[Fixed] HP Prodesk 600 G4 mini upgrade to full Intel vPro ME/AMT/KVM

Thank you. Sorry, I will look again. I must have missed it because I couldn’t find the 12.0.95.

But that won’t help you, these are most probably HPs anti tampering measures. There’s (probably) another chip on the board which has copies of the firmware for automatic recovery.

That’s why I was hoping @dpcwr could tell me the bios settings he had on his machine. They re basically the same except his is the micro version and mine is the SFF. He was able to get it done just a few months ago, so I’m guessing there is a way.

If I can find the current ME firmware, I’ll give that a shot next. :slight_smile:

Again, I appreciate your help…

I believe I picked COR_H version due to having Firmware SKU = Corporate H displayed when running my dumped firmware through ME Analyzer as explained in this post:

Also note that my machine was Prodesk 600 G4 mini, not G5 so there are probably some additional differences to be considered in your case.
I also think that my BIOS had settings for Data Recovery set to something other than Automatic, but I’m not 100% sure on that.
In any case it does appear you managed to load a new firmware but failed to boot due to some other issue. Search online for HP Prodesk 600 G5 SFF Service Manual - see if beeps are explained there.
Or perhaps @lfb6 is onto something here and HP changed BIOS anti tampering protections in G5+ variants in which case I’m not sure how to proceed at this time.

Thanks for the info! I’m going to try a few more things later today. First, I was able to find the newest firmware… Not sure why I couldn’t before… But I totally overlooked it.

I’ll also mess with the data recovery settings… I have a few of these including a G4, although they are all SFF not mini’s… I may play with the G4 also, as that one is not in service and it won’t matter if I brick it.

In any event, this has been a fun project and I’m not giving up! I have other HP machines that have full AMT natively running so I was hoping to get these SFF’s doing it also. :slight_smile:

Ok, to further add to this project, I found the following. Upon opening up my other Prodesk 600’s, a mixture of both G4 and G5’s, I found three different BIOS chips. One of my G5’s has the same BIOS chip at the OP of this thread @dpcwr. Its a Winbond 25Q256JVFQ.

Yesterday as I was exploring how to add my particular chip to NeoProgrammer, I opened my programmer dumped full bios file with UEFITool. In that report, I found something that indicates they use three different chips for these computers. That is now consistent with my findings in the different computers I have.

Here is what the BIOS dump said:

Flash chips in VSCC table:

C22019 (Macronix MX25L256)

EF4019 (Winbond W25Q256)

C84019 (GigaDevice GD25x256C)

I’m continuing to try to make it work on my machines… :slight_smile:

@lfb6

Where can I find unconfigured COR H BA v12.0.92.2145 & COR H BA v12.0.94.2380?

Either somwhere this thread or from station drivers. Stitched update- files can be decomposed in FIT, the file in the decomposed folder is normally usable for reinitializing, too. But as written, this isn’t a version problem.

Thank you. I’m continuing to play with it by downgrading BIOS firmware, etc.

@dpcwr @lfb6

I got it to work twice on my two G4 SFF machines. They have older firmware and ME versions from 2022, but it worked and I was then able to upgrade to the latest BIOS/ME with no issues… KVM working!

So there might be something to the idea the G5’s being a newer model have something I can’t get past.

However, two of my G5’s have the most current firmware and the one I have been playing with has firmware from 2022.

So I’m going to continue playing with the G5 with older firmware and try lowering the BIOS version back even further to see what happens… It has ME 12.0.92.2145 on it…

Anyway, great work by all and thank you all for your help!

PS I bought a 16 pin clip on for programming as the tiny needles were driving me nuts!

https://www.3m.com/3M/en_US/p/d/b00035147/

1 Like

Try to find and dump the second chip for the G5s

Just got back from a business trip and started looking for the additional chip that may be there… Not sure where it might be as nothing jumps out.

Also not seeing any differences between the G4 and G5 boards… The info I have read about HP’s “Sure Start” seems to indicate it could be the problem. But it exists on the G4’s and previous models and I believe I have all the options turned off.

Anyway, the boards and BIOS settings I have appear to be identical between the two models… The G4’s just worked with these instructions and the G5’s didn’t. I believe it might be something different in the BIOS firmware that enables protection on the G5’s but not the G4’s?

And I’m assuming its the “Sure Start” feature although I can’t prove that either… All I know is after the flashing on the G5’s, I get nothing but two long beeps and three short beeps. If I flash back the original programmer dump, it boots up… The G4’s worked just like expected from the instructions above.

The other weird thing is one of my G4’s is actually newer than the G5 I’m working on… So either there is something I’m missing or they enabled something on the G5 models that is different.

Here is info on Sure Start:
http://h10032.www1.hp.com/ctg/Manual/c05163901

Can you post a link to / attach a G5 dump?

EDIT And there should be another 16 MByte SPI chip.

I don’t see any other 16MByte SPI chips at all… There are what appear to be 8MByte SPI chips in other places, but nothing near the BIOS.

And what type of dump do you want? A software dump from the flash programming tool or a programmer dump from the CH341A?

Better read these two, both GigaDevice on this photo but yours could be another vendor.
image

Here are pics from my G5/G4 machines… The G5 is the top one. They have different 16pin BIOS chips (only one on each board), but I have found they actually use three different manufacturers and I have the three different chips in different G4’s and G5’s so its not unique to one or another…

But there is no 8pin SPI chip nearby… You can see the TPM chip near the BIOS chips. Its a SLB9670. Nothing else in that area.


Type of dump doesn’t matter if it covers a complete firmware. But that’s just for checking if they did hide the redundandt parts sowmewhere in padding, but you’d need a 64 MByte chip for that, normally.

Had a look into some badcaps threads where people had dumped a 16 MB chip in addition shich was wrongly called EC firmware but it had the recovery information.

Content should like this, parts of parts of ME region, parts of bios region can be recognized:

image

​​

Ok here are the programmer dumps… First is the G4

G4

G5

Didn’t mean screen dumps of UEFITool??

@lfb6 Here ya go… :slight_smile:
programmerdump.rar (9.9 MB)
softwaredump.rar (9.9 MB)

These are a G5

@lfb6 Any thoughts after looking at the files?

Did check some G5 dumps from badcaps. They all had a 32MB dump working bios and a 16 MB dump recovery/anti-tamper image like the one shown earlier. Since your bios had the ability to restore a ME region tampered with there has to be such a chip somewhere.

You can’t find such a chip on your machine and even if one would have this dump it’s unclear if they didn’t store hashes of the redundant bios parts in an unaccessible place like the TPM.