PDA

View Full Version : Problem cleaning rom 10x


maxheadroom
11-23-2005, 01:41 AM
I've programed 1 card successfully with the standard patches
on a second rom 10, I decided to add my own tiers using n2 tier maker program. I applied it as the second patch
Any how this did not work.
I cleaned the card with nagra 4.0 surprisingly it reverted to A16 version during the clean process.
Anyhow I attempted to program the card again this time replacing the tier 6 locals to the posted internationals,
did not work
got message saying "your card is not yet activated by dish network call .........."
I erased is again tried to change the black out string to 7f 7f 7f....
also added the current keys.
same message does not work
but now I am having problems cleaning the card.
I tried removing the card lock
said successful then bad communications try again.
Did one step clean in nagra 4.1
opening com port successful
reset failed
error reseting card, atr string invalid
closing com1 successful
error detected, one step clean incomplete.
I tried the unlock command d2c file
did test no erors detected
did send d2c
Rx no response
tx 21 00 08 a0 ca 00 00 02 ff 00 06 b8
rx no response

can't seem to clean this card, do not understand why
I kept a copy of the bin file before sending it to the card, not sure what is the best way of posting it.

Why has it stopped working what am I doing wrong
please help.

maxheadroom
11-23-2005, 01:47 AM
also I'm seeing lots of files for unlocking rom 10 with extention xvb
what software opens these files????

woods
11-23-2005, 03:19 AM
sounds like you looped it. find my thread on broke my rom10 for some ideas on fixing it. Looped is not a good way to be. very diffecult to fix. mine is still dead

winexplorer uses the xvb. files they are scripts

woods

maxheadroom
11-23-2005, 04:25 AM
I do not understand how I looped it.
I went through the same procedure each time so that I do not loop it.
More like the card looped itself or dish had something in the stream that changed it.

JT
11-23-2005, 04:51 AM
.xvb files run in winexplorer 5.0. They work with a modified HU unlooper in most cases. Depending on the task they may work with an ISO too.

If your rom is just software looped and not stream looped, you may have some luck unlocking it.

maxheadroom
11-23-2005, 09:05 AM
I'm pretty sure its software looped since I had a password on it
It got looped during erase. I do not understand why.
What xvb file do you recommend trying with winexplorer and iso?
I do not yet have a hu unlooper that will be the next step.

A-Team
11-23-2005, 09:38 AM
more than likely you will need an modded loader. you can try rompopperV2 you can find it in the files section might work with your iso it's worth a try very easy to use.

maxheadroom
11-23-2005, 09:51 AM
ok read the card in winexplorer
the atr is now ok
when I do one step clean, i'm getting
Opening of COM5 was successful
ATR String: 3F FF 95 00 FF 91 81 71 FF 47 00 44 4E 41 53 50
31 30 32 20 52 65 76 32 34 30 60
ROM Revision: 102
EEPROM Revision: Rev240
Error, unsupported card type
Closing of COM5 was successful
Error detected, One Step Clean incomplete

what does this mean???

Cimba
11-23-2005, 05:35 PM
You could try using the unlock feature in Nagraedit 4.1, click on the key and when prompted enter the password you put in the card as per the 8b fix instructions.(if you did). If you did not change the password then enter AA BB CC DD AA BB CC DD and click ok. No matter what message it gives you then go to comm and enter the D2C script as per the fix package. Saw this elsewhere and don't know if it works but they said try it a few times.

FRESENG
11-23-2005, 06:10 PM
Cimba
I have the same problem . I can not unloop/unlock my Bev 288-11/DA-03

I followed your info and tis is what i got:
0303Rom RX: [no response]
TX: 21 00 08 A0 CA 00 00 02 FF 00 06 B8
RX: [no response], ca you please help me?

Cimba
11-23-2005, 06:15 PM
I'm sorry but what rom is that and what does it read in NagraEdit if you click reset ATR. The above info was only for a card locked by the rom 10x fix.

maxheadroom
11-23-2005, 08:22 PM
I tried the d2c it gave similar numbers as a reply but not exactly as in the memo section of that file.
I'd like to try something else,
I think the lock got removed but the card is not reverting to a16 during clean, I'll try it again on a different computer.
Just reading the card in winexplorer 5.0 got the atr to reset.

I do not think my card is looped, it is just not reverting maybe some other commands need to be sent to it?????

Cimba
11-23-2005, 09:59 PM
Did you try the 2 step procedure above in post 9 ?

maxheadroom
11-23-2005, 10:31 PM
Did you try the 2 step procedure above in post 9 ?

yes that was the first thing I tried after regular erase failed.

Cimba
11-23-2005, 11:43 PM
I found another method at another site, it uses a different program called xncs 1.8 in your ISO .I know nothing about this and take no responsibility or credit but it is reported to work for some. I am attaching files & how-to. Change the .txt to .zip when you get it & let me know as I won't leave it for long. Uploaded to downloads forum as xncs[1]1.8.zip

maxheadroom
11-24-2005, 05:52 AM
ok thanks I'll give it a try.

maxheadroom
11-24-2005, 08:22 AM
didn't work or I culd not get the window to pop up as per instructions
the program just read my card
It's a nifty program too bad there is no one step clean function like in nagra edit.

