28.09.2019
Posted by 
  1. Tevion Fta 2005 Software Update

JKEYS BY D2 This is the useful tool to programming our receivers. Download Jkeys and Jkeys definiation here from Sir Kevo's web JKEYS 2911026 (Jkeys.def (Regards.

Hi, I have an FTA Digital Receiver GS-1590 with a Fujitsu processor MB86H25A and a flash memory S29VL800BE. The receiver is frozen and I need to revive it. I have all the components to build a JTAG but I need the wiring connection to a 10 pin header. Also I need the proper Jkey software to access the receiver and open it up again. I would appreciate very much if you can help me in this respect.

Note The following table lists some devices which have been explicitely tested in our lab or by users of the software but in general Mobile DTV Viewer can be used with all DVB-T/-T2 RF receivers for which legacy BDA drivers are available. Most vendors already provide such drivers for their devices. Before we getting start, you have to down load all the software you will need and install them. Down load the file you need from below link, then create a folder, and save as any name you want ( I name my Pansat UtilitiesProgramming), then unzip the file into the same folder. Pansat FTA Loader: Get your PanSat loader here. Firmware upgrade for Tevion Televisions. If your set up menu does not look like the image below, do not install this firmware update. Note: You will need a USB.

Hi, I have an FTA Digital Receiver GS-1590 with a Fujitsu processor MB86H25A and a flash memory S29VL800BE. The receiver is frozen and I need to revive it.

I have all the components to build a JTAG but I need the wiring connection to a 10 pin header. Also I need the proper Jkey software to access the receiver and open it up again. I would appreciate very much if you can help me in this respect. Most Fujitsu chips can't JTag'ing but u can take out the flash to Stixxx base receivers and program ur flash.Then put it back to ur receiver and it'll work but this is the dangerous play for everyone. Otherwise, if u have a Labtool programmer then it's more easy to program. Hope it'll help u anyway. Its dagerous play.

You need to boot first else, dcupeek error. Hi, Thank you for your reply.

What is ' Stixxx'? I have a jkey very close to it but it asks me about hexadecimal. Input and I have no idea where to get it from and how to do it. I got from other forums flash dump files for the MB86H25A and the flash memory S29LV800BE, but i do not know how to use it or how to run it. Maybe my wiring is wrong.

Have you got any idea how to wire it. I followed the original wiring from the RS-232 conector at the back of the STB to the 10 pin header with a voltmeter and the sequence I am getting to the 10 pin header is 1,3,4,5 and 8. Does that make sense to you.

I have not tried it as yet. When you say to take the flash out and put it to a Stixxx receiver. Do you mean to unsolder it and resolder it to a different board belonging to a standard top box for a TV antenna digital receiver? If this is the case, how can I reprogram it? I am very handy with electrical wiring but not with electronic components and software. I need to know how step by step before I venture to do another mistake. I can see you are very well experienced with Jtagging and Jkeys and I am listening for your advice in this matter.

I appreciate very much your help in this matter. Hello everybody, I have an yumatu 800 reciever, i want to put keys for RTVi, how do i do it? Where i should go at the key editor? And how do i recognize the key line? (after intering the 9339.) pls give a link or explane. Most Fujitsu chips can't JTag'ing but u can take out the flash to Stixxx base receivers and program ur flash.Then put it back to ur receiver and it'll work but this is the dangerous play for everyone.

Otherwise, if u have a Labtool programmer then it's more easy to program. Hope it'll help u anyway.Hi, Thank you for your reply. What is ' Stixxx'? I have a jkey very close to it but it asks me about hexadecimal. Input and I have no idea where to get it from and how to do it.

I got from other forums flash dump files for the MB86H25A and the flash memory S29LV800BE, but i do not know how to use it or how to run it. Maybe my wiring is wrong.

Have you got any idea how to wire it. I followed the original wiring from the RS-232 conector at the back of the STB to the 10 pin header with a voltmeter and the sequence I am getting to the 10 pin header is 1,3,4,5 and 8. Does that make sense to you. I have not tried it as yet. When you say to take the flash out and put it to a Stixxx receiver. Do you mean to unsolder it and resolder it to a different board belonging to a standard top box for a TV antenna digital receiver? If this is the case, how can I reprogram it?

I am very handy with electrical wiring but not with electronic components and software. I need to know how step by step before I venture to do another mistake. I can see you are very well experienced with Jtagging and Jkeys and I am listening for your advice in this matter. I appreciate very much your help in this matter. Dear KO Yan Naing, I want to JTAG 29LV800 in Newshine.But Newshine receiver does not have 10 pin JTAG socket.That's why,may i know where can i buy a programmer in Myanmar? Where can i buy 'WILLEM EPROM 'programmer in Myanmar?

Thanks Regards. Most Fujitsu chips can't JTag'ing but u can take out the flash to Stixxx base receivers and program ur flash.Then put it back to ur receiver and it'll work but this is the dangerous play for everyone. Otherwise, if u have a Labtool programmer then it's more easy to program. Hope it'll help u anyway. Hi, Thank you for your reply.

What is ' Stixxx'? I have a jkey very close to it but it asks me about hexadecimal.

Input and I have no idea where to get it from and how to do it. I got from other forums flash dump files for the MB86H25A and the flash memory S29LV800BE, but i do not know how to use it or how to run it. Maybe my wiring is wrong.

Have you got any idea how to wire it. I followed the original wiring from the RS-232 conector at the back of the STB to the 10 pin header with a voltmeter and the sequence I am getting to the 10 pin header is 1,3,4,5 and 8. Does that make sense to you. I have not tried it as yet. When you say to take the flash out and put it to a Stixxx receiver. Do you mean to unsolder it and resolder it to a different board belonging to a standard top box for a TV antenna digital receiver?

If this is the case, how can I reprogram it? I am very handy with electrical wiring but not with electronic components and software. I need to know how step by step before I venture to do another mistake. I can see you are very well experienced with Jtagging and Jkeys and I am listening for your advice in this matter. I appreciate very much your help in this matter.

Regards I mean u should take out this flash and put it in Sti5518 CPU ( eg. Starsat, Viva, Metabox, etc. ) base receivers and reprogram with flash dump bcoz. Sti5518 CPU receivers can directly Jtag'ing through JTag dongle.After u finish successful program ur flash in Sti5518 CPU receiver, then put in again in ur receiver and it'll work. Hope it will help this time. Check 'How to unlock flash' on this thread and hope it'll solve ur problem.

Hi' yan naing I wonder if u can help me i have a wiztech 3010 with ERROR message E000 loader image invalid, i tried RS323 port but it won't detect STB,so i tried jtag with JKEYS and even that it won't detect tried WALLS and still the same i'm suspecting hardware and software LOCK.However before i start cuutting the STB tracks could you be kind enough to upload or email me JTAG TESTER also flash for STI5518bvc TE28F160c3 thx in advance mashe. Hi all, I hope someone can help. I have a Digifusion FVRT400 Freeview Digital Video Recorder in the UK, which uses an STi5514 chip. The company no longer support this model, so in the event of a flash failure on the box, it will be dead - on similar earlier released models users are able to reflash a bin file to the box via the RS232 port on the box, to repair a non working box. However these working bin files are not available for the FVRT400 (They were captured following an OTA update which is no longer sent). For info, The FVRT series can boot from either the flash or the HDD, and if one goes wrong the other can be used if present. The OTA update downloads a bin file to the HDD, which can then be extracted via software to the PC, and also reloaded to the HDD.

I would like to be able to READ the bin file that is stored on the flash chip of the FVRT400 box, such that I can get a working bin file in the event of box failure. I have no need to WRITE or REPROGRAM the flash via JTAG. All writing can be done via other methods - direct to the HDD or via RS232 to the flash The FVRT400 has a 20 pin JTAG header, and I have ordered a suitable cable (which has not yet arrived!). Details from the MB are: Omega STi5514AWD DOK LF 545004 MLT 22619 AT49BV162AT 70TU 0549 SAMSUNG K4S641632K-UC75 I was hoping to be able to use jkeys to READ this flash, then exit the programme without doing anything else to the flash - 1) is this possible? 2) Will just accessing the flash chip via jkeys make changes to the flash? 3) Will jkeys even work, as I guess there are no def files available for this box? - do you need def files to READ?

4) If I do manage to extract the bin file from the flash via jkeys - will this be in the same format as the bin file that I then load onto the HDD or via RS232? - Currently the bin file is 2229468 KB for the FVRT400 and 2218152 KB for the FVRT 150 (they have tweaked the FW on the FVRT400 hence the change in size), or will it need to be altered?

I was planning on testing the set up with an FVRT150, for which I do have a working bin file backed up, before playing with the FVRT400. Details for the FVRT150 are: (again it has a 20 pin header) Omega STi5514AWD-ES DOK LF 419062 MLT 22444 ST M29W160ET 70N6 GA0DXVS CHN 8B 436 SAMSUNG K4S641632H-TC75 New to this, so i hope some of you experts will be able to offer some advice! Thanks for the reply. Thanks again for the reply! // AT 49BV162AT - from Flash, 32, 'AT49BV162AT', 0xC0, 0x200000, 1, 1, 0, 1, 39, 0 Sector, 32, 31,0x0, 0x10000 // 64 KByte 31 sectors Sector, 32, 8, 0x1F0000, 0X2000 // 8 KByte 8 sectors // AT 49BV162AT - by oxygen007m Flash, 71, 'AT49BV162AT', 0xC2, 0x200000, 1, 1, 0, 1, 39, 1 Sector, 71, 31, 0x00000, 0x10000 Sector, 71, 8, 0x1F0000, 0x2000 I found the first one via google, and it sems slightly different to the second one which you posted - any ideas why, or which is likely to be the better file to use? I assume I just copy and paste one of these into the jkeys def file, like I did for the STi5514 chip, plus the manufacturer code bit at the bottom? The IRD in the def file currently that matches the M29W160 seems to list 2 flashes - I don't know if my box has 2 flashes - I don't think so.

Would I still select this IRD 9? I am newbie in this forum. I have a receiver but without IRD and Boxkey.

2005

I have made a simple and a buffer jtag. However, I still cannot get the IRD and Boxkey.

I use JTAG Version: 2.9.11.026 Model: QCR1032 CPU: STi5518BVC Flash: ST M29W320ODT Eprom: 24C128N When I jtag it, the jtag program find 'STi5518BMV-X', there is a little bit different from the CPU inside (STi5518BVC), However, the progrom does not find match ID model (model unknow), I can only try all the models provided in the jtag program, the result is negative. I can dump file using the jtag program and save it up. I want to read IRD and Boxkey from the dump file, However, I do not know the absolute starting address of the flash (I know it is 4M byte flash). Anyone know what is the absolute address of the IRD and Boxkey for the receicve, are all the models with the same address. I find some information on web that as follows but still not know how to modify the jtag.def, I have tried, but not works (same result as before). IRD, 20, '301-013', 8, 3, 1, 1, 2, 2, 0x7FFFFF40, 0x7FFFFF44, 0x7FFFBFE0, 0x7FFFFFA8, 0x7FFDFFF4, 0x7FFDFFF8, '10E', 3, 4 IRDFlash, 20, 'Flash 1(U12-M29W320DT)', 0x22CA, 0x7FC00000, 0x400000, 2, 2, 0 // STMicro M29W320DT - 32MBit Flash, 15, 'M29W320DT', 0x22CA, 0x400000, 1, 1, 0, 1, 67, 1 Sector, 15, 63,0x0, 0x10000 // 64 KByte 63 sectors Sector, 15, 1, 0x3F0000, 0x8000 // 32 KByte Sector, 15, 1, 0x3F8000, 0x2000 // 8 KByte Sector, 15, 1, 0x3FA000, 0x2000 // 8 KByte Sector, 15, 1, 0x3FC000, 0x4000 // 16 KByte - Thank your!!! Reciver is klone Dragon s 1200.

What cable are you using for dragon s1200 flash dump? My dragon s1200 stopped on 'boot' and there is no success further. What program are you using for flashing? Can you give me much informations how to work on Dragon-SHADOW s 1200? Thanks:punk: System Resources - CPU: IBM Vulcan - Flash Memory: 2MB - E2PROM: 24C16 - SDRAM for MPEG: 16MB. FOR EMETABOX Metabox I TE28F160C3 (Metabox II 29LV160ATTC (Metabox III 29LV160ATTC (Metabox 10 TE28F160C3 (Metabox 10 29LV160 (Hi yan Do you have for Zenega 1004iS? If yes please post it.

Secondly- Iwant to change the STB for Dish TV in India to FTA Channels whether I hv to chane any chips or Firmware & progamming will serve the purpose? Master, I desperatly need your help. I read as much as I could your adveices but I couldn´t fix it. It´s Kaon KSC 570 12.c1.a5, without socket for jtag so. I did your unbuffered cable for jtag with resistors and tried to fix my box. Processor: STI5518 Flash: M29W160ET JKEYS found my Kaon 2 MB (IRD model) - everything ok until now.

Development panel: 2000E020 with Data: 01 (I haven´t tried to ground during flashing BFR - pin 115 until now - I´ll do it as soon as you´ll think I´ll not damage the processor) Flash programming went 'just fine' - it was erasing and writing (programming). BUT, after restarting the box it is like nothing happening - no change - same blue TV screen and same black display-box.

What should I do, Master Yan? I have an opentel ODS 3000. It has a SST39VF1601 Flash Chip and DCU OMEGA STI5518BQC. I connect my JTAGand i try it. I use JKeys unlock. I detect the IRD ST 5518 QVC and then flash programming- ok. I select Read memory flash -ok and i save it in my documents.

And then 'Earse' -ok. When i try programming 'error programming flash at offset 0x7fe00000' appears. I get off my reciever and i get on later after some minutes and in 'reciever's display' is shown onlY - or -.

When i do dedect is shown DCU Peek. I have saved old flash file before earsing and programming. I tryed the Development Panel to lock hardware and software but it doesn't open. I can't understand where the problem stands.

Would you try just to help me in resolving this problem? I have a smart receiver with the same data but i'm afraid i can damege it.

I'm wanting for your answer. Hello all, I'm also working on a new STB with STx5105.

I'm stucked in the corner with the STx5105 Power on Reset vector. I've dumped the flash of that STB (rebadged from a Jiuzhou dts1601 STB STI5105) and I cannot find any Reset vector/jump @ 0x7FFFFFFEh. From a post on another web site (ftatalk), I see that the FLASH BASE is @ 0x40000000h which was the address that I've used for the JTAG dump. FLASHBASE = (0x40000000) memory FLASH (FLASHBASE) (FLASHPSIZE) ROM ## memory STEM0 0x41000000 (32.MB) DEVICE ## memory STEM1 0x43000000 (32.MB) DEVICE memory STFMICI 0x7F400000 (4.MB) DEVICE memory STFMIC 0x7F800000 (2.MB) DEVICE memory STFMID 0x7FC00000 (2.MB) DEVICE bootiptr (addressof -q FLASH) On the last line there is: bootiptr (addressof -q FLASH) Does that mean that this processor starts from 40000000h i.o 7FFFFFFEh? My binary dump should be OK as it looks very similar to a Goldvision Magic STB dump with the same processor and the same amount of flash mem (2 Mb).

Thanks for your help. I have a UEC DSD720i receiver originally from South Africa.

Tevion Fta 2005 Software Update

It was used in Australia, where it packed up. The suspicion is that this happened due to receiving over air updates. It has a known working PSU, but the large upd61030 chip has no clocking on external bus lines. Could be in permanent reset. The leds in front may occasionally latch on when powered up. Could it be the flash memory that is lost and if so, could using jtag sort the problem.

Further I am looking for the circuitdiagram of this box as well as the datasheet for NEC uPD61030 mpeg chip. I loaded another boot file and this time 'on and strt' did appear on the front panel but as soon as i removed the jtag cable and then powered up the stb there's nothing on front display???

When using the jkey program is it necessary to use the correct ird model? I've read somewhere that for metabox 3 you have to use 4900? Is this correct? I re-tried the same file but this time after i loaded the flash and exited jkeys and wall, i pressed and held the standby button at the front of receiver and 'strt' appeard and then it went to the clock digits, i pressed it again and NOcha appeared on display but as soon as i power the machine off to do factory reset the machine nothing appears on the front panel.

These Space Marines are all (beings who possess psychic powers) and are dedicated to the extermination of Chaos and its minions. Adeptus astartes codex pdf. • Grey Knights, the Chamber Militant of the Ordo Malleus (Daemon Hunters) of the Inquisition.

Im getting there??? I loaded another boot file and this time 'on and strt' did appear on the front panel but as soon as i removed the jtag cable and then powered up the stb there's nothing on front display??? When using the jkey program is it necessary to use the correct ird model? I've read somewhere that for metabox 3 you have to use 4900? Is this correct? As u said, u flash rom has some problems but don't worry u can do it with JTag.But u need to patient.

Only u need to match with the right dump file I'll upload it later today when I get free time.Try them and ur receiver will working back to normal when u got the right one.Then keep that dump in the safe place. Yes u can use IRD 4900 or 4700 no problem.

To yan naing or any other genius. My box is an old uec 720i.

Uses NEC upd6130 main chip and 29dl323bd flash. I found a reset chip faulty and fixed that which brought machine to life. However after leaving it running it started half booting up showing led activity, and now the micro is active for about a sec (examining with a 100mhz scope, and stops so nothing shows on panel. I can't get any info on the upd6130/5, but it seems to have a so-called n-wire connection to a 10 pin header.

I got some data from a upd61051. 1.10 N-Wire IE Port for firmware of Internal CPU evaluation When not connecting an in-circuit emulator, take countermeasures against noise by pulling up the NDI pin to avoid the pin becoming low level.

NMOD I 178 Pin used when connecting IE Pull up when connecting IE H NCLK I 174 Serial clock ↑ NRST I 176 N-wire reset L NDI I 179 Data input NDO O 180 Data output Ok, my question is whether this may be a JTAG implementation? I have another identical working box, so I'd want to read from the good one and write to the bad. Also anyone got a datasheet on the upd61030/5, pretty please. I loaded another boot file and this time 'on and strt' did appear on the front panel but as soon as i removed the jtag cable and then powered up the stb there's nothing on front display??? When using the jkey program is it necessary to use the correct ird model? I've read somewhere that for metabox 3 you have to use 4900?

Is this correct? HERE IS YOUR ANSWER, MOSAT: Try to verify the POWER SOURCE OF YOUR RECEIVER!!!!

If the receiver display is black and tv screen is blue (or not), jtag it´s workind but it´s blocking and you have to use wall.exe to 'trap', then the problem is your POWER SOURCE of your receiver! There are some condensators on that board witch witch are blowing away, even if they are looking like normal ones!!!

Check them all or, in the case you have not the possibility to measure them, replace them all. If the source board is SSV6025A Rev 3.0, then, most likely, C118 and C121 must be replaced. When it is happening that the source is getting old, receiver instability, frames, a blocking image from time to time, you can not rewrite flash with null-modem cable every time you want and, the most important, signal loss. After fixing your power source, take care! - there is no sign of recovering your receiver immediatly - I mean, you have black receiver display and blue TV screen! - You have to reprogramm with jtag before recover your receiver!

In summary: 1. Change all condensators on power board. Reprogram with jtag. Good luck MOSAT! HERE IS YOUR ANSWER, MOSAT: Try to verify the POWER SOURCE OF YOUR RECEIVER!!!! If the receiver display is black and tv screen is blue (or not), jtag it´s workind but it´s blocking and you have to use wall.exe to 'trap', then the problem is your POWER SOURCE of your receiver! There are some condensators on that board witch witch are blowing away, even if they are looking like normal ones!!!

Check them all or, in the case you have not the possibility to measure them, replace them all. If the source board is SSV6025A Rev 3.0, then, most likely, C118 and C121 must be replaced. When it is happening that the source is getting old, receiver instability, frames, a blocking image from time to time, you can not rewrite flash with null-modem cable every time you want and, the most important, signal loss. After fixing your power source, take care! - there is no sign of recovering your receiver immediatly - I mean, you have black receiver display and blue TV screen!

- You have to reprogramm with jtag before recover your receiver! In summary: 1. Change all condensators on power board. Reprogram with jtag. Good luck MOSAT! Thanks I will give my stb for repair to a electronic expert.

Dear Everyone, I have a receiver SNA-951 could anybody please give me the steps/procedure how to JTAG on it, the program need to use and the code to load in the ROM. Is it possible to JTAG it through RS-232?

It has a RS-232 at the back panel on it. If not possible, please give the pin connection of 10-pin JTAG. What type of cable connector or programmer do i need to use on it? What program/software do i need to run to reprogram its ROM? Please help me. For anyone who knows ho to do this, please help me.

Thank you in advance. Here is the photo of my receiver. Can anyone help me find the jtag pads on a motorola 6412 ph2 board it is using broadcom i have plenty of pics of the board. The only help i been able to get is from a forum this is what was said 'I did make the Jfinder with USB JTAG NT hardware. Basically it can brute force the pins and find what is TDI and TDO TMD and TCK.

It is harder to use printer port to do the same job as the input in is not as easy to switch. But my tool is still very limited as I can only scan 5 pins. I know someone had created tool that can scan 32 pins.' 'HOW TO UNLOCK BOTH HARDWARE AND SOFTWARE LOCK FLASH' Intel: TE28F400C3, 28F800C3, 28F160C3, 28F320C3 ST: M28W800CB, M28W800CT, M28W160CB, M28W160CT PROCEDURE same as above until step 8 9. This step sends a command to the processor (Omega) chip to make it cooperate with us and enable flashing. Click 'Development Panel' and Ignore the instructions in the box and click OK. On the left side of 'Development Panel' enter Address: 2000E020 (all ‘0’s are zeros) Data: 01 then Click on 'Write Byte' 11.

This step “unlocks” the special locking feature of the Listed flash chips. For example if you want to unlock sector 0 SA0 At the address 7FE00000 you must do the following steps: With the Development Panel still open enter: Address: 7FE00000 (all ‘0’s are zeros) Data: 60 (six-zero) Click Write Byte Data: D0 (‘D’-zero) Click Write Byte Data: FF Click Write Byte now SA0 unlocked if you need to unlock all sectors you must repeat Step 11 for each sector with its Starting address. 12.Close Development Panel 13.Click 'Flash programming' and complete the other steps. Don't forget to Reset factory. Hi i have a STi5119ALC processor and a 39vf3201 flash chip and i understand the hardware unlock but not software unlock for this flash. The SST39VF1601/3201/6401 support bottom hardware block protection, which protects the bottom 32 KWord block of the device. Bottom Boot Block SST39VF1601/3201/6401 000000H-007FFFH this flash is software protected anyway??????

If yes, the values to use with 'Development Panel'?????????? I need some help. I have an Skymaster DCX 10 with 5518 CPU and ST M29W160EB flash. I try to jtag with patched strong fw but its always stoped with offset error. After i heard from somebody that use the sector clear and sector programming in jkeys. This is really working except one sector i could program every sector and my receiver show me some life.

(On self screen 8:8. And change my tv to av (but there is dont show nothing)). The one sector when i try to erase or program always get error. I this sector is: 27-M29W160DT - Flash 1(M29W160DT) - SA5 (7FC20000 - 7FC30000).bin If any body have any idea pls tell me! Byez Janaboy. Hi Yan and everyone, I found out on this board i can´t Jtag these receivers because they use fujitsu mb86h25b chips.

(got lasat built V901 FUSMP V1.5 board). Now the fact is, some guys around here set up their 'own little re-broadcasting system, (not legal anyway in our country)', and they 'scramble' the signal, and descramble? Using exact these boxes but i assume they flashed those boxes because on those manipulated boxes u cannot go into the installers menu at all., there´s no CI slot or anything, and since i´ve got about 20 of them lying around and i have got 3 manipulated boxes so i thought of extracting the flash file and programming the virgin ones with that bin file.I cant use Jtag as explained by Yan naing to extract that flash. Another important thing is that those boxes are Identical, there is NO sign of the flash been removed and put back again.How can I find out?? If only I could decompile that bin like with a st20 family box. Now i ask another question, is it possible they flashed that box with an encryption procedure, can it be a constant control word they put in because i cant see they can rewrite the flash with a let's say conax encryption routine.) (they say conax but i dont believe it for that reason). I like to be able to have more insight in this box, is anyone out there who could teach me a bit more about the possibilities of that box, so I can give my friends and family some TV without them having to pay their hard earned money to those ripoff people.

Anybody here knows more about these boxes and their possibility? Many times thanx to the experts here!! Well,no, i´m in cyprus @ the moment brother.

I guess from your reply there is similar situation in spain? Have u more knowledge about this system? I already managed to get serial link with terminal into management mode for virgin box,can access bootloader and management menu from there;but cant get into modified one yet. I guess i have to unsolder the modified flash and have a look with protool programmer. I know the fujitsu chip has got embedded CI support but i still wonder because there is no CI connected, and a softCAM implementation in that flash seems too far fetched.

Just a nice project to keep old brain from dying;) If anyone out there has more suggestions feel free to give opinion!! The sti5119 requires a dcu3 capable jtag program,so jkeys is useless unless you are just dumping the flash. The sti5519 is older and totally different. The sst39vf3201 has a bootsector protect capability. This is a resistor installed on the mainboard going to pin 14 of the flash chip.

There is no dcu3 jtag program available at this time. Hi slugworth, i'm reading your posts around the forums, here, on fta, usbjtag etc. And i have a question what you think, how many time we all need to wait for a dcu3 capable jtag program?months. I can dump the flash but have not a flash file. Exsist any possibility to save the full flash of these receivers using jtag? Thanks in advance. What you think, how many time we all need to wait for a dcu3 capable jtag program?months.

I believe the biggest deterrent is people out there don't want you to clone receivers. Jkeys for sti5518 was originally for north american echostar receivers and people just modified the.def files to do fta receivers.The closest I've seen for dcu3 was a program that was for the sti5514 based pace3100.It was a condensed version of st20 toolkit with.lku files written especially for the pace3100.You may never see a dcu3 jtag program that will do all dcu3 based receivers,you may see a program that works along with st20 toolkit for a specific receiver if some generous coder comes up with one. The sti5119 requires a dcu3 capable jtag program,so jkeys is useless unless you are just dumping the flash. The sti5519 is older and totally different. The sst39vf3201 has a bootsector protect capability. This is a resistor installed on the mainboard going to pin 14 of the flash chip. There is no dcu3 jtag program available at this time.

Thanks, excellent as always in the replies. Then the only way is to unplug the flash and use a flash programmer to read it, and then write receivers using jkeys. This is not tested by me, but I think that works. Read with jkeys but there is no way to write.

Most flash nowadays is surface mount soldered,not an easy task unless you are experienced and have a hot air desoldering station. If you want to see what a dcu3 jtag for sti5514 looks like,scour the earth for a file called pvr2flash.rar I don't understand the diference between 'dump' and 'write'.:confused: I want to save the flash and put it to an other receiver. (ODS2000C to ODS2000C) How can I make it??!!??!! Jtag jkeys, flash programmer, or I can't do nothing???!!! Soldering, desoldering - there is no problem, one of my friends do it for me.

Thanks in advance mr. Slugworth Mr. Yan what do you think, can you help me? Regards, AlexTrask. The receiver is an OPENTEL ODS2000C (Conax CAS Embedded) 1 Processor STi5119ALC 1 Flash SST 39VF3201 On the mother board is written ODS1500C Ver1.0 but the receiver is an ODS2000C:bored: That is strange,the only upgrade firmware I could find on the net for the ods2000ci/civ/cip was for a 1meg flash receiver and the upgrade firmware had the.pgm filetype.Where did you get the usual upgrade firmware from? At least you have a jtag port,I would solder in the 100ohm resistors and get a dump at least.Thats a 4meg flash chip,so it will be a 4meg dump.

That is strange,the only upgrade firmware I could find on the net for the ods2000ci/civ/cip was for a 1meg flash receiver and the upgrade firmware had the.pgm filetype.Where did you get the usual upgrade firmware from? At least you have a jtag port,I would solder in the 100ohm resistors and get a dump at least.Thats a 4meg flash chip,so it will be a 4meg dump. Upgrade via satellite ('DigitAlb' on Eutelsat W2) If I try to reinstall her firmware 'main.pgm' extracted with ODSLoader (via RS232)give me 'FAIL':dontgetit: My jtag here full size (here full size (How can i get a dump?. Using jkeys with this jtag? Is that an eeprom next to the flash chip?(8pin chip) If a 24c64 or 24c128 or 24c256 that may be a factor if you try to clone the receiver.

I have no idea what is that chip. I use the simple jtag like in the poster befores' picture.

If you use a jtag with a ribbon cable you need somebody to solder in pins on the mainboard for the jtag connector. I couldn't find any upgrade firmware for the osd2000 sti5119 based. Eeprom is an 8pin chip that saves user settings and keys. The 8pin chip is an eeprom 24LC64 Trying to save the flash using the buffered jtag: 1-Jtag connected and receiver powered on 2-Opened wall.exe and RessetUp three times and leaved open. 3-Opened jkeys, but 'Device ID' = 0x00000000 Added a wire +3.3v to pin14 of the flash and repeat three steps. Here the 'story' changed. Now 'Device ID'=0x1E827041 On repeating the three steps, the 'Device ID' change all times, not in 0x0000000 or 0xFFFFFFFF but in 0x(different numbers and letters):dontgetit::dontgetit::dontgetit::2guns::idea: Give me some hope slugworth Thank you.

Upgrade via satellite ('DigitAlb' on Eutelsat W2) If I try to reinstall her firmware 'main.pgm' extracted with ODSLoader (via RS232)give me 'FAIL':dontgetit: So you are saying the receiver took an upgrade off the sat and now you can't downgrade via serial port? That is why I was asking about the eeprom,the rev may be stored in that and the firmware won't let you downgrade.This is just a guess since I don't have that type receiver.The eeprom can be erased or programmed a lot easier than the flash. So you are saying the receiver took an upgrade off the sat and now you can't downgrade via serial port? That is why I was asking about the eeprom,the rev may be stored in that and the firmware won't let you downgrade.This is just a guess since I don't have that type receiver.The eeprom can be erased or programmed a lot easier than the flash.

Yes, but anyway it is not a solution because i want to install a firmware that permit to add TP manually, not only the frequencies that DigitAlb wants I'm not so good at file modifying.:nono: If someone can modify the original main file, unlocking 'Add TP Manually' and -As you say,- 'The 0123 on the second line- firmware rev? Might be edited to fool the receiver into thinking it is getting an upgrade when it is actually getting a downgrade.' Done so, we do not need to touch the eeprom. The situation: ABOUT Digitalb (package on Eutelsat W2) Digitalb sell receivers without any contract and without tell people about limitations or about release upgrades via satellite with limitations. When I bought the receiver (ODS3000C) it was without limitations but after a few upgrades via satellite it became with limitations. The solution for ODS3000C was a backup of (main.pgm) an earlier firmware version (1.22 wich was without limitations) modifying only the line wich determines the version making it higher.

OR Using jtag to write a dump file of version 1.22 (ODS3000C is STI5518BCQ and SST39VF1601 based) ABOUT ODS2000C I'm not an user of this receiver but a lot of albanians and many of my friends have it, so I and other fiends are trying with your help slugworth, to do something. The people want only to ADD and MODIFY the frequencies, nothing else (I don't understand how DigitAlb can do that, it would be fined) I coudn't find the micro definitions for a STi5119 As you say 0xD427041 is the id for a STi5105.

Every your ideas are welcome Regards, AlexTrask. Jkeys should detect the sti5119 as unknown,but will give you the micro id.You then edit the jkeys def and add that micro to the list.I would then use the skyview.def settings to get the flash address and size.

IRD, 24, 'SkyView 1000', 15, 1, 1, 1, 2, 2, 0, 0, 0, 0,0x40010151, 0, 'BA-', 3, 4 IRDFlash, 24, 'Flash 1(SST39VF3201)', 0x235B, 0x40000000, 0x400000, 2, 2, 0you would have to select the model id manually in jkeys after the.def file is edited. Device ID STi5119 detected but 'Save Mem' get error reading memory!!! Maybe 'SkyView 1000' isn't the right IRD Model!?!?!? The sti5105 uses address 40000000 for the flash,so your ird1 line 2 and line 3 are garbage. You can manually select an address in jkeys to read,if you doubt the address.Take small dumps,like 64k until you get a correct reading.Jkeys should detect the micro id every time. Sti5105 and sti5119 firmware always starts with hex 20 20 20 24 and the first chunk of flash should be the bootstrap.0x7FE00000 is not the correct address for a 4meg flash.It would have to be 0x7FC00000 if it were like a sti55xx based receiver. Here is an example of one line in flash.def.

0x0001,0x22F9,AMD 29lv320DB,0x400000,0,8,0x2000,63,0x10000 If you have new flash you need to add this is the format. A and B is manufacture ID and device ID. These two values can be read after flshdct and can not be recognized. C is the name on the flash. Just read the flash and any string is fine. D is the size of flash.

0x200000 is for 2M flash. Normally like 29XX160YY or 28XX160XX. E =0 uses AMD protocol. E=1 use Intel protocol. E=2 use SST protocol(non other value are valid at this time). The following is the definition of the sectors.

In this example. First 8 sector has the size of 0x2000. The rest 63 sectors have each sector 0x10000. Add the total sectors together should equal to D. If the flash support page program mode (this step is optional and only work for Intel now,it might speed up the programming.) you can add ',page size'. Here is the example with page program mode and each page is 32 bytes.

0x0089,0x0017,Intel 28F640J3,0x800000,1,64,0x20000,32. Dear ko yan naing! I'm very very thank to you for your reply to me. I'm a beginner of your jtag section. I very interested in satellite receiver software and jtagging it.

Please let me give the SuperDyna loader, Innovia 3088CA & Newstar receiver loader and Some of smart card softwares. I have the software of victory 80818 software and NewB630 firmware. How I send it to you? Please give me all my request at Because your download link is hard to download for me. Please kind to me. I'll be waiting your reply. Forgive my poor in saying English.:naughty.

Here is an example of one line in flash.def. 0x0001,0x22F9,AMD 29lv320DB,0x400000,0,8,0x2000,63,0x10000 If you have new flash you need to add this is the format. A and B is manufacture ID and device ID. These two values can be read after flshdct and can not be recognized. C is the name on the flash. Just read the flash and any string is fine.

D is the size of flash. 0x200000 is for 2M flash. Normally like 29XX160YY or 28XX160XX.

E =0 uses AMD protocol. E=1 use Intel protocol. E=2 use SST protocol(non other value are valid at this time). The following is the definition of the sectors. In this example. First 8 sector has the size of 0x2000.

The rest 63 sectors have each sector 0x10000. Add the total sectors together should equal to D. If the flash support page program mode (this step is optional and only work for Intel now,it might speed up the programming.) you can add ',page size'. Here is the example with page program mode and each page is 32 bytes. 0x0089,0x0017,Intel 28F640J3,0x800000,1,64,0x20000,32 Hi yang naing, let me ask: What program uses flash.def Following your instruction, I have made this definition 0xBF, 0x235B, SST 39VF3201, 0x400000, 2, 1024, 0x?

I know that each sector is 4KByte but i can not calculate it for that stringI'm using Jkeys on STi5119 and SST39VF3201. Thank you for the instructions.

I really need a litlle help i got a BALMET bt 9520-s Device Id: 0x1D405041 Device: STi5518MVB-X whit the jkeys i dont get the ird model when i open flash programming IRD Model: unknown Flash: User Specified Flash info: - Part: TE28F160C3B - Manufacturer: Intel - MFG/Device: 89/88C3 - Base Address: 7FF80000 the problem is. When i hit the erase button i got an error: Error detected erasing sector when i hit Program button i got errors: - Flash selected is not curently Blank.

Continue anyway? (i hit yes) than i chose a firmware upload block at 98% and hit me whit another erorr: Error programming flash at offset 0x7ff80000 i have tried to upload by sector i got sector they let me upload and others not i really dont know what to do i past mi last 2weeks searching on forums and google but steel nothing for balmet i see on this forum this error but not for balmet in mi jkeys i dont have ird model balmet so pls can u advice me:death. Greetings to all of the RDI forum, for `educational` reasons, we have been trying to hack a router known as the BT home hub v1.0, the processor is a MIPS32 BCM6348, with a spansion S29GL064A, through research we discovered it infact runs linux, the reason we ask about this here is becouse we have intrest in using NewCS and/or a B2C2 device off the USB that is on this router sofar the only sucess we've had is deleteing root, writing back to it seems to be problematic, any advise and does Jkeys support mips32 processors? Hi, this is my first post although been reading for quite a while. I find it impossible to gather any information on the STi7100. This is used in the Fortec HD receivers (amongst many others i know).

I'm using a buffered jtag interface and to see if was working used jtag on a pace 3100. Of course it didn't recognise the box but would the id 0x3D40A041 be correct for a STI5514SWC. I tried it on a Fortec Passion+ which has a 20 pin header, i presume it's for JTAG! Using the pins: 9 -TMS 11-TCK 13-TDI 19-TRST 20-GROUND There didn't seem to be any coms happening,maybe the wrong pins but i cannot find the pinout for the STi7100.

I can remove the chip if need be to trace the lines but without the pinout i'm lost. Anyone any ideas. Thanks, brilliant.

Now as i understand from reading this forum and i have to say from the forums i've been involved, i prefer this one, modification of the ST20 files from pvr2 (Pace 3100) is neccessary. I don't know how to do this but will try to learn. Actually,the sti7100 is an st40 based processor,so pvr2flash won't do you any good. That was based on the older st20 processors. I don't know if the st40 has a toolset like the st20 does.

I don't know how jkeys will react to a st40 based receiver,since I don't have one. Im looking for anyone that might be able to help me source copies of the register manual or chip manual for the STi5100 chips. Currently working on software that will run on the Ipro2000 units and have been able to build all the burner files using the 2.3.1 toolset, ive dumped the existing firmware and am in the middle of disassembling it and things would be much quicker and easier if i had the specific documentation for the chip.

Any pointers to the right direction to find the docs would be appreciated. Dear frineds,I made the programming of these two types of devices with jtag interface,Dump SR-X 650CI-Super - (Flash 1M29LV160ET) - Full.

The both device working fine,but after that i cant update any kind of software via rs-port 232. Starsat 650 super cl do not comunicate nowise with my pc. In starsat 650 ultra when i press prg-SimpleUpload2M,apears waiting boob i klik ok then apears to display Load 0% and noway does not go further, after this,device runs on ristart.

2005

Are there any way how to resolve this problem? Thanks for any reply and sory for my English. When something went wrong with transfering the software to my Metabox 1, I usually simply did the flash transfer with Jkeys and then MTG-10 transfer with FileSend utility.

That was my usual rescue routine with the same flash file (for M29W160ET) and it worked every time. I was away from house for some time and when I returned the Metabox didn't work. So I went and did the usual rescue routine, but now it's not working, it's stuck on 'ON' and after pressing the button on the front panel it's stuck on 'Strt'.

What might be the problem, hardware or software? Is there some internal clock lock software code in some flash files or MTG,Dreamsoft.? Hi all, This looks like an excellent place to find some answers. I have been trying to read the flash on my Coship CDVBS5110D for days now.

The CDVB5110 has a LSILogic SC2015 or SC2005 which is the same as SC2000? It also has a single flash which is a S29AL016M90TAI02. This is a 2MB with bottom boot sector I have built the 16pin JTAG and I do get the CPU ID is correct SC2000.

