Welcome to Mili's Marauders.
Header

 
ViP211 modded HDTV IRD

ViP211 modded receiver

Slinger ready
Free shipping

SALE PRICE: $349!!!
RomCode DishTV Subscription

RomCode DishTV Subscription

FROM: $69.00
Slinger IKS Kit
FREE SHIPPING

Slinger kit
PRICE: ONLY $199!!!
CLICK
HERE FOR INSTRUCTIONS
ViP622 modded HDTV IRD

ViP622 modded receiver

Slinger ready
Free Canada shipping

PRICE: ONLY $549!!!
BGA TSOP programming for ViP722 IRD

BGA tsop programming services for ViP722 receivers

PRICE: $144.00
FREE CANADA SHIPPING
Buffered JTAG Programmer

JTAG programmer

 PRICE: $39.00
MaxMel Emulator
MaxMel Emulator
PRICE: $59.00
FREE SHIPPING
SB5101 Diagnostics Modem

VIP downloads
PRICE
: $149.00
ViP722 modded HDTV IRD

ViP722 modded receiver

Slinger ready
Free Canada shipping

PRICE: ONLY $649!!!
BGA TSOP programming for most IRDs
BGA tsop programming services

PRICE: $124.00
FREE CANADA SHIPPING
Latest developments:
Slinger IKS boxes are now in store. All porn open, all premium chanels open. Hindi, Latino, Urdu Internationals. Running on Nagra 3 already and right now. Get them today HERE

Router Configuration

Slinger FAQ

Slinger Instructions

Files and VIP

VID Mod Instructions

JTAG-ing

Mili's Marauders » mili's Forums » Dish Network and Bell ExpressVU » Nagra Glitching and Unlocking » Here is the MOD on ((MIKOBU III ))......

Notices


Nagra Glitching and Unlocking Discussions on unlocking ROM 3-11 cards, unlocker how tos, modifications and hopefully Nagra 2 glicthing

Reply
Thread Tools vBmenu Seperating Image
Here is the MOD on ((MIKOBU III ))......
Old 10-06-2004   #1
mike68
 
Status: Guest
Posts: n/a
Here is the MOD on ((MIKOBU III ))......

C/P

--------------------------------------------------------------------------------------------------------
cut n paste from another site,,thanks go to those that made it,,,,,
Gently lift pins 1 and 4 of the HC00 chip. Lift pin 10 on the 232 chip, if your board has a 233 chip then lift pin 1.

Solder jumper from AT90S2313 pin 14 to HC00 pin 10.
Solder jumper from AT90S2313 pin 18 to HC00 pin 4.
Solder jumper from HC00 pin 8 to HC4053 pin 9 (the one to the left looking at front of loader).
Solder jumper from HC00 pin 9 to HC04 pin 2.
Solder jumper from HC00 pin 1 to HC74 pin 5 (located right above HC00).
Solder 2.2k resistor or (trim pot not really needed) from card slot vcc to ground (c10 is close by).
Install switch from 232 pin 10 (or 233 pin 1) to AT90S2313 pin 18 (on for flashing and off for unlocking.

this is supose to mod the mik3 to unlocker
Attached Files
File Type: zip mk3workingmod.zip (526.5 KB, 1723 views)
  Reply With Quote
Old 10-06-2004   #2
JT
 
JT's Avatar
 
Status: Assistant Bonaparte
Join Date: Jun 2003
Posts: 7,485
Anyone tried this yet with the Mik III? I got a couple of these and I can read this version of the how-to. Thinking of trying it but would like to see someone reputable say it works before I get too far into this.
JT is offline   Reply With Quote
Old 10-06-2004   #3
caminodelsol
 
Status: Guest
Posts: n/a
absolute1

how about absolute1 modified

thanks
  Reply With Quote
Old 10-06-2004   #4
mike68
 
Status: Guest
Posts: n/a
Here is what I got with no trimmer or switch, i need too go to radioshack

Executing Script: C:\Documents and Settings\mike\Desktop\ROM3 UNLOCKER\unlockrom3.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data :

Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script



Script Error on Line 77
Sc.GetByte: Requested Byte Exceeds Last Read Request
  Reply With Quote
Old 10-06-2004   #5
JT
 
JT's Avatar
 
Status: Assistant Bonaparte
Join Date: Jun 2003
Posts: 7,485
What about trace cuts on the bottom of the board? Do we just not worry about cutting any traces with this mod? I sure don't see where the how to calls for it. Going to get a trimmer myself. With just the resistor we can't fine tune the mod like the directions indicate we may have to.

