[Offer] Unlocked Asus ROG Strix Z790-A Gaming WIFI D4 BIOS

This is a straightforward process, but it is important to understand that you are working with low-level firmware.
Improper flashing always carries risk.

  • The ASUS ROG STRIX Z790 series supports USB BIOS FlashBack, giving you a reliable recovery path.
  • Keep a second USB stick with the official firmware (same version) ready so you can quickly revert if needed.
  • This modded BIOS unlocks many hidden settings — some are experimental and can destabilize your system.
  • Change only what you understand, and document any adjustments you make.

Scope of Modification

  • Source: Official ASUS UEFI package for the Z790-A GAMING WIFI D4 (DDR4).
  • Change: Advanced setup menus unlocked; AI Tweaker expanded; voltage sections and BCLK tuning exposed.
  • Stability focus: Hazardous options (PCIe base clocks, debug voltages, experimental menus known to freeze UEFI or break boot selection) remain hidden.
  • Unlocked & functional:
    • CFG Lock
    • BIOS Lock
    • Overclock Lock
    • Additional OC & debug options (research before enabling)

Board / Version

  • Motherboard: ASUS ROG STRIX Z790-A GAMING WIFI D4
  • Current Mod: Version 3001 (unlocked advanced menus)

Flashing Instructions (USB BIOS FlashBack)

  1. Prepare the USB Drive

    • Format as FAT32 (MBR partition table).
    • Copy the BIOS file to the root of the USB drive:
      SZ790AD4.CAP
  2. Power State

    • Shut the system down completely.
    • Leave the PSU switch set to ON so the board has standby power.
  3. Start FlashBack

    • Insert the USB into the dedicated BIOS FLASHBACK port (rear I/O, labeled).
    • Press and hold the FLASHBACK button for ~3 seconds until the LED blinks three times.

  1. Wait for Completion

    • Flashing typically takes 1–8 minutes.
    • Do not unplug power, remove the USB, or press any buttons.
    • Completion is indicated when the FlashBack LED turns off.
  2. First Boot

    • Power on and press DEL or F2 to enter BIOS.
    • Confirm version reads 3001 on the Main page.
    • Press F7 for Advanced Mode and reapply settings manually.
    • Do not restore saved profiles from older BIOS versions.

Recovery & Warnings

  • FlashBack is your primary safety net. If something goes wrong, re-run with a clean official BIOS of the same version on another USB stick.
  • Avoid flashing during storms or unstable power.
  • If FlashBack cannot recover the board, a hardware programmer (CH341A + SOIC clip) can reflash the BIOS chip. Tutorials are available on this forum.

Downloads (Version 3001)


Unlocked Advanced Menus

Category Description Safe to Adjust Risky / Leave Alone
Intel Platform Debug DSP routing, ICC clock tuning Rarely needed outside dev work May destabilize audio/bus
Secure Boot Modes AuditMode, DeployedMode, SecureVarPresent Switch Standard ↔ Custom Deployed/FIPS lock may brick
Debug Configuration DebugSetupVolatileData & DebugConfigData Leave disabled Can flood NVRAM, hurt perf
Board / Platform Overrides BoardInfoSetup & SIBoardItemControl Not recommended Breaks updates & drivers
Extended OC Registers (OCMR) Memory training beyond GUI For extreme OC only POST loops / black screens
iGPU / Display Options Intel PEI, DVMT, VBT, CdClock DVMT Pre-Alloc, enable/disable iGPU VBT wrong panel = no display; CdClock unstable
Intel ME Configuration ME State, PTT, FIPS, erase/unconfig PTT, ME State (caution) Erase/Unconfig wipes ME; FIPS lock
Intel ME Debug Menus HECI timeouts, polling, MCTP None for normal use Breaks PCIe/USB/ME → POST fail

Best regards,
NOLIMITS.MAX

4 Likes

Thank you for sharing with us.

1 Like

Could you share how you unlocked these hidden options? A lot of the guides are out of date now and I’d like to do this to my own bios files.

1 Like
1 Like

Hey man. Question to you.
I got the Z790-A Gaming Wifi, but without D4, basically the DDR5 equivalent.
Can you make such an mod bios too?
Do also think it would be possible to switch out the microcode?
Im planning on to use an intel core i5 12400F (if BCLK OC is doable), but this requires a different
MC for the processor in order to make the BCLK OC working. Some boards still show the BCLK
option, even with fixed MC, but you will see those capping out at around 103MHz.
Which is more or less normal.

1 Like

any chance you can unlock the latest bios 3001?

1 Like

Sure! Getting started on it right now. Check back in a few hours, should be up by then.

Yes, sorry, just saw this. Do you still need it for the none D4 version?

Okay! I’ll check back in a few hours!

As a curious request, I’m not quite sure what the limitations of editing BIOS are, but is there any way to allow for a lower BCLK (say 25MHz) and higher core, cache, and graphics ratios?

I know certain settings can be unhidden and have defaults changed, but I don’t know if limits are able to be changed. I also know that core ratios can be up to 120x in the standard BIOS.

In my particular case, I want to use a low BCLK (25 or 50 for example) paired with higher core ratios to achieve better granularity in adjustment of overclocks. I can do this to some extent currently with the stock BIOS, but the limitation is that the maximum iGPU ratio is 42x (2100MHz @ BCLK 100MHz), which would be an abysmal 840MHz at the standard minimum BCLK of 40MHz, and that wouldn’t be desirable for my use cases.

pieha,

Short version: with the modded Setup (we only changed the SuppressIf conditions and AccessLevel=05 to unhide the menus—no new options were invented), we can expose all the ratio/ICC knobs that Intel already baked into this platform. We cannot bypass fuse limits or add a brand-new BCLK domain that doesn’t exist in the PCH/FSP.

Details, tied to this exact board/CPU:

  1. BCLK at 25–50 MHz
  • Intel’s clocking on this platform uses fixed “straps” (100/125/167/250). 25/50 MHz are internal reference values for certain PLLs, not valid system BCLKs.
  • Dropping BCLK far below ~80–90 MHz destabilizes DMI/PCIe/SATA because they derive from the same clock tree. Even with ICC (Integrated Clock Controller) unlocked, ME will usually reject boots that far out of spec.
  • Conclusion: true 25–50 MHz system BCLK isn’t feasible here. The lowest practical range is roughly 80–90 MHz, and even that’s hit-or-miss.
  1. Core / Ring (Cache) ratios
  • Setup can now show very high ratio numbers (the UI goes to 120x), but the effective caps are enforced by CPU fuse/microcode (MSR 0xCE/0x194). On non-K parts you can’t exceed the fused max/turbo bins; the CPU ignores out-of-range requests.
  • Bottom line: we can expose and use the ratios, but we cannot raise maximum bins beyond what the silicon allows.
  1. iGPU (GT) ratio vs BCLK
  • On this CPU, the GT max ratio is fuse-limited (yours shows 42 → ~2.1 GHz at BCLK 100). When you lower BCLK, GT frequency scales down proportionally because the GT PLL follows the same reference.
  • Unless the CPU advertises “GT OC” via the OC mailbox (generally K-SKU behavior), raising GT ratio above the fused max is blocked. BIOS options can be unhidden, but the hardware limit still wins.
  • That’s why BCLK 40 MHz turns 42× into ~0.84–0.88 GHz—undesirably low—and there’s no safe way on this board/CPU to keep 2.1 GHz GT while running a 25–50 MHz system BCLK.

What we can do that actually works

  • Use the 100 MHz strap and rely on per-core and ring ratios for granularity (now unhidden), instead of dragging BCLK down into the danger zone.
  • If you need fractional headroom without hurting GT/DMI, use 125-strap and then fine-tune down a bit with ICC; this keeps the clock tree in a supported window while giving you smaller ratio steps.
  • If present in your CPU/FSP, we’ve also unhidden “GT Min/Max Ratio,” “GT Voltage,” and related GT controls. They’ll help stabilize at the fused limit, but they won’t lift the 42× ceiling.

Net answer to your question:

  • BIOS editing can unhide the relevant knobs and remove vendor-placed guards, but it cannot add a brand-new low-BCLK operating mode or bypass Intel’s fuse/microcode limits. On this motherboard/CPU, 25–50 MHz BCLK isn’t realistic, core/cache max ratios still respect fuses, and the iGPU’s 42× ceiling is hard-limited—so a low BCLK will inevitably drag GT frequency down unless you stay on a supported strap and tune with ratios/ICC instead.

I’ll be uploading the patched UEFI BIOS file with the unlocked values shortly, so you can flash it and explore the settings yourself. That’s my perspective on your question, though.

Thank you very much for your insight and detailed explanation! I’ll keep these in mind when I flash the patched BIOS.

1 Like

I’m making a few final adjustments. The previous version exposed too many unnecessary string entries, which only duplicated existing options and added clutter. These duplicates don’t affect UEFI configuration at all, but they slow down load times since more strings have to be generated.

For example, in the newly unlocked CPU CONFIGURATION section, the “string” subsections serve no purpose for configuration—they are purely descriptive. The only items that should have their accessLevel flipped (from 01, 29, or 09 to 05) are entries of type Numeric or OneOf.

Anyone modifying an ASUS ROG UEFI BIOS ROM should note: only Numeric and OneOf entries need to appear in the GUI, not strings.

Give me about 15 minutes to finalize and verify everything. Thanks for your patience.

1 Like

Version 3001, Z790-a strix WIFI-D4. Modified and unlocked GUI settings for hidden options.

or press here

I also work in cybersecurity, so as a matter of best practice I audit and analyze the files I download and modify. With that in mind, I verified both the original CAP file from ASUS as well as my modified version using VirusTotal. Both came back clean.

The one thing that initially raised concern was a “PEDLL” detection when VirusTotal unpacked the UEFI. In reality, this was a false identification: the file was flagged as a Windows DLL, when in fact it was a legitimate firmware module. This same signature appears consistently across all versions of the ROG Z790-A UEFI firmware, so it is not unique to my modified build. When scanned in the correct context as firmware, it shows zero detections. I also performed a deeper forensic audit, which confirmed that the image is clean.

This type of false positive is not unusual. A well-known example is how VirusTotal and ESET often flag official Dell BIOS files as UEFI malware because they include anti-theft tracking functionality. While technically accurate that these modules alter firmware behavior, they are in fact intentional and legitimate features, not malicious implants.

That little misstep is why this analysis took longer than expected. A brief scare, but ultimately nothing malicious at play.

Let me know if you have any further questions!

Keep the official version on an empty FAT formatted USB drive, with the .cap file directly in the root folder (if your USB drive is a D:\ drive, it would be D:\SZ790AD4.CAP) just in case you face an unexpected power outage or accidentally unplug the USB during flashing too early. It’s always good to have a known good image to revert to or upgrade to)

Looks great! Thank you very much for your help today! Have a great week!

1 Like

I have a asus maximus z790 hero. I am interested in deblobbing the intel me from the bios, and setting the HAP bit. I’ve done some research on it and i have compiled ifdtool to check the mz790h.cap file, which gave me some information about the bios, but most of the tools for checking intel me is compiled on linux. I don’t have a problem booting into linux and doing any of that, I am at the point where I think I need to extract an image of the bios chip so that me_cleaner can read the file because when i run it on the cap file it says “unknown image”. any help with this would be great. I am taking classes towards a cybersecurity degree, so security of my own system has become a project.

On the Hero board you’ve got two solid ways to check and pull Intel ME from the BIOS. The easy one is just using UEFITool - open the .CAP file and it automatically lays out the sectors. You can click into the ME region and extract it directly without guessing.

The more manual method is downloading the Intel ME update package from ASUS, then doing a hex/decimal comparison against your BIOS dump. You’re looking for matching headers, end markers, and overall structure — once you spot that, you can carve out the ME region yourself.

Both get the job done, but UEFITool saves a lot of time since it parses the regions for you instead of hunting offsets by hand.

Does that answer your question or do you have trouble actually pulling the UEFI firmware file from your board in its existing state? Because if that’s the case, the easiest way is from an SPI ch341-a tool, but if you insist on going software route; simply use Linux’s flashrom (compile the latest dev builds with flags for INTERNAL dump allowed, or find a or a precompiled version with that in there. On windows, there are several ways, though, I don’t recommend you use random GitHub and online tools that claim to do this. Being in cybersecurity, you should understand the risk of running a tool with access to your uefi, bios… which is terrible for security. Id suggest Intel ME tools, csme 16.1 version. If you need that and can’t find on this site, let me know. I’ll upload a version of it, that I’ve checked on virustotal and disassembled in ghidra, ida64, and it’s clean Intel tools.

1 Like

Thanks, all of your info is very useful. I will order the spi programmer, just in case. I thought I would pull the bios from within windows with some simple program or commands but you are correct about giving anything that kind of access. I’ll find some official intel tools for the ME, I saw a section about intel me and csme on this forum. If I can just pull intel me portion of the bios cap file with uefitool then I could probably deblob it myself, set the descriptors, flags, pointers, etc and set the hap bit and I assume repack the bios cap file with the updated me. I haven’t had time to look over uefitool yet. The latest cap file also has 0x12f microcode. Not sure if there is any newer microcode, but I could update at the same time. In any case, I need some time to research more. Thank you for your help!

1 Like

Everything you describe doing, is all possible with Intel ME tools; for z790 you’re looking at CSME 16.1 ideally, and don’t deblob it, use MFIT.exe inside the CSME tools, that tool is Intel’s internal developer tool, and it can effectively reinitialize the ME, null the ME; and you can extract, modify, reload into Mfit.exe which will build it into the full CAP / ROM.

1 Like