TX Product(s) used: CR3 Lite
Console Type Corona v2
NAND size: 4 GB
Dashboard version: before update 2.0.16203
CB version: 13121
Screenshot of NAND details from J-Runner:
J-Runner log:
===================================================
19 تشرين الثاني, 2014 09:31:11 ص
J-Runner v0.3 Beta (5) Started
It's advised to run in administrator mode on Windows 8
WARNING! - Your selected working directory already contains files!
You can view these files by using 'Show Working Folder' Button
Initializing flashdmp.bin..
Corona 4GB
RGH2 Selected
Nand Initialization Finished
Checking Files
Finished Checking Files
Downloaded *xeBuild/16747/_glitch2.ini
Downloaded *xeBuild/16747/_glitch2m.ini
Finished Checking Files
Load Files Initiliazation Finished
16747
Started Creation of the 16747 xebuild image
KV Info saved to file
---------------------------------------------------------------
xeBuild v1.12.659
---------------------------------------------------------------
base path changed to D:\XBOX 360 ALL IN ONE\J-Runner\xeBuild
---- { Image Build Mode } ----
building glitch2 image
---------------------------------------------------------------
D:\XBOX 360 ALL IN ONE\J-Runner\027928722443\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.16747.0
Console : Corona
NAND size : 48MiB MMC (system only)
Build : Glitch (v2)
Xell : power on console with console eject button
Serial : 0279*****443
ConsoleId : 532****50898
MoboSerial: 79102****1852235
Mfg Date : 06/12/2012
CPU Key : ***54A
1BL Key : ***3EFA
DVD Key : ***A718
CF LDV : 1
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
Saved to D:\XBOX 360 ALL IN ONE\J-Runner\027928722443
Image is Ready
Initializing updflash.bin..
Corona 4GB
Nand Initialization Finished
updflash.bin log :
base path changed to D:\XBOX 360 ALL IN ONE\J-Runner\xeBuild
---- { Image Build Mode } ----
building glitch2 image
<enter> key on completion suppressed
data directory overridden from command line to '16747\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'D:\XBOX 360 ALL IN ONE\J-Runner\027928722443\updflash.bin'
------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1b0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0x54A
(weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to : 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to : 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)
------ parsing ini at '16747\_glitch2.ini' ------
ini version 16747
ini: label [coronabl] found
found (1) 'cba_13121.bin' crc: 0x9255dfb1
found (2) 'cbb_13121_corona.bin' crc: 0xa716445f
found (3) 'cd_12905.bin' crc: 0x58221592
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_16747.bin' crc: 0x94a4ef68
found (6) 'cg_16747.bin' crc: 0x88e1e9b9
ini dictates dual CB for this model
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x12d353e9
found (2) 'bootanim.xex' crc: 0x151b0618
found (3) 'createprofile.xex' crc: 0x32ceed5a
found (4) 'dash.xex' crc: 0x4103a319
found (5) 'deviceselector.xex' crc: 0xfe497738
found (6) 'gamerprofile.xex' crc: 0xef9022d5
found (7) 'hud.xex' crc: 0xc0e76e31
found (8) 'huduiskin.xex' crc: 0x155495d3
found (9) 'mfgbootlauncher.xex' crc: 0xdecbab8e
found (10) 'minimediaplayer.xex' crc: 0x2892b8d5
found (11) 'nomni.xexp' crc: 0xdcef767a
found (12) 'nomnifwk.xexp' crc: 0x0d14c998
found (13) 'nomnifwm.xexp' crc: 0xdc46bb6e
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0xcbfce61f
found (16) 'updater.xex' crc: 0xafef5cf0
found (17) 'vk.xex' crc: 0xf2caff49
found (18) 'xam.xex' crc: 0x79f6eabf
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x4c2f6bd1
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0x34c9b084
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: D:\XBOX 360 ALL IN ONE\J-Runner\027928722443\updflash.bin
1BL RSA pub key file is not available, signature checks will not be performed
PIRS RSA pub key file is not available, signature checks will not be performed
MASTER RSA pub key file is not available, signature checks will not be performed
------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x3000000
nanddump header checks passed OK!