Mike68, could you please PM me the site where you found this?
JT is offline   Reply With Quote
Old 10-06-2004   #6
coolc44
 
Status: Guest
Posts: n/a
Please PM me the site also.I need it too.Thanks.
  Reply With Quote
Old 10-06-2004   #7
indal_98
 
Status: Guest
Posts: n/a
Quote:
Originally Posted by JT
What about trace cuts on the bottom of the board? Do we just not worry about cutting any traces with this mod? I sure don't see where the how to calls for it. Going to get a trimmer myself. With just the resistor we can't fine tune the mod like the directions indicate we may have to.

Mike68, could you please PM me the site where you found this?
No traces to be cut on M-3.

And yes it works on A23 with 2.2K resistor.....Don't have 383 to try.

All loader mods are at cardcoders.org

G'L
  Reply With Quote
Old 10-06-2004   #8
mike68
 
Status: Guest
Posts: n/a
Thank you indal_98 for the info.
  Reply With Quote
Old 10-07-2004   #9
JT
 
JT's Avatar
 
Status: Assistant Bonaparte
Join Date: Jun 2003
Posts: 7,485
Quote:
Originally Posted by indal_98
No traces to be cut on M-3.

And yes it works on A23 with 2.2K resistor.....Don't have 383 to try.

All loader mods are at cardcoders.org

G'L
Thanks indal_98. Much appreciated.
JT is offline   Reply With Quote
Old 10-07-2004   #10
anthony101
 
Status: Registered User
Join Date: Jun 2004
Posts: 286
do you use with the jumper on or off???ya know the one on the outside of the loader where the card goes in at
anthony101 is offline   Reply With Quote
Old 10-07-2004   #11
pablillitos
 
Status: Registered User
Join Date: Jul 2004
Posts: 19
hello guys i have 3 louders one t6,xp red dragon and another the name is like suresho i want to know if you guys got some info about a mod this louders for unlock my cards please let me know thank .
pablillitos is offline   Reply With Quote
Old 10-07-2004   #12
Gillis65
 
Status: Guest
Posts: n/a
Leave the jumper on.
  Reply With Quote
Old 10-07-2004   #13
mike68
 
Status: Guest
Posts: n/a
Guys can you tell if I'm close

working on a rom10 with t911, does that look good

Executing Script: C:\Documents and Settings\administrators\New Folder (5)\Rom10-A23 OPEN.XVB

TX Data : A0

TX Data : A0

TX Data : A1

TX Data : 07 0E 03 10 01 03 9A 00

RX Data : 06 00

TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E

03 85 00

RX Data : 03 00

Now we will try 123E delay

RESET 696969FFFFFF696969FF6969FF69696969696969FFFF696969 696969FFFF696969696969FF696969696969FFFFFF69696969 6969FF696969696969696969696969696969FF696969696969 FF69696969696969696969696969696969FFFF696969696969 69FF6969696969FF69696969696969696969696969696969FF 6969696969FF6969FF69696969696969FF6969696969696969 696969696969FFFF69696969696969696969696969FF696969 696969696969FF69696969696969FF69696969696969FF6969 6969696969696969696969FF69FF696969696969FFFF696969 696969FF696969696969696969696969 RESET 696969FF69696969696969FF69696969696969FF6969696969 69FFFF6969696969FF696969696969FF69FFFF696969696969 69FF6969696969FF RESET FF

now we will try 123F delay

696969696969FFFF696969696969696969696969696969FF69 6969696969FFFF696969696969696969696969696969696969 6969696969FF696969696969FF69696969696969FFFF696969 6969FFFF69696969696969FFFF696969696969696969696969 696969FF696969696969FF69696969696969FFFF6969696969 69FF6969696969696969696969696969696969696969696969 6969696969696969FFFF6969696969FF6969696969696969FF FF696969696969FFFF69696969696969FF69696969696969FF 696969696969FF696969696969696969696969696969696969 6969696969FF69696969696969696969696969696969FF6969 696969FF696969696969FF6969FF6969696969FF6969696969 696969FFFF6969696969FF6969696969 RESET RESET 6969FF6969696969FFFF

now we will try 1240 delay

FF69696969696969696969696969FF696969696969696969FF 6969696969696969696969696969696969696969696969FF69 696969696969696969696969FF696969696969696969696969 6969696969FF696969696969FF696969696969696969696969 69696969696969696969FF6969696969696969FF6969696969 6969696969696969FF69696969696969696969696969696969 FF6969696969696969 RESET FF6969696969696969696969696969FFFF696969696969FFFF 696969696969FFFF6969 RESET 69696969FF6969696969FFFF6969696969696969FF69696969 FF6969FF696969696969FFFF69696969696969FF6969696969 FF69FF696969696969FFFF6969696969FF6969696969696969 69696969696969FFFFFF69696969696969696969696969FFFF 69696969696969

