FIXED R-JTAG zephyr no boot

Itxtutor

Junior Member
Jul 9, 2013
10
0
Hi guys, i have a big problem.

I have R-jtagged my xbox 360 (zephyr)

I´m not sure if the little point on the R-jTAG QSB has good contact ?! any alternate point ?

I have succesfully booted into XELL and retrieved my CPU key. ( with the 3 way switch on 1 ?!?! not middle , on the r-jtag qsb)

With the 3 way switch in the middle it did not boot..

Aud clamp installed.

4 nand dumps before , all OK , no bad blocks. Created R-jTAG aud clamp image in Jrunner and flashed succesfully (3.5min)

Now with the image flashed , it does not glitch anymore
Tried all dip settings , with and without aud clamp , 330 and 475 , different voltage etc... no boot


then i flashed back xell reloaded , and boots fine with 3 way switch on 1..

log on http://pastebin.com/rvEkueAG

Can somebody please help me :S

That would help alot !

Thanks
 
Last edited:

Itxtutor

Junior Member
Jul 9, 2013
10
0
Ok i´ve now updated the information and attched pictures. Had to wire up 2 points on the QSB because the pads were broken.

Console Type
: Zephyr

NAND size: 16

Dashboard version: 16547

CB version:

Screenshot of NAND details from J-Runner: attachement 1

J-Runner log:

POST output from J-Runner (either POST_OUT monitor or RATER output):
Code:
DIP 1 -


Checking Files
Finished Checking Files
Version: 10
Press Escape to exit
Waiting for POST to change
Post 10 - Payload/1BL started
Post 03
Post 76 - INIT_SYSTEM_ROOT
Post FE
Post F6
Post FE
Post FE
Post FE
Post FE
Post 86 - Panic - EXTERNAL
Post FE
Post 86 - Panic - EXTERNAL
Post 06
Post FE
Post 86 - Panic - EXTERNAL
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 06
Post FE
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 12 - FSB_CONFIG_RX_STATE
Post 13 - FSB_CONFIG_TX_STATE
Post 14 - FSB_CONFIG_TX_CREDITS
Post 15 - FETCH_OFFSET
Post 16 - FETCH_HEADER
Post 17 - VERIFY_HEADER
Post 18 - FETCH_CONTENTS
Post 19 - HMACSHA_COMPUTE
Post 1A - RC4_INITIALIZE
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post A0 - Panic - VERIFY_SECOTP_6
Post FC
Post F8
Post F8
Post F8
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post F8
Post F8
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post FC
Post F8
Post F8
Post F8
Post FC
Post F8
Post F8
Post F8
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post F8
Post F8
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 12 - FSB_CONFIG_RX_STATE
Post F8
Post F8
Post 70 - INIT_VIDEO_DRIVER
Post F8
Post F8
Post F8
Post F8
Post F8
Post F8
Post F8
Post F8
Post F8
Post FC
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post FA
Post F8
Post FE
Post F8
Post F8
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post F8
Post FE
Post FA
Post FE
Post FA
Post F8
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post FE
Post 82 - Panic - DATA_STORAGE
Post FA
Post F8
Post C8 - SHA_VERIFY
Post 80
Post FD

DIP 3-

Post A0 - Panic - VERIFY_SECOTP_6
Post 80
Post 70 - INIT_VIDEO_DRIVER
Post FC
Post 70 - INIT_VIDEO_DRIVER
Post FC
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post F8
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post F8
Post 30 - VERIFY_OFFSET_4BL_CD
Post F8
Post 80
Post F8
Post F8
Post F0 - Panic - VERIFY_OFFSET_CB_B
Post F8
Post F8
Post 70 - INIT_VIDEO_DRIVER
Post F8
Post F8
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 12 - FSB_CONFIG_RX_STATE
Post 13 - FSB_CONFIG_TX_STATE
Post 15 - FETCH_OFFSET
Post 16 - FETCH_HEADER
Post 17 - VERIFY_HEADER
Post 18 - FETCH_CONTENTS
Post 19 - HMACSHA_COMPUTE
Post 1A - RC4_INITIALIZE
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post A0 - Panic - VERIFY_SECOTP_6
updflash.bin log (if applicable):

Code:
base path changed to C:\Users\itxtutor\Desktop\RJTAGBACKUP\J-Runner\xeBuild
---- { Image Build Mode } ----
building jtag image
<enter> key on completion suppressed
data directory overridden from command line to '16547\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'C:\Users\itxtutor\Desktop\224926373505\updflash.bin'

------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1b0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0x8C4E30C1AAAB3A229FDA9FF8ACC8FC90 (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to  : 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to  : 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)

------ parsing ini at '16547\_jtag.ini' ------
ini version 16547

ini: label [zephyrbl] found
found (1) 'cb_4558.bin' crc: 0x57dba8ff
found (2) 'cd_4558.bin' crc: 0x3286f409
found (3) 'ce_1888.bin' crc: 0xff9b60df
found (4) 'cf_4532.bin' crc: 0xd28ef722
found (5) 'cg_4532.bin' crc: 0x2530f8ce
found (6) 'cb_4579.bin' crc: 0xa504b0f1
found (7) 'cd_8453.bin' crc: 0x25e0acd0
found (8) 'cf_16547.bin' crc: 0xa54f9efc
found (9) 'cg_16547.bin' crc: 0xc34c06ed

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0xf2808dc5
found (2) 'bootanim.xex' crc: 0xd5c63122
found (3) 'createprofile.xex' crc: 0xf7e474ef
found (4) 'dash.xex' crc: 0x2a153493
found (5) 'deviceselector.xex' crc: 0x09e04596
found (6) 'gamerprofile.xex' crc: 0x4647565d
found (7) 'hud.xex' crc: 0xa6f9c197
found (8) 'huduiskin.xex' crc: 0x1d296f10
found (9) 'mfgbootlauncher.xex' crc: 0x33d5771b
found (10) 'minimediaplayer.xex' crc: 0x4de56d9c
found (11) 'nomni.xexp' crc: 0x97cadcec
found (12) 'nomnifwk.xexp' crc: 0xc7ab2e5b
found (13) 'nomnifwm.xexp' crc: 0x22253a42
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0xaffe7f78
found (16) 'updater.xex' crc: 0xf6e1cdd5
found (17) 'vk.xex' crc: 0xb916846b
found (18) 'xam.xex' crc: 0x027463e8
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0xa86f3ef4
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0x186d8df9
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: C:\Users\itxtutor\Desktop\224926373505\updflash.bin

1BL RSA pub key file is not available, signature checks will not be performed
PIRS RSA pub key file is not available, signature checks will not be performed
MASTER RSA pub key file is not available, signature checks will not be performed

------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
    NAND dump is from a small block machine
    NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x10 Pairing: 0x585232
CF slot 1 decrypted ok LDV 0x11 Pairing: 0x585232
setting LDV from image to 17
setting pairing data from image to 0x585232
pairing set to: 58 52 32
MobileB.dat found at block 0x3d5, page 0x18 (page 0x7ab8), size 2048 (0x800) bytes
MobileC.dat found at block 0x49, page 0x1c (page 0x93c), size 512 (0x200) bytes
MobileD.dat found at block 0x3f, page 0x10 (page 0x7f0), size 2048 (0x800) bytes
MobileE.dat found at block 0xf5, page 0x0 (page 0x1ea0), size 2048 (0x800) bytes
Statistics.settings found at page 0x7bc0, size 4096 (0x1000) bytes
Manufacturing.data found at page 0x7bc0, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at block 0x36d, page 0x0 (page 0x6da0) raw offset 0x6da0
seeking security files...
crl.bin found in sector 0x3d3 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x3cd size 0xde60...verified! Will use if external file not found.
extended.bin found in sector 0x207 size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x36c size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image

------ loading system update container ------
16547\su20076000_00000000 found, loading...done!
    Read 0xb35000 bytes to memory
checking integrity...
header seems valid, version 2.0.16547.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7a010 bytes)
decrypting SUPD\xboxupd.bin\CF_16547.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16547.bin (0x75aac bytes)...done!

------ Loading bootloaders and required security files ------
could not read 16547\bin\payload.bin, using built in payload (0x200 bytes)
reading data\SMC.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cb_4558.bin (0x7a70 bytes)
loaded cb_4558.bin, could not check signature rsa key not present!
reading .\common\cd_4558.bin (0x5700 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\common\cf_4532.bin (0x44c0 bytes)
reading .\common\cg_4532.bin (0x2ef40 bytes)
extracted SUPD\xboxupd.bin\CF_16547.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16547.bin (0x75aac bytes)
could not read 16547\bin\freeboot.bin, using built in core (0xd40 bytes)
reading 16547\bin\patches_zephyr.bin (0x9d4 bytes)
reading data\xell-2f.bin (0x40000 bytes)
reading .\common\cb_4579.bin (0x7f20 bytes)
loaded cb_4579.bin, could not check signature rsa key not present!
reading .\common\cd_8453.bin (0x5780 bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu:  80øC Gpu:  75øC Edram:  78øC
Max temps   : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan     : (auto)
Gpu Fan     : (auto)
MAC Address : 00:17:fa:7b:d2:a3
AVRegion    : 0x00000300 (PAL50)
GameRegion  : 0x02fe (PAL/EU)
DVDRegion   : 2
resetKey    : DAYL
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cb_4558.bin, 1BL RSA key not present!
could not check signature of cb_4579.bin, 1BL RSA key not present!
done!

------ Patching boot reasons and options into flash header ------
    Patching header for xell power reason

------ Encrypting and finalizing bootloaders ------
Fuse CPU Key set to: 0x8C4E30C1AAAB3A229FDA9FF8ACC8FC90
Fuse CF LDV set to : 0xFFFFFFFFFFFFFFFFF000000000000000
encoding payload.bin size 0x200 (JTAG)
patching payload.bin to load size 0xd40 (0x350 reps)
encoding SMC.bin size 0x3000 (JTAG)
SMC checksum: a6ee8b80
unknown SMC found, type: Jasper v4.1(2.03)
jtag hack found in smc.bin!

******* WARNING: could not patch SMC reset limit!

encoding kv.bin size 0x4000 (JTAG)
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cb_4558.bin size 0x7a70 (JTAG)
CB 4558 seq 0x0104000c type: 0x01 cseq: 0x04 allow: 0x000c
    expected fuses:
    fuseset 00: C0FFFFFFFFFFFFFF
    fuseset 01: 0F0F0F0F0F0F0FF0
    fuseset 02: 000F000000000000 (sequence)
    fuseset 02: 00F0000000000000 (allow cseq 3)
    fuseset 02: 000F000000000000 (allow cseq 4)
encoding cd_4558.bin size 0x5700 (JTAG)
encoding ce_1888.bin size 0x56070 (JTAG)
encoding cf_4532.bin size 0x44c0 (JTAG)
encoding cg_4532.bin size 0x2ef40 (JTAG)
encoding cf_16547.bin size 0x4560 (JTAG)
encoding cg_16547.bin size 0x75ab0 (JTAG)
encoding freeboot.bin size 0xd40 (JTAG)
patching freeboot.bin with with kernel version string '16547'
Boot options set:
    - console DVD eject button is being used to start xell 
    - alternate xell button disabled
encoding patches_zephyr.bin size 0x9d8 (JTAG)
encoding fuses.bin size 0x60 (JTAG)
encoding xell-2f.bin size 0x40000 (JTAG)
encoding cb_4579.bin size 0x7f20 (JTAG)
CB 4579 seq 0x01060024 type: 0x01 cseq: 0x06 allow: 0x0024
    expected fuses:
    fuseset 00: C0FFFFFFFFFFFFFF
    fuseset 01: 0F0F0F0F0F0F0FF0
    fuseset 02: 00000F0000000000 (sequence)
    fuseset 02: 00F0000000000000 (allow cseq 3)
    fuseset 02: 00000F0000000000 (allow cseq 6)
CBENC pairing set to: 58 52 32
encoding cd_8453.bin size 0x5780 (JTAG)

Virtual Fuses set to:
    fuseset 00: C0FFFFFFFFFFFFFF
    fuseset 01: 0F0F0F0F0F0F0FF0
    fuseset 02: 00000F0000000000
    fuseset 03: 8C4E30C1AAAB3A22
    fuseset 04: 8C4E30C1AAAB3A22
    fuseset 05: 9FDA9FF8ACC8FC90
    fuseset 06: 9FDA9FF8ACC8FC90
    fuseset 07: FFFFFFFFFFFFFFFF
    fuseset 08: F000000000000000
    fuseset 09: 0000000000000000
    fuseset 10: 0000000000000000
    fuseset 11: 0000000000000000
done!

------ Adding bootloaders to flash image ------
adding payload.bin at raw offset 0x00000200 len 0x200 (end 0x400)
adding SMC.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cb_4558.bin at raw offset 0x00008000 len 0x7a70 (end 0xfa70)
adding cd_4558.bin at raw offset 0x0000fa70 len 0x5700 (end 0x15170)
adding ce_1888.bin at raw offset 0x00015170 len 0x56070 (end 0x6b1e0)
adding cf_4532.bin at raw offset 0x00070000 len 0x44c0 (end 0x744c0)
adding cg_4532.bin at raw offset 0x000744c0 len 0x2ef40 (end 0x80000, rest in fs)
adding cf_16547.bin at raw offset 0x00080000 len 0x4560 (end 0x84560)
adding cg_16547.bin at raw offset 0x00084560 len 0x75ab0 (end 0x90000, rest in fs)
adding freeboot.bin at raw offset 0x00090000 len 0xd40 (end 0x90d40)
adding patches_zephyr.bin at raw offset 0x00091000 len 0x9d8 (end 0x919d8)
adding fuses.bin at raw offset 0x00095000 len 0x60 (end 0x95060)
adding xell-2f.bin at raw offset 0x00095060 len 0x40000 (end 0xd5060)
adding cb_4579.bin at raw offset 0x000d5060 len 0x7f20 (end 0xdcf80)
adding cd_8453.bin at raw offset 0x000dcf80 len 0x5780 (end 0xe2700)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
    at raw offset 0xe4000 len 0x00023400 (end: 0x00107400)...done!
Writing target CG patch slot overflow data to sysupdate.xexp2
    at raw offset 0xe4000 len 0x0006a010 (end: 0x0014e010)...done!

------ adding 28 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0xf2808dc5 ini: 0xf2808dc5)
    adding as aac.xexp2 at raw offset 0x172010 len 0x00014000 (end 0x00186010)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0xd5c63122 ini: 0xd5c63122)
    adding as bootanim.xex at raw offset 0x188000 len 0x00061000 (end 0x001e9000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0xf7e474ef ini: 0xf7e474ef)
    adding as createprofile.xex at raw offset 0x1e9000 len 0x0000c000 (end 0x001f5000)
extracted SUPD\dash.xex (0x598000 bytes) (crc32: 0x2a153493 ini: 0x2a153493)
    adding as dash.xex at raw offset 0x1f8000 len 0x00598000 (end 0x00790000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0x09e04596 ini: 0x09e04596)
    adding as deviceselector.xex at raw offset 0x790000 len 0x0000a000 (end 0x0079a000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0x4647565d ini: 0x4647565d)
    adding as gamerprofile.xex at raw offset 0x79a000 len 0x0001b000 (end 0x007b5000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xa6f9c197 ini: 0xa6f9c197)
    adding as hud.xex at raw offset 0x7b7000 len 0x0001d000 (end 0x007d4000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x1d296f10 ini: 0x1d296f10)
    adding as huduiskin.xex at raw offset 0x7d5000 len 0x00014000 (end 0x007e9000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x33d5771b ini: 0x33d5771b)
    adding as mfgbootlauncher.xex at raw offset 0x7ec000 len 0x00008000 (end 0x007f4000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x4de56d9c ini: 0x4de56d9c)
    adding as minimediaplayer.xex at raw offset 0x7f4000 len 0x0000c000 (end 0x00800000)
extracted SUPD\nomni.xexp (0xc800 bytes) (crc32: 0x97cadcec ini: 0x97cadcec)
    adding as nomni.xexp2 at raw offset 0x800000 len 0x0000c800 (end 0x0080c800)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0xc7ab2e5b ini: 0xc7ab2e5b)
    adding as nomnifwk.xexp2 at raw offset 0x80c800 len 0x00002000 (end 0x0080e800)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0x22253a42 ini: 0x22253a42)
    adding as nomnifwm.xexp2 at raw offset 0x812000 len 0x00005000 (end 0x00817000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
    adding as SegoeXbox-Light.xtt at raw offset 0x819000 len 0x00006000 (end 0x0081f000)
extracted SUPD\signin.xex (0x19000 bytes) (crc32: 0xaffe7f78 ini: 0xaffe7f78)
    adding as signin.xex at raw offset 0x822000 len 0x00019000 (end 0x0083b000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xf6e1cdd5 ini: 0xf6e1cdd5)
    adding as updater.xex at raw offset 0x83d000 len 0x00007000 (end 0x00844000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xb916846b ini: 0xb916846b)
    adding as vk.xex at raw offset 0x847000 len 0x0000b000 (end 0x00852000)
extracted SUPD\xam.xex (0x253000 bytes) (crc32: 0x027463e8 ini: 0x027463e8)
    adding as xam.xex at raw offset 0x853000 len 0x00253000 (end 0x00aa6000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
    adding as xenonclatin.xtt at raw offset 0xaa7000 len 0x0011b000 (end 0x00bc2000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
    adding as xenonclatin.xttp2 at raw offset 0xbc3000 len 0x00018000 (end 0x00bdb000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
    adding as xenonjklatin.xtt at raw offset 0xbdc000 len 0x001a8000 (end 0x00d84000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
    adding as xenonjklatin.xttp2 at raw offset 0xd84000 len 0x00007000 (end 0x00d8b000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0xa86f3ef4 ini: 0xa86f3ef4)
    adding as ximecore.xex at raw offset 0xd8b000 len 0x00017000 (end 0x00da2000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
    adding as ximedic.xex at raw offset 0xda3000 len 0x00090000 (end 0x00e33000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0x186d8df9 ini: 0x186d8df9)
    adding as ximedic.xexp2 at raw offset 0xe34000 len 0x00002800 (end 0x00e36800)
reading 16547\..\launch.xex (0xd000 bytes)
    adding as launch.xex at raw offset 0xe36800 len 0x0000d000 (end 0x00e43800)
reading 16547\..\lhelper.xex (0x6000 bytes)
    adding as lhelper.xex at raw offset 0xe45000 len 0x00006000 (end 0x00e4b000)
***** could not read file '..\launch.ini', skipping *****

------ adding 4 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
    adding as crl.bin at raw offset 0xe50000 len 0x00000a00 (end 0x00e50a00)

<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
    adding as dae.bin at raw offset 0xe54000 len 0x0000ad30 (end 0x00e5ed30)

<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
    adding as extended.bin at raw offset 0xe60000 len 0x00004000 (end 0x00e64000)

<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
    adding as secdata.bin at raw offset 0xe64000 len 0x00000400 (end 0x00e64400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
    adding MobileB.dat as type 0x31 at raw offset 0xe68000 len 0x800 (end 0xe68800)
MobileC.dat found, adding from previous parse
    adding MobileC.dat as type 0x32 at raw offset 0xe6c000 len 0x200 (end 0xe6c200)
MobileD.dat found, adding from previous parse
    adding MobileD.dat as type 0x33 at raw offset 0xe70000 len 0x800 (end 0xe70800)
MobileE.dat found, adding from previous parse
    adding MobileE.dat as type 0x34 at raw offset 0xe74000 len 0x800 (end 0xe74800)
Statistics.settings found, adding from previous parse
    adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)
Manufacturing.data found, adding from previous parse
    adding Manufacturing.data at raw offset 0xf74000 len 0x1000 (end 0xf75000)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe78000 len 0x4000 (end 0xe7c000)...done!
calculating ECD bytes and assembling raw image...done!
done remapping!

------ writing image to disk ------
writing file 'C:\Users\itxtutor\Desktop\224926373505\updflash.bin' to disk...done!
---------------------------------------------------------------
C:\Users\itxtutor\Desktop\224926373505\updflash.bin image built, info:
---------------------------------------------------------------
Kernel    : 2.0.16547.0
Console   : Zephyr
NAND size : 16MiB
Build     : JTAG
Xell      : power on console with console eject button
Serial    : 224926373505
ConsoleId : 021941795806
MoboSerial: 7190672113317315
Mfg Date  : 08/30/2007
CPU Key   : 8C4E30C1AAAB3A229FDA9FF8ACC8FC90
1BL Key   : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key   : 1AE3BA1A5D2BB1CA16BA6E9174D13DA6
CF LDV    : 17
KV type   : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
    xeBuild Finished. Have a nice day.
---------------------------------------------------------------

Image of R-JTAG board: See attachement

Images of close-up soldering to motherboard: See attachement

Description of problem: Doesnt glitch / boot. No RROD

Was the console working before you started: Yes , stock nand works perfectly ! ALso xell reloaded boots up ! But not freeboot :(
 

Attachments

Last edited:

Itxtutor

Junior Member
Jul 9, 2013
10
0
Ok i updated now the informations. Thanks for your help

SO as i have seen , the console does not get post 2E , stops before :( indicates bad setup ? am i right ?

i had to solder bridge the resistor switch because i lost that jumper. righ

Also had to wire up 2 points on the first QSB because the pads went off after i took it off :( i hope its correct this way.

CPU_rst taken from the top.

Getting no RROD , just shuts down after some glitches. depends on dip settings.

i´m now trying all dips with different voltage.

If some pro could help me out , regarding the log , i would be so thankful :)
 
Last edited:

Martin C

VIP Member
Jan 10, 2004
35,981
0
Scotland, UK
www.team-xecuter.com
MOTHERBOARD VERSION:
JASPER DIP 7-8 ON ON
ZEPHYR DIP 7-8 OFF OFF <---- NEW
FALCON DIP 7-8 ON OFF

It looks like you have DIPs 7-8 set to on?

Also, you need to try all combinations. You have 6 DIPs and 3 power settings.
 
  • Like
Reactions: Itxtutor

Itxtutor

Junior Member
Jul 9, 2013
10
0
Hi , 7 and 8 are off. Also on the picture.

I´m pretty sure that on is on that side where it says on XD

ok i´ll try default , 1,2V and 1,8V on all dips. How long should i try each dip ?

On the JTAG QSB , there is this little point which goes to that line on the board... it was not tinned on my board. So i tried to put some tin on it with many flux. Not sure if it has a good contact, any alternate point for that ??

thanks for your help !
 

Itxtutor

Junior Member
Jul 9, 2013
10
0
OMFG !!!!!!!!!! I FLASHED A FALCON NAND AND IT BOOTED !!!!!!!!

F*CK that zephyr ! Booted after the first glitch, no tweaks...

Thanks anyway. TX always a great product and great support :)
 
  • Like
Reactions: Martin C

nofeloniesyet

VIP Member
Jan 16, 2011
4,830
128
Nowhere
OMFG !!!!!!!!!! I FLASHED A FALCON NAND AND IT BOOTED !!!!!!!!

F*CK that zephyr ! Booted after the first glitch, no tweaks...

Thanks anyway. TX always a great product and great support :)
this was a common solution even back in the old regular jtag days,glad ur sorted!
 

Itxtutor

Junior Member
Jul 9, 2013
10
0
Oh sh*t.. i put it back together in the case.. then r8c2 wire came off , with half of the resistor... pads still OK on the board.

Can i bridge and connect to the chip , or resolder a 1K ohm resistor ? Does it change dip settings ?

still got 2 other xenon boards with RROD here , would be no problem to replace.

Please help :S

thanks !
 
Last edited:

Itxtutor

Junior Member
Jul 9, 2013
10
0
OK i now bridged it and it doesnt Boot. only fast green led blinking.

can i leave it bridged and go for an alt point ? if yes , which one ?

thanks again for your support. you are awesome :)
 

skillet34

VIP Member
Jun 21, 2012
1,067
68
MA USA
OK i now bridged it and it doesnt Boot. only fast green led blinking.
can i leave it bridged and go for an alt point ? if yes , which one ?
You can try the original point on the bottom of the board or scrape the trace carefully and solder to it..
 

Itxtutor

Junior Member
Jul 9, 2013
10
0
hi.the pads Form r8c2 are OK. dont need To cut the Trace. just bridged the two soldering point where the resistor was.

i just need to know if i can leave it bridged without the resistor or if i have To resolder a resistor.

so can i leave it bridged and take the alt point in the bottom ? :D
 

Itxtutor

Junior Member
Jul 9, 2013
10
0
Oh yeah great. Bridged the R8C2 and went to the point on the underside of the board. Works well , but had to go from 1.8V to 1.2V to receive a good boot :)

Thanks guys ! :D
 

skillet34

VIP Member
Jun 21, 2012
1,067
68
MA USA
hi.the pads Form r8c2 are OK. dont need To cut the Trace. just bridged the two soldering point where the resistor was.

i just need to know if i can leave it bridged without the resistor or if i have To resolder a resistor.

so can i leave it bridged and take the alt point in the bottom ? :D
I only ment scrape the trace if you still wanted to use the top point. glad your sorted :)