Console Type: Falcon
NAND size: 16
Dashboard version: 16202
CB version: 5774
Screenshot of NAND details from J-Runner:

RATER log:
updflash.bin log:
Image of R-JTAG board:

Images of close-up soldering to motherboard:

Description of problem:
XeLL boots fine, orig. NAND works fine, no RGH Dashboard.
Was the console working before you started: Y
UPDATE: Edited SMC Config and it works, but freezing.
NAND size: 16
Dashboard version: 16202
CB version: 5774
Screenshot of NAND details from J-Runner:

RATER log:
Code:
Phat Selected
Version: 10
Power Up
Waiting for POST to change
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post D9 - SHA_COMPUTE_CB_B
Post C9
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 2E - HWINIT
Post 33 - FETCH_CONTENTS_4BL_CD
Post 34 - HMACSHA_COMPUTE_4BL_CD
Post 35 - RC4_INITIALIZE_4BL_CD
Post 36 - RC4_DECRYPT_4BL_CD
Post 37 - SHA_COMPUTE_4BL_CD
Post 3A - BRANCH
Post 40 - Entrypoint of CD reached
Post 42 - FETCH_HEADER
Post 44 - FETCH_CONTENTS
Post 45 - HMACSHA_COMPUTE
Post 46 - RC4_INITIALIZE
Post 47 - RC4_DECRYPT
Post 48 - SHA_COMPUTE
Post 4B - LZX_EXPAND
Post 4E - FETCH_OFFSET_6BL_CF
Post 4F - VERIFY_OFFSET_6BL_CF
Post 51 - LOAD_UPDATE_2
Post 50 - LOAD_UPDATE_1
Post 52 - BRANCH
Post 58 - INIT_HYPERVISOR
Post 5A - INIT_XEX_TRAINING
Post 61 - INIT_HAL_PHASE_0
Post 63 - INIT_KERNEL_DEBUGGER
Post 64 - INIT_MEMORY_MANAGER
Post 65 - INIT_STACKS
Post 66 - INIT_OBJECT_SYSTEM
Post 67 - INIT_PHASE1_THREAD
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS
Post 69 - INIT_KEY_VAULT
Post 6A - INIT_HAL_PHASE_1
Post 6B - INIT_SFC_DRIVER
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 12 - FSB_CONFIG_RX_STATE
Post 13 - FSB_CONFIG_TX_STATE
Post 15 - FETCH_OFFSET
Post 16 - FETCH_HEADER
Post 18 - FETCH_CONTENTS
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 23 - INIT_SYSRAM
Post 31 - FETCH_HEADER_4BL_CD
Post 33 - FETCH_CONTENTS_4BL_CD
Post 44 - FETCH_CONTENTS
Post 45 - HMACSHA_COMPUTE
Post 46 - RC4_INITIALIZE
Post 47 - RC4_DECRYPT
Post 4B - LZX_EXPAND
Post 4D - DECODE_FUSES
Post 4E - FETCH_OFFSET_6BL_CF
Post 51 - LOAD_UPDATE_2
Post 52 - BRANCH
Post 59 - INIT_SOC_MMIO
Post 5A - INIT_XEX_TRAINING
Post 5B - INIT_KEYRING
Post 5C - INIT_KEYS
Post 5F
Post 61 - INIT_HAL_PHASE_0
Post 62 - INIT_PROCESS_OBJECTS
Post 63 - INIT_KERNEL_DEBUGGER
Post 64 - INIT_MEMORY_MANAGER
Post 65 - INIT_STACKS
Post 66 - INIT_OBJECT_SYSTEM
Post 67 - INIT_PHASE1_THREAD
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS
Post 69 - INIT_KEY_VAULT
Post 6A - INIT_HAL_PHASE_1
Post 6B - INIT_SFC_DRIVER
Post 6C - INIT_SECURITY
Post 6D - INIT_KEY_EX_VAULT
Post 6E - INIT_SETTINGS
Post 6F - INIT_POWER_MODE
Post 70 - INIT_VIDEO_DRIVER
Post 71 - INIT_AUDIO_DRIVER
Post 72 - INIT_BOOT_ANIMATION + XMADecoder & XAudioRender Init
Shutdown
Power Up
Waiting for POST to change
Post D9 - SHA_COMPUTE_CB_B
Post DB - BRANCH_CB_B