now we will try 1241 delay

FF6969696969696969FF69696969696969FF69696969FF6969 FF696969696969696969696969FF6969FF696969696969FFFF 69696969696969696969696969FF RESET FF69696969696969FF69696969696969696969 RESET 69696969696969696969696969696969FF6969FF6969696969 696969FF696969696969FFFF69696969696969FF6969696969 6969FF69696969696969FF696969696969FF69696969696969 FF69696969696969FFFF696969696969FF696969696969FFFF 6969696969FF6969FF696969696969FFFF69696969696969FF 696969FF6969696969696969696969FF69696969FF6969FF69 696969696969FF696969696969FFFF696969696969FFFF6969 696969696969696969696969FFFF6969696969696969696969 6969696969696969696969FF696969696969

now we will try 1242 delay
  Reply With Quote
Old 10-08-2004   #14
weirdml
 
Status: Guest
Posts: n/a
Hi mike68,
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 77 ...

It means your mod is not power up... Is is correct?
  Reply With Quote
Old 10-08-2004   #15
slu3
 
Status: Guest
Posts: n/a
Hi All,

I have a couple of questions about the mod tho?

1. Do I have to lift PIN10 on my 232 chip and connect it to AT90S2313 pin 18 or can I just leave it alone cause it so tought to lift that particular one tho.

2. Stupid question but what is a Trimmer?
3. What is the setting under WinEx is it Unlooper or 3.68mhz?

Thanks,
Slu3
  Reply With Quote
Old 10-08-2004   #16
Gillis65
 
Status: Guest
Posts: n/a
You need to lift the pin for program mode. Pindown for flashing, or run a switch between the lifted pin and pin 18 on the atmel chip. The trimmer you don't even need just use a 2.2k resistor instead. Trimmer is just an adjustable resistor. Read the read me with the files and you will see you need to make your own setting in winex.
  Reply With Quote
Old 10-08-2004   #17
Gillis65
 
Status: Guest
Posts: n/a
Rom 10's are popping fine here, but when i do a rom3 the program runs fine and will ultimately glitch and say cam is now open. Problem is that when i read them in NagraEdit i get

rom revision383
logging into card
checking for backdoor
backdoor appears to be open continuing..
retrieving backdoor password

then theres like a 30 second delay then....

error reading image from card
closing of com1 was succesful
error detected one step clean incomplete

No matter how many times i run the rom3 script with the modded mikIII i can't clean a rom3.. Rom10's no problem...Any help would be much appreciated.

Last edited by Gillis65; 10-08-2004 at 06:27 PM..
  Reply With Quote
Old 10-08-2004   #18
slu3
 
Status: Guest
Posts: n/a
Thanks for the info, I'll try it later on today.

Slu3
  Reply With Quote
Old 10-09-2004   #19
weirdml
 
Status: Guest
Posts: n/a
[QUOTE=mike68]C/P

--------------------------------------------------------------------------------------------------------
cut n paste from another site,,thanks go to those that made it,,,,,
Gently lift pins 1 and 4 of the HC00 chip. Lift pin 10 on the 232 chip, if your board has a 233 chip then lift pin 1.
--------------
Hi mike68,

This is my Mikobu III... But I don't see the 232 chip. Is the 233 chip on the board? ... Its y2 is 20 pin. What pin will I lift now?
Thanks
Attached Images
File Type: jpg DSC01461.JPG (552.7 KB, 565 views)

Last edited by weirdml; 10-09-2004 at 01:43 AM..
  Reply With Quote
Old 10-09-2004   #20
mike68
 
Status: Guest
Posts: n/a
I have the blackbroad Mikobu3 REV :B with all number on the chips erased.

This one I have also is shipping to my tech for him to test.
  Reply With Quote
Old 10-09-2004   #21
moses
 
moses's Avatar
 
Status: Registered User
Join Date: Nov 2003
Posts: 33
What about the Mikobu 4 that mili sell in his store
moses is online now   Reply With Quote
Old 10-10-2004   #22
Caesar_Mikey
 
Status: Guest
Posts: n/a
Ok I did the mod but the flash files I have new6 and new7 dont work I try to flash in xpatmel
flashFailure. Unable to locate hex files for
Newd6
Initializing ...
Initialized
Syncing ...
Synchronized
Vendor Code: 1e (Atmel)
Part Family: 91 AT90S2313
Issuing Chip Erase ...
Erased
Vendor Code: 1e (Atmel)
Part Family: 91 AT90S2313
Programming EEPROM ...
Programming Flash ...
Verifying EEPROM ...
Verifying Flash ...
Setting Lock Bits ...
Lock Bits Set!
Complete!


