Z80, IDA correctly interprets the code as PE AMD64 (in top window dialog).

FWIW, the correct setting should be Intel 8086 (metapc) or some such; will check exactly when I'm back on terra firma
find
quote
thx jkbuha

I will wait your return Wink

anyway many people told me about is useless what I'm trying to do with my current proccesor ...Big Grin

however, I still interested, even it will not work with my CPU, its good to have it unlocked in case I upgreade the CPU again

also I'm pretty sure the people at NBR using my L502X bioses will like it.
find
quote
(04-27-2014, 04:47 AM)follow_me Wrote: Sorry for a delay, had a long backup/restore cycle
I have tested the latest firmware :

- RAID mode works, I was able to create stripe array with 2 disks
- Legacy boot wortks, was able to boot Linux from this disk
- UEFI boot works , was able to boot UEFI Shell from this disk and it's fs was mapped
- TRIM is NOT WORKING , tested by removing file, forcing Linux to trim filesystem and then reading physical sectors of underlying SSD , and there was data,not zeroes as it shold be with trim working

* UPDATE *
as it turned out TRIM should be tested with the latest WINDOWS driver , I will make some addition tests to clarify weather TRIM working or not

To be able to boot from Raid disk it is required to add boot record using bcfg
for the RAID mode device handle is
UnknownDevice ExtendedSCSIPassThru EfiAtaPassThruProtocolGuid UnknownDevice UnknownDevice PCIIO DevicePath(PciRoot(0x0)/Pci(0x1F,0x2))

and there is one small issue - I have 3 ssd drives , one of whitch is replaced stock DVD-Drive , and I can't find a handle of it in RAID mode, may be it was just renamed to something else


so - most features are working with a little bcfg magic , TRIM, unfortunately, not

I will be glad to answer any questiong you have, or make some additional tests if neeeded

BTW: @brabbelbla do you have any other thoughts about TRIM to be enabled ? Can I have a FW with a fancy RAID menus ? Smile

One more thing @brabbelbla - can you please replace SystemIsaFloppyDxe.efi with this one https://dl.dropboxusercontent.com/u/1694672/FfsDxe.efi ?

Hi there, I have xps l502x with kasars modified 12A bios with unlocked RAID option seems very similar to your one

I've been reading all your post re RAID and already reached the UEFI shell and tried to add some boot options without success, 
I'm not really experienced with all bios unlocking tools, so can't really do it myself and looking for help.
What I'm really not getting is how did you build a RAID array?
I'm guessing I can't boot into the OS because I'm simple haven't build the array it self but how do I do it? 
I tried to follow that guide

Quote:
  1. Before you start, go to firmware setup and adjust the boot order so the USB and CD/DVD entries are on top. Should anything go wrong you will at least be able to boot an external device. Also enable UEFI boot for the shell.

  2. Fetch yourself a USB flash drive, format it to FAT32, and place the attached file on it as EFI\boot\bootx64.efi.

  3. Boot your machine from the USB drive.

  4. Type "dh -b -p blockio". This should present you with a list of driver handles connected to the protocol BlockIO. You are looking for entries ending with an SCSI adress. Probably it will show ../Pci(0x1F,0x2)/Scsi(0x0,0x0). Take a note of the hexadecimal handle number.

  5. Type "bcfg boot dump -b" and look for the number of boot entries presented. By default there should be 10 (Boot0000 up to Boot0009).

  6. Type "bcfg boot addh (hexadecimal number of boot entries present + 1) (handle number) "Some description"". With only the default boot entries in place and handle number 199, it would be
    Code:


I though I can simply add my HDD to the boot list and simple boot with RAID enabled but it's seems I can't find proper boot string or I just need to build RAID before boot.... Please point me to the right direction.

Basically my goal is to enable intel smart response, but for that RAID must be enabled.....
find
quote


Forum Jump:


Users browsing this thread: 34 Guest(s)