Xbox won't turn on if DemoN nand is selected (Phat)

koetjuh

Senior Member
Dec 17, 2011
110
0
NL
TX Product(s) used: DemoN
Console Type: Jasper
NAND size: 512
Dashboard version: 2.0.16203.0
CB version: 6754
Screenshot of NAND details from J-Runner:


jrunner.JPG


J-Runner log:


Code:
===================================================
vrijdag 8 maart 2013 21:10:46


J-Runner v0.2 Beta (287) Started






Checking Files
Finished Checking Files
Initializing nanddump1.bin..
CpuKey is Correct
Key already Exists
Nand Initialization Finished
Load Files Initiliazation Finished
16203
Started Creation of the 16203 xebuild image
KV Info saved to file
---------------------------------------------------------------
     xeBuild v1.07.561
---------------------------------------------------------------
building retail image
---------------------------------------------------------------
C:\Documents and Settings\Koetjuh\Bureaublad\xbox360\RGH\J-Runner\605038693105\updflash.bin image built, info:
---------------------------------------------------------------
Console   : Jasper
NAND size : 16MiB
Build     : Retail
Serial    : 605038693105
ConsoleId : 019587937942
MoboSerial: 705673A201849315
Mfg Date  : 07/28/2009
CPU Key   : xxx
1BL Key   : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key   : xxx
CF LDV    : 16
KV type   : type2 (hashed)
---------------------------------------------------------------
    xeBuild Finished. Have a nice day.
---------------------------------------------------------------
Saved to C:\Documents and Settings\Koetjuh\Bureaublad\xbox360\RGH\J-Runner\605038693105
Image is Ready
DEMON
Hardware   : Demon Phat
Firmware   : 1.4
Flash ID   : 0x73AD Hynix (16MiB - Small block)
Flash Size : 0x400 blocks of 0x4200 bytes
Writing Nand
Done!
in 0:32 min:sec
updflash.bin log

Code:
---------------------------------------------------------------     xeBuild v1.07.561
---------------------------------------------------------------
building retail image
<enter> key on completion suppressed
data directory overridden from command line to '.\xeBuild\16203\'
per build directory overridden from command line to 'xeBuild\data'
file name overridden from command line to 'C:\Documents and Settings\Koetjuh\Bureaublad\xbox360\RGH\J-Runner\605038693105\updflash.bin'


------ parsing user ini at '.\xeBuild\data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1b0 bytes in memory
loading cpukey.txt from .\xeBuild\data\cpukey.txt
CPU Key set to: xxx
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to: 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)


------ parsing ini at '.\xeBuild\16203\_retail.ini' ------
ini version 16203


ini: label [jasperbl] found
found (1) 'cba_6754.bin' crc: 0x4f16775e
found (2) 'cbb_6754.bin' crc: 0x4ac39cb1
found (3) 'cd_6754.bin' crc: 0x1d685a08
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_16203.bin' crc: 0xc4c27121
found (6) 'cg_16203.bin' crc: 0xcbb44eac
ini dictates dual CB for this model


ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x62924e10
found (2) 'bootanim.xex' crc: 0xc8b660b2
found (3) 'createprofile.xex' crc: 0x9f6efee2
found (4) 'dash.xex' crc: 0x18ea6c7e
found (5) 'deviceselector.xex' crc: 0x75c32b5b
found (6) 'gamerprofile.xex' crc: 0xec9746f7
found (7) 'hud.xex' crc: 0xabf19107
found (8) 'huduiskin.xex' crc: 0xf3563a5c
found (9) 'mfgbootlauncher.xex' crc: 0x763c73fe
found (10) 'minimediaplayer.xex' crc: 0xda1d0a4a
found (11) 'nomni.xexp' crc: 0xaae9ad36
found (12) 'nomnifwk.xexp' crc: 0xb3c2c31b
found (13) 'nomnifwm.xexp' crc: 0xf69cf9fc
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0xc1d7185d
found (16) 'updater.xex' crc: 0x19286110
found (17) 'vk.xex' crc: 0xefcbab82
found (18) 'xam.xex' crc: 0xf8db3557
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0xe85e813b
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xfb2bb58c


ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------


output name overridden to: C:\Documents and Settings\Koetjuh\Bureaublad\xbox360\RGH\J-Runner\605038693105\updflash.bin