So I tried Ufp16 and get flash error. when trying to write. I tried reflashing back to m6.2 and it works fine. any help?
  Reply With Quote
Old 10-10-2004   #23
Gillis65
 
Status: Guest
Posts: n/a
Caesar_Mikey you have PM
  Reply With Quote
Old 10-10-2004   #24
JT
 
JT's Avatar
 
Status: Assistant Bonaparte
Join Date: Jun 2003
Posts: 7,485
How did you guys fix your error on line 77?
JT is offline   Reply With Quote
Old 10-10-2004   #25
JT
 
JT's Avatar
 
Status: Assistant Bonaparte
Join Date: Jun 2003
Posts: 7,485
Quote:
Originally Posted by JT
How did you guys fix your error on line 77?
If you get this message you need to reflash. This is what I get now.

AAFFFFAAFFFFAAFFFFAAAAAAFFFFFFAAFFFFFFFFFFAAFFAAAA FFFFFFAAFFFF--- try to hit 0C bug at 10AD
FFFFAAFFFFFFAAFFAAFFFFAAAAFFAAFFAAAAFFFFAAFFFFFFFF FFFFAAAAFFFF--- try to hit 0C bug at 10AE
FFAAFFFFAAAAFFFFAAAAFFFFAAAAAAFFAAAAFFAAFFAAFFFFFF AAFFFFAAAAFF--- try to hit 0C bug at 10AF
FFFFFFAAFFAAFFFFFFAAAAFFFFAAFFFFAAFFAAFFFFAAAAFF
===========================================
VCC = 59-0710AF GLITCHED past 0C BUG
3FFF9500
===========================================
FFAAAAFFFFFFAA--- try to hit 0C bug at 10B0
FFFFAAFFFFAAAAFFAAAAFFAAFFFFFFAAFFFFFFFFFFFFAAFFFF FFFFAAFFFFAA--- try to hit 0C bug at 10B1
AAFFFFFFAAAA
===========================================
VCC = 57-0710B1 GLITCHED past 0C BUG
3FFF9500
===========================================
FFAAFFFFFFAAAAAAFFAAAAFFFFAAFFFFFFAAAAFFFFFFAAFFFF--- try to hit 0C bug at 10B2
FFFFFFAAFFFFAAFFAAFFFFFFAAAAFFFFFFFFAAFFFFAAFFFFAA AAFFAAAAFFFF--- try to hit 0C bug at ....

Success! Now we just need some flashes to unloop with. Huge thanks goes out to Penga, no1b4me and everyone who took the time to post their pics. I took this pic of my MikIII revC and I think it turned out better than most. I also came up with a better way to install the flash enable/disable switch. The MikIII revC has a trace that comes off pin10 of U3 and goes under the board about a 1/4 inch behind the chip. (MikIII revD does not have this trace route) You can just solder one lead to lifted pin 10 and the other to the hole where the trace goes under the board. Much better way to do it than to put second lead to pin 18 of the atmel. That way puts two wires to pin 18 on the atmel is kind of a pain. Plus, it's farther away. Here's the pic.

Last edited by JT; 10-10-2004 at 01:04 PM..
JT is offline   Reply With Quote
Old 10-10-2004   #26
Caesar_Mikey
 
Status: Guest
Posts: n/a
hey JT what did you flash with I have the same rev loader. and cant get it to flash with the new6 and 7 files
  Reply With Quote
Old 10-10-2004   #27
Gillis65
 
Status: Guest
Posts: n/a
Caesar_Mikey check your mail.
  Reply With Quote
Old 10-10-2004   #28
Caesar_Mikey
 
Status: Guest
Posts: n/a
still get the same thing. why would it load with anything but the new flash?
  Reply With Quote
Old 10-10-2004   #29
JT
 
JT's Avatar
 
Status: Assistant Bonaparte
Join Date: Jun 2003
Posts: 7,485
I had the right flashes and xpatmel was telling me it was writing successfully to the eeprom, but it just wasn't. I had to change xpatmel's timing settings. To do this, right click on the center bar in xpatmel, when you see the timing options box appear, change the settings to 60/50/1. Here are the flashes I am using. Thanks to Ziffler at cardcoders for putting this collection of flashes together.
JT is offline   Reply With Quote
Old 10-10-2004   #30
lips905
 
Status: Registered User
Join Date: Jun 2004
Posts: 403
Quote:
Originally Posted by mike68
Here is what I got with no trimmer or switch, i need too go to radioshack

Executing Script: C:\Documents and Settings\mike\Desktop\ROM3 UNLOCKER\unlockrom3.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data :

Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script



Script Error on Line 77
Sc.GetByte: Requested Byte Exceeds Last Read Request


do not buy the trimmers from radio shack they are useless .I moded 6 loaders and none ogf them were working a 100% So i went out to a electronic components store and bought multi turn 5K trimmers and now all loaders are working perfectly
__________________
"We don't stop playing cause we grow old"We grow old cause we stop playing"(CATCH ME IF YOU CAN)I doubt it
lips905 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 11:05 PM.

[Output: 129.12 Kb. compressed to 116.12 Kb. by saving 12.99 Kb. (10.06%)]