Loading NAND dump (0x3000000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a mmc machine
NAND dump uses big block controller
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x800 of size 0x3800
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0x2ffc000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x01 Pairing: 0x35d57f
setting LDV from image to 1
setting pairing data from image to 0x35d57f
pairing set to: 35 d5 7f
attempting to find valid anchor block
anchor block v 475 at 0x2fe8000 is valid
anchor block v 474 at 0x2fec000 is valid
anchor block v 475 at 0x2fe8000 is selected
MobileB.dat found at sector 0x550 (offset 0x1540000), size 2048 (0x800) bytes
MobileC.dat found at sector 0x386 (offset 0xe18000), size 512 (0x200) bytes
MobileD.dat found at sector 0x39b (offset 0xe6c000), size 2048 (0x800) bytes
MobileE.dat found at sector 0x387 (offset 0xe1c000), size 2048 (0x800) bytes
Statistics.settings found at offset 0x2ff8000, size 4096 (0x1000) bytes
Manufacturing.data found at offset 0x2ff4000, size 4096 (0x1000) bytes
seeking security files...
crl.bin found in sector 0x37f size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x380 size 0xad30...verified! Will use if external file not found.
extended.bin found in sector 0x398 size 0x4000...verified! Will use if external file not found.
fcrt.bin found in sector 0x384 size 0x4000...pub key to verify signature is not available, skipping!
verified! Will use if external file not found.
secdata.bin found in sector 0x385 size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image
------ loading system update container ------
16747\su20076000_00000000 found, loading...done!
Read 0xb35000 bytes to memory
checking integrity...
header seems valid, version 2.0.16747.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7a010 bytes)
decrypting SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)...done!
------ Loading bootloaders and required security files ------
reading data\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x800 size 0x3800
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cba_13121.bin (0x1af0 bytes)
loaded cba_13121.bin, could not check signature rsa key not present!
reading .\common\cbb_13121_corona.bin (0x90d0 bytes)
reading .\common\cd_12905.bin (0x5090 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading data\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)
reading 16747\bin\patches_g2corona.bin (0x8cc bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 82ّC Gpu: 78ّC Edram: 76ّC
Max temps : Cpu: 89ّC Gpu: 82ّC Edram: 82ّC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 7c:1e:52:be:f3:f1
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : DDUX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cba_13121.bin, 1BL RSA key not present!
done!
patch slot offset reset to: 0xb0000
------ Patching BLs and modifying patches ------
Patching BLs...Done!
------ Patching boot reasons and options into flash header ------
Patching header for xell power reason
------ Encrypting and finalizing bootloaders ------
encoding smc.bin size 0x3800
SMC checksum: 39a623be
unknown SMC found, type: Corona v6.2(2.05)
glitch hack found in SMC binary!
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cba_13121.bin size 0x1af0
encoding cbb_13121_corona.bin size 0x90d0
CB 13121 seq 0x0304000e type: 0x03 cseq: 0x04 allow: 0x000e
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0FF0F0
fuseset 02: 000F000000000000 (sequence)
fuseset 02: 0F00000000000000 (allow cseq 2)
fuseset 02: 00F0000000000000 (allow cseq 3)
fuseset 02: 000F000000000000 (allow cseq 4)
**dual CB flag detected!**
encoding cd_12905.bin size 0x5400
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_16747.bin size 0x4560
encoding cg_16747.bin size 0x75ab0
encoding patches_g2corona.bin size 0x4f0
done!
------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00000800 len 0x3800 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_13121.bin at raw offset 0x00008000 len 0x1af0 (end 0x9af0)
adding cbb_13121_corona.bin at raw offset 0x00009af0 len 0x90d0 (end 0x12bc0)
adding cd_12905.bin at raw offset 0x00012bc0 len 0x5400 (end 0x17fc0)
adding ce_1888.bin at raw offset 0x00017fc0 len 0x56070 (end 0x6e030)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_16747.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_16747.bin at raw offset 0x000b4560 len 0x75ab0 (end 0xc0000, rest in fs)
adding patches_g2corona.bin at raw offset 0x000c0010 len 0x4f0 (end 0xc0500)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xd0000 len 0x0006a010 (end: 0x0013a010)...done!
