|
|
ak475671 發表於 2011-8-22 13:03 9 B4 Y, S, v1 X+ t4 o1 W. J& Y1 w
版主你好
@7 k, n: C7 z3 |版主知道哪裡有教學嗎使用DOS提KYE的過程不是很了解不知道有沒有教學可以參考的呢
3 p, ^9 v5 I$ e8 E另外你說他提取 ...
. ~, @4 W G! N/ h4 g' v3 TDosFlash ReadMe.txt 說明文件
0 ~/ c! M7 W' r% R5 |0 B( N, a7 a. j/ `9 d! M- @
DosFlash V1.9 Release Date 01.01.2011
3 R. w3 V! u; A' V9 l2 J---------------------------------------+ p/ n- ~) M e0 }) F' t
- SATA and IDE port scan improved in DOS and Windows
# c2 f5 z, o. {$ r! |" C The ports are now enumerated with the CONFIG_ADDRESS and CONFIG_DATA register instead of using interrupts
; I" j. |# y8 n( i in DOS and SetupDixx functions in Windows. This change will detect more ports in Windows than the old . T( X( q. h) c: v
SetupDixx method.& U$ z0 O% F5 j9 k% v) V
- Settings saved to ini file for DosFlash32 and DosFlash64
$ A W& v6 H' ?( o m8 ?7 p Settings like Port, Position, Task, COM Port, Enable Drives and DvdKey state are now saved to an ini file' u) e" e/ K( v
inside the program folder. If the ini file is not present it is created after the first run. On the first; c0 N4 v/ n4 {9 W8 ~' ^0 |8 l# Y
startup DosFlash will choose the most common and stable settings.
8 P! F0 o6 E* ]' j! f+ \) T' P- EnableDrives option included in dialog as a check box
1 q6 Y1 x, y5 Z6 e2 X" b& J8 g7 R Due to high demand we removed the "Enabling CD-/DVD-ROMs" MessageBox on program termination and included
0 n$ s( Z, N# q5 C5 n: J a check box "Enable Drives" inside the dialog. For security and more stability this is deactivated on the
5 M2 V: J/ U! T6 r( |% N first run. If you enable it the checked state is saved to the ini file.4 C/ s& t- f4 W5 Y
- enabling drives in Windows caused some hangs from time to time, this is now fixed by a recoded enable
; O- b% X6 x3 { drives function7 Z. j$ ]0 s, C, ]; ^1 j0 N
- port drivers portio32.sys and portio64.sys are now added to the executable and unpacked during runtime" o" v+ u9 f0 [% y1 q9 k4 E6 B& u
- PATA and SATA controllers list updated- H, V& k5 `9 b" k. d. c& U
- Fix for NForce motherboards in combination with drives like the "Samsung SH-D163C", "LG DH18NS40" or! d; c9 e l& ~' T1 z8 ~
"LiteOn iHDS118"
2 C0 w |& O( x2 Y Some drives have problems with flash identify, read, write and erase. This is clearly related to the
5 d* r0 T% `$ r: e+ L R NVidia NForce chipset. For manual mode in DosFlash16 an additional command line parameter is added called$ F. ^( V1 ?) W* E: n: c5 O
"NFORCE FIX". This parameter should be set to 1 for NForce chipsets if you experience strange problems.
" s5 `, z: } A/ k( U In DosFlash32 and DosFlash64 we added a static control which shows if the NForce Fix is applied or not. r3 S! L& `2 L) H) d( D
Remember there is no need to activate this with every drive. It seems to be a combination between drive
4 M: o5 y& C& c2 ~5 H and NForce chipset that causes the problem. The fix is automatically applied for DosFlash16 in auto mode,' i9 j ]- w& M. {. P
DosFlash32 and DosFlash64.
3 l0 L7 O1 N+ S- f, i- DosFlash32 and DosFlash64 are now DPI Aware for Windows7+ L* e3 ^& x$ k6 |1 p
- New task Verfiy Key/Inject Key added for verification/injection of drive keys& }+ w4 Q' ^, s4 M! u
All DosFlash versions now have the possibility to validate drive keys against an XBOX360 drive and set
* ~- \6 a+ ^" i- _, H1 p" m8 p the key for an XBOX360 drive. We use the same authentication method like the console to verify a key.
# J' m" C2 F/ g8 p% p In the Windows versions you have the choice to paste the drive key from the clipboard to our custom hex/ q5 X6 |( x/ ]5 S6 i" T
edit control or load a key file. To add a key simply click right inside the hex edit control and select. @$ k* W6 e1 H4 p% u4 |1 r0 a$ f
your choice from the shortcut menu. In DosFlash16 you can enter the key in the format "1A-2B-3C" without
1 [* T! Z* v. e quotes. Remember that a key has 16 bytes of data. The key file to import should also have 16 bytes of data
/ J6 a: i9 v6 T7 e+ H. ~$ n like the key files exported by LiteOn Key functions.* `7 b* t2 j9 o6 W; ]0 y/ \3 t* l/ F
- Removed multiple key extractions for LiteOn Key functions, added Verify Key after extraction2 a- Z6 h. ]# @
For LiteOn Key functions we removed the multiple extractions, because the key is now verified immediately
2 \( }' M% J' I4 Y- x+ U( ^ against the XBOX360 drive.2 P+ [: X+ r6 N7 \3 B
- LiteOn Key V1 and V2 now also extract the file Serial.bin and the 2nd inquiry file Inquiry2.bin ]4 Z* P0 b' z, v
We added the file Serial.bin and Inquiry2.bin to LiteOn Key functions. Inquiry2.bin is only generated for" W G: E% P, g, |- A, ]3 A- a
LiteOn drives V1 and V2.. ?. a/ n8 Y) G/ R, N( g
- The drive key of Maximus patched UART drives can be extracted by using the task "LiteOn Key V1 (DvdKey)"
4 S! f1 q; I* ? D" e C& L The drive check has been removed from LiteOn Key functions. This way we can extract a key from an UART % Z4 ~" M( t% e! {- M" ]' ^% K9 Z
patched drive firmware by Maximus.3 h0 [" P0 c! |, T# `/ s
- LiteOn files are now extracted to a destination folder instead of prompting the user for every file name.
4 J4 @- H: s) l% s5 A- LiteOn key extraction tasks separated per drive version in "LiteOn Key V1 (DvdKey)", "LiteOn Key V2 (FreeKey)"8 A" u! z: [" R
and "LiteOn Key V3 (Tarablinda)"
6 ]2 A7 m f+ @( O1 K% T- In DosFlash32 and DosFlash64 the number of installed COM ports in the system are now enumerated instead of* {" c A9 Q: s
adding port 1 to 4! b8 d1 h+ Z7 I! _" s- G$ d4 J
- For failing cdb commands the sense code is returned
! R0 z( ]/ y$ O) X- Geremia's Tarablinda functionality added
3 i- e. ]9 h* N$ t( O/ R We added all Tarablinda tasks to every DosFlash version. You can extract the key by choosing the task7 n+ o5 W* P% g, [* M" X
"LiteOn Key V3 (Tarablinda)". For read, write and erase of the flash simply use the standard functions.
" i6 Q( z% N7 C- |8 ]+ F Pay attention that the "LiteOn Erase V1/V2" task is only available for older LiteOns and not for the Slim.
6 s* ~7 z2 ^' R2 l You should use "Read Flash", "Write Flash" and "Erase Flash" for the Slim. "LiteOn Key V3 (Tarablinda)"
& B+ x. \1 {+ W' o/ {# f extracts 1 additional file in comparison to Tarablinda v04b, this file is called Xtram.bin and contains8 p$ L5 M- v3 x7 Y! ]& s
a dump of the XTRAM8000 area. This can differ in a few bytes from one dump to the next.. j) M1 \: [* N; e/ \: Y3 t/ a
- Device Reset in DosFlash16 manual mode is now done automatically, there is no option to turn it off anymore
) d& Y$ ~+ x9 \+ G- Code optimization to work with modern SATA2 controllers added, remember to set SATA controllers to IDE and- U* Z9 ?# } m0 l/ x
not AHCI mode otherwise Port I/O will not work4 N1 m. n" u2 P, F8 B" M+ ?% Q# |
- Warning: The read, write and erase of the Slim drive is considered risky in general! So pay attention and! [0 j" r4 A) X: b( l6 e
always remember you use DosFlash on your own risk every time! Even during flash read the Slim gets flashed
' U" d$ x! t% @( ^: D6 S( L with a patched firmware sector to retrieve the complete dump!! Q# [8 S) Q* f' z/ ]
- We had to change many command line arguments for DosFlash16 Manual Mode, because of the NForce Fix, added6 p% I% N7 W7 k' a
Tarablinda support and splitting of LiteOn Key functions. To get a better understanding we added the example. P: o- c# X* Y, w0 y, [9 e
section below.4 J- q4 C! d" O" ~5 {+ Q- F
# `8 q5 ?2 E- r) V3 P$ h; {
( R3 Q6 ]" `9 g5 iDosFlash16 Manual Mode Examples
1 F1 U) \% }+ s, y& r; n) }# z---------------------------------
- B( b/ f" e! z7 k/ H3 M9 y- Extract drive key on a " LDS DG-16D2S 74850C" over UART -> "LiteOn Key V1 (DvdKey)"' ~0 u' D8 f+ U0 d* D0 M
DOSFLASH LITEON K V1 0970 A0 1
Z8 P5 B; K/ V3 X: v5 F/ j7 |' D0 j% M+ t
- Extract drive key on a " LDS DG-16D2S 83850C" over SATA -> "LiteOn Key V2 (FreeKey)"
. l$ V$ w: x# C# D! w DOSFLASH LITEON K V2 0970 A0/ z5 u" M; h( k, O% {" N! D. Y
" X, K* }. K: X9 ] h- Extract drive key on a " LDS DG-16D4S 9504" over SATA -> "LiteOn Key V3 (Tarablinda)"
6 }9 S+ [( q4 a, t3 D$ M DOSFLASH LITEON K V3 0970 A0
7 A5 {. z8 Y: }1 ]" j \& h5 G% e
- Read firmware on a " LDS DG-16D4S 9504" -> "Read Flash" this is considered risky!
7 P' e+ m- ~" _ ?6 s1 T DOSFLASH R 0970 1 A0 3 0 4 FWOUT.BIN 0
5 m) ~0 x0 X( s8 m4 E
' |, u ]5 G) V/ J9 A- Write firmware on a " LDS DG-16D4S 9504" -> "Write Flash" this is considered risky!
; x; I7 u) M1 X) I* {& |8 j DOSFLASH W 0970 1 A0 3 0 4 FWIN.BIN 00 Y) {! P( |% C5 }7 m; B3 I
- p+ l" a( y1 q. h/ \4 b H- ]1 C2 F
- Erase firmware on a " LDS DG-16D4S 9504" -> "Erase Flash" this is considered risky!
/ u3 C& f' p2 c5 D4 p DOSFLASH E 0970 1 A0 3 0 4 C7 0- p, n) h( X9 L% c! ]5 V
3 |- G9 U& z. |3 W- Erase firmware on a " LDS DG-16D2S 74850C" or a " LDS DG-16D2S 83850C" -> "LiteOn Erase V1/V2"" V3 a' ^/ W/ Q4 V% d
DOSFLASH LITEON E 0970 A0+ N* f$ y/ Q$ f2 E
$ ?" F; V" ]* F" X9 n6 Z8 |8 q- Read firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Read Flash"
) Y4 \& M$ E/ y1 E& g/ D DOSFLASH R 0970 1 A0 2 0 4 FWOUT.BIN 1
* `2 h! G# Z, a0 M3 D
- z7 m; R0 s1 D5 m$ i' r- Write firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Write Flash"9 c2 H0 L2 [- o# _* p8 u8 r
DOSFLASH W 0970 1 A0 2 0 4 FWIN.BIN 1: x0 Y/ l) A. e+ N+ R: M; M- B$ ^/ R
) l& q$ h, B, I1 z8 b0 j- Erase firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Erase Flash"
8 s; V( D1 Y: e/ X% g' ^ DOSFLASH E 0970 1 A0 2 0 4 C7 19 s8 W; T4 {9 H
$ b7 T2 Y- ]* l$ J+ }- Verify drive key on a XBOX360 drive, enter the drive key manual
# }, m+ R0 T2 x DOSFLASH V 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF" K! }9 P- U# \9 w9 P) s, J
2 m" A' @" T6 q/ Y3 o- Verify drive key on a XBOX360 drive, load a drive key file2 D4 R7 p' X) r8 ?
DOSFLASH V 0970 A0 KEY.BIN: c8 [1 g5 I; c# n5 @1 v, l, A
& [% z g" o( y- F' B
- Inject drive key on a XBOX360 drive, enter the drive key manual" j! t, u- B) n7 k) h, n# ^/ I
DOSFLASH I 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF
, f( ?8 W; v0 d6 G# [9 |
) }9 G* X3 _4 h; Q' d5 z" y* |- Inject drive key on a XBOX360 drive, load a drive key file, t S6 |* |" }. S5 |: O
DOSFLASH I 0970 A0 KEY.BIN
& s/ P, H _, [7 O/ _& F3 ` Q+ Z$ F, {* E' M) p; o
For DosFlash drives on which we can extract the key via UART are considered V1. Drives we get the key over2 t8 p6 v/ D7 Y
SATA are considered V2. The new Slim is considered V3 but only firmware version 9504 is supported atm.8 t. h, Q; M! A: n, Q
1 X' O' s1 c* |& P+ D
8 d7 m; `# F3 M% `/ L4 s
Many thanks to Geremia, Modfreakz, Redline99 and Tiros for their support. Special thanks to Geremia and: K2 Y; |8 Z9 } ?9 y
Modfreakz for drive sponsoring, testing, coding and much more. It is always a pleasure to work with you! \. S6 t, x; }. d
professional guys! Respect to Maximus for his UART enable patch. I'm looking forward to your magic Lizard2 P7 n+ p7 K; R6 h( k/ i
hardware flasher!
$ g( f1 X0 V# o6 E' F/ {2 g4 |- F0 y9 [
Happy new year 2011!
0 d$ u+ m8 o! h2 d- zKai Schtrom% J8 G% R( D- g. C9 j9 y
6 N; e/ U* b1 C! F
************************************************************************************************
* S+ l2 d- ^' d. v" A" u( {- ?3 i/ r+ z$ N, O1 i
6 f, `$ Q. Q% C3 W9 M
DosFlash V1.8 Release Date 08.08.2009
s1 ?2 l; s- \4 G5 R---------------------------------------- _+ [2 |, _7 ^6 A( V
- now supports LiteOn PLDS DG-16D2S 83850C V2 Geremia/Maximus LiteOn FreeKey method- ~3 d9 g2 J' {' d6 E+ j
- huge firmware read/write speed increase, especially if run from a floppy disk' C0 @4 V9 a- S% t6 }
- updated IDE/SATA motherboard chipset list
6 A5 h' E# K e% }- E- new IDE/SATA detection for Windows and DOS' z- v1 b. Q. C* |$ s" @- A
- DosFlash.typ embedded in executable file5 V9 x O4 X2 I3 y T
- LiteOn V1 drive key is now extracted 10 times and compared against each other,% V$ j$ Q. O/ o; i3 l4 c
after the extraction a summary is displayed sorted by the most common matches
/ i4 ]( V: X6 `4 t# ?: ?- LiteOn V2 drive key is extracted 2 times and compared+ u) e8 e* [5 Q& a# U/ K3 V1 R
- new BenQ unlock keys added to unlock all known BenQ drive firmwares: R, a* d4 `4 I% b( b! Y
- command line parameter "EnableDrives" removed, DosFlash asks the user on
: e( e9 @4 _$ d0 O" s, }% G application close if he wants to enable the drives or not, during the tests it; P: v2 X) c2 R) a0 M) j
seems that IDE drives have problems with the enable, SATA drives seem to
+ O& T9 \2 M0 z/ x! d work fine
: a7 x8 z$ l0 c) z- new 64-bit DosFlash edition added called DosFlash64, because some driver! Z8 b. }# o- W; q* a5 k. P# Q4 K
functions don't work as expected in the 32 bit compatibility mode on Windows x640 `- ]$ V& t3 g1 @' Z8 g
- Beta state removed
" M. {( F# D1 K$ Z- ready and tested on Windows7 X86 and x64) |1 x k/ ?/ A: ]/ l1 u, B9 `7 i
: T0 ]5 E8 J# I" u% H' }
" `1 p% o' i6 |; E/ V& [+ OGeremia/Maximus FreeKey method with DosFlash167 S* {- f* A6 V( J% a4 j9 K
------------------------------------------------- L) p+ z$ R$ G7 j, l: {
We have added one cmd line parameter for DosFlash16 in manual mode. The COM port8 f$ D( M7 T6 H+ V7 b
is simply ignored and can have any value for the V2 drives.
% h( t! G( x1 t6 Y' E3 GUse the following command line to extract your free key from 83850C:5 ~: X- o2 f- G: L- c& m! j
- DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin enckey.bin
8 y, m9 z) W2 J# z: k9 w1 ^8 e3 B( S" P8 V4 C4 s' i. W' d
5 T6 ~4 b' o) u: V& ^; W
Tips for running DosFlash on Windows 7
& A$ F) w6 y" Q----------------------------------------
# i0 k3 |0 y' C; ], \" p, ]
4 B7 C6 X- h& R# t! Q( eSince Windows Vista 64 Bit and upwards it is necessary that every driver is signed. Because
+ y1 D- K+ B* I1 o& n* N# Zthe DosFlash driver will not be signed by MS due to some unknown reason we need to circumvent( C' f+ S, N" k. p5 i
this check. You have the following 2 possibilities to do this.
8 h: B& v" Z1 K0 c
3 m; i) M0 Z) a3 CSafe Way of Disabling Driver Signature Enforcement$ ~: e8 B+ Y9 x
1) On Windows 7 bootup press F8 to get to the extended boot options screen
- ?% D m/ d( O5 J8 ^. e, B2) Choose "Disable Driver Signature Enforcement"
& C/ h8 ^0 z& L/ G3) To start DosFlash right click on it in Windows Explorer and choose& v& z0 z' z( a) A. [% G
"Run as administrator" > answer the message box with "Yes"$ |' n f) L/ i1 _. N+ |
4) Short after the program started a " rogram Compatibility Assistant" warning message# F! X/ l* n) F- Y) h- w/ \
is displayed, you can simply ignore this by pressing the "Close" button
7 w7 q4 u) G( ^. _7 |% u" S( f& f" f2 s* o( m4 ]! |
Recommended Way of Disabling Driver Signature Enforcement
o, X# Q1 t0 P. f1) Disable User Account Control (UAC)8 V: N: m& z6 S- U
- go to "Start Menu" > "Control Panel" > "User Accounts and Family Safety" > "User Accounts"$ \5 @6 s3 ?* W3 v9 W/ `0 e8 O
- click on "Change User Account Control settings"* G! ]; B5 B+ a4 k; @5 B
- set the slider bar to the lowest value (Never notify) > click "OK"; A* @; L) K# `0 @& s& ~+ }
2) Sign the DosFlash driver+ m6 q o- |' S3 n
- download the "Driver Signature Enforcement Overrider" (DSEO) from4 u' _6 w! H; h" ^2 X1 K! O3 {
http://www.ngohq.com/home.php?page=dseo
, w4 a0 q! U8 ~ Q) l - start DSEO > click "Next" > "Yes" > choose "Sign a System File" > "Next" > enter the path to
9 a2 X$ c5 c1 l( Z* L- q the used driver (portio32.sys or portio64.sys) > "OK" > "OK"7 b4 q6 f0 Q6 s* r9 U" M
3) Disable Driver Signature Enforcement) i/ U% K9 I* R; C H1 ~
- start DSEO > click "Next" > "Yes" > choose "Enable Test Mode" > "Next" > "OK"9 m3 q8 r5 e& ~
4) Restart the computer1 t$ d2 C, m6 [' [
V' G' g$ g4 _( \Keep in mind that with the recommended way the changes will have effect on every reboot without
* X/ _4 b9 _% ]doing anything manual. The first way needs to be done over and over again. In addition the second
8 H& ]8 |5 }. j. U0 y& r5 ], `2 Mway can be used to sign every driver that doesn't run natively on Windows 7.
- I9 j t2 Y7 q O
7 ]( H. p( o# Q6 f4 \For use of the VIA Cards in Windows 7 it is recommended to uninstall the VIA driver. This can be
+ l" _% y) W1 p7 ]done like follows:# R) V% G" P+ o" s
- start "Device Manager" > expand "Storage controllers" > right click on "VIA RAID Controller" >
8 J H0 N1 y% u: }! u2 A. G1 P choose "Uninstall" > "OK"
8 V I/ @6 G$ }; h. g! Y- rename C:\Windows\inf\vsmraid.inf to vsmraid.inf_
( R; [5 z- ^4 d% F! O- rename C:\Windows\inf\vsmraid.PNF to vsmraid.PNF_
9 q& v: H; b# e6 [! o9 Y& Y/ f- rename C:\Windows\System32\drivers\vsmraid.sys to vsmraid.sys_
; a! e$ x* C- ?) r; j- l5 A- reboot computer' d+ ^# I2 {/ e* V3 @1 D
E ?' x k: n9 Z
( l9 t, l" _% m; t1 DMuch respect and credits go to Geremia and Maximus for their money saving FreeKey app* [0 a+ ^ I4 C' [& _% \4 u
and their lightning like decryption speed!
1 P+ g, r8 S7 X) p
+ p) |/ ~3 z4 Q2 @In Dedication To The Birth Of FreeKey On August Fifth 2009
. J1 I: H3 {: c- G( zKai Schtrom0 N }9 |- D1 \& B! _
2 n8 w8 m! D/ J# V# f. b% l7 }! z
************************************************************************************************6 h: [7 w( \4 k% Q3 d
1 x7 D' y5 k, i1 G0 y. I8 a) n
: D: B# c) |, L* M1 uDosFlash and DosFlash32 V1.7 Beta Release Date 23.12.2008
* \, z5 Z. C) @-----------------------------------------------------------/ j. {+ S0 G6 e4 g
- now supports LiteOn PLDS DG-16D2S 74850C and Geremia's LiteOn Erase and DvdKey method5 U o, W. G; U8 y7 U4 c2 k
, P5 ]8 g; k# M+ w, j
0 [0 c& [; ~ b+ y# b
The following only applies to the new XBox360 LiteOn drive PLDS DG-16D2S 74850C.* b1 Y/ C& g: `2 Q \
' D. c* t. F4 u+ q1 a& r8 U: c2 V+ V6 C4 \5 s+ d+ F
Geremia's DvdKey method with DosFlash16 with the PC's psu. S- T: K: H. X3 N8 o) V
-----------------------------------------------------------; `8 k' Z' p; u4 _
- disable CD-ROM boot option in BIOS
: K! ?0 G! u: e. E4 n* a# M- connect LiteOn to your PC's power supply unit and SATA port% F( r$ {( h4 @& [" |
- power up PC, wait until bootup is finished
! Q3 \) T7 R0 N+ H8 R$ H- eject tray of the LiteOn and shutdown PC completely
! y2 |1 b% D9 w: g4 w/ Z- push the LiteOn tray half in0 d8 I+ e- S. q
- power up PC and boot into DOS
9 p0 a" [/ E5 I9 R9 n' @9 e) J; r- run DosFlash16 in auto mode- g+ c7 n' `5 e
- if you read the following:$ k7 P) _6 D+ `$ c. {2 P6 ]1 m1 o
MTK Vendor Intro failed on port 0x????.
( I, Y; @- b6 Y* Z$ d. } If you choose to resend the command you should turn the drive off and on
% E5 w8 d# b2 U$ X after you pressed "Yes".
: M X1 ?- a6 x Do you want to resend the command until the drive responds (Y/N)?
+ O7 A1 F1 _, x; n ~$ ^) o9 [( Q- press 'N' for "No"
0 z @$ R$ N: a# m- choose the number of your LiteOn ATAPI drive
i8 y- e: g0 Y7 r- enter "LITEON K" to read the drive key
0 Q5 Y% f+ d7 H B) l" m0 n- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files' t5 `9 I' v% c* @/ T; V) a# w
- enter the number of the COM port
. }* T! L7 i( B* y% |- if you read the following:; H2 H3 ~: @) l5 G! x
To receive the drive key use Geremia's DvdKey method like follows:2 E! e8 O. A# n
- Connect your drive with a serial cable to the COM port
& L* v" a' s# [& H" n }0 }, u - Eject drive tray* Y2 A0 s/ `: t" N
- Power off drive e, b( r1 i1 w0 U$ D
- Push drive tray in until it is half open
0 z1 @! R9 ~+ P1 @" W3 L - Power on drive X, b6 J$ C) o/ P& `
- Press "Yes" if you are ready' V+ |% j! B% A
Are you ready (Y/N)?
) x6 U0 s# o) w6 S- simply press 'Yes' without doing anything of the above, because we
2 v- }; c0 l, i0 l1 J: c- o already did that before2 J g0 r6 @( Y' F' M' n* C
- after this DosFlash16 displays your DVD-Key and saves your key and identify data; Z9 {" Z. V3 F6 x m: _! i6 _
- to do the above steps in manual mode use the following command line if your drive
8 }) G* Z) a8 l is connected to port 0x0970 and serial cable is on COM port 16 K" K6 k& Y* A* q I
DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin' K# b+ x, a4 Y' r: J% Y
0 W/ P9 f$ E) ^
; N9 n. E; _" [3 P K9 CGeremia's DvdKey method with DosFlash16 and 2nd psu
& r9 s6 H4 ?( q7 ^1 e# B9 [-----------------------------------------------------1 {- K! M1 _. t/ ^/ z
- connect a separate power supply unit to the LiteOn, don't turn it on yet- W) I! i! h" R" }9 ~
- power up PC and boot into DOS
( k( w) O$ p! M3 H' }+ E! |- turn on the LiteOn psu
$ o+ m# i4 d$ n' l2 X- f/ ]- run DosFlash16 in auto mode
9 f! _3 {/ H" ?" _3 D& L- if you read the following:
. O% j# Y, u3 z2 x# q7 N* F' j MTK Vendor Intro failed on port 0x????." `& \: v" d4 n
If you choose to resend the command you should turn the drive off and on5 B/ X4 o; l2 ]! K5 g$ d
after you pressed "Yes".
' f7 l I! `) p" B& V Do you want to resend the command until the drive responds (Y/N)?& V# R5 h. x) ]. n6 l5 h6 |
- press 'N' for "No"
: y8 U6 S6 e) e8 D$ i# g- choose the number of your LiteOn ATAPI drive& E6 q( m. g+ p! k2 |
- enter "LITEON K" to read the drive key, i6 I) C% x) u1 ]# b' Q
- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files
0 X2 n) F/ t0 N ~! U- enter the number of the COM port; L. B O8 x# u$ G
- if you read the following:: B0 A, P, ^! o+ D9 g* |
To receive the drive key use Geremia's DvdKey method like follows:
+ X; s3 Z, X9 A) m - Connect your drive with a serial cable to the COM port7 m( w* A) w& P: G
- Eject drive tray
6 H$ s5 Q+ `- R% F, x& ~ - Power off drive
2 I5 f. Q+ Y$ W8 e; v+ h - Push drive tray in until it is half open
- V7 Q7 Q# J0 d/ X: B - Power on drive: ?. w2 v" O$ w3 _( `) L' t- ~8 \
- Press "Yes" if you are ready* @- A0 L* X3 w' j2 N- q; {
Are you ready (Y/N)?
2 q) a- L4 ?7 |' t: p- do the above and press 'Yes'
; ?. N! |; Z2 |. S- after this DosFlash16 displays your DVD-Key and saves your key and identify data% X3 }9 t! j" t
Q! F- H9 z: P6 ^8 e" M
( n) Z0 B, c, v# G3 X# O2 pGeremia's LiteOn Erase method with DosFlash16 and 2nd psu; W: P! C. C5 o `, M
-----------------------------------------------------------# k% Q l( m F" O+ _9 S/ v
- connect a separate power supply unit to the LiteOn, don't turn it on yet
& b* {4 ]6 {7 G/ W( r6 O- power up PC and boot into DOS+ Z0 d, }" [/ X) X3 X9 q
- turn on the LiteOn psu
7 R+ [4 e6 ~, z- x# R. K- run DosFlash16 in auto mode
/ d T U5 ~2 M; X- if you read the following:0 V/ q( @' R; N# b* Y9 W; L! C
MTK Vendor Intro failed on port 0x????.3 r. [& J; q I: P" R7 p# o
If you choose to resend the command you should turn the drive off and on
. A/ T0 J4 o1 _' R& G+ S: u( s after you pressed "Yes".& F W6 f# Z' s+ i4 `' I3 R" i
Do you want to resend the command until the drive responds (Y/N)?. \8 D9 D5 `/ L- \* a
- press 'N' for "No"
& p. `0 w$ v/ U# | M- choose the number of your LiteOn ATAPI drive5 E7 P, s% _- q% U1 K- b/ }
- Warning!!! Keep in mind that you will need the drive key before you erase the flash,6 O' d3 G" G, y: d
without the drive key your XBox360 will not work anymore# K& P' x& b8 K$ x
- enter "LITEON E" to erase the flash
2 u# l8 B& K& |$ ~; [* C2 l. Z' v- the first time after the LiteOn Erase the drive needs to be repowered to give
, Y2 ^( y7 a k, r flash chip access, this can be achieved by repowering the drive before another# ?' L) x% Z& V$ P2 g L5 _- z
DosFlash16 start in auto mode or by doing a MTK Vendor Intro Power Brute$ `8 [) a+ H# L" ]5 ^0 `+ Z
- in my tests it did not work to power the drive with the PC's psu, because it will
. ^. [' x0 b- ^& T+ o3 o always respond with busy status7 A( w. V; I& [7 u
- DosFlash16 can now read, write and erase the flash chip like usual2 |4 I3 c- [& v) a' k7 f) l3 \
- to do the above steps in manual mode use the following command line if your drive6 W: b' u4 t# J* E5 M2 @
is connected to port 0x09704 ~& v- n4 Z5 w
DosFlash LITEON E 09704 _3 L: x& Q8 Y* W6 K/ ^
0 |3 [' J6 T+ ]* S6 D5 r
9 c e. n% p z$ B+ o
Geremia's DvdKey method with DosFlash32 with the PC's psu
! {' A" e7 S5 { }8 L5 S( W1 w-----------------------------------------------------------. r, P4 |* D8 G+ g A4 Y
- disable CD-ROM boot option in BIOS
! F, Y! e b5 d5 j- connect LiteOn to your PC's power supply unit and SATA port$ x( \5 z! I3 f( W3 e9 o* v! }
- power up PC, wait until bootup is finished( p0 F( Z( d" ?& I6 t9 g9 x( Q
- eject tray of the LiteOn and shutdown PC completely
! u8 P9 z; G0 ?! O; E3 o- push the LiteOn tray half in& L1 C$ d% s6 h+ }
- power up PC and boot into Windows
: g8 b$ t0 S: T* r% b0 N2 s- run DosFlash32- d b! {0 H$ Y Y! y* N
- if you read the following:9 g) `: }+ K) k# n1 v1 `
MTK Vendor Intro failed on port 0x????.
$ t7 ^% t8 k2 a9 M7 m If you choose to resend the command you should turn the drive off and on
' R+ w7 }! ?' p/ w4 o after you pressed "Yes".
5 x+ J- ~) k B( m Do you want to resend the command until the drive responds?+ n* _7 g# U- v/ a/ j* ~
- press 'No'! A0 Q# ?/ ]5 w5 P, ^' o
- choose "LiteOn DvdKey" as flashing task+ Q6 ~7 g. }+ s+ J) e
- choose the COM port number. N2 E4 ]" ?$ T5 ^. I% D! Z
- press on "LiteOn DvdKey" button
. N5 J( @* W& c, @/ o- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files
5 ]; x# p+ v" Q) Y d; @& k- if you read the following:0 Q7 h, Z( q5 c+ ?( D
To receive the drive key use Geremia's DvdKey method like follows:; H8 j. K; r% h% L* q3 f: _
- Connect your drive with a serial cable to the COM port O" q& f1 ~* {: K
- Eject drive tray6 f# E) L) i6 c9 F3 _
- Power off drive
6 D5 U! R- ~) U- R* h ? - Push drive tray in until it is half open
; Q$ G* ]. r8 ]/ e8 p+ S - Power on drive
7 g6 I8 ~* R: {1 g - Press "Yes" if you are ready
7 r7 o' T- ?5 k$ r. Y Are you ready?
: H. Y, U( Y$ l. o: _ p- simply press 'Yes' without doing anything of the above, because we' W5 ]# X8 X% E" p; O
already did that before
9 ^' ?. e1 ]0 b+ z$ I- after this DosFlash32 displays your DVD-Key and saves your key and identify data
0 e5 P/ U" M- u) Z8 R% x/ X
) X5 ?. H l6 r, W3 e9 U
) C2 V% Q4 |5 b! {% @8 w) XGeremia's DvdKey method with DosFlash32 and 2nd psu
}0 G7 [! M4 C3 F3 ?# p( |-----------------------------------------------------2 i8 _: Q0 {& Y( H- U- d
- connect a separate power supply unit to the LiteOn, don't turn it on yet
* j) P$ A. ~ }( P1 M7 R! `- power up PC and boot into Windows
1 e0 k" @+ R ]$ `; A6 f( K- turn on the LiteOn psu
7 {5 Q3 L" \4 N" Y! C% J- run DosFlash32& m6 t3 U, u- |* N. i: C/ p* B
- if you read the following:0 }" b4 b: e5 h$ }: _
MTK Vendor Intro failed on port 0x????.
1 a5 |3 _# ?, w! z. H% J- D% d If you choose to resend the command you should turn the drive off and on
" @0 Y' @2 ~9 J2 J after you pressed "Yes".5 O6 U, t5 i, s1 _; r: I3 N6 w
Do you want to resend the command until the drive responds?
1 z6 }! ^: ^* ]! ]+ q; G& P- press 'No'8 V/ T0 y& T( o: |# ?1 N
- choose "LiteOn DvdKey" as flashing task% h9 P8 B0 P: K6 q
- choose the COM port number
8 n) \5 \8 P: B. D+ u( @* }# w- press on "LiteOn DvdKey" button
% @! e4 n0 r! _, W- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files) X n0 u3 M* W; h1 ^, U
- if you read the following:
) \4 d \( y, C To receive the drive key use Geremia's DvdKey method like follows:' n6 k+ b$ w1 f. d
- Connect your drive with a serial cable to the COM port
/ y4 {5 `! P2 o - Eject drive tray% T" N6 M; G- w
- Power off drive7 I2 A. b/ Y5 }
- Push drive tray in until it is half open/ C% e. x2 I* ?/ U
- Power on drive+ E2 L; x: x2 T9 I& |! ]. s# ? B
- Press "Yes" if you are ready
) M* H! K; y) j) @, _ Are you ready?- G8 W# L" ~3 \4 G. f v$ y5 a, h
- do the above and press 'Yes'
4 x! y3 j/ w0 R5 C) s1 s- after this DosFlash32 displays your DVD-Key and saves your key and identify data, B: m6 Q( ~: E7 m5 X* g( n
0 Q; d4 r7 t. {2 [6 @" C/ T7 L
" j$ ^/ p: L2 ?5 Q2 u hGeremia's LiteOn Erase method with DosFlash32 and 2nd psu3 q7 e3 w! m5 i+ ` l- S+ K* E
-----------------------------------------------------------
7 |- {) l: B9 Q; H, C# J! }6 Q- connect a separate power supply unit to the LiteOn, don't turn it on yet
1 ~0 e) i) z2 N5 m- power up PC and boot into Windows
( _6 r# Z! t1 y# B5 x) u* O$ [- turn on the LiteOn psu& M3 K |2 p: q5 q5 P
- run DosFlash32
) [; |( h+ x, ?" z( @- if you read the following:
" v' T, G T* Y% n0 | MTK Vendor Intro failed on port 0x????.
0 [$ V4 [4 n: E {" |* U If you choose to resend the command you should turn the drive off and on7 P9 a8 X' N" {1 F
after you pressed "Yes".. |! z8 S% w& w' c1 [5 M1 K4 h
Do you want to resend the command until the drive responds?
7 {6 l- Y5 @% |+ J9 m- press 'No'
( V6 V( q I. [" j8 x, Q- the LiteOn flash is not identified
- I4 S7 p. Z( d2 l- choose "LiteOn Erase" as flashing task
/ d9 g8 D& X5 p) U2 l! ~: H- C- Warning!!! Keep in mind that you will need the drive key before you erase the flash,$ ]% M& ?2 T# k" s# w3 I$ n1 N
without the drive key your XBox360 will not work anymore
" C! A+ g4 A+ j, [- press on "LiteOn Erase" button
0 l. w$ L7 D* l, `9 I3 v- the first time after the LiteOn Erase the drive needs to be repowered to give
% Q. [1 d" \7 p flash chip access, this can be achieved by repowering the drive before another. |+ \7 v3 F* P3 N
DosFlash32 start or by doing a MTK Vendor Intro Power Brute
% t% f Z7 G9 b t3 y( k; q- in my tests it did not work to power the drive with the PC's psu, because it will
% j! K. C; L% _" C! W; X6 D always respond with busy status/ r0 M s7 q0 ?. z) V b* H( F% H
- DosFlash32 can now read, write and erase the flash chip like usual4 V1 _- L& f3 z% h5 U, ]
( _% V- O) `3 {0 e* _" E" v5 O3 f* h9 M) d, r: M a
Respect to Geremia, Modfreakz, Podger, Redline99 and Tiros.) L0 N2 e4 K9 R( S% i
; Q5 h; f o+ n0 v. M
Like a wise man said: "0x2E is the MTK Intro of Death"
. a$ s6 p7 ~% WKai Schtrom
- v, U5 A2 s M, |2 q/ f: E' K- t( h# Y, _) k" E V0 i
1 w+ c2 N l$ l7 @6 w
************************************************************************************************3 u& z# X4 ]/ D* U
) g2 w9 D Q V! i: Y
$ F" n1 y; r8 @& ~5 S) U" b) C
DosFlash and DosFlash32 V1.6 Beta5 [& I* Y" F2 z O* ]0 W& d
-----------------------------------7 y# `+ w4 R$ r( `3 z
- fixed power brute unlock bug for VIA cards, this can stop your VIA from working0 Y; |& r) a0 U, C1 b- V
with the power brute unlocking in Version 1.5. {, v$ W0 I) Q: S7 i
- for DosFlash16 in auto mode on DOS my VIA card works best if I do a cold boot
% D. N5 ]* R$ a, [, F* C4 ?+ Z+ J and power up the drive short before or with the PC
" Z. O+ m1 S0 L. z- for DosFlash32 on Windows my VIA card works best if I power up the drive short7 |7 W# Y. ^) I' S7 w
before starting DosFlash32( Z% L# ?. f0 Z4 Q; T4 g6 ]6 [
- for me the VIA works with internal and external connectors on DOS and Windows: ~% w6 l% z! x
, Z F1 h/ R7 G# Q8 o5 ^! JSorry for the trouble!
/ x! G! g; |8 }8 SKai Schtrom7 F1 p6 L9 e& y9 X. W
H Z$ \, ?& p3 g8 H* }) r
4 _9 l4 `5 X0 a; m) `************************************************************************************************, }% L" @, U' `* Y r1 o
3 F5 {. l$ M4 h- ]. {. _2 f& w" k5 n4 W. n. q
DosFlash and DosFlash32 V1.5 Beta
8 D! a5 Y2 P6 J8 U-----------------------------------$ b4 X6 Z4 J: i" C1 {. D
- now supports serial flash chip MT1309E with mediatek status 0x72 like the SH-D163B, SH-D162D,
( w+ W$ W V3 A0 Q; l" K# c9 E Asus DVD-E616A3, Asus DVD-E818A3, Sony Optiarc DDU1671S2 d2 v% K1 C; t, x
- SST25LF020A and SST25LF040A chip support added
3 f- q; A4 T' p- j% L9 _- DosFlash32.exe ported from MFC to plain Windows API, exe size is now 22 KB
& A/ P4 r7 a ^9 M$ g# B* E- new port i/o driver, because giveio.sys can't be compiled for 64 Bit Windows1 B2 c- k% m! S
- DosFlash16 changed slighly in manual mode, one parameter is added to support SST25LF020A and) R/ I3 `0 U2 L. `" D0 U6 w
SST25LF040A
# P( d* E: c2 A( ?( s6 l4 B) H- two new methods of BenQ soft unlock are now possible on all motherboards with only one power
1 p+ y% i' S% W supply unit
0 N+ {4 O! j1 f1 n- 1st method is powered by Geremia's unlock core, thanks for the complete idea, concept and
7 ~+ K, R, }! o' P source to Geremia, M: v) {0 r% c+ |) F4 K
- 2nd method is the Magic28 key send, this only works on BenQ VAD6038 firmware, thanks to$ A, k! e- [3 ~1 Y/ r! V8 A
c4eva and podger for the initial idea
9 K; [: H* N4 F. @1 M+ \0 u" b5 c! c3 \- the two unlock methods are send one after the other if the drive is a possible unlock
5 o) L+ c* Y9 K. Z7 w/ } candidate, first the Magic28 command, then Geremia's unlock commands and after that the4 E& Z( W9 R% ]
already known power brute unlock is send to the drive, you can cancel any of these methods$ n- ]" }5 m* b
before they are send to the target, this only applies to BenQ drives with a locked flash
6 H: [# l! n" ^, |1 P- DosFlash.typ updated( L' F. z, W; k7 i
- other minor improvements3 s& T3 R3 H+ |% C9 R
- DosFlash32 is now ready for* y1 M% }' Z, K& ~4 G
- Windows 2000/ s) ~, M) t4 U% Y8 o
- Windows XP 32 Bit; [2 _* f8 \# c2 `0 ?! _
- Windows XP 64 Bit
( ?+ k5 q$ q4 Q - Windows Server 2003 32 Bit
6 J# p: @8 L- F2 P1 W - Windows Server 2003 64 Bit4 c# {/ z! b5 n [. O4 r V8 ~
- Windows Vista 32 Bit
3 a& |6 v8 ^6 T9 P. [+ t - Windows Vista 64 Bit
0 q. E9 ^! |/ w/ h- Warning: Drivers for Windows Vista 64 Bit need to be signed, because we can't afford the
' o% H2 T: z. |0 z7 s money to let portio64.sys sign you need to do the following:" ?4 C/ m+ r4 y/ F( R- m' X
1) Log on as Administrator; {$ T, `) f' f
2) Enter the following command in a Dos-Box:# \3 T4 V5 v' }- K
"bcdedit -set loadoptions DDISABLE_INTEGRITY_CHECKS"
4 y0 }( j% D5 o. X (we made sure there are no typos in the line above) 1 l9 h" Z: ^( `( V0 V$ ^' I* }
3) Press enter and reboot your PC: h1 r2 `! J# K1 Z* b. o" ^
4) Press F8 key upon initial system boot up% g, ? t( @* {4 Q* @- F0 l1 m% Z
5) Choose to disable forced driver signing enforcement for that boot session
- @3 `# P9 X2 e. O& t
9 }" k! e+ x/ N
0 w8 H" m) }4 f& A! E% cThe following only applies to drives with a locked BenQ flash.
3 y6 W3 x& m3 u4 w% W5 u' G( H1 A- N/ M2 r& t1 l5 Z ?3 z5 R
. Z$ I0 M; Y# A
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with the PC's psu7 T( o+ o* L% b7 h6 o
-----------------------------------------------------------------------------------------3 X% O8 w# N! I1 C
- disable CD-ROM boot option in BIOS
% S5 o1 n2 Q2 G) Z- W- connect BenQ to your PC's power supply unit and SATA port( ]# F: z( } f" B8 @* j' R
- power up PC, wait until bootup is finished
+ Q3 L- X, {. s& A, I6 B* y* H- ^- eject tray of the BenQ and shutdown PC completely C9 h& M( }% r- r2 y
- push the BenQ tray half in* s" J) \4 I) @$ M
- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash32' h' L) n8 k9 \) q2 f' D
- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
2 q9 @( b, f; c- if you read the following:
# P8 l4 J; p$ m! y/ n MTK Vendor Intro failed on port 0x????. Because there seems: l" b- o! J6 B' ^7 F) J5 l
to be a BenQ drive connected you should try Geremia's1 p9 `; w: Y" U/ X9 j3 {8 _
unlock method.
! e0 u2 l$ i8 W - Eject drive tray: x# m4 Q8 ]5 D7 `" A: i
- Power off drive b v$ A: y; W1 ]8 {
- Push drive tray in until it is half open
" E' {8 M- n/ r+ t - Power on drive( t1 B U/ }8 F3 Y5 s
- Press "Yes" if you are ready
* f9 Q1 V1 E6 P0 h8 H0 A1 j+ E Are you ready (Y/N)?
- Z0 g( b8 Y1 `5 S. }! }& M- simply press 'Yes' without doing anything of the above, because we1 ]& R5 L S& _# p, ^5 `7 S
already did that before starting DosFlash16 / DosFlash32
$ N J' c/ w( H4 \- the BenQ flash should now be identified
7 M: f3 i6 z s' p2 a" N- go on like usual6 G0 u7 C, V+ Q
: a8 B/ ]0 Q. ~& m
4 W1 _. M W3 v E, y6 j
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with 2nd psu
7 k R' w6 c, T: }+ q5 @4 Q& j- H C------------------------------------------------------------------------------------% t/ q! C% M- c1 Q4 m
- connect a separate power supply unit to the BenQ, don't turn it on yet
& z9 \' J3 M1 H0 C' F6 }0 n- power up PC and boot into DOS6 l; [6 e! T! f4 j$ W# B
- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
7 F- L* R' d4 j8 H- if you read the following:& F( W4 u y/ s7 H/ _6 N
MTK Vendor Intro failed on port 0x????. Because there seems0 R) t8 S5 J2 @' x
to be a BenQ drive connected you should try Geremia's
' U+ e4 H6 V) l: G8 i unlock method.
r! N4 L% @0 S) a; O% W/ t! c - Eject drive tray
3 x# A: x, j, e# m/ C6 i: ? - Power off drive m$ {# y7 X9 g2 A: _( r
- Push drive tray in until it is half open% r% o+ Y. T; s
- Power on drive
% G; P/ g% g5 |# a' \) }/ Q& | - Press "Yes" if you are ready
^ l7 j Z6 f) o; Z4 m7 b7 S Are you ready (Y/N)?
( S8 g- w' h% r