PDA

View Full Version : help with loading a good rom3 bin


metwo
09-17-2005, 07:45 PM
can't seem to find any info as to how you load a good rom3 bin to programs to unlock a rom 3 at rev 383. i have a good- open rom3 but i can;t seem to get it to analize. i am using a nexus modded t911. i read a lot about putting a good script in the program but no one says how to do this. any help would be appreciated

redwingfan
09-17-2005, 07:51 PM
I don't think you can use a t911. You need a ISO reader / writer.

#40Fan
09-17-2005, 08:24 PM
That modded Nexus should do it. You need to download WinExplorer and some Rom3 unlocking scripts which can be found in the download section. You might do some searching on this site. There has been a lot of posts about it.

metwo
09-17-2005, 08:39 PM
i have the unlocking scripts but not a how to load a good rom3 script for analizing

#40Fan
09-17-2005, 08:49 PM
Search the forums. It is here.

metwo
09-18-2005, 05:58 PM
i have read both of crazy1 79 posts on how to use your modded loader- it says load a rom3 test bin but as i said before it does not say how you do it

riverman
09-19-2005, 03:58 PM
I think the plan was you load the test bin to an open card to get the settings for your loader so you can then try to open the locked card.I don't see much purpose currently of wasting time on unlocking Rom 3 cards but maybe you know something I don't.

Caddylover
09-19-2005, 04:52 PM
The easy way to do it is to just flash the loader with newd6 and run an unlocking script like ToysRom3.

Guaranteed to pop. Just let it run.

Caddy

metwo
09-20-2005, 12:21 AM
thanks for the replies- will give it a try and see what happens- i think i tried toysrom3 already. pretty much tried them all but what the heck- nothing to loose. and to powell- no i don't know anything you don't . just like to toy with these things ( kind of a sick fettish i think)

Cimba
09-21-2005, 04:30 PM
What return do you get when you try to read the card in NagraEdit 4.1 ?
In my Sticky in this sub-forum there are all kinds of unlocking programs.
Do you get a good read from any card using your modded loader, the nexus is notoriously unstable.
There's a start, report back.

metwo
09-21-2005, 10:32 PM
Opening of COM1 was successful
ATR String:xx xx xx xx .........ok ROM Revision: 003
EEPROM Revision: Rev383
Logging into card
Checking for BackDoor
BackDoor appears to be closed, aborting
Error reading image from card
Closing of COM1 was successful
this is what i get when i read the card i am trying to unlock- is that what you are looking for or the read i get from the open rom3

metwo
09-21-2005, 10:33 PM
Opening of COM1 was successful
ATR String:xx xx xx etc. (is good)ROM Revision: 003
EEPROM Revision: Rev383
Logging into card
Checking for BackDoor
BackDoor appears to be open, continuing...
Retrieving BackDoor password
Password: xx xx xx OK
Login successful
Reading image from card
Card read successfully with 0 retries
Card read successfully
Efficiency: 100.0%, Packets: 260, Retries: 0, Time: 5.78s
Closing of COM1 was successful
this is the open rom3

metwo
09-21-2005, 11:25 PM
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data :xx xx xx..........ok
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A5
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A6
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A7
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A2
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A3
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A4
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A5
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A6
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A7
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A2
o6Fo6Fo6Fo6Fo6Fo6Fo6F

this goes for a long time and eventually it will time out

metwo
09-21-2005, 11:29 PM
should add- this loader does not have a pot- has the resistor

metwo
09-22-2005, 12:29 AM
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo

Script Error on Line 236
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read
this happened after about 1 hour- using new6 with settings at 33-50-1. did not change the script at all

Cimba
09-22-2005, 09:35 PM
What unlocking proggie are you using ?

Suggest PowersynvUnlockall V2b, unlockrom3.xvb, Toys rom3 v3.

Cimba
09-22-2005, 09:54 PM
http://www.dssftp.com/forum/attachment.php?attachmentid=5686

In this proggie you flash your modded loader with the recommended flash and then load the test bin in NagraEdit 4.1 to your good rom 3. Run the program and get your vcc and delay values using the good card, use those values in the unlocking proggies with the locked card in your modded loader.
In my regular T911 I found that a vcc of 23 hi and 1E low, with a delay range of 10A4- to 10B3 worked well.

metwo
09-22-2005, 10:11 PM
thanks for the reply cimba- i have flashed the loader with newd6- opened nagra edit- don't know how to load the test bin and run it in nagra edit

Cimba
09-22-2005, 10:12 PM
There is a program for 383's using an ISO to unlock, I've heard it has worked but have no personal experience. It's called RomPopper 383. I will try to attach but it may not let me, stay online for a bit while I try this. Nope won't let me, will try to add elsewhere, hang tight.

Cimba
09-22-2005, 10:20 PM
This can be run in your ISO programmer, try it first.

Addie didn't work, getting pissed. Do a search in the downloads section for RomPopper 383, it is there. Open it and run your locked card in it.

metwo
09-22-2005, 10:23 PM
thanks will give it a try and let you know how i made out

metwo
09-22-2005, 10:33 PM
cimba-that is for dishnet- this 383 is bev

Cimba
09-22-2005, 11:11 PM
Alot of proggies are for both, try it anyway and the worst that can happen is it will get looped. Remember you are doing this program on your locked 383 card, not the good one.
By the way o6fo6fo6f etc. is a good return, some cards take overnight to unlock.

Cimba
09-22-2005, 11:17 PM
Also, that open card read at 383 which is odd, have you done a one step clean on it ?

metwo
09-22-2005, 11:19 PM
thanks again- did try it a number of times and no luck. story is i must love misery. if i get the card to open- what next- just like trying to learn something as i have opened about 5 rom10's. a little easier than this sucker. i have been at this one for weeks now

metwo
09-22-2005, 11:20 PM
i believe if i knew how to analyze the card and load it i may have half a chance to pop it

metwo
09-22-2005, 11:22 PM
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 38 33 F5
ROM Revision: 003
EEPROM Revision: Rev383
Logging into card
Checking for BackDoor
BackDoor appears to be closed, aborting
Error reading image from card
Closing of COM1 was successful
Error detected, One Step Clean incomplete

Caddylover
09-22-2005, 11:36 PM
Why don't you just send it to me and I'll open it for ya.

Caddy

metwo
09-23-2005, 03:09 AM
thanks for the offer- i just like to play with it (the card too) the jou of accomplishment i guess. why- don't know as it can be very fustrating

Cimba
09-23-2005, 05:25 AM
Well I'll play along when I can, did you try the vcc and delay settings I suggested in any of the proggies ? Penga's unlooper-glitcher is a good program(called just unlocker-glitcher in my Sticky). What were you running when you got the o6fo6fo6f ?

Don't be afraid to run a program for overnight or longer if you are getting a good return like that, rom 3's can be a real stubborn item and often will pop after a very long run at it.
If you want more help let me know, its hard right now cause I took all the programs off my PC so I'm reading from disk.

Cimba
09-23-2005, 06:04 AM
i believe if i knew how to analyze the card and load it i may have half a chance to pop it


You can;t do either while it is locked. Gotta pop her first, then one-step clean and then if you want proceed on to applying a working .ep file and blocker.
Is there a chance that there is a blocker on it ?

metwo
09-23-2005, 11:13 AM
i belive this was dealer locked and most likely a blocker on it. i do have a rom3 at 383 that is open and want to analyze that one but don;t know how to do it. yjought that may give me the settings for my loader. tried a lot of settings and ran the programs overnite when they would run. getting time out error a lot

werks
09-23-2005, 02:42 PM
i belive this was dealer locked and most likely a blocker on it. i do have a rom3 at 383 that is open and want to analyze that one but don;t know how to do it. yjought that may give me the settings for my loader. tried a lot of settings and ran the programs overnite when they would run. getting time out error a lot
why are we talking about ROM 3? No good for anything but lifting dog pooooooo off the floor! lol I got an open one here...if ya want it!

Cimba
09-23-2005, 07:49 PM
It's just the sport I believe, part of learning curves, fun ! Am really ill right now metwo, read Crazy's Sticky, Cid's Sticky. I'll try to get on later with some info.

Here is a good guide to programming an open rom 3.



With Dishnet, the card must contain the receiver's ID and box keys or nothing works
If the receiver is hooked up and you insert your card with no blocker, it will get hit immediately with the newest Rev and you will be stream-locked.
After you install a blocker, either Mili's or a public one, do not read the card with the blocker in place. It can loop it, and then it's a trashcan item. Remove the blocker first if you need to read the card.
Let's try running a ROM3 card first,

OK, now let me try to step you through a programming procedure:
First, create a folder, if you haven't already done so, for files like DishBlocker 4.1, Tier Lists, JKeys, etc...download and extract that stuff in your folder. Also, get your receiver ID (converted to hex) box keys and CAMID (converted to hex) ready to go. You'll need all of that during the programming sequence.
Quick tutorial on that:
Take the receiver ID number, drop off the first three characters (like R00) and the last two (after the hyphen)..you'll be left with 8 numbers. That's the ID. Convert this number to hex, in Windows Calculator. If you're left with only 6 or 7 digits, add the appropriate amount of zeros to the beginning of the sequence to make it an 8 digit number. Example - if the hex conversion shows 338657, then you'll need to use 00338657. You'll also need to convert your zipcode ( you may have to use the closest USA zip to you) to hex. Same deal...add enough zeros to it to make it 8 characters long.
OK, power up your loader and insert the Rom3 . It's unlocked and clean. I'm going to start you from the top,

Open NagraEdit 4.1. Click CARD, then Reset Card (ATR)...let it reset. After each Nagra function is complete, you'll get a message, "such and such completed successfully, Com Port 1 closed"..or something similar.
Now, Click CARD and READ the card. When done, click CARD, and ONE STEP CLEAN the card. It will ask you, "full clean?"...click OK. Let it clean...takes maybe 30 seconds. Notice the cleaning steps taking place...make sure you see "backdoor appears to be open" messages as you go through your steps.
After the cleaning,
Now , come down a couple of lines in Nagra, to DATA EDITOR (small box) and click on it. To the right, you'll see all the pertinent data on your card. It will start at the top..this is where you type in the 8 character Receiver ID, in hex conversion format. Then, the Box Keys in hex, then, the time zone in hex, not sure where you are...but Central , for example, is EC. Now, the zip code in hex.. Then, you'll see three lines for the CAMID. Drop down to where it says "code space", "low provider info", and "high provider info". Enter the camid, in hex format .
Now, just LEAVE that information. Again, don't try to send it anywhere or write it to anything.
OK, now look to the right of the Data Editor box...click PATCH. Then, look down a couple of spaces..click the larger box that says Open Patch. It will prompt you for it...select the tier list you created in whatever program you used ie: TCFD 2. Use the .ne / .ep file that you created or the supplied test bin and matching the ROM version of your card. Open it..you'll see a big list of tiers in the screen. Now, go to the right of the OPEN PATCH box, find and click RUN PATCH. You should get a message at the bottom of the tiers that says "Patch installed with 0 errors".
If you're still with me, and all is well, go back to CARD, and click WRITE TO CARD. Click it, you'll get a window asking you to confirm...click OK. At this time, the program will write all the data you entered in Data Editor, and the tier list patch...all at the same time. If you see the message at the bottom, when it's done, "card written successfully"...well, then - pour yourself a cold one !!
OK, that's it for now...if everything went according to plan, you should be watching TV.

realfire
09-23-2005, 08:57 PM
why are we talking about ROM 3? No good for anything but lifting dog pooooooo off the floor! lol I got an open one here...if ya want it!

I beg to differ sir also works well for chewing gum on the floor tracked in @ my business, the rom 2 when sharpened makes a light box cutter for cutting the seal on boxes also

metwo
09-23-2005, 09:21 PM
cimba- i think there is a little confusion- i know how to program the card - this is all about unlocking a dealer or stream locked rom3 rev 383. i notice in a lot of the scrips it says to load a good- open rom3 to get the settings for glitching- thats where the problem comes in. i unlocked about 5 stream locked rom 10's- however i am having a lot of trouble with this sucker. and yes - werks thats about all it may be good for- this is all about learning how to. personal satisifaction. wife won't play with me anymore and the girlfriend is fed up with me so i have to do something to keep myself occupied

metwo
09-23-2005, 09:26 PM
cimba- sorry to hear you are not feeling well- maybe a bottle of good ole cape breton moonshine might help you out. i know when i had a bad cold it didn't make the cold any better but made me feel a little better about having it

Cimba
09-24-2005, 12:11 AM
Lets start over and you tell me what programs you have tried, what vcc and delays you used in each and what return you get. It sounds like you are close when you get the o6fo6fo6f return, try adjusting the vcc and delay values. Change those values only before you run a program, I cut up my one looped rom 3 so its hard to guide you through.
Try a vcc range of 23 and 1F with a delay of 10A5 to 10B3 in the program called unlockrom3.zip, also in Smart Toys Modded Rom3 & 10 unlocker, and PowerSyncunlockall V2b. Skip any analyzer steps and go right to the unlocking portions. If those vcc/delay ranges don't give a good return(let it run a bit)then post the return and try the values you were getting the o6fo6f from and post the values&returns.
Make sure your pads are clean and power is good, and that you are setting the modded loader to the correct settings as given in the proggies somewhere, you know the ones you have to enter in Program parameters and name Loader 1 or Loader 2.

As to my illness it is no cold, this is slow death and I do my best to stay in forum and help out. Nuff said, no response please.

Cimba
09-24-2005, 12:25 AM
cimba- i think there is a little confusion- i know how to program the card - this is all about unlocking a dealer or stream locked rom3 rev 383. i notice in a lot of the scrips it says to load a good- open rom3 to get the settings for glitching- thats where the problem comes in. i unlocked about 5 stream locked rom 10's- however i am having a lot of trouble with this sucker. and yes - werks thats about all it may be good for- this is all about learning how to. personal satisifaction. wife won't play with me anymore and the girlfriend is fed up with me so i have to do something to keep myself occupied

(For Programs that have the testing portion)

No I'm not confused, I know what you are supposed to do. You have to have 2 cards, one open and the locked one. With your ISO you load the test bin to your good open card just like you load any script. You then run that test bin loaded card in the modded loader until it pops a few times and you write down the values that you get from it. These hits will give you the optimal range that your loader works in on rom 3's. The analyser programs work similarly.
You then take your modded loader and start up the unlocking program, in the right hand top window you will scroll down and see where it says vcc= and delay= , "you can change these to"......."x"...........(it usually gives a range). You then click the run button and let it go

metwo
09-24-2005, 01:07 AM
ok-over the last 3 weeks i ran all tha programs you stated-the results have been fairly steady- in one of the prgrams i had a quite even mix of + and_. it was looking good but after 5 hours or so it got error and timed out. as far as vcc i have been staying in the range for the program- have tried lowering and increasing in each of the programs. but as you are well aware there are so many variables. going to try the values you gave and will see how it goes. as for the flash i have been using newd6. i did try as was stated in one of the read me's- changeg to 60-50-1. for the most part i would hit analyse and program those values. will get back to you and let you know how this is going. i appreciate your patience and help

metwo
09-24-2005, 01:15 AM
it is running with those values and getting 6f0 so i will let it run and keep you posted- may take a while lol

Cimba
09-24-2005, 01:57 AM
Let it go overnight if you can, the 3's can be really stubborn items.

metwo
09-24-2005, 11:08 AM
o6F--- try to hit 0C bug at 10A5
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A6
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A7
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A2
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo

Script Error on Line 236
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read
as you can see it ran for some time. this was the unlockrom3zip with the values you suggested. i will now try powersycunlockv2

Cid6.7
10-04-2005, 07:12 AM
Let me know if yah gott'er popped...I'll help I'm bored aswell..lol Need something to do...
I remember changing something in the script to 0C20 & 0C40 for dealer locked cards..
Its been so long I cant rememebr if it was the VCCStart or something like that..lol

metwo
10-04-2005, 11:28 AM
not yet- tried all that was stated but still no luck- but i ain't no quitter. going to keep trying. strange things happen. when i was trying to pop a rom10 a81 i ran differet scripts with no luck then went back to a script i ran before with same values and it popped. so with not a whole lot to do (bell does suck) i will keep trying- if you have any luck let me know

wizari
10-13-2005, 06:14 PM
Metwo:
Try different computers if you are able to. I had the same problem and I have one computer of four that for some reason has better results than the others. I have unlocked Stream and Dealer locked cards of all kinds.