------ Checking .\xeBuild\data\nanddump.bin ------
.\xeBuild\data\nanddump.bin file size: 0x21000000
nanddump header checks passed OK!
Loading NAND dump (0x4200000 bytes)...done!
Detecting NAND controller type from dump data...
    NAND dump is from a big block machine
    NAND dump uses big block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0x3be0000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x0f Pairing: 0xa578fe
CF slot 1 decrypted ok LDV 0x10 Pairing: 0xa578fe
setting LDV from image to 16
setting pairing data from image to 0xa578fe
MobileB.dat found at page 0x1d30c, size 2048 (0x800) bytes
MobileC.dat found at page 0x1d300, size 512 (0x200) bytes
MobileD.dat found at page 0x1d304, size 2048 (0x800) bytes
MobileE.dat found at page 0x1d308, size 2048 (0x800) bytes
Statistics.settings found at page 0xef000, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at page 0x18f20 raw offset 0x5ef3200
seeking security files...
crl.bin found in sector 0x21c size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x228 size 0xd9c0...verified! Will use if external file not found.
extended.bin found in sector 0x21f size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x3f5 size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image


------ loading system update container ------
.\xeBuild\16203\su20076000_00000000 found, loading...done!
    Read 0xb31000 bytes to memory
checking container integrity...
header seems valid, version 2.0.16203.00
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x79a60 bytes)
decrypting SUPD\xboxupd.bin\CF_16203.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16203.bin (0x754f2 bytes)...done!


------ Loading bootloaders and required security files ------
reading .\xeBuild\data\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x1000 size 0x3000
reading .\xeBuild\data\kv.bin failed, using kv.bin from nand dump
reading .\common\cba_6754.bin (0x2000 bytes)
reading .\common\cbb_6754.bin (0x96c0 bytes)
reading .\common\cd_6754.bin (0x5080 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
extracted SUPD\xboxupd.bin\CF_16203.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16203.bin (0x754f2 bytes)
reading .\xeBuild\data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu:  80øC Gpu:  75øC Edram:  77øC
Max temps   : Cpu:  95øC Gpu:  90øC Edram:  92øC
Cpu Fan     : (auto)
Gpu Fan     : (auto)
MAC Address : 00:22:48:c0:d2:42
AVRegion    : 0x00000300 (PAL50)
GameRegion  : 0x02fe (PAL/EU)
DVDRegion   : 2
resetKey    : LLDX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
done!
patch slot offset reset to: 0x70000


------ Encrypting and finalizing bootloaders ------
initializing random nonces
encoding smc.bin size 0x3000
SMC checksum: 5b3aed00
known clean SMC found, type: Jasper v4.1(2.03)
clean smc.bin found!
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
encoding cba_6754.bin size 0x2000
encoding cbb_6754.bin size 0x96c0
CB 6754 seq 0x010c0ad0 type: 0x01 cseq: 0x0c allow: 0x0ad0
    expected fuses:
    fuseset 00: C0FFFFFFFFFFFFFF
    fuseset 01: 0F0F0F0F0F0F0FF0
    fuseset 02: 00000000000F0000 (sequence)
    fuseset 02: 0000F00000000000 (allow cseq 5)
    fuseset 02: 000000F000000000 (allow cseq 7)
    fuseset 02: 0000000F00000000 (allow cseq 8)
    fuseset 02: 000000000F000000 (allow cseq 10)
    fuseset 02: 00000000000F0000 (allow cseq 12)
    **dual CB flag detected!**
    **15572+ CBB crypto method detected!**
encoding cd_6754.bin size 0x5080
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x0
encoding cf_16203.bin size 0x4560
encoding cg_16203.bin size 0x75500
encoding patches_fat.bin size 0x0
done!


------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_6754.bin at raw offset 0x00008000 len 0x2000 (end 0xa000)
adding cbb_6754.bin at raw offset 0x0000a000 len 0x96c0 (end 0x136c0)
adding cd_6754.bin at raw offset 0x000136c0 len 0x5080 (end 0x18740)
adding ce_1888.bin at raw offset 0x00018740 len 0x56070 (end 0x6e7b0)
retail image, skipping xell-gggggg.bin
adding cf_16203.bin at raw offset 0x00070000 len 0x4560 (end 0x74560)
adding cg_16203.bin at raw offset 0x00074560 len 0x75500 (end 0x80000, rest in fs)
retail image, skipping patches_fat.bin
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
    at raw offset 0x90000 len 0x00069a60 (end: 0x000f9a60)...done!


------ adding 25 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x62924e10 ini: 0x62924e10)
    adding as aac.xexp1 at raw offset 0xf9a60 len 0x00014000 (end 0x0010da60)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0xc8b660b2 ini: 0xc8b660b2)
    adding as bootanim.xex at raw offset 0x110000 len 0x00061000 (end 0x00171000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x9f6efee2 ini: 0x9f6efee2)
    adding as createprofile.xex at raw offset 0x171000 len 0x0000c000 (end 0x0017d000)
extracted SUPD\dash.xex (0x59c000 bytes) (crc32: 0x18ea6c7e ini: 0x18ea6c7e)
    adding as dash.xex at raw offset 0x180000 len 0x0059c000 (end 0x0071c000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0x75c32b5b ini: 0x75c32b5b)
    adding as deviceselector.xex at raw offset 0x71c000 len 0x0000a000 (end 0x00726000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xec9746f7 ini: 0xec9746f7)
    adding as gamerprofile.xex at raw offset 0x726000 len 0x0001b000 (end 0x00741000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xabf19107 ini: 0xabf19107)
    adding as hud.xex at raw offset 0x743000 len 0x0001d000 (end 0x00760000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0xf3563a5c ini: 0xf3563a5c)
    adding as huduiskin.xex at raw offset 0x761000 len 0x00014000 (end 0x00775000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x763c73fe ini: 0x763c73fe)
    adding as mfgbootlauncher.xex at raw offset 0x778000 len 0x00008000 (end 0x00780000)
extracted SUPD\minimediaplayer.xex (0xb000 bytes) (crc32: 0xda1d0a4a ini: 0xda1d0a4a)
    adding as minimediaplayer.xex at raw offset 0x780000 len 0x0000b000 (end 0x0078b000)
extracted SUPD\nomni.xexp (0xe000 bytes) (crc32: 0xaae9ad36 ini: 0xaae9ad36)
    adding as nomni.xexp1 at raw offset 0x78b000 len 0x0000e000 (end 0x00799000)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0xb3c2c31b ini: 0xb3c2c31b)
    adding as nomnifwk.xexp1 at raw offset 0x79a000 len 0x00002000 (end 0x0079c000)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0xf69cf9fc ini: 0xf69cf9fc)
    adding as nomnifwm.xexp1 at raw offset 0x79e000 len 0x00005000 (end 0x007a3000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
    adding as SegoeXbox-Light.xtt at raw offset 0x7a5000 len 0x00006000 (end 0x007ab000)
extracted SUPD\signin.xex (0x16000 bytes) (crc32: 0xc1d7185d ini: 0xc1d7185d)
    adding as signin.xex at raw offset 0x7ae000 len 0x00016000 (end 0x007c4000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0x19286110 ini: 0x19286110)
    adding as updater.xex at raw offset 0x7c6000 len 0x00007000 (end 0x007cd000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xefcbab82 ini: 0xefcbab82)
    adding as vk.xex at raw offset 0x7cf000 len 0x0000b000 (end 0x007da000)
extracted SUPD\xam.xex (0x24f000 bytes) (crc32: 0xf8db3557 ini: 0xf8db3557)
    adding as xam.xex at raw offset 0x7db000 len 0x0024f000 (end 0x00a2a000)
reading .\xeBuild\16203\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
    adding as xenonclatin.xtt at raw offset 0xa2b000 len 0x0011b000 (end 0x00b46000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
    adding as xenonclatin.xttp1 at raw offset 0xb47000 len 0x00018000 (end 0x00b5f000)
reading .\xeBuild\16203\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
    adding as xenonjklatin.xtt at raw offset 0xb60000 len 0x001a8000 (end 0x00d08000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
    adding as xenonjklatin.xttp1 at raw offset 0xd08000 len 0x00007000 (end 0x00d0f000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0xe85e813b ini: 0xe85e813b)
    adding as ximecore.xex at raw offset 0xd0f000 len 0x00017000 (end 0x00d26000)
reading .\xeBuild\16203\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
    adding as ximedic.xex at raw offset 0xd27000 len 0x00090000 (end 0x00db7000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0xfb2bb58c ini: 0xfb2bb58c)
    adding as ximedic.xexp1 at raw offset 0xdb8000 len 0x00002800 (end 0x00dba800)


------ adding 5 security files ------
<- Processing crl.bin ->
reading .\xeBuild\data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
    adding as crl.bin at raw offset 0xdbc000 len 0x00000a00 (end 0x00dbca00)


<- Processing dae.bin ->
reading .\xeBuild\data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
    adding as dae.bin at raw offset 0xdc0000 len 0x0000ad30 (end 0x00dcad30)


<- Processing extended.bin ->
reading .\xeBuild\data\extended.bin (0x4000 bytes)
    adding as extended.bin at raw offset 0xdcc000 len 0x00004000 (end 0x00dd0000)


<- Processing fcrt.bin ->
    fcrt.bin not found and not required by keyvault, skipped


<- Processing secdata.bin ->
reading .\xeBuild\data\secdata.bin (0x400 bytes)
    adding as secdata.bin at raw offset 0xdd0000 len 0x00000400 (end 0x00dd0400)


------ checking for Mobile*.dat ------
MobileB.dat found, adding from nanddump.bin
    adding MobileB.dat as type 0x31 at raw offset 0xdd4000 len 0x800 (end 0xdd4800)
MobileC.dat found, adding from nanddump.bin
    adding MobileC.dat as type 0x32 at raw offset 0xdd8000 len 0x200 (end 0xdd8200)
MobileD.dat found, adding from nanddump.bin
    adding MobileD.dat as type 0x33 at raw offset 0xddc000 len 0x800 (end 0xddc800)
MobileE.dat found, adding from nanddump.bin
    adding MobileE.dat as type 0x34 at raw offset 0xde0000 len 0x800 (end 0xde0800)
Statistics.settings found, adding from nanddump.bin
    adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)


------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400


------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xde4000 len 0x4000 (end 0xde8000)...done!
fixing up big block controller on small block NAND LBA numbers...done!
calculating ECD bytes and assembling raw image...done!
writing file 'C:\Documents and Settings\Koetjuh\Bureaublad\xbox360\RGH\J-Runner\605038693105\updflash.bin' to disk...done!
C:\Documents and Settings\Koetjuh\Bureaublad\xbox360\RGH\J-Runner\605038693105\updflash.bin written OK


---------------------------------------------------------------
C:\Documents and Settings\Koetjuh\Bureaublad\xbox360\RGH\J-Runner\605038693105\updflash.bin image built, info:
---------------------------------------------------------------
Console   : Jasper
NAND size : 16MiB
Build     : Retail
Serial    : 605038693105
ConsoleId : 019587937942
MoboSerial: 705673A201849315
Mfg Date  : 07/28/2009
CPU Key   : xxx
1BL Key   : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key   : xxx
CF LDV    : 16
KV type   : type2 (hashed)
---------------------------------------------------------------
    xeBuild Finished. Have a nice day.
---------------------------------------------------------------
Images of close-up soldering to motherboard:

20130308_211310.jpg20130308_211407.jpg

Description of problem:

When the DemoN nand is selected, the xbox won't turn on.
No problems with the stock nand, the box turns on and boots.
There is a CR rev C in the box, but disabled (set to PRG). I put the CR in there about a year ago (RGH2 with dash 14719) and disabled it (just for getting the key, since there was no BB addon at that time).
Before installation I used the DemoN toolbox to verify everything was ok.

For now I only want to boot the DemoN on a retail nand, so no glitching to do yet.
I can read and write to the DemoN. I can switch NANDs using toolbox, J-runner, sync button and ext. module.
I checked all soldering points for continuity. Also checked the points using the alt rebuild point for phat.
Everything looks fine.

I'm puzzled now why the box won't turn on with the DemoN selected.

:confused: someone can help/hint me with this?


Edit: has this something to do with it? http://team-xecuter.com/forums/show...graded-to-1-04-not-connected-in-DemoN-Toolbox
 
Last edited:

nofeloniesyet

VIP Member
Jan 16, 2011
4,830
128
Nowhere
did u update the firmware on the demon?
 

koetjuh

Senior Member
Dec 17, 2011
110
0
NL
thank you for your response.
I updated it a few times. Updated it using "demon_firmware_1.04.bin" on the Demon toolbox and j-runner.
the box still won't turn on (when demon nand is selected) :frown:

demon1.04fw.JPG

any other clue?

Edit 10-03-2013: Figured it out. After i dumped the xbox nand using J-runner through the demon i got a "wrong header" which gave me a thought about the nand points. After examing the nand points with a magnifying glass i noticed that D2 and D3 barely had a connection to the MB (there was however continuity between bottom and top of mobo). Reflowed D2 and D3 and voila.. box boots on DemoN nand!

thanks for reading and hopefully someone else can use this information when facing something similiair
 
Last edited:
  • Like
Reactions: acs420 and akawtu