I sent the command that was included with penga's crack
and this is what I get
RX: 3F FF 95 00 FF 91 81 71 FF 47 00 44 4E 41 53 50
31 30 32 20 52 65 76 32 34 30 60
TX: 21 00 08 A0 CA 00 00 02 FF 00 06 B8
RX: 12 00 02 69 00 79

supposed to be as per the memo in the file

;... Unlocks patch
;You should see this for successfull unlock , if not try again
;RX: 3F FF 95 00 FF 91 81 71 FF 47 00 44 4E 41 53 50
; 31 30 32 20 52 65 76 31 30 33 64
;TX: 21 00 08 A0 CA 00 00 02 FF 00 06 B8
;RX: 12 00 02 6F 00 7F
; Anarky

as you can see the last rx line is slightly different

I do not think the card is looped since it accepts commands and replies
i think something else is preventing it from reverting to rom 10 rev a16.

Cimba
11-24-2005, 08:57 AM
Go down-load xncs[1] 1.8.zip in the files section.
Then goto comm,click;
In cmd send this (21 00 0A A0 FF BA BA CA DD AD BB CC DD 74) **or what ever your password was**
Now go to the 11 button settings, check dump with command priority bug. (HAD A BITCH FINDING THIS ONE) to the right of the magnifying glass is a button for settings, click it and look down to the bottom option which is "dump with c.p.b.", check it
Then go to yellow triangle hit ghost
When its done go to add ghost then read now
Go back to nagra edit do one step clean hope this helps you out.

I am reluctant to try it yet, my card reads the same way but is working perfect so I'll wait till it ain't. Wife would kill me if I screwed it up, just more support for her assertion that I don't know jack-****.

Iou1Dave
11-24-2005, 06:54 PM
tRY the unlock card like cimba sugested AA BB CC DD AA BB CC DD after u try key go to notepad open the file unlockN2Rom10Emu replace

: 210008A0CA000002FF0006B8
with
: 21000AA0FFBABACADDADBBCCDD74

run this file unlockN2Rom10Emu in comm in Nagra 4.1 send the file

after that try cleaning card and it should be now ready 4 more playing (lol)

worked for me hope this helps

the above was a combination of bothe methods sugested above. i had tryied to unlock this card for a while know with no lock. this work great.

take care

iou1dave
;D

krameel
11-26-2005, 01:55 AM
You could try using the unlock feature in Nagraedit 4.1, click on the key and when prompted enter the password you put in the card as per the 8b fix instructions.(if you did). If you did not change the password then enter AA BB CC DD AA BB CC DD and click ok. No matter what message it gives you then go to comm and enter the D2C script as per the fix package. Saw this elsewhere and don't know if it works but they said try it a few times.

This worked for me. Rom 10 wouldn't open when I used the D2C, but it open with AA BB CC DD AA BB CC DD. Big shout out to Milli and the ftp crew, from the reggae testers.

maxheadroom
11-26-2005, 06:49 AM
ok I tried the password aabbccddaabbccdd to remove the lock using nagra4.1 then one step clean and success card cleaned to a16.
Thanks guys.

I do not get it I changed the password in the patch to 0000000011223344 and that's what i've been using but it did not take for some reason without me knowing it. A mistery I guess.

maxheadroom
11-26-2005, 07:24 AM
ok figured it out
the d0d6 field got reset to aabbccdd in the tiers patch
in otherwords the password is messed with in both patches and when i changed it in the first patch the second overwrote the entry.

toto3
12-30-2005, 04:04 AM
I applied this patch after a key change and now I can't get back into card.
apparently it over wrote something, but I don't know what.
Can anyone help?

here's the patch:

; Patch to existing code
$C940=BFB7BFAE3FE6809DE7885A2AF8CCCC30
$C950=0000000000000000CDCDB7AE07E688E7
; New code
$CC30=C60309A886AA0F9097AE0F90D6D863D7
$CC40=0200905A5A2AF4CCC958000000000000

; Idea Key 86:
$D863=F29874441C6577D817E3E11D894E5345
; Idea Key 96:
$D873=3D731922275DC2C997965A0CA57927F9

#40Fan
12-30-2005, 05:09 AM
What did you write that patch to, toto3? A rom 10 or 102?

toto3
12-30-2005, 05:22 AM
to a rom 10

toto3
12-30-2005, 05:23 AM
I put the penga patch on then the 3m then that one.

#40Fan
12-30-2005, 05:30 AM
Look at the 3mTierPatch file and see what the password is that was used.

Did you use the 8b version?

toto3
12-30-2005, 06:04 AM
I used the 8b version. I looked at both and the password is what I am trying.
When I wrote it to the card, it finished really quick, like it did not complete.

this is what i get when I try the d2c:

RX: 3F FF 95 00 FF 91 81 71 FF 47 00 44 4E 41 53 50
31 30 32 20 52 65 76 31 30 33 64
TX: 21 00 0A A0 FF AA BB CC DD AA BB CC DD 74
RX: 12 00 02 69 00 79
I read somewhere that the 79 meant the password was still locking it. I have tried the AABB... as well
with no luck.

#40Fan
12-30-2005, 06:08 AM
Yes, you need to get 7f at the end. After unlocking with the AA BB CC DD password, it will say that it didn't unlock, but if you clean it anyways, it will clean if there isn't any other problems.

toto3
12-30-2005, 06:12 AM
I had used the same patches several times, with no problem, until I updated the idea key the last time. I was in a hurry, and i'm not sure if I did a clean or not.
Any other ideas? I have another d2c that does multiple tries with different passwords, but no success.

#40Fan
12-30-2005, 06:14 AM
A modded loader might be able to break into it.

toto3
12-30-2005, 06:18 AM
unfortunately I don't have one. I guess I will just keep trying.

Thanks

#40Fan
12-30-2005, 06:21 AM
Good luck. I hope that you get it.