Post CB
Post DB - BRANCH_CB_B
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post CB
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post FB
Post 8B - Panic - HYPERVISOR_DECREMENTER
Post FB
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 2E - HWINIT
Post 31 - FETCH_HEADER_4BL_CD
Post 33 - FETCH_CONTENTS_4BL_CD
Post 34 - HMACSHA_COMPUTE_4BL_CD
Post 35 - RC4_INITIALIZE_4BL_CD
Post 36 - RC4_DECRYPT_4BL_CD
Post 37 - SHA_COMPUTE_4BL_CD
Post 3A - BRANCH
Post 40 - Entrypoint of CD reached
Post 42 - FETCH_HEADER
Post 44 - FETCH_CONTENTS
Post 20 - CB entry point reached
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 10 - Payload/1BL started
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 10 - Payload/1BL started
Post 15 - FETCH_OFFSET
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 2E - HWINIT
Post 33 - FETCH_CONTENTS_4BL_CD
Post 34 - HMACSHA_COMPUTE_4BL_CD
Post 35 - RC4_INITIALIZE_4BL_CD
Post 36 - RC4_DECRYPT_4BL_CD
Post 37 - SHA_COMPUTE_4BL_CD
Post 3A - BRANCH
Post 40 - Entrypoint of CD reached
Post 42 - FETCH_HEADER
Post 44 - FETCH_CONTENTS
Post 45 - HMACSHA_COMPUTE
Post 46 - RC4_INITIALIZE
Post 47 - RC4_DECRYPT
Post 48 - SHA_COMPUTE
Post 4B - LZX_EXPAND
Post 4E - FETCH_OFFSET_6BL_CF
Post 4F - VERIFY_OFFSET_6BL_CF
Post 51 - LOAD_UPDATE_2
Post 50 - LOAD_UPDATE_1
Post 52 - BRANCH
Post 58 - INIT_HYPERVISOR
Post 5A - INIT_XEX_TRAINING
Post 60 - INIT_KERNEL
Post 61 - INIT_HAL_PHASE_0
Post 62 - INIT_PROCESS_OBJECTS
Post 63 - INIT_KERNEL_DEBUGGER
Post 64 - INIT_MEMORY_MANAGER
Post 66 - INIT_OBJECT_SYSTEM
Post 67 - INIT_PHASE1_THREAD
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS
Post 69 - INIT_KEY_VAULT
Post 6A - INIT_HAL_PHASE_1
Post 6B - INIT_SFC_DRIVER
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 12 - FSB_CONFIG_RX_STATE
Post 13 - FSB_CONFIG_TX_STATE
Post 18 - FETCH_CONTENTS
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 23 - INIT_SYSRAM
Post 31 - FETCH_HEADER_4BL_CD
Post 33 - FETCH_CONTENTS_4BL_CD
Post 44 - FETCH_CONTENTS
Post 45 - HMACSHA_COMPUTE
Post 47 - RC4_DECRYPT
Post 4B - LZX_EXPAND
Post 4D - DECODE_FUSES
Post 4E - FETCH_OFFSET_6BL_CF
Post 4F - VERIFY_OFFSET_6BL_CF
Post 51 - LOAD_UPDATE_2
Post 52 - BRANCH
Post 59 - INIT_SOC_MMIO
Post 5A - INIT_XEX_TRAINING
Post 5B - INIT_KEYRING
Post 5C - INIT_KEYS
Post 5F
Post 60 - INIT_KERNEL
Post 61 - INIT_HAL_PHASE_0
Post 62 - INIT_PROCESS_OBJECTS
Post 63 - INIT_KERNEL_DEBUGGER
Post 64 - INIT_MEMORY_MANAGER
Post 65 - INIT_STACKS
Post 66 - INIT_OBJECT_SYSTEM
Post 67 - INIT_PHASE1_THREAD
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS
Post 69 - INIT_KEY_VAULT
Post 6C - INIT_SECURITY
Post 6D - INIT_KEY_EX_VAULT
Post 6E - INIT_SETTINGS
Post 6F - INIT_POWER_MODE
Shutdown
Power Up
Waiting for POST to change
Post D9 - SHA_COMPUTE_CB_B
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post C9