------ adding 25 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x12d353e9 ini: 0x12d353e9)
adding as aac.xexp1 at raw offset 0x13a010 len 0x00014000 (end 0x0014e010)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x151b0618 ini: 0x151b0618)
adding as bootanim.xex at raw offset 0x150000 len 0x00061000 (end 0x001b1000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x32ceed5a ini: 0x32ceed5a)
adding as createprofile.xex at raw offset 0x1b1000 len 0x0000c000 (end 0x001bd000)
extracted SUPD\dash.xex (0x598000 bytes) (crc32: 0x4103a319 ini: 0x4103a319)
adding as dash.xex at raw offset 0x1c0000 len 0x00598000 (end 0x00758000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0xfe497738 ini: 0xfe497738)
adding as deviceselector.xex at raw offset 0x758000 len 0x0000a000 (end 0x00762000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xef9022d5 ini: 0xef9022d5)
adding as gamerprofile.xex at raw offset 0x762000 len 0x0001b000 (end 0x0077d000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xc0e76e31 ini: 0xc0e76e31)
adding as hud.xex at raw offset 0x77f000 len 0x0001d000 (end 0x0079c000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x155495d3 ini: 0x155495d3)
adding as huduiskin.xex at raw offset 0x79d000 len 0x00014000 (end 0x007b1000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xdecbab8e ini: 0xdecbab8e)
adding as mfgbootlauncher.xex at raw offset 0x7b4000 len 0x00008000 (end 0x007bc000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x2892b8d5 ini: 0x2892b8d5)
adding as minimediaplayer.xex at raw offset 0x7bc000 len 0x0000c000 (end 0x007c8000)
extracted SUPD\nomni.xexp (0xc800 bytes) (crc32: 0xdcef767a ini: 0xdcef767a)
adding as nomni.xexp1 at raw offset 0x7c8000 len 0x0000c800 (end 0x007d4800)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x0d14c998 ini: 0x0d14c998)
adding as nomnifwk.xexp1 at raw offset 0x7d4800 len 0x00002000 (end 0x007d6800)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0xdc46bb6e ini: 0xdc46bb6e)
adding as nomnifwm.xexp1 at raw offset 0x7da000 len 0x00005000 (end 0x007df000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x7e1000 len 0x00006000 (end 0x007e7000)
extracted SUPD\signin.xex (0x19000 bytes) (crc32: 0xcbfce61f ini: 0xcbfce61f)
adding as signin.xex at raw offset 0x7ea000 len 0x00019000 (end 0x00803000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xafef5cf0 ini: 0xafef5cf0)
adding as updater.xex at raw offset 0x805000 len 0x00007000 (end 0x0080c000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xf2caff49 ini: 0xf2caff49)
adding as vk.xex at raw offset 0x80f000 len 0x0000b000 (end 0x0081a000)
extracted SUPD\xam.xex (0x253000 bytes) (crc32: 0x79f6eabf ini: 0x79f6eabf)
adding as xam.xex at raw offset 0x81b000 len 0x00253000 (end 0x00a6e000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xa6f000 len 0x0011b000 (end 0x00b8a000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xb8b000 len 0x00018000 (end 0x00ba3000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xba4000 len 0x001a8000 (end 0x00d4c000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp1 at raw offset 0xd4c000 len 0x00007000 (end 0x00d53000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x4c2f6bd1 ini: 0x4c2f6bd1)
adding as ximecore.xex at raw offset 0xd53000 len 0x00017000 (end 0x00d6a000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xd6b000 len 0x00090000 (end 0x00dfb000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0x34c9b084 ini: 0x34c9b084)
adding as ximedic.xexp1 at raw offset 0xdfc000 len 0x00002800 (end 0x00dfe800)
------ adding 5 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe00000 len 0x00000a00 (end 0x00e00a00)
<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe04000 len 0x0000ad30 (end 0x00e0ed30)
<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe10000 len 0x00004000 (end 0x00e14000)
<- Processing fcrt.bin ->
could not read fcrt.bin, using data from previous parse...
adding as fcrt.bin at raw offset 0xe14000 len 0x00004000 (end 0x00e18000)
<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe18000 len 0x00000400 (end 0x00e18400)
------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe1c000 len 0x800 (end 0xe1c800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe20000 len 0x200 (end 0xe20200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe24000 len 0x800 (end 0xe24800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe28000 len 0x800 (end 0xe28800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0x2ff8000 len 0x1000 (end 0x2ff9000)
Manufacturing.data found, adding from previous parse
adding Manufacturing.data at raw offset 0x2ff4000 len 0x1000 (end 0x2ff5000)
------ adding smc_config.bin ------
adding smc config to offset 0x02ffc000, len 0x400
------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe2c000 len 0x4000 (end 0xe30000)...done!
copying anchor block 1 to offset 0x2fe8000
copying anchor block 2 to offset 0x2fec000
------ writing image to disk ------
writing file 'D:\XBOX 360 ALL IN ONE\J-Runner\027928722443\updflash.bin' to disk...done!
---------------------------------------------------------------
D:\XBOX 360 ALL IN ONE\J-Runner\027928722443\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.16747.0
Console : Corona
NAND size : 48MiB MMC (system only)
Build : Glitch (v2)
Xell : power on console with console eject button
Serial : 027*****2443
ConsoleId : 532*****0898
MoboSerial: 7910271121852235
Mfg Date : 06/12/2012
CPU Key : ****54A
1BL Key : ****EFA
DVD Key : ****718
CF LDV : 1
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
Image of Coolrunner:
i have an xbox corona v2 with 16203 dash i got my cpu key and flashdump and creat new image for 16747 dashboard. after i flash updflash the xbox won't boot. i open my xbox and it corona v2 rgh with cr3 lite wi s1 1 ,5 on s2 all off the green pulse is flashing but not booting try defferent cable and other tv with no luck i dont know what to do now any help will be appreciated
P.S. i dont rgh my xbox i buy it rghed
i dont have any nand RW kit