That's all I can get, nothing more. I have added the flash to the jkeys.def as: Flash, 24, 'S29AL016M', 0x2249, 0x200000, 1, 1, 0, 1, 35, 1 Sector, 24, 1, 0, 0x4000 Sector, 24, 1, 0x4000, 0x2000 Sector, 24, 1, 0x6000, 0x2000 Sector, 24, 1, 0x8000, 0x8000 Sector, 24, 31,0x10000, 0x10000 which i derived from the datasheet for the flash. I have also added the IRD as follows: IRD, 24, 'CDVB5110D', 11, 2, 1, 2, 2, 2, 0x1FC0FFF0, 0x1FC0FFF4, 0x1FC0FFC0, 0x1FC0FFC8, 0x1FFEFFF4, 0x1FFEFFF8, 'XXX', 0, 3 IRDFlash, 24, 'Flash 1(S29AL016M)', 0x2249, 0x7FE00000, 0x200000, 2, 2, 0 which is associated to micro: // LSI Micros // Micro, 11, 2, 'LSI SC2000',0x400006d,0xfffffff what I dont understand is the J-O of the IRD. I don't think they are correct as the flash is a bottom boot not a top boot or uni so J.

0x1FC0FFF0 - Absolute memory address of IRD number. 0x1FC0FFF4 - Absolute memory address of Box Keys. 0x1FC0FFC0 - Absolute memory address of Boot Strap. 0x1FC0FFC8 - Absolute memory address of Build Configuration. 0x1FFEFFF4 - Absolute memory address of Model ID O.

0x1FFEFFF8 - Absolute memory address of Flash. I believe are incorrect.

I'm also not sure if the 2249 adress of the flash ID register is correct as I see many STB's use fake addresses. Can anyone please help with this?:lookaround: Regards, MM. What I dont understand is the J-O of the IRD. I don't think they are correct as the flash is a bottom boot not a top boot or uni so J.

0x1FC0FFF0 - Absolute memory address of IRD number. 0x1FC0FFF4 - Absolute memory address of Box Keys. 0x1FC0FFC0 - Absolute memory address of Boot Strap. 0x1FC0FFC8 - Absolute memory address of Build Configuration.

0x1FFEFFF4 - Absolute memory address of Model ID O. 0x1FFEFFF8 - Absolute memory address of Flash. I believe are incorrect. I'm also not sure if the 2249 address of the flash ID register is correct as I see many STB's use fake addresses. Jkeys was originally for dishnetwork echostar receivers,so those settings are useless anyway. They show a span that covers 4meg, which is wrong.The 7fe00000 address is probably wrong also.You are better off with a jtag program for the sc2005 if there is one.Wall was for the echostar receivers with the sc2000 but I have never used it.

For sti5xxx processors the first step is getting the processor id into the def file. Then adding the flash type/size to the def file if it isn't in there already.

The tricky part is then finding the correct flash address for your receiver. You can start dumping small dumps at the usual addresses; like 7FC00000 or 7FE00000 or in the case of sti51xx receivers 40000000.That part can be misleading,because you may see a mirror image of flash at the wrong address- like in the case of the sti51xx the flash is at 40000000 but you will see an identical dump at address 70000000 but that address isn't flash but is actually ram.The eeprom can't be accessed directly so that isn't a factor.Don't forget,jkeys was originally written 8 years ago- a lifetime in fta years.

The ID Codes are used to identify the associated processor. The following shows the definition for the STi5500.

Micro, 1, 1, 'STi5500', 0xd4c9041, 0xfffffff Where: Micro - indicates the line contains microprocessor ID information 1 - is an index number used for cross referencing 1 - JTAG device 1 - for JTAG and STiXX00 (STi based micro) 2 - for EJTAG and LSI SC2000 'STi5500' - name of microprocessor 0xd4c9041 - JTAG Identifier 0xfffffff - JTAG ID mask NOTE - valid identifications must be made prior to specifying that in the IRD definitions. As long as the base address is correct,no need for other info. I never heard of anybody programming the flash in a sc20xx receiver,so you are the pioneer. Hi Slugworth, Well. It does have a EJTAG header and I can reed the Firmware at that address 1560 0000 but when I go into the Program flash menu it says that the Mfg/Device codes 1/1000 are not recognised by jkeys. On the bottom right of the Flash Programming screen it says 'Control Functional' but because the flash info is not recognised the Erase Read and Program are all greyed out. What would be my next step?

I went through the SC2000 pdf and see that the ebus addresses should be from 1400 0000. Am I reading this right? Where do I point jkeys to read the correct Mfg/Device codes? Boot vector was the clue. 0x1F00.0000 0x1FFE.FFFF 15.9 Mbytes E-bus address space (Boot vector) That's what the receiver boots from (flash) I would start at 1FC0 0000 and work my way up to 1FFF 0000 Hmmm, I did a scan of the whole section (from 0x1F00.0000 to 0x1FFE.FFFF) twice. A bit here and there (no more that about 5 bits all together).

The two scans showed that the bits were different as I pewer cyccled the box before doing the second scan. It looks like it is a RAM section? Hi Slugworth, I did a scan of four whole 256MBytes blocks. 0x0000.0000 to 0x0FFF.FFFF 0x1000.0000 to 0x1FFF.FFFF 0x2000.0000 to 0x2FFF.FFFF 0x7000.0000 to 0x7FFF.FFFF and the only place I saw code that didn't change when rescanned was from 0x1560.0000 and about 2MBytes. There was two mirrors of it at 0x0000.0000 and 0x0080.0000 which I presume are SDRAM? Sections of them change somewhat every time I rescan them but some areas are constant.

Another thing I found is that the code in all places reads every 4 bytes backwards. 04 03 02 01 08 07 06 05 0C 0B 0A 09. Wierd, I know.

So I read it with no probleb but jkeys wont let me wright at all. I wonder if it has to do with the EJTAG interface the SC2000 uses. When I JTAG the unit it doesn't halt.

The EJTAG interface in this unit uses the MIPS 16 pin that has a SRSTN ans well as a TRSTN. I'm sure JKeys use it (Although my buffered JTAG interface only has the TRSTN) as the.def file asks what type of JTAG Interface is in use (Position G in the IRD definition).

JTAG device: (USE) 1 for JTAG mode and all STi micro's. 2 for EJTAG mode and all LSI SC2000 micro's. Do I need a EJTAG Interface or is it just software diferences?

^^^ ENTER HERE:.