Post 89 - Panic - FPU_UNAVAILABLE
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post C9
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post F9
Post 89 - Panic - FPU_UNAVAILABLE
Post C9
Post F9
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 2E - HWINIT
Post 31 - FETCH_HEADER_4BL_CD
Post 33 - FETCH_CONTENTS_4BL_CD
Post 34 - HMACSHA_COMPUTE_4BL_CD
Post 35 - RC4_INITIALIZE_4BL_CD
Post 36 - RC4_DECRYPT_4BL_CD
Post 37 - SHA_COMPUTE_4BL_CD
Post 3A - BRANCH
Post 40 - Entrypoint of CD reached
Post 44 - FETCH_CONTENTS
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 30 - VERIFY_OFFSET_4BL_CD
Post 12 - FSB_CONFIG_RX_STATE
Post 18 - FETCH_CONTENTS
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 2E - HWINIT
Post 31 - FETCH_HEADER_4BL_CD
Post 33 - FETCH_CONTENTS_4BL_CD
Post 34 - HMACSHA_COMPUTE_4BL_CD
Post 35 - RC4_INITIALIZE_4BL_CD
Post 36 - RC4_DECRYPT_4BL_CD
Post 37 - SHA_COMPUTE_4BL_CD
Post 3A - BRANCH
Post 40 - Entrypoint of CD reached
Post 42 - FETCH_HEADER
Post 44 - FETCH_CONTENTS
Post 45 - HMACSHA_COMPUTE
Post 46 - RC4_INITIALIZE
Post 47 - RC4_DECRYPT
Post 48 - SHA_COMPUTE
Post 4B - LZX_EXPAND
Post 4E - FETCH_OFFSET_6BL_CF
Post 4F - VERIFY_OFFSET_6BL_CF
Post 51 - LOAD_UPDATE_2
Post 50 - LOAD_UPDATE_1
Post 52 - BRANCH
Post 58 - INIT_HYPERVISOR
Post 5A - INIT_XEX_TRAINING
Post 60 - INIT_KERNEL
Post 61 - INIT_HAL_PHASE_0
Post 62 - INIT_PROCESS_OBJECTS
Post 64 - INIT_MEMORY_MANAGER
Post 66 - INIT_OBJECT_SYSTEM
Post 67 - INIT_PHASE1_THREAD
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS
Post 69 - INIT_KEY_VAULT
Post 6A - INIT_HAL_PHASE_1
Post 6B - INIT_SFC_DRIVER
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 10 - Payload/1BL started
Post 11 - FSB_CONFIG_PHY_CONTROL
Post 12 - FSB_CONFIG_RX_STATE
Post 13 - FSB_CONFIG_TX_STATE
Post 16 - FETCH_HEADER
Post 1B - RC4_DECRYPT
Post 1C - SHA_COMPUTE
Post 1D - SIG_VERIFY
Post 1E - BRANCH
Post 20 - CB entry point reached
Post 21 - INIT_SECOTP
Post 22 - INIT_SECENG
Post 2F - RELOCATE
Post 23 - INIT_SYSRAM
Post 31 - FETCH_HEADER_4BL_CD
Post 33 - FETCH_CONTENTS_4BL_CD
Post 44 - FETCH_CONTENTS
Post 45 - HMACSHA_COMPUTE
Post 46 - RC4_INITIALIZE
Post 48 - SHA_COMPUTE
Post 4B - LZX_EXPAND
Post 4D - DECODE_FUSES
Post 4E - FETCH_OFFSET_6BL_CF
Post 51 - LOAD_UPDATE_2
Post 52 - BRANCH
Post 59 - INIT_SOC_MMIO
Post 5A - INIT_XEX_TRAINING
Post 5B - INIT_KEYRING
Post 5C - INIT_KEYS
Post 5F
Post 60 - INIT_KERNEL
Post 61 - INIT_HAL_PHASE_0
Post 62 - INIT_PROCESS_OBJECTS
Post 64 - INIT_MEMORY_MANAGER
Post 65 - INIT_STACKS
Post 66 - INIT_OBJECT_SYSTEM
Post 67 - INIT_PHASE1_THREAD
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS
Post 69 - INIT_KEY_VAULT
Post 6A - INIT_HAL_PHASE_1
Post 6C - INIT_SECURITY
Post 6D - INIT_KEY_EX_VAULT
Post 6E - INIT_SETTINGS
Post 6F - INIT_POWER_MODE
Post 70 - INIT_VIDEO_DRIVER
Post 71 - INIT_AUDIO_DRIVER
Shutdown
Code:
base path changed to E:\X360\J-Runner\xeBuild
---- { Image Build Mode } ----
building jtag image
<enter> key on completion suppressed
data directory overridden from command line to '16537\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'E:\X360\J-Runner\177381183505\updflash.bin'
------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1b0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0xEBAAF40C39E65F6EA2E018AD843575D5 (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to : 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to : 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)
------ parsing ini at '16537\_jtag.ini' ------
ini version 16537
ini: label [falconbl] found
found (1) 'cb_5770.bin' crc: 0x3279f0d5
found (2) 'cd_5770.bin' crc: 0xd04e8927
found (3) 'ce_1888.bin' crc: 0xff9b60df
found (4) 'cf_4532.bin' crc: 0xd28ef722
found (5) 'cg_4532.bin' crc: 0x2530f8ce
found (6) 'cb_5771.bin' crc: 0x859140f0
found (7) 'cd_8453.bin' crc: 0x25e0acd0
found (8) 'cf_16537.bin' crc: 0xd2f70347
found (9) 'cg_16537.bin' crc: 0xcf8a8c3c
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x340f017f
found (2) 'bootanim.xex' crc: 0x1a64dd1c
found (3) 'createprofile.xex' crc: 0xbb5dfa34
found (4) 'dash.xex' crc: 0x40671195
found (5) 'deviceselector.xex' crc: 0xf80b066f
found (6) 'gamerprofile.xex' crc: 0xb55d0d4f
found (7) 'hud.xex' crc: 0xd1e27e82
found (8) 'huduiskin.xex' crc: 0x98c75ba1
found (9) 'mfgbootlauncher.xex' crc: 0x773ee67d
found (10) 'minimediaplayer.xex' crc: 0x0411007d
found (11) 'nomni.xexp' crc: 0x323c6e47
found (12) 'nomnifwk.xexp' crc: 0xbe5a4208
found (13) 'nomnifwm.xexp' crc: 0xc9c3f0e0
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0x4dd243b2
found (16) 'updater.xex' crc: 0xe93cef2e
found (17) 'vk.xex' crc: 0xac383a80
found (18) 'xam.xex' crc: 0x18496d9a
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0xc558548c
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0x4da51d92
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: E:\X360\J-Runner\177381183505\updflash.bin
1BL RSA pub key file is not available, signature checks will not be performed
PIRS RSA pub key file is not available, signature checks will not be performed
MASTER RSA pub key file is not available, signature checks will not be performed
------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 1 decrypted ok LDV 0x0e Pairing: 0x223c11
setting LDV from image to 14
setting pairing data from image to 0x223c11
pairing set to: 22 3c 11
MobileB.dat found at page 0x7260, size 2048 (0x800) bytes
MobileC.dat found at page 0x7280, size 512 (0x200) bytes
MobileD.dat found at page 0x72a0, size 2048 (0x800) bytes
MobileE.dat found at page 0x72c0, size 2048 (0x800) bytes
Statistics.settings found at page 0x7bc0, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at page 0x72e0 raw offset 0xecee00
seeking security files...
