View Full Version : Here is the MOD on ((MIKOBU III ))......
mike68
10-06-2004, 07:30 AM
C/P
--------------------------------------------------------------------------------------------------------
cut n paste from another site,,thanks go to those that made it,,,,,
Gently lift pins 1 and 4 of the HC00 chip. Lift pin 10 on the 232 chip, if your board has a 233 chip then lift pin 1.
Solder jumper from AT90S2313 pin 14 to HC00 pin 10.
Solder jumper from AT90S2313 pin 18 to HC00 pin 4.
Solder jumper from HC00 pin 8 to HC4053 pin 9 (the one to the left looking at front of loader).
Solder jumper from HC00 pin 9 to HC04 pin 2.
Solder jumper from HC00 pin 1 to HC74 pin 5 (located right above HC00).
Solder 2.2k resistor or (trim pot not really needed) from card slot vcc to ground (c10 is close by).
Install switch from 232 pin 10 (or 233 pin 1) to AT90S2313 pin 18 (on for flashing and off for unlocking.
this is supose to mod the mik3 to unlocker
Anyone tried this yet with the Mik III? I got a couple of these and I can read this version of the how-to. Thinking of trying it but would like to see someone reputable say it works before I get too far into this.
caminodelsol
10-06-2004, 06:56 PM
how about absolute1 modified
thanks
mike68
10-06-2004, 07:24 PM
Here is what I got with no trimmer or switch, i need too go to radioshack
Executing Script: C:\Documents and Settings\mike\Desktop\ROM3 UNLOCKER\unlockrom3.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data :
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 77
Sc.GetByte: Requested Byte Exceeds Last Read Request
What about trace cuts on the bottom of the board? Do we just not worry about cutting any traces with this mod? I sure don't see where the how to calls for it. Going to get a trimmer myself. With just the resistor we can't fine tune the mod like the directions indicate we may have to.
Mike68, could you please PM me the site where you found this?
coolc44
10-06-2004, 09:54 PM
Please PM me the site also.I need it too.Thanks.
indal_98
10-06-2004, 10:17 PM
What about trace cuts on the bottom of the board? Do we just not worry about cutting any traces with this mod? I sure don't see where the how to calls for it. Going to get a trimmer myself. With just the resistor we can't fine tune the mod like the directions indicate we may have to.
Mike68, could you please PM me the site where you found this?
No traces to be cut on M-3.
And yes it works on A23 with 2.2K resistor.....Don't have 383 to try.
All loader mods are at cardcoders.org
G'L
mike68
10-06-2004, 10:34 PM
Thank you indal_98 for the info.
No traces to be cut on M-3.
And yes it works on A23 with 2.2K resistor.....Don't have 383 to try.
All loader mods are at cardcoders.org
G'L
Thanks indal_98. Much appreciated.
anthony101
10-07-2004, 03:16 AM
do you use with the jumper on or off???ya know the one on the outside of the loader where the card goes in at
pablillitos
10-07-2004, 05:00 AM
hello guys i have 3 louders one t6,xp red dragon and another the name is like suresho i want to know if you guys got some info about a mod this louders for unlock my cards please let me know thank .
Gillis65
10-07-2004, 05:30 AM
Leave the jumper on.
mike68
10-07-2004, 07:16 AM
Guys can you tell if I'm close
working on a rom10 with t911, does that look good
Executing Script: C:\Documents and Settings\administrators\New Folder (5)\Rom10-A23 OPEN.XVB
TX Data : A0
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 03 00
Now we will try 123E delay
RESET 696969FFFFFF696969FF6969FF69696969696969FFFF696969 696969FFFF696969696969FF696969696969FFFFFF69696969 6969FF696969696969696969696969696969FF696969696969 FF69696969696969696969696969696969FFFF696969696969 69FF6969696969FF69696969696969696969696969696969FF 6969696969FF6969FF69696969696969FF6969696969696969 696969696969FFFF69696969696969696969696969FF696969 696969696969FF69696969696969FF69696969696969FF6969 6969696969696969696969FF69FF696969696969FFFF696969 696969FF696969696969696969696969 RESET 696969FF69696969696969FF69696969696969FF6969696969 69FFFF6969696969FF696969696969FF69FFFF696969696969 69FF6969696969FF RESET FF
now we will try 123F delay
696969696969FFFF696969696969696969696969696969FF69 6969696969FFFF696969696969696969696969696969696969 6969696969FF696969696969FF69696969696969FFFF696969 6969FFFF69696969696969FFFF696969696969696969696969 696969FF696969696969FF69696969696969FFFF6969696969 69FF6969696969696969696969696969696969696969696969 6969696969696969FFFF6969696969FF6969696969696969FF FF696969696969FFFF69696969696969FF69696969696969FF 696969696969FF696969696969696969696969696969696969 6969696969FF69696969696969696969696969696969FF6969 696969FF696969696969FF6969FF6969696969FF6969696969 696969FFFF6969696969FF6969696969 RESET RESET 6969FF6969696969FFFF
now we will try 1240 delay
FF69696969696969696969696969FF696969696969696969FF 6969696969696969696969696969696969696969696969FF69 696969696969696969696969FF696969696969696969696969 6969696969FF696969696969FF696969696969696969696969 69696969696969696969FF6969696969696969FF6969696969 6969696969696969FF69696969696969696969696969696969 FF6969696969696969 RESET FF6969696969696969696969696969FFFF696969696969FFFF 696969696969FFFF6969 RESET 69696969FF6969696969FFFF6969696969696969FF69696969 FF6969FF696969696969FFFF69696969696969FF6969696969 FF69FF696969696969FFFF6969696969FF6969696969696969 69696969696969FFFFFF69696969696969696969696969FFFF 69696969696969
now we will try 1241 delay
FF6969696969696969FF69696969696969FF69696969FF6969 FF696969696969696969696969FF6969FF696969696969FFFF 69696969696969696969696969FF RESET FF69696969696969FF69696969696969696969 RESET 69696969696969696969696969696969FF6969FF6969696969 696969FF696969696969FFFF69696969696969FF6969696969 6969FF69696969696969FF696969696969FF69696969696969 FF69696969696969FFFF696969696969FF696969696969FFFF 6969696969FF6969FF696969696969FFFF69696969696969FF 696969FF6969696969696969696969FF69696969FF6969FF69 696969696969FF696969696969FFFF696969696969FFFF6969 696969696969696969696969FFFF6969696969696969696969 6969696969696969696969FF696969696969
now we will try 1242 delay
weirdml
10-08-2004, 05:49 AM
Hi mike68,
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 77 ...
It means your mod is not power up... Is is correct?
Hi All,
I have a couple of questions about the mod tho?
1. Do I have to lift PIN10 on my 232 chip and connect it to AT90S2313 pin 18 or can I just leave it alone cause it so tought to lift that particular one tho.
2. Stupid question but what is a Trimmer?
3. What is the setting under WinEx is it Unlooper or 3.68mhz?
Thanks,
Slu3
Gillis65
10-08-2004, 06:17 PM
You need to lift the pin for program mode. Pindown for flashing, or run a switch between the lifted pin and pin 18 on the atmel chip. The trimmer you don't even need just use a 2.2k resistor instead. Trimmer is just an adjustable resistor. Read the read me with the files and you will see you need to make your own setting in winex.
Gillis65
10-08-2004, 06:20 PM
Rom 10's are popping fine here, but when i do a rom3 the program runs fine and will ultimately glitch and say cam is now open. Problem is that when i read them in NagraEdit i get
rom revision383
logging into card
checking for backdoor
backdoor appears to be open continuing..
retrieving backdoor password
then theres like a 30 second delay then....
error reading image from card
closing of com1 was succesful
error detected one step clean incomplete
No matter how many times i run the rom3 script with the modded mikIII i can't clean a rom3.. Rom10's no problem...Any help would be much appreciated.
Thanks for the info, I'll try it later on today.
Slu3
weirdml
10-09-2004, 01:03 AM
[QUOTE=mike68]C/P
--------------------------------------------------------------------------------------------------------
cut n paste from another site,,thanks go to those that made it,,,,,
Gently lift pins 1 and 4 of the HC00 chip. Lift pin 10 on the 232 chip, if your board has a 233 chip then lift pin 1.
--------------
Hi mike68,
This is my Mikobu III... But I don't see the 232 chip. Is the 233 chip on the board? ... Its y2 is 20 pin. What pin will I lift now?
Thanks
mike68
10-09-2004, 01:32 AM
I have the blackbroad Mikobu3 REV :B with all number on the chips erased.
This one I have also is shipping to my tech for him to test.
moses
10-09-2004, 08:07 PM
What about the Mikobu 4 that mili sell in his store
Caesar_Mikey
10-10-2004, 05:27 AM
Ok I did the mod but the flash files I have new6 and new7 dont work I try to flash in xpatmel
flashFailure. Unable to locate hex files for
Newd6
Initializing ...
Initialized
Syncing ...
Synchronized
Vendor Code: 1e (Atmel)
Part Family: 91 AT90S2313
Issuing Chip Erase ...
Erased
Vendor Code: 1e (Atmel)
Part Family: 91 AT90S2313
Programming EEPROM ...
Programming Flash ...
Verifying EEPROM ...
Verifying Flash ...
Setting Lock Bits ...
Lock Bits Set!
Complete!
So I tried Ufp16 and get flash error. when trying to write. I tried reflashing back to m6.2 and it works fine. any help?
Gillis65
10-10-2004, 05:38 AM
Caesar_Mikey you have PM
How did you guys fix your error on line 77?
How did you guys fix your error on line 77?
If you get this message you need to reflash. This is what I get now.
AAFFFFAAFFFFAAFFFFAAAAAAFFFFFFAAFFFFFFFFFFAAFFAAAA FFFFFFAAFFFF--- try to hit 0C bug at 10AD
FFFFAAFFFFFFAAFFAAFFFFAAAAFFAAFFAAAAFFFFAAFFFFFFFF FFFFAAAAFFFF--- try to hit 0C bug at 10AE
FFAAFFFFAAAAFFFFAAAAFFFFAAAAAAFFAAAAFFAAFFAAFFFFFF AAFFFFAAAAFF--- try to hit 0C bug at 10AF
FFFFFFAAFFAAFFFFFFAAAAFFFFAAFFFFAAFFAAFFFFAAAAFF
===========================================
VCC = 59-0710AF GLITCHED past 0C BUG
3FFF9500
===========================================
FFAAAAFFFFFFAA--- try to hit 0C bug at 10B0
FFFFAAFFFFAAAAFFAAAAFFAAFFFFFFAAFFFFFFFFFFFFAAFFFF FFFFAAFFFFAA--- try to hit 0C bug at 10B1
AAFFFFFFAAAA
===========================================
VCC = 57-0710B1 GLITCHED past 0C BUG
3FFF9500
===========================================
FFAAFFFFFFAAAAAAFFAAAAFFFFAAFFFFFFAAAAFFFFFFAAFFFF--- try to hit 0C bug at 10B2
FFFFFFAAFFFFAAFFAAFFFFFFAAAAFFFFFFFFAAFFFFAAFFFFAA AAFFAAAAFFFF--- try to hit 0C bug at ....
Success! Now we just need some flashes to unloop with. Huge thanks goes out to Penga, no1b4me and everyone who took the time to post their pics. I took this pic of my MikIII revC and I think it turned out better than most. I also came up with a better way to install the flash enable/disable switch. The MikIII revC has a trace that comes off pin10 of U3 and goes under the board about a 1/4 inch behind the chip. (MikIII revD does not have this trace route) You can just solder one lead to lifted pin 10 and the other to the hole where the trace goes under the board. Much better way to do it than to put second lead to pin 18 of the atmel. That way puts two wires to pin 18 on the atmel is kind of a pain. Plus, it's farther away. Here's the pic.
Caesar_Mikey
10-10-2004, 03:39 PM
hey JT what did you flash with I have the same rev loader. and cant get it to flash with the new6 and 7 files
Gillis65
10-10-2004, 04:38 PM
Caesar_Mikey check your mail.
Caesar_Mikey
10-10-2004, 04:55 PM
still get the same thing. why would it load with anything but the new flash?
I had the right flashes and xpatmel was telling me it was writing successfully to the eeprom, but it just wasn't. I had to change xpatmel's timing settings. To do this, right click on the center bar in xpatmel, when you see the timing options box appear, change the settings to 60/50/1. Here are the flashes I am using. Thanks to Ziffler at cardcoders for putting this collection of flashes together.
lips905
10-10-2004, 11:02 PM
Here is what I got with no trimmer or switch, i need too go to radioshack
Executing Script: C:\Documents and Settings\mike\Desktop\ROM3 UNLOCKER\unlockrom3.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data :
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 77
Sc.GetByte: Requested Byte Exceeds Last Read Request
do not buy the trimmers from radio shack they are useless .I moded 6 loaders and none ogf them were working a 100% So i went out to a electronic components store and bought multi turn 5K trimmers and now all loaders are working perfectly
shoes
10-10-2004, 11:06 PM
jt and lips i am going to mod my m3 with the picture that u attached jt. did u get ur to work fully? and where is the script for winexp. and wich flash should i use. thanks for all the info.and lips did u get a m3 working?
Eldune
10-10-2004, 11:19 PM
jt and lips i am going to mod my m3 with the picture that u attached jt. did u get ur to work fully? and where is the script for winexp. and wich flash should i use. thanks for all the info.and lips did u get a m3 working?
Use this for your moded unlooper. Good luck!
shoes
10-10-2004, 11:44 PM
do u have one working?
jt and lips i am going to mod my m3 with the picture that u attached jt. did u get ur to work fully? and where is the script for winexp. and wich flash should i use. thanks for all the info.and lips did u get a m3 working?
Yep, my modded MikIII works fully on both rom3 and rom10. The flash enable/disable switch is working perfectly now that I've worked out the timing with xpatmel. The .xvb scripts you need to test your mod and unlock are in Pengas files. I posted the flashes that are working for me in this thread already and uploaded them to dssftp. I did upgrade my mod from the pic above with a trimmer pot from rat shack. I didn't use one of those crappy little plastic ones though. Rat shack does sell some little blue plastic multi-turn trimmers that I've read work great and they also sell the linear-taper potentiometers that I used. I havn't noticed any performance differences with the trimmer though. When I installed it I set it to 2.23K ohms and I didn't even need to change my winex settings from when the plain old 2.2k resistor was installed. (a trimmer set to 2.23k ohms is functionally identical to a 2.2k ohm 5% tolerance resistor) At present, I havn't seen where the trimmer pot has any advantages over just using the 1/4 watt 2.2k resistor. My take on that aspect may change over time though. The trimmer pot does open the door to a much wider range of VCC settings which, hopefully anyway, will become a powerfull tool for us to unlock future rev's and maybe even unloop.
Eldune
10-10-2004, 11:52 PM
do u have one working?
Yes I do if that was dirrected to me. Its A Timeshift Ultra Repair Station.
shoes
10-11-2004, 12:17 AM
what do u mean a timeshift ultra repair station do u have the symatics for it and i was wondering if anyone had a m3 working?
Caesar_Mikey
10-11-2004, 12:58 AM
well I got my mods working and flashed trimmer and all. But all I get is FFFFFFFFFFFFF or reset reset reset
well I got my mods working and flashed trimmer and all. But all I get is FFFFFFFFFFFFF or reset reset reset
How to correct this is discussed in detail in the read me in both Penga's files. You probably just need to tweak your VCC start and VCC limit values in the script.
Caesar_Mikey
10-11-2004, 02:05 AM
ok thats cool how long did it take you to get yours tweaked
jim7219
10-11-2004, 06:02 AM
Will the mods for the MIKOBU III work for the one Mili sells (MIKOBU IV)?
lips905
10-11-2004, 06:35 AM
It is taking me about 10 minuts to pop a card I've done about 60 so far
coolwind
10-11-2004, 06:44 AM
HELP freinds modded m3 6.2 & cant get erase to verify & have write errors can someone tell me whats wrong ??
Thanks Coolwind
It is taking me about 10 minuts to pop a card I've done about 60 so far
This mod has been out for about a week. 60 pops in that time period means that you have been popping at minimum 10roms/day. Lips, I don't doubt that this is possible. I do very much question your motives though. It's been almost a month since your signature has stated that your donations to the ACS has increased.
lips905
10-11-2004, 10:37 AM
This mod has been out for about a week. 60 pops in that time period means that you have been popping at minimum 10roms/day. Lips, I don't doubt that this is possible. I do very much question your motives though. It's been almost a month since your signature has stated that your donations to the ACS has increased.
Well i had t911"s from the good old days and the cards that i poped were mine i bought them on ebay.I'm not going to deny the fact that i do make some money out of this As you are aware i have been unlocking rom 3 for a while and i do sell some cards and systems.
lips905
10-11-2004, 11:35 AM
Guys can you tell if I'm close
working on a rom10 with t911, does that look good
Executing Script: C:\Documents and Settings\administrators\New Folder (5)\Rom10-A23 OPEN.XVB
TX Data : A0
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 03 00
Now we will try 123E delay
RESET 696969FFFFFF696969FF6969FF69696969696969FFFF696969 696969FFFF696969696969FF696969696969FFFFFF69696969 6969FF696969696969696969696969696969FF696969696969 FF69696969696969696969696969696969FFFF696969696969 69FF6969696969FF69696969696969696969696969696969FF 6969696969FF6969FF69696969696969FF6969696969696969 696969696969FFFF69696969696969696969696969FF696969 696969696969FF69696969696969FF69696969696969FF6969 6969696969696969696969FF69FF696969696969FFFF696969 696969FF696969696969696969696969 RESET 696969FF69696969696969FF69696969696969FF6969696969 69FFFF6969696969FF696969696969FF69FFFF696969696969 69FF6969696969FF RESET FF
now we will try 123F delay
696969696969FFFF696969696969696969696969696969FF69 6969696969FFFF696969696969696969696969696969696969 6969696969FF696969696969FF69696969696969FFFF696969 6969FFFF69696969696969FFFF696969696969696969696969 696969FF696969696969FF69696969696969FFFF6969696969 69FF6969696969696969696969696969696969696969696969 6969696969696969FFFF6969696969FF6969696969696969FF FF696969696969FFFF69696969696969FF69696969696969FF 696969696969FF696969696969696969696969696969696969 6969696969FF69696969696969696969696969696969FF6969 696969FF696969696969FF6969FF6969696969FF6969696969 696969FFFF6969696969FF6969696969 RESET RESET 6969FF6969696969FFFF
now we will try 1240 delay
FF69696969696969696969696969FF696969696969696969FF 6969696969696969696969696969696969696969696969FF69 696969696969696969696969FF696969696969696969696969 6969696969FF696969696969FF696969696969696969696969 69696969696969696969FF6969696969696969FF6969696969 6969696969696969FF69696969696969696969696969696969 FF6969696969696969 RESET FF6969696969696969696969696969FFFF696969696969FFFF 696969696969FFFF6969 RESET 69696969FF6969696969FFFF6969696969696969FF69696969 FF6969FF696969696969FFFF69696969696969FF6969696969 FF69FF696969696969FFFF6969696969FF6969696969696969 69696969696969FFFFFF69696969696969696969696969FFFF 69696969696969
now we will try 1241 delay
FF6969696969696969FF69696969696969FF69696969FF6969 FF696969696969696969696969FF6969FF696969696969FFFF 69696969696969696969696969FF RESET FF69696969696969FF69696969696969696969 RESET 69696969696969696969696969696969FF6969FF6969696969 696969FF696969696969FFFF69696969696969FF6969696969 6969FF69696969696969FF696969696969FF69696969696969 FF69696969696969FFFF696969696969FF696969696969FFFF 6969696969FF6969FF696969696969FFFF69696969696969FF 696969FF6969696969696969696969FF69696969FF6969FF69 696969696969FF696969696969FFFF696969696969FFFF6969 696969696969696969696969FFFF6969696969696969696969 6969696969696969696969FF696969696969
now we will try 1242 delay
Yes you are close but i believe that the card you are trying to open has blocker and is not streamlocked that is why you are geting 96969696696 instead of f6f6f6f6f6f6ff6f6
lips905
10-11-2004, 01:05 PM
guys use this program A++++++
Do not change settings adjust trimer to look like this
6f6f6f6f6f6f6ffffffff6f6f6f6f6f6f6f6f6f6fffff6f6f6 f6f6f6f6f6ff6f6f6fffff6f6f6f6f
ffff6f6f6f6f6f6f6f6ff6f6f6f6f6ffffffffffffffffffff ffff6f6f6f6f6f66f6f6f6f6f6ff6fffffffffff6ff6f6f6f
6f6f6f6ff6f6fffffffffff6f6f6f6f6f6f6f6ffffffffffff 6f6f6f6ffffffffffffffff6f6f66f6f6f6fffffffffffffff fff6f6f6f6f
fffffffffffffff6f6f6f6f6f6ff6f66f6f6f6f6f6ffffffff fff6f6f666f6f6f6f6f6ffffffffffffffff6f6f6f6f6f6f6f 6ff6
It will work just let it run
Use newd9 in folder
For those who can't get fffffffffff use new d7 or eight
If your log looks like this card will not open 6f6f6f6f6f6f6f6f6f6f6f6f6f6f6f6f6f6f6f6f6ff6 You need the odd 4 or 5 straight fffffffffffffffff in each line
I owe lips905 a public apology. I'M SORRY lips905. I was out of line and not accurate when I said I questioned lips motives. I have never seen anyone have anything to say about lips other than praise. I was just trying to say wow, that's a lot a roms to be working on in a short period of time. Lips is very generous to have donated even one dollar of his profits to the ACS and I have no right to criticize. I myself have yet to take this hobby into the realm of profit. Once again, I was out of line to make the comments I did referring to lips in the post above.
shoes
10-12-2004, 12:48 AM
well i just finished modin my m3 so here i go tring to get into a card. where should i start know i am going to try this that lips posted thanks jt for the picture hope mine works i used a 5k trimmer with 25 turn adj.
mike68
10-12-2004, 01:04 AM
The rom10 It's stremed locked, I did a clean after having a blocker on the card then loaded a scrip on-to the card then put back in the stream on A16 and took 2 days to jump to A23.
Yes you are close but i believe that the card you are trying to open has blocker and is not streamlocked that is why you are geting 96969696696 instead of f6f6f6f6f6f6ff6f6
dell1234
10-12-2004, 02:33 AM
All i get on a streamlockd rom3 is either... reset reset reset reset..., or Reset ATR OK, both over and over according to tiny ajustments on 5k ohm 500vdc .5W linear-taper pot. Whats the deal, because i am about to give it up.
shoes
10-12-2004, 02:46 AM
hay i have been playing wiht mine and all i get is FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFfff what is up with that? should i try anouther flash instead of the one i am using?
shoes
10-12-2004, 04:34 AM
i also noticed that it said unrecgonized atmel any clues or is that normall?
someone please help me.
lips905
10-12-2004, 07:57 AM
I owe lips905 a public apology. I'M SORRY lips905. I was out of line and not accurate when I said I questioned lips motives. I have never seen anyone have anything to say about lips other than praise. I was just trying to say wow, that's a lot a roms to be working on in a short period of time. Lips is very generous to have donated even one dollar of his profits to the ACS and I have no right to criticize. I myself have yet to take this hobby into the realm of profit. Once again, I was out of line to make the comments I did referring to lips in the post above.
No problem JT everything is cool here :) :)
lips905
10-12-2004, 07:58 AM
All i get on a streamlockd rom3 is either... reset reset reset reset..., or Reset ATR OK, both over and over according to tiny ajustments on 5k ohm 500vdc .5W linear-taper pot. Whats the deal, because i am about to give it up.
Linear is your problem you need is a multi turn trimmer
lips905
10-12-2004, 07:59 AM
hay i have been playing wiht mine and all i get is FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFfff what is up with that? should i try anouther flash instead of the one i am using?
bad trace cut i believe
shoes
10-12-2004, 01:37 PM
what trace needs cut on a mikobu3? i didn't cut any traces i finally with alot of tweaking got 1 a23 card unlocked.
baruskie
10-13-2004, 09:06 AM
what trace needs cut on a mikobu3? i didn't cut any traces i finally with alot of tweaking got 1 a23 card unlocked.
I'm getting all F's as well. What flash did you use and what was your final settings?
shoes
10-14-2004, 07:06 AM
i used flas 8 and my pot is set a 2.23 my vcc is 4f and delay was between 124b and 123f hope this helps.
coolwind
10-14-2004, 08:30 PM
Would someone Please Post a Pic of the MIII Rev c for me
Thanks as I am unable to get mine working any help thanks to all
indal_98
10-14-2004, 08:54 PM
Would someone Please Post a Pic of the MIII Rev c for me
Thanks as I am unable to get mine working any help thanks to all
GL
skinerd
10-16-2004, 12:53 AM
Linear is your problem you need is a multi turn trimmer
Linear is just the type of taper the pot adjustment is, not important for something like what we are doing here. A multi-turn pot can also be linear. The key word is multi-turn, giving a finer adjustment range, because we are mainly concerned for a setting around 2.2k, with slight variations either side.
lips905
10-16-2004, 07:16 PM
Linear is just the type of taper the pot adjustment is, not important for something like what we are doing here. A multi-turn pot can also be linear. The key word is multi-turn, giving a finer adjustment range, because we are mainly concerned for a setting around 2.2k, with slight variations either side.
skinnerd I've opened all my rom 10 cards under 2k. I was using linear tapers and had no luck what so ever until i started using the multi turn trimmers they are more precise in adjustment.Sure the normal tapers work but you get better results with the other ones.
dssdork
10-17-2004, 07:29 AM
hi fellas i hope some one can help me i have a mik3 i modded it flashed it i tried it with the trimmer and with a resister all im getting is 6fffff6fffff6ffff66ffffff6fffffff6fffff6fffff6fff6 ff6f6f6f6f6ffff6f6f6ffffff6ff6f6fffff6ff6fffff6fff ff6fff6ff6ffff6fffffffff6ffff...i let it run for about a hour and no luck my setting is vcc start 57 vcc linit 51 what am i doing wrong or am i close thanx in advance
lips905
10-17-2004, 07:33 AM
hi fellas i hope some one can help me i have a mik3 i modded it flashed it i tried it with the trimmer and with a resister all im getting is 6fffff6fffff6ffff66ffffff6fffffff6fffff6fffff6fff6 ff6f6f6f6f6ffff6f6f6ffffff6ff6f6fffff6ff6fffff6fff ff6fff6ff6ffff6fffffffff6ffff...i let it run for about a hour and no luck my setting is vcc start 57 vcc linit 51 what am i doing wrong or am i close thanx in advance
You are on the right track let it run longer i had cards that took up to 7 hrs.Try to get some more 6 in there and it will work
dssdork
10-17-2004, 08:01 AM
lips i took off the trimmer and with the settings i have vcc start 57 vcc limit 51 and it still does 6F6F6F6FFFFF6F6FFFFF6FFFFFF6FFFFFFF6FFFFFFF6FFFFFF F6FFFFFF6FFFFF6FFFFFF6FFF6F6FF6F6F6F6FFFFFF6F6F6FF FFF6FFFFF6FFFFF6FFFFFF6F6FFFF6F6F6F6F6FFFFFFF..... ..is that normal i checked all my wiring and it is correct im just a little confused on why it is still showing that without a trimmer or a 2.2k resister
dssdork
10-17-2004, 08:10 AM
Executing Script: C:\Documents and Settings\john\Local Settings\Temp\Temporary Directory 29 for rom10unlocker-glitcher[1].zip\Rom10-A23 OPEN.XVB
TX Data : A0
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 12 06
RX Data : 12 00 08 92 04 00
Now we will try 123E delay
6FFF6FFF6FFFFF6FFF6FFF6FFF6FFF6F6FFF6FFFFFFF6F6FFF 6FFFFF6FFFFFFF6F6F6FFF6FFFFF6F6F6FFF6F6F6FFF6F6F6F FFFFFF6FFF6F6F6FFFFFFF6F6F6F6F6F6F6F6FFF6F6F6FFF6F FFFF6F6F6F6F6F6FFFFF6FFF6F6F6F6FFFFFFFFF6F6F6FFF6F FFFF6F6F6F6F6FFF6F6F6F6F6F6F6FFF6F6F6F6F6F6F6F6FFF FFFF6F6F6F6F6F6F6FFF6F6F6F6FFF6FFFFF6FFF6F6FFFFF6F 6F6F6FFF6FFF6FFFFF6F6FFFFF6F6FFFFFFFFFFFFFFFFFFF6F FFFF6FFF6FFFFFFF6F6FFF6FFF6F6FFF6F6F6F6FFFFF6FFFFF 6FFF6FFFFFFF6F6F6FFF6FFFFF6FFF6F6F6FFFFFFF6FFF6F6F 6FFFFF6F6F6F6FFF6F6FFF6F6FFF6F6FFF6F6FFFFFFF6F6F6F 6F6F6F6FFF6F6F6FFF6FFF6F6F6F6FFF6F6FFF6F6F6F6FFFFF 6FFF6FFFFF6FFFFF6F6FFFFF6FFF6F6FFF6FFF6F6F6FFF6F6F
now we will try 123F delay
6FFF6F6FFFFFFF6F6FFF6F6F6F6FFF6F6FFF6FFFFF6F6F6F6F FF6FFF6F6F6F6FFFFF6F6F6F6F6F6F6F6F6F6F6F6FFF6F6F6F FF6FFF6FFF6F6F6FFFFF6F6FFF6F6F6F6F6F6F6F6FFF6FFFFF 6F6F6FFFFF6FFFFFFF6F6F6F6F6F6FFF6F6FFF6F6FFF6FFF6F FFFF6F6F6FFFFFFF6FFF6F6F6FFF6FFF6F6FFFFF6FFF6FFF6F FFFF6F6F6FFF6FFF6F6FFF6F6FFF6F6F6FFFFF6F6F6F6F6F6F 6F
Script Error on Line 125
Script Aborted By User
.................................................. ................this it what it looks like with or without the trimmer help!!!
dssdork
10-17-2004, 08:38 AM
this is totally weird i just popped my first a23 in less then 1 minute going figure i was tweaking on for the last 3 days and all of a sudden it popped in less then 1 min
lips905
10-17-2004, 09:37 AM
this is totally weird i just popped my first a23 in less then 1 minute going figure i was tweaking on for the last 3 days and all of a sudden it popped in less then 1 min
Great to hear that now all you do if you have more cards dont touch the settings and try them out.Whaen you get 60% ffff and 40% 66666 your cards will all pop.Some take longer than others just leave them in there.There is a new proggy out ther called a23vu V1 and you will get better sucess. :)
warrior_joe
10-17-2004, 04:54 PM
i am about to mod my loader.I have a dumb question..When it is said to lift the pin, does that mean unsolder the pin going to the board and lift it?
thanks
joe
dssdork
10-17-2004, 06:26 PM
i am about to mod my loader.I have a dumb question..When it is said to lift the pin, does that mean unsolder the pin going to the board and lift it?
thanks
joe
yes you have to heat up that pin and use something that will go between your pin so you can lift it up i used a really fine metal pick with a curve on the end of it
dssdork
10-17-2004, 06:28 PM
Great to hear that now all you do if you have more cards dont touch the settings and try them out.Whaen you get 60% ffff and 40% 66666 your cards will all pop.Some take longer than others just leave them in there.There is a new proggy out ther called a23vu V1 and you will get better sucess. :)
lips does the newd9 flash also work for rom 3 or is that just for rom 10 and i have to reflash it with newd6
dssdork
10-17-2004, 07:58 PM
ok i have 1 more problem i just caught my nephew (who is 6) with a 9 volt battery and he was in the area where i got all my stuff at anyways i have a rom 3 that he had in his hand as well i went to go check it it said invalid atr i know the card was open before he got to it and it had valid atr so i asked him if he had touched the battery to the card he said yes i tried running bugbuster but will not help is there anyway i can restore this card or is it just an ice scrapper now?
newd6 for rom3 and newd7 for rom10. newd8 and 9 are also for rom10
bummer about your rom. never heard of looping a rom with a battery before. What a drag.
justmeandthem
10-20-2004, 02:42 AM
? for anyone who can answer or shed some insite.... I am trying a rom 3 and when I run my unlocker I get all : o6f... what am I doing wrong... anyone? help please....
fdish
10-20-2004, 04:41 AM
any clue why im getting this error in winex guys?
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
0032FF
Sc.Read: Timeout Reading Data From Card - 9 Bytes Requested, 5 Bytes Read, Continuing Script
00
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 101
Sc.GetByte: Requested Byte Exceeds Last Read Request
justmeandthem
10-20-2004, 05:18 AM
Can anyone tell me what this means.. this is all I get is it right... will it eventually pop it...
Executing Script: C:\dish net\zips\new\mik3mod\TestGlitcher_Analyzer.xvb
Start Time: 10/19/2004 8:55:08 PM
TX Data : A0
TX Data : A1
TX Data : 02 03 00
TX Data : 02 02 00
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
FFAAFFAAAAAAFFAAAAAA--- try to hit 0C bug at 10A8 FF: 30% AA: 70% 10/19/2004 8:55:10 PM
FFAAAAAAAAAAAAFFAAFFAA--- try to hit 0C bug at 10A9 FF: 30% AA: 80% 10/19/2004 8:55:10 PM
AAFFFFFFFFFFAAFFAAFFFF--- try to hit 0C bug at 10AA FF: 80% AA: 30% 10/19/2004 8:55:11 PM
FFAAFFFFFFAAFFAAAAAAFF--- try to hit 0C bug at 10AB FF: 60% AA: 50% 10/19/2004 8:55:11 PM
AAAAAAFFFFAAAAAAFFAAAA--- try to hit 0C bug at 10AC FF: 30% AA: 80% 10/19/2004 8:55:12 PM
FFFFFFFFFFFFAAFFFFFFAA--- try to hit 0C bug at 10AD FF: 90% AA: 20% 10/19/2004 8:55:13 PM
AAFFAAAAAAFFFFAAAAAAAA--- try to hit 0C bug at 10AE FF: 30% AA: 80% 10/19/2004 8:55:13 PM
AAAAAAAAFFAAAAAAAAFFFF--- try to hit 0C bug at 10AF FF: 30% AA: 80% 10/19/2004 8:55:14 PM
AAFFAAFFFFAAAAFFAAAAFF--- try to hit 0C bug at 10B0 FF: 50% AA: 60% 10/19/2004 8:55:14 PM
indal_98
10-20-2004, 05:35 AM
Can anyone tell me what this means.. this is all I get is it right... will it eventually pop it...
Executing Script: C:\dish net\zips\new\mik3mod\TestGlitcher_Analyzer.xvb
Start Time: 10/19/2004 8:55:08 PM
TX Data : A0
TX Data : A1
TX Data : 02 03 00
TX Data : 02 02 00
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
FFAAFFAAAAAAFFAAAAAA--- try to hit 0C bug at 10A8 FF: 30% AA: 70% 10/19/2004 8:55:10 PM
FFAAAAAAAAAAAAFFAAFFAA--- try to hit 0C bug at 10A9 FF: 30% AA: 80% 10/19/2004 8:55:10 PM
AAFFFFFFFFFFAAFFAAFFFF--- try to hit 0C bug at 10AA FF: 80% AA: 30% 10/19/2004 8:55:11 PM
FFAAFFFFFFAAFFAAAAAAFF--- try to hit 0C bug at 10AB FF: 60% AA: 50% 10/19/2004 8:55:11 PM
AAAAAAFFFFAAAAAAFFAAAA--- try to hit 0C bug at 10AC FF: 30% AA: 80% 10/19/2004 8:55:12 PM
FFFFFFFFFFFFAAFFFFFFAA--- try to hit 0C bug at 10AD FF: 90% AA: 20% 10/19/2004 8:55:13 PM
AAFFAAAAAAFFFFAAAAAAAA--- try to hit 0C bug at 10AE FF: 30% AA: 80% 10/19/2004 8:55:13 PM
AAAAAAAAFFAAAAAAAAFFFF--- try to hit 0C bug at 10AF FF: 30% AA: 80% 10/19/2004 8:55:14 PM
AAFFAAFFFFAAAAFFAAAAFF--- try to hit 0C bug at 10B0 FF: 50% AA: 60% 10/19/2004 8:55:14 PM
Justmeandthem.
You should of gotten all the info down before you try to mod the M-3.
If you look at what you post....you are getting a pretty Rx (Receiving data) back from the card, so that means that your WinEX settings is correct.
Now look at the first line of the script, notice where it says "Read card..." If you would do just that and verify that the Overflow on your M3 is working, which means the loader IS glitching.
But obviously it is glitching, so you can just stick the locked Rom3 in, flash the loader with new7d.hex and start adjusting your Vcc setting to get ffff6f6f6f6fffff.
I've done 7 M-3 loader mods, all used 2.2K resistors...
G'L
justmeandthem
10-20-2004, 05:50 AM
where did you set your Vcc too... So I can have a good starting point..... Thanks..
justmeandthem
10-20-2004, 05:53 AM
I ran it and all I get is :
Executing Script: C:\dish net\zips\new\mik3mod\f\unlockrom3.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 38
o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o0 0o00o00o00o00o00o00o00o00o00o00o00o00o00--- try to hit 0C bug at 10A5
o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o0 0o00o00o00o00o00o00o00o00o00o00o00o00o00o00--- try to hit 0C bug at 10A6
o00o00o00o00o00o00o00o00o00o00o
I ran it and all I get is :
Executing Script: C:\dish net\zips\new\mik3mod\f\unlockrom3.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 38
o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o0 0o00o00o00o00o00o00o00o00o00o00o00o00o00--- try to hit 0C bug at 10A5
o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o0 0o00o00o00o00o00o00o00o00o00o00o00o00o00o00--- try to hit 0C bug at 10A6
o00o00o00o00o00o00o00o00o00o00o
That's what you get when you try to unlock a looped card. So far we don't do unlooping with these mods unless it's just software looped.
justmeandthem
10-20-2004, 06:30 AM
how can I find out if it is software looped?
warrior_joe
10-22-2004, 05:26 AM
Executing Script: C:\WINDOWS\Desktop\test\unlockrom3-b.xvb
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 38
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 10A2 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 10A3 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 10A4 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 10A5 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 10A6 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 10A7 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 10A8 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
whats goin on with this? am i close, far, i donno what i should do next. any help?
work4dss
10-22-2004, 01:15 PM
Did a mod for Mk3 Rev C.....
Cleaned & load ROM 3 w/ TESTglitch.bin in NE 4.1...
Used a trimer pot 5K w/ 3 pin.... only soldered 2 pin... to C10 & the VCC on card slot.....
When I ran the TESTglitchFIND.XVB w/ correct settings. All I got is the following:
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050 CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
<--- try to hit 0C bug at 10A5
<--- try to hit 0C bug at 10A6
<--- try to hit 0C bug at 10A7
<--- try to hit 0C bug at 10A2
<--- try to hit 0C bug at 10A3
<----try to hit 0C bug at 10A4
<--- try to hit 0C bug at 10A5
<----try to hit 0C bug at 10A6
<--- try to hit 0C bug at 10A7
<--- try to hit 0C bug at 10A2
<--- try to hit 0C bug at 10A3
<--- try to hit 0C bug at 10A4
On & on & on....... (No FFFFFF or AAAAA)
Any1 know wat I did wrong? or any sugestions?
davesnightmare
10-22-2004, 08:22 PM
Executing Script: C:\Documents and Settings\Desktop\DSS\Dish Network\unlockers\Penga\3-TESTFILES\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data :
Script Error on Line 70
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read
-------------------------------
i get this error no matter what flash, also with or with out card in loader.
im running a rev c, with 2.2k resistor
ps2 power
can anyone help??
dssdork
10-23-2004, 02:58 AM
any clue why im getting this error in winex guys?
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
0032FF
Sc.Read: Timeout Reading Data From Card - 9 Bytes Requested, 5 Bytes Read, Continuing Script
00
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 101
Sc.GetByte: Requested Byte Exceeds Last Read Request
what voltage is you adapter if it is to low it might be from that try 7.5 or 9 volts i had better luck with a 9v
Why don't we just admit this doesn't work?
It works great at my house; and not just with the MikIII either. The physical part of this mod is the easy part. Setting up the software can be a little tricky. Just follow the directions in the read me's exactly and you'll be fine.
Gillis65
10-23-2004, 06:33 PM
My Mikobu III mod is working great here. Read read read... Don't give up. Make sure your mod is taking the flash for sure. Jt, aside from adjusting your trimmer and vcc settings- did you need to play with the timeout or any other settng? I only needed to calibrate the vcc settings before seeing the beautiful CAM IS NOW OPEN message. Good luck guys.
The only thing I do is adjust the trimmer as the testglitch.xvb is running until I see the right response. I don't even mess with the VCC start or limit in the software. As Gillis65 said, read, read, read and don't give up. This project works great. As Gillis65 alluded to, I do think the most significant problem people are having is not getting the flash on correctly. I changed the timing settings in xpatmel to 60/50/1 by right clicking on the bar in the middle of the xpatmel window and that seems to help get the loaders flashed correctly. If your getting the timeout errors, your probably not flashed correctly.
warrior_joe
10-23-2004, 09:16 PM
This is where im at:
i use a open card with the test bin for rom3...it says:
VCC = &h5E
glitch type = &h07
glitch delay = &h10A4
GLITCHED past 0C BUG!!!, unlocker is good to go.
use the above settings on real unlocker script
3FFF9500
i insert the info into the unlockRom3
i run the program for ten hour only to get:
--- try to hit 0C bug at 0023 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 0024 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 0025 -
I put in a 5k multi trimmer...no matter where i set it...it doesnt change a thing ..except to get 0o0o0o0o0o0o0o0o0o.
i changed vcc setting and still get:
--- try to hit 0C bug at 0023 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 0024 --
O6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6 FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6FO6F
--- try to hit 0C bug at 0025 -
What is a tester to do at this point but to turn to a more knowledgable tester!
I know my unlooper is flashed properly.
I have run all the programs available for the rom3
I have read every post from this forum and more...
anyone have any relevant imput to help me become a beleiver?
When i put an unlocked cam in the unlooper..i get:
Executing Script: C:\WINDOWS\Desktop\satallite folder\mic3\test\unlockrom3-b.xvb
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
O63
===============================
= Rom 3 CAM IS OPEN NOW !!!!! =
===============================
Everyone keeps telling me to let it run...when 14hours and no pop yet!
I need some homework..please advise..Thanks
Joe
Caesar_Mikey
10-23-2004, 09:16 PM
well I had same errors that all are haveing so I tired takeing trimmer off and replaceing with a 2.2k restor and it works opened 2 rom10s havent got any rom3s open yet
dssdork
10-23-2004, 09:23 PM
where did you set your Vcc too... So I can have a good starting point..... Thanks..
on my mik3 my settings are vcc start=59 vcc limit=51 fisrt rom10 a23 took less then a minute and the other ones ranged from 15 min to 1 hour just make sure it says 6fffff6fffff6ff6f6fffff6ffffff6fff6fffff6fff and leave it alone and let it run it will pop.....but i have this other rom 10 rev23 i let it run approx 14 hours and did noting to it so what im saying is that for rom 10 rev23 it ranges from 1 minute to a few hours dont give up it will pop if you are getting 6ff6ff6f6fff6f6fffff6ff6ffffff6f6f6ff also i have rom 10's rev21 it literally took 1 second to pop those ones!!!!!!
warrior_joe
10-23-2004, 09:39 PM
i will attemp a rom10 this evening and reflash my loader. I do beleive rom10's can be opened, but am skeptical about rom3's.
For now i am still awaiting a guru to give me some insight in opening a rom3. Its hard to beleive, that rom3 can open..ive tested hard for days and cant get one open....i am still optimistic but need imput.
my mod mk3 flashes fine, but when i run testglitch it keeps trying to hit bug, no 0000 or ffffff , i checked e050 its still at ff any ideas where to start for fix, thanx
work4dss
10-25-2004, 02:33 AM
Questions?
I keep trying testglitchfind.vxb and varies the trimmer pot to like 2.24, 2.23, 2.21, 2.20, 2.19, 2.17, 2.16 K ohm..... (let it run like 90 min+ on each setting)
Using original testglitchfind.vxb.... I notice around 2.23 & 2.24 ( the SUCCESS glitch come in faster and earlier after the script ran)
++--++--++-+---+-+-++-++--+-+-++-+-+++--+---++-+++----- try to hit 0C bug at 10AA
+-+++---++--+---++-
===========================================
Success on Test Glitch, Try #19
VCC = 36 (~1.05882352941176 vdc)
Glitch Delay = 002D
Glitch type 05
READ 20-23 from ram, glitch =CCE280
===========================================
++---++-+---++---+------+++-++++--- try to hit 0C bug at 10AB
+----+-+-+----+-+-+-+-++++-+---+-+-++++--+-+-+----++--- try to hit 0C bug at 10AC
-+--++-+-+----+++-+-+---+++++--+++---+++-+-+-+-++--+--- try to hit 0C bug at 10B3
+--+---+-+---++-+---++++++---++
===========================================
Success on Test Glitch, Try #31
VCC = 35 (~1.03921568627451 vdc)
Glitch Delay = 002D
Glitch type 05
READ 20-23 from ram, glitch =CCE280
===========================================
-+--+++--++---+-+-+---- try to hit 0C bug at 10B4
-+--+-+-++++-+-+-+--++-++++--+--++--++--+++-+---+--+--- try to hit 0C bug at 10B5
Keep getting Success on Test Glitch & VCC = VARIES.....
BUT I CANNOT HIT THIS: (maybe except 1 time)
===========================================
VCC = ????
glitch type = ????
glitch delay = &h10A5
GLITCHED past 0C BUG!!!, unlocker is good to go.
use the above settings on real unlocker script
3FFF9500
===========================================
Should I try to ADJUST THE SETTING INSIDE the TESTglitchFIND.xvb?
VCC = &h37 'YOU CAN CHANGE THIS FROM 20 TO 50 241A
trylimit = 51
VCCLimit = VCCStart - &h28 'YOU CAN CHANGE THIS FROM 1A TO 30
Could some1 advices or comments on this a little? pretty sure many that started the unlocker mod wanted to hit the sweet spot more easier....Thanks
JigaX
10-25-2004, 07:12 AM
Hello everyone this is the second mikobu I try to mod when i try flashing it i get
Hex Files Loaded.
Initializing ...
Initialized
Syncing ...
Failed: Could not find Active Atmel!
Complete!
Can someone please help me out.
did u run a toggle switch to switch it over when u flash it
JigaX
10-26-2004, 02:27 AM
did u run a toggle switch to switch it over when u flash it
I read that when pin 232 is down it's for flashing and up for programing, i didn't run any switch, i did try with just two wires but nothing.... when i run the program all i get FFFFFFFFFF and with the TESTglitchFIND.XVB i get Script Error on Line 152
Sc.GetByte: Requested Byte Exceeds Last Read Request
After running the script for a little bit not even a min...
baruskie
10-28-2004, 11:09 AM
I have a MIII revC black board. I have a mini toggle switch mounted next to the top for flashing and unlocking. I am using a 2.2K resister that measures 2.13K with a meter. I flashed it with d7 file and was getting all F’s. I played around with the VCC settings and finally found the settings that popped my ROM10 A23 in less than a minute. VCCStart = &h80 VCCLimit = &h40. Hope this helps some people out.
disher1
10-29-2004, 06:20 AM
okaY I got the loader modified and flashed I think? ran test file without card in mk3 and here's what I get
Executing Script: C:\Documents and Settings\All Users\Documents\Charlie Files\mik3flash\test and flasher\3-TESTFILES\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
--- try to hit 0C bug at 10A5
--- try to hit 0C bug at 10A6
--- try to hit 0C bug at 10A7
--- try to hit 0C bug at 10A8
--- try to hit 0C bug at 10A9
--- try to hit 0C bug at 10AA
--- try to hit 0C bug at 10AB
--- try to hit 0C bug at 10AC
--- try to hit 0C bug at 10AE
and it just keep going like this ! I have loader flashed with #8 ..I have been reading and think I need to load test bin on good card is this correct I only have one good rom3 and a lock a-23 rom ten Please dont flame just point me to the thread or give help! Help
indal_98
10-29-2004, 06:29 AM
1) load test bin on good card ..
2) Flash new6d.hex to loader...
Read the readme.txt file for more info.
G'L
disher1
10-29-2004, 09:31 AM
Executing Script: C:\Documents and Settings\All Users\Documents\Charlie Files\mik3flash\test and flasher\3-TESTFILES\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
--- try to hit 0C bug at 10A5
--- try to hit 0C bug at 10A6
okay tried with card in loader with sample bin and hex # 6 flashed in loader same result as above. I even tried an old unlooper without any flash same as above! That telling maybe it not flashing the chip even if the amtel flash program.says it is ...JT in an earlier thread mention ther was some setting in amtel flash that if you right clicked on the blue bar in the progam it gave you setting options ..I got nothing. I notce in the reading above from my loader that my RX values are just two set of numbers 06 00 Explorer is not read from card, double checked all setting in Explorer per read me fle at dead end ....Need Yea Help!
disher1
10-29-2004, 10:03 AM
[QUOTE=disher1]Executing Script: C:\Documents and Settings\All Users\Documents\Charlie Files\mik3flash\test and flasher\3-TESTFILES\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
Okay,finally getting some were just tookout the trimmer and replaced it with 2.23 reesistor nowI got alll fffffffffffffffffffff, not how due you set the vcc value?
...JT in an earlier thread mention ther was some setting in amtel flash that if you right clicked on the blue bar in the progam it gave you setting options ..I got nothing. I notce in the reading above from my loader that my RX values are just two set of numbers 06 00 Explorer is not read from card, double checked all setting in Explorer per read me fle at dead end ....Need Yea Help!
If your right handed, your index finger is left clicking. You 'pinkie' click on the bar in the center of the window when xpatmel is open. Then you will see an option to open the timing settings menu. I don't think your getting flashed properly. Change timing to 60/50/1. The read me's in Penga's files tell you how to adjust trimmer AND/OR VCC start and limit in the software to acheive the pattern of F's and A's you want to see. (assuming your using rom3 and testglitchfind.xvb)
disher1
10-29-2004, 07:46 PM
If your right handed, your index finger is left clicking. You 'pinkie' click on the bar in the center of the window when xpatmel is open. Then you will see an option to open the timing settings menu. I don't think your getting flashed properly. Change timing to 60/50/1. The read me's in Penga's files tell you how to adjust trimmer AND/OR VCC start and limit in the software to acheive the pattern of F's and A's you want to see. (assuming your using rom3 and testglitchfind.xvb)
Okay changed vcc 59 and 51
AAAAFFAAFFFFAAFFAAAAAAFFFFFFAAFFFFAAAAAAAAFFAAFFAA FFAAAAAAAA--- try to hit 0C bug at 10A5
AAFFAAFFFFAAAAAAAAFFAAFFFFFFAAAAAAAAAAFFFFFFFFAAAA AAFFAAFFAAFF--- try to hit 0C bug at 10A6
FFAAAAAAAAAAFFFFFFFFAAAAAAAAAAFFFFAAFFAAFFAAAAAAAA AAAAFFAAAAAA--- try to hit 0C bug at 10A7
FFFFFFFFFFFFAAAAAAFFFFFFFFAAFFAAAAFFAAFFAAFFFFFFAA AAAAFFAAAAFF--- try to hit 0C bug at 10A8
FFFFAAAAAAAAFFFFFFFFFFAAAAAAAAAAFFFFFFFFAAAAAAFFFF AAFFAAFFAAAA--- try to hit 0C bug at 10A9
AAAAAAAAFFAAFFAAAAFFAAFFAAFFFFFFAAAAAAAAFFAAFFFFFF AAAAAAAAAAFF--- try to hit 0C bug at 10AA
FFFFFFAAAAAAAAFFFFAAFFFFAAAAAAFFFFFFAAFFFFAAAAAAAA FFAAFFFFFFAA--- try to hit 0C bug at 10AB
AAAAAAFFFFFFAAFFAAAAAAFFAAFFAAFFFFAAAAAAAAFFAAFFFF FFAAAAAAFFAA--- try --- try to hit 0C bug at 10B0
JT am I getting there? I am using amtel flasher to flash using #6 You keep refering to the Penga read me file in your reply in thread ? can you Pm or link me unclear on were its located. I have download every downable file in this thread can;t find!
Also you are spelling your flash program as xpatmel are we talk the same file? because when I cick left or right in Amtel flaher nothing! no ettig options
xpatmel and atmel flasher are NOT the same program. No wonder the right click thing wasn't working for ya. That looks like a pretty good combo of F's and A's to me. You should hit the bug with those settings.
disher1
10-29-2004, 08:47 PM
xpatmel and atmel flasher are NOT the same program. No wonder the right click thing wasn't working for ya. That looks like a pretty good combo of F's and A's to me. You should hit the bug with those settings.
So let it run? okay will do ....can you send me your flash and the read me file in penga
disher1
11-02-2004, 09:58 AM
So let it run? okay will do ....can you send me your flash and the read me file in penga
All Right,SUCESS pop two 383 rom 3 about in three hours , but get a load of this never seen these numbers posted 4's! Stated of glitching like this then changed to below .
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6
Could never get test glicthes to work got tried and went for the real thing!
Milk 3 rev c ## DelayStart = &h10A4 ( Flash #6)
DelayLimit = &h10A5
VCCStart = &h77 'YOU CAN CHANGE THIS FROM 20 TO 50-SET TO TEST BIN
VCCLimit = &h1A 'YOU CAN CHANGE THIS FROM 1A TO 30-SET TO TEST BIN
GlitchType = &h07
4o04o04o04o00o00o00o00o00o00o00o00o00o00o00o00o00o 00o00o00o00o00o00o00o00o00o00o00o00o00o00--- try to hit 0C bug at 10A5
o00o00o00o00o00o00o00o00o00o00o04o04o04o04o04o04o0 4o04o04o04o04o04o04o04o04o04o04o04o04o04o04--- try to hit 0C bug at 10A6
o04o04o04o04o04o04o04o04o04o04o04o04o04o04o04o04o0 4o04o04o04o04o04o04o04o04o04o04o04o04o04o04--- try to hit 0C bug at 10A7
o04o04o04o04o04o00o00o00o00o00o00o00o00o00o00o00o0 0o00o00o00o00o00o00o00o00o00o00o00o00o00o00--- try to hit 0C bug at 10A2
o00o00o00o00o00o00o00o00o04o04o04o04o04o04o04o04o0 4o04o04o04o04o04o04o04o04o04o04o04o04o04o04--- try to hit 0C bug at 10A3
o04o04o04o04o04o04o04o04o04o04o04o04o04o04o04o04o0 4o04o04o04o04o04o04o04o04o04o04o04o04o04o04--- try to hit 0C bug at 10A4
o04o04o04o04o04o63
=========================
= CAM IS OPEN NOW !!!!! =
=========================
Script C:\Documents and Settings\Desktop\unlockrom3.XVB Transmission Completed
coolwind
11-03-2004, 07:30 AM
Hello Fellow members
I have a MK3 Rev C modded I am having troubles getting Rom 10 a 23 to pop cam someone Pm me with good info as VCC Analyzer is not working for me or I am Doing something wrong TKS To all
Coolwind
debauche
11-04-2004, 05:16 AM
I get
o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o0
only when flashing with 7,8 or 9 and rom3, so I think if you get that, the flash is screwey or wrong for the card you are trying..
Flash 6 has opened 2 rom 3's, but one last streamlocked I have only gives me
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 F
How does one read the bin file winex generates?
warrior_joe
11-04-2004, 02:58 PM
Just a note to all who are having trouble opening a Rom3....
I have spent over a week trying to get a rom3 to open. I ran the rom3 program every night ..all night , changing every setting i could with no luck. Changed the resistor to a pod and back....using a pod again...
I used the test bin and gathered all the info and used that info on my rom3 program.
Last night i ran the test script again and let it run until i had alot of hits. I took the info and set the limits within the info i obtained in the test script. I have successfully gotten the card to open this morning...what a feeling, after all that testing..it does really work....I beleive other peoples setting will not work for you. I think every computer is different..Here are my settings that opened my rom3:
DelayStart = &h10AC
DelayLimit = &h10A7
VCCStart = &h60 'YOU CAN CHANGE THIS FROM 20 TO 50-SET TO TEST BIN
VCCLimit = &h64 'YOU CAN CHANGE THIS FROM 1A TO 30-SET TO TEST BIN
GlitchType = &h07
TryCnt = 1
TryLimit = 2
Delay = DelayStart
dont stop trying...it will happen for you........
I want to thank all of the fine peeps who responded to my questions along the way..Happy testing
Joe
dssdork
11-04-2004, 11:38 PM
Hello Fellow members
I have a MK3 Rev C modded I am having troubles getting Rom 10 a 23 to pop cam someone Pm me with good info as VCC Analyzer is not working for me or I am Doing something wrong TKS To all
Coolwind
try 59 ad 51
warrior_joe
11-05-2004, 03:33 AM
after 60 hours of testing, i finally got the rom3 opened....here were my settigs:
Sub Main()
DelayStart = &h10AC
DelayLimit = &h10A7
VCCStart = &h60 'YOU CAN CHANGE THIS FROM 20 TO 50-SET TO TEST BIN
VCCLimit = &h64 'YOU CAN CHANGE THIS FROM 1A TO 30-SET TO TEST BIN
GlitchType = &h07
TryCnt = 1
TryLimit = 2
Delay = DelayStart
i believe that each computer will give you different settings...i used a pod and it was set at 2.24...i feel ive accomplished something
Squidly
11-07-2004, 03:08 AM
I modded a MikIII, have XP Pro, WinEx5.0. I went over everything a number of times with a DMM. everything is fine. MikIII takes the flash with no problem.
Here is what I get off the bat.
Getting Cam ID for Log File
Timeout from 2A command
Have changed the settings in WinEx to loader2, turn switch on & flash with anyone of the files & it's sucessfull. Can I be missing a file for winex??? My PC did crash & I have winex to work with other apps. I also did install a 2.2K 1/2 watt resistor. TIA
Squidly
11-07-2004, 05:22 AM
Ok, Got WinEx5.42 & now getting this
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 0E
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 03 00
Now we will try 123E delay
RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET
dssdork
11-07-2004, 05:25 PM
Ok, Got WinEx5.42 & now getting this
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 0E
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 03 00
Now we will try 123E delay
RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET
you have to change your vcc settings until you get a mixture of 6F FF and let it run it will pop i had good luck with vcc start 59 vcc limit 51 also had luck with vcc start 57 and vcc limit 51
Squidly
11-07-2004, 06:11 PM
Sorry, forgot to mention that I have ROM10
' These are the variables you can change for rom 10 dish A23
VCCStart = &h1A 'YOU CAN CHANGE THIS FROM 18-30
VCCLimit = &h13 'YOU CAN CHANGE THIS FROM 10-20
DelayStart=&h123E 'DISH A23 is 123E- could be as low as 1100
DelayEnd = &H125A 'DISH A23 IS 125A- could be as high as 127A
TryCnt = 300 'Number of tries per delay FROM 5-50000
TestMode = 0 'TestMode, 1 = ON, 0 = OFF
'TestMode is used to find a glitch point on A81 cam. once you find the
'delay and vcc settings on cam then set TestMode = 0, and open the cam.
ismarhadzia
11-11-2004, 02:14 AM
Anybody knows how to resolve this problem.
This was initialy Stream locked card.
I tried running new unlockers for Rev81 with moded loaders.
but this A81 shows CamID: 00 00 00 00 which is weard and I dont have any success while unlocking.
I am using A81/A23 unlocker V 1.0
I was successful on my other card revA23 wich opened with no porblem in few minutes.
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 38 31 43
ROM Revision: 010
EEPROM Revision: RevA81
ProviderID: 08
CamID: 00 00 00 00
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BD3 login failed
Reading ROM10 failed
Closing of COM1 was successful
Modded my m3 flashed with newd7 for my A81 rom3. I get this error when running a test
Executing Script: C:\Documents and Settings\UTILITY BOX\Local Settings\Temp\Temporary Directory 2 for unlooperflashes.zip\3-TESTFILES\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data :
Script Error on Line 70
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read
One odd thing is that I get this error whether there is a card in the loader or not. I get the same error with no power to the loader.I do have the settings in winex right. I have checked at least 50 times (not kidding) It seems no matter what I do I get the same error. Unplugging the loader from com1 also produces the same result.
What the heck am I missing? It is 1:30 am maybe I am just too tired to think.
Or maybe I just didn't do the mod on the loader right. (it does flash properly though)
Anyone got any ideas?
sfg
What really dumb thing am I missing? (I hope its simple)
I should also metion that in nagra I get an invalid atr with my subbed card that works just fine in the receiver.
The script is failing on the first read attempt from the card so this tells me that I am not communicating with the card but I don't know why.
I have checked the mod over and over ( I am using a 2.2k resistor) Is there any other way to check if the mod was successfull?
Nifty
11-16-2004, 07:11 AM
Likely an incorrect setting in Winex
dssdork
11-17-2004, 02:30 AM
Modded my m3 flashed with newd7 for my A81 rom3. I get this error when running a test
Executing Script: C:\Documents and Settings\UTILITY BOX\Local Settings\Temp\Temporary Directory 2 for unlooperflashes.zip\3-TESTFILES\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data :
Script Error on Line 70
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read
One odd thing is that I get this error whether there is a card in the loader or not. I get the same error with no power to the loader.I do have the settings in winex right. I have checked at least 50 times (not kidding) It seems no matter what I do I get the same error. Unplugging the loader from com1 also produces the same result.
What the heck am I missing? It is 1:30 am maybe I am just too tired to think.
Or maybe I just didn't do the mod on the loader right. (it does flash properly though)
Anyone got any ideas?
sfg
What really dumb thing am I missing? (I hope its simple)
I should also metion that in nagra I get an invalid atr with my subbed card that works just fine in the receiver.
The script is failing on the first read attempt from the card so this tells me that I am not communicating with the card but I don't know why.
I have checked the mod over and over ( I am using a 2.2k resistor) Is there any other way to check if the mod was successfull?
well do you have a toggle switch installed for flashing and programming that might be your problem
chithead
11-22-2004, 01:40 AM
Neen help here. i'm using win 98se so i flash chip with Ufp1.6 I dont understand how get both Newd6.hex and Newd6.asm to load to the chip.
I can flash the .hex and it does verify good. this is what i have done so far.
1.) flashed modded mik3 rev:c with newd6.hex
2.)loaded testglitch.bin to a clean open rom3.
3.)in winex v.5.0 ran testglitchfind.xvb
I am using a 2.2 ohm but do have a pot trimmer that i can add. Can anyone tell me where i need to go from here?
A:\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
FFAAAAFFFFFFAAAAAAAAAAAAAAAAAAAAAAAAAAFFAAFFAAAAFF FFFFAAFFFF--- try to hit 0C bug at 10AD
AAAAAAAAFFFFFFFFAAAAAAFFAAFFFFAAAAAAAAFFAAAAFFAAAA FFAAAAAAFFAA--- try to hit 0C bug at 10AE
FFAAFFAAFFAAFFFFAAAAFFAAFFAAAAAAAAAAAAAAAAAAFFAAFF FFFFAAAAAAAA--- try to hit 0C bug at 10AF
AAAAAAFFAAFFAAFFFFFFAAFFAAFFFFAAFFAAFFAAAAAAAAAAFF FFAAFFAAFFFF--- try to hit 0C bug at 10B0
AAAAFFAAFFFFFFFFFFAAAAAAAAAAAAFFAAAAAAFFAAAAFFFFFF FFFFAAAAAAFF--- try to hit 0C bug at 10B1
AAFFAAFFAAFFAAAAFFFFAAAAAAFFAAFFAAAAAAAAAAAAFFAAAA AAFFFFFFFFAA--- try to hit 0C bug at 10B2
AAFFFFFFAAAAAAAAAAFFAAFFFFFFAAFFAAAAAAAAAAAAFFAAFF FFAAAAAAFFAA--- try to hit 0C bug at 10B3
AAFFFFAAAAFFFFFFFFFFAAAAAAAAFFFFFFAAAAFF
Crazy1_79
12-02-2004, 03:54 AM
Neen help here. i'm using win 98se so i flash chip with Ufp1.6 I dont understand how get both Newd6.hex and Newd6.asm to load to the chip.
I can flash the .hex and it does verify good. this is what i have done so far.
1.) flashed modded mik3 rev:c with newd6.hex
2.)loaded testglitch.bin to a clean open rom3.
3.)in winex v.5.0 ran testglitchfind.xvb
I am using a 2.2 ohm but do have a pot trimmer that i can add. Can anyone tell me where i need to go from here?
A:\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
FFAAAAFFFFFFAAAAAAAAAAAAAAAAAAAAAAAAAAFFAAFFAAAAFF FFFFAAFFFF--- try to hit 0C bug at 10AD
AAAAAAAAFFFFFFFFAAAAAAFFAAFFFFAAAAAAAAFFAAAAFFAAAA FFAAAAAAFFAA--- try to hit 0C bug at 10AE
FFAAFFAAFFAAFFFFAAAAFFAAFFAAAAAAAAAAAAAAAAAAFFAAFF FFFFAAAAAAAA--- try to hit 0C bug at 10AF
AAAAAAFFAAFFAAFFFFFFAAFFAAFFFFAAFFAAFFAAAAAAAAAAFF FFAAFFAAFFFF--- try to hit 0C bug at 10B0
AAAAFFAAFFFFFFFFFFAAAAAAAAAAAAFFAAAAAAFFAAAAFFFFFF FFFFAAAAAAFF--- try to hit 0C bug at 10B1
AAFFAAFFAAFFAAAAFFFFAAAAAAFFAAFFAAAAAAAAAAAAFFAAAA AAFFFFFFFFAA--- try to hit 0C bug at 10B2
AAFFFFFFAAAAAAAAAAFFAAFFFFFFAAFFAAAAAAAAAAAAFFAAFF FFAAAAAAFFAA--- try to hit 0C bug at 10B3
AAFFFFAAAAFFFFFFFFFFAAAAAAAAFFFFFFAAAAFF
If you can't hit the bug where you have your vcc settings, I would lower them a bit, looks like you have a few too many AA's to me.
Crazy1_79
12-02-2004, 03:56 AM
By the way, does anyone know if that USB edition MIK, 3 can be modded, I don't see the setting in winexplorer for usb port. I have a MIK 3 on the line from a guy in my area and I haven't seen it yet, don't know if it is a usb edition or not, just wondering if I should buy it if it is. I don't think I should.
Smith2619
12-02-2004, 05:33 AM
is this the mikobu for HU back in the day or the mikobu iso
Crazy1_79
12-02-2004, 10:32 PM
the mikobu for hu back in the day
Smith2619
12-02-2004, 10:40 PM
i have the one with the green casing but ti doesnt have that white plug port
Crazy1_79
12-03-2004, 04:31 AM
I just finished my mod to a mikobu 3 and It says it is unable to find active atmel. I double checked my connections, all looks well. Any suggestions? by the way I have the rev C board
BIGLONGDONG
12-08-2004, 07:11 AM
If you get this message you need to reflash. This is wha
AAFFFFAAFFFFAAFFFFAAAAAAFFFFFFAAFFFFFFFFFFAAFFAAAA FFFFFFAAFFFF--- try to hit 0C bug at 10AD
FFFFAAFFFFFFAAFFAAFFFFAAAAFFAAFFAAAAFFFFAAFFFFFFFF FFFFAAAAFFFF--- try to hit 0C bug at 10AE
FFAAFFFFAAAAFFFFAAAAFFFFAAAAAAFFAAAAFFAAFFAAFFFFFF AAFFFFAAAAFF--- try to hit 0C bug at 10AF
FFFFFFAAFFAAFFFFFFAAAAFFFFAAFFFFAAFFAAFFFFAAAAFF
===========================================
VCC = 59-0710AF GLITCHED past 0C BUG
3FFF9500
===========================================
FFAAAAFFFFFFAA--- try to hit 0C bug at 10B0
FFFFAAFFFFAAAAFFAAAAFFAAFFFFFFAAFFFFFFFFFFFFAAFFFF FFFFAAFFFFAA--- try to hit 0C bug at 10B1
AAFFFFFFAAAA
===========================================
VCC = 57-0710B1 GLITCHED past 0C BUG
3FFF9500
===========================================
FFAAFFFFFFAAAAAAFFAAAAFFFFAAFFFFFFAAAAFFFFFFAAFFFF--- try to hit 0C bug at 10B2
FFFFFFAAFFFFAAFFAAFFFFFFAAAAFFFFFFFFAAFFFFAAFFFFAA AAFFAAAAFFFF--- try to hit 0C bug at ....
Success! Now we just need some flashes to unloop with. Huge thanks goes out to Penga, no1b4me and everyone who took the time to post their pics. I took this pic of my MikIII revC and I think it turned out better than most. I also came up with a better way to install the flash enable/disable switch. The MikIII revC has a trace that comes off pin10 of U3 and goes under the board about a 1/4 inch behind the chip. (MikIII revD does not have this trace route) You can just solder one lead to lifted pin 10 and the other to the hole where the trace goes under the board. Much better way to do it than to put second lead to pin 18 of the atmel. That way puts two wires to pin 18 on the atmel is kind of a pain. Plus, it's farther away. Here's the pic.
What are the white and red wires running to?? Stupid question but need answer...
entrypoint
12-09-2004, 06:06 AM
O.k. this may seem a little odd, but is anyone out there willing to program my cards (rom3& 10),atmega cards and do a mod on my mikIII. If so please pm me I have all items needed sub,jtags etc.. I have tried unsucessfully to program my atmegas and get nothing but failure to go into program mode.. I read a lot of the posts and quite honestly I get even more frustrated not that I don't understand it is just so much and every problem seem to apply to me some way.directv was so much easier. I would appreciate someone's help who truly wants to truly help and not take me for a ride... Thanks so much
BIGLONGDONG
12-10-2004, 04:22 AM
When trying to flash this Mikobu III Rev c piece of crap I keep getting the following in xpatmel: error verifying eeprom addr 0010, expected 00 found 10
What am I missing here??? I am not an expert but usually I figure this stuff out...
help the dummies please......
I am not even sure I know how to flah correctly either... Flashed Mikobu back in the HU days but don't remember how... I have been reading this forum for awhile and everyone says to look here and there in the read me files but half the time you can't find them or they don't have read me files.. Please help.
Crazy1_79
02-16-2005, 12:37 AM
I just received a mikobu 3 rev C form a member of this forum he could not get it to work. I checked the vcc at the pot while the script was running and it was jumping all over the place, everywhere from 1.4 to 3.7 volts, while the script was running, this is way to low to glitch, I removed the pot put in a 2.2K resistor thinking the pot was defective, the same thing occured with the 2.2K reistor as well. So I removed the resistor and tried to get some negative hits in glitch analyzer without any resistance in there at all, I managed to get a good mix around 40 and 35 on a card returning the 69 response (don't take the vcc to seriously this can vary drastically from one card to the next) and I set it to run in the dealer locked delays of 0c20 to 0c40 and the card popped in a couple seconds. This post is being made to point out that the vcc at the two points the pot or resistor meet must maintain at least a 4.6 to 5.0 voltage to properly glitch so if you are having issues check the vcc at the points where the pot or resistor hook up or even try it without one at all relying solely on the vcc of the script settings.
Smith2619
02-19-2005, 09:17 PM
I have the Mikobu 3 with the green casing, can i do anything with that ?
Godfather1971
03-02-2005, 11:13 PM
hey all i'm using the a23 unlocker v1.0. Flashed mik3 with newd8 been trying to pop card for hours now with no luck..... Been trying everything but nothing working....anyone know if I have to change the vcc and delays or anything else on the settings so this card will finally pop............any help will be great..............Thanks
seanvan
03-06-2005, 01:55 AM
Helllo provider:
I recently purchase a T911 MODES from dsshouse, I am unable to unlock the card room 10, eventhough I did follow your direction, . Please advise me what I should do or, what's the next step to resolve this problems. The below message is what it gave me when I try to unlock the card.
________________Setting up WinExplorer_________________
Chip is flashed with D9(version REK9)and was verified.
VCC High &h1a
VCC Low &h10
TX Data : 02 03 00
TX Data : 02 02 00
TX Data : 08 0E 03 10 01 01 03 9A 00
RX Data : 08 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 8B 00
RX Data : 12 0C
RX Data : 12 00 08 92 04 00 C9 9B 4D 90 00 03
@@@@@@@@@@@@ Testing for good glitch voltage @@@@@@@@@@@@@
VCC 1A: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 19: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 18: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 17: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 16: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 15: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 14: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 13: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 12: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 11: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC 10: ++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++++++++
VCC Ceiling: 1A
VCC Floor..: 10
################################################## #######
# #
# For Dealer locked A23 try using Delay range 0C20-0C40 #
# #
################################################## #######
Delay Start &h0c20
Del End &h0c40
TX Data : A0
TX Data : A0
TX Data : A1
TX Data : 08 0E 03 10 01 01 03 9A 00
RX Data : 08 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 12 06
RX Data : 12 00 08 92 04 00
Now we will try 0C20 delay
6F6F6F6F6F6F6F6F6F6F6F6F6F6F RESET 6F6F6F6F6F6F6F6F6F6F6F6F
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 795
Sc.GetByte: Requested Byte Exceeds Last Read Request
newbie1conobie
03-06-2005, 02:09 AM
you need to run vcc analyzer first, which will give you your VCC ranges...
From reading Crzy1_79 guide, since you're getting all ++++++++, you need to lower your VCC start....
but vcc analyzer will give you the ranges you really need...
hope this helps
seanvan
03-06-2005, 02:36 AM
I am not sure I know how to lower VCC start, because I use the range that the script gave it to me to start Please advise me on how or what is the lower VCC I should use? I start my VCC @ 35 and end it at 01.
lips905
03-09-2005, 10:31 AM
try to get 65%fff and 35% 6666 it will pop.For stubborn cards use 0c20 to 0c40 Same thing you need 65% fffff and about 35% 6666
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.