crl.bin found in sector 0x38d size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x38e size 0xad30...verified! Will use if external file not found.
extended.bin found in sector 0x391 size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x392 size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image
------ loading system update container ------
16537\su20076000_00000000 found, loading...done!
Read 0xb34000 bytes to memory
checking integrity...
header seems valid, version 2.0.16537.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7a010 bytes)
decrypting SUPD\xboxupd.bin\CF_16537.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16537.bin (0x75aa2 bytes)...done!
------ Loading bootloaders and required security files ------
could not read 16537\bin\payload.bin, using built in payload (0x200 bytes)
reading data\SMC.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cb_5770.bin (0x8e40 bytes)
loaded cb_5770.bin, could not check signature rsa key not present!
reading .\common\cd_5770.bin (0x56c0 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\common\cf_4532.bin (0x44c0 bytes)
reading .\common\cg_4532.bin (0x2ef40 bytes)
extracted SUPD\xboxupd.bin\CF_16537.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16537.bin (0x75aa2 bytes)
could not read 16537\bin\freeboot.bin, using built in core (0xd40 bytes)
reading 16537\bin\patches_falcon.bin (0x9d4 bytes)
reading data\xell-2f.bin (0x40000 bytes)
reading .\common\cb_5771.bin (0x9340 bytes)
loaded cb_5771.bin, could not check signature rsa key not present!
reading .\common\cd_8453.bin (0x5780 bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80řC Gpu: 75řC Edram: 78řC
Max temps : Cpu: 100řC Gpu: 100řC Edram: 102řC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:86:db:67
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : UYDA
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cb_5770.bin, 1BL RSA key not present!
could not check signature of cb_5771.bin, 1BL RSA key not present!
done!
------ Patching boot reasons and options into flash header ------
Patching header for xell power reason
------ Encrypting and finalizing bootloaders ------
Fuse CPU Key set to: 0xEBAAF40C39E65F6EA2E018AD843575D5
Fuse CF LDV set to : 0xFFFFFFFFFFFFFF000000000000000000
encoding payload.bin size 0x200 (JTAG)
patching payload.bin to load size 0xd40 (0x350 reps)
encoding SMC.bin size 0x3000 (JTAG)
SMC checksum: a6ee8b80
unknown SMC found, type: Jasper v4.1(2.03)
jtag hack found in smc.bin!
******* WARNING: could not patch SMC reset limit!
encoding kv.bin size 0x4000 (JTAG)
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cb_5770.bin size 0x8e40 (JTAG)
CB 5770 seq 0x01050018 type: 0x01 cseq: 0x05 allow: 0x0018
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 0000F00000000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
encoding cd_5770.bin size 0x56c0 (JTAG)
encoding ce_1888.bin size 0x56070 (JTAG)
encoding cf_4532.bin size 0x44c0 (JTAG)
encoding cg_4532.bin size 0x2ef40 (JTAG)
encoding cf_16537.bin size 0x4560 (JTAG)
encoding cg_16537.bin size 0x75ab0 (JTAG)
encoding freeboot.bin size 0xd40 (JTAG)
patching freeboot.bin with with kernel version string '16537'
Boot options set:
- console DVD eject button is being used to start xell
- alternate xell button disabled
encoding patches_falcon.bin size 0x9d8 (JTAG)
encoding fuses.bin size 0x60 (JTAG)
encoding xell-2f.bin size 0x40000 (JTAG)
encoding cb_5771.bin size 0x9340 (JTAG)
CB 5771 seq 0x01070058 type: 0x01 cseq: 0x07 allow: 0x0058
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 000000F000000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
fuseset 02: 000000F000000000 (allow cseq 7)
CBENC pairing set to: 22 3c 11
encoding cd_8453.bin size 0x5780 (JTAG)
Virtual Fuses set to:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 000000F000000000
fuseset 03: EBAAF40C39E65F6E
fuseset 04: EBAAF40C39E65F6E
fuseset 05: A2E018AD843575D5
fuseset 06: A2E018AD843575D5
fuseset 07: FFFFFFFFFFFFFF00
fuseset 08: [URL="tel:0000000000000000"]0000000000000000[/URL]
fuseset 09: [URL="tel:0000000000000000"]0000000000000000[/URL]
fuseset 10: [URL="tel:0000000000000000"]0000000000000000[/URL]
fuseset 11: [URL="tel:0000000000000000"]0000000000000000[/URL]
done!
------ Adding bootloaders to flash image ------
adding payload.bin at raw offset 0x00000200 len 0x200 (end 0x400)
adding SMC.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cb_5770.bin at raw offset 0x00008000 len 0x8e40 (end 0x10e40)
adding cd_5770.bin at raw offset 0x00010e40 len 0x56c0 (end 0x16500)
adding ce_1888.bin at raw offset 0x00016500 len 0x56070 (end 0x6c570)
adding cf_4532.bin at raw offset 0x00070000 len 0x44c0 (end 0x744c0)
adding cg_4532.bin at raw offset 0x000744c0 len 0x2ef40 (end 0x80000, rest in fs)
adding cf_16537.bin at raw offset 0x00080000 len 0x4560 (end 0x84560)
adding cg_16537.bin at raw offset 0x00084560 len 0x75ab0 (end 0x90000, rest in fs)
adding freeboot.bin at raw offset 0x00090000 len 0xd40 (end 0x90d40)
adding patches_falcon.bin at raw offset 0x00091000 len 0x9d8 (end 0x919d8)
adding fuses.bin at raw offset 0x00095000 len 0x60 (end 0x95060)
adding xell-2f.bin at raw offset 0x00095060 len 0x40000 (end 0xd5060)
adding cb_5771.bin at raw offset 0x000d5060 len 0x9340 (end 0xde3a0)
adding cd_8453.bin at raw offset 0x000de3a0 len 0x5780 (end 0xe3b20)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xe4000 len 0x00023400 (end: 0x00107400)...done!
Writing target CG patch slot overflow data to sysupdate.xexp2
at raw offset 0xe4000 len 0x0006a010 (end: 0x0014e010)...done!
------ adding 25 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x340f017f ini: 0x340f017f)
adding as aac.xexp2 at raw offset 0x172010 len 0x00014000 (end 0x00186010)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x1a64dd1c ini: 0x1a64dd1c)
adding as bootanim.xex at raw offset 0x188000 len 0x00061000 (end 0x001e9000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0xbb5dfa34 ini: 0xbb5dfa34)
adding as createprofile.xex at raw offset 0x1e9000 len 0x0000c000 (end 0x001f5000)
extracted SUPD\dash.xex (0x597000 bytes) (crc32: 0x40671195 ini: 0x40671195)
adding as dash.xex at raw offset 0x1f8000 len 0x00597000 (end 0x0078f000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0xf80b066f ini: 0xf80b066f)
adding as deviceselector.xex at raw offset 0x78f000 len 0x0000a000 (end 0x00799000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xb55d0d4f ini: 0xb55d0d4f)
adding as gamerprofile.xex at raw offset 0x79a000 len 0x0001b000 (end 0x007b5000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xd1e27e82 ini: 0xd1e27e82)
adding as hud.xex at raw offset 0x7b7000 len 0x0001d000 (end 0x007d4000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x98c75ba1 ini: 0x98c75ba1)
adding as huduiskin.xex at raw offset 0x7d5000 len 0x00014000 (end 0x007e9000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x773ee67d ini: 0x773ee67d)
adding as mfgbootlauncher.xex at raw offset 0x7ec000 len 0x00008000 (end 0x007f4000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x0411007d ini: 0x0411007d)
adding as minimediaplayer.xex at raw offset 0x7f4000 len 0x0000c000 (end 0x00800000)
extracted SUPD\nomni.xexp (0xc800 bytes) (crc32: 0x323c6e47 ini: 0x323c6e47)
adding as nomni.xexp2 at raw offset 0x800000 len 0x0000c800 (end 0x0080c800)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0xbe5a4208 ini: 0xbe5a4208)
adding as nomnifwk.xexp2 at raw offset 0x80c800 len 0x00002000 (end 0x0080e800)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0xc9c3f0e0 ini: 0xc9c3f0e0)
adding as nomnifwm.xexp2 at raw offset 0x812000 len 0x00005000 (end 0x00817000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x819000 len 0x00006000 (end 0x0081f000)
extracted SUPD\signin.xex (0x19000 bytes) (crc32: 0x4dd243b2 ini: 0x4dd243b2)
adding as signin.xex at raw offset 0x822000 len 0x00019000 (end 0x0083b000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xe93cef2e ini: 0xe93cef2e)
adding as updater.xex at raw offset 0x83d000 len 0x00007000 (end 0x00844000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xac383a80 ini: 0xac383a80)
adding as vk.xex at raw offset 0x847000 len 0x0000b000 (end 0x00852000)
extracted SUPD\xam.xex (0x253000 bytes) (crc32: 0x18496d9a ini: 0x18496d9a)
adding as xam.xex at raw offset 0x853000 len 0x00253000 (end 0x00aa6000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xaa7000 len 0x0011b000 (end 0x00bc2000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp2 at raw offset 0xbc3000 len 0x00018000 (end 0x00bdb000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xbdc000 len 0x001a8000 (end 0x00d84000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp2 at raw offset 0xd84000 len 0x00007000 (end 0x00d8b000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0xc558548c ini: 0xc558548c)
adding as ximecore.xex at raw offset 0xd8b000 len 0x00017000 (end 0x00da2000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xda3000 len 0x00090000 (end 0x00e33000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0x4da51d92 ini: 0x4da51d92)
adding as ximedic.xexp2 at raw offset 0xe34000 len 0x00002800 (end 0x00e36800)
------ adding 4 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe38000 len 0x00000a00 (end 0x00e38a00)
<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe3c000 len 0x0000ad30 (end 0x00e46d30)
<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe48000 len 0x00004000 (end 0x00e4c000)
<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe4c000 len 0x00000400 (end 0x00e4c400)
------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe50000 len 0x800 (end 0xe50800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe54000 len 0x200 (end 0xe54200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe58000 len 0x800 (end 0xe58800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe5c000 len 0x800 (end 0xe5c800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)
------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400
------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe60000 len 0x4000 (end 0xe64000)...done!
calculating ECD bytes and assembling raw image...done!
done remapping!
------ writing image to disk ------
writing file 'E:\X360\J-Runner\177381183505\updflash.bin' to disk...done!
---------------------------------------------------------------
E:\X360\J-Runner\177381183505\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.16537.0
Console : Falcon
NAND size : 16MiB
Build : JTAG
Xell : power on console with console eject button
Serial : [URL="tel:177381183505"]177381183505[/URL]
ConsoleId : [URL="tel:022066532871"]022066532871[/URL]
MoboSerial: 757844D229618355
Mfg Date : 08/29/2008
CPU Key : EBAAF40C39E65F6EA2E018AD843575D5
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key : A0C96986290178E52C6247B37C0C2060
CF LDV : 14
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------

Images of close-up soldering to motherboard:

Description of problem:
XeLL boots fine, orig. NAND works fine, no RGH Dashboard.
Was the console working before you started: Y
UPDATE: Edited SMC Config and it works, but freezing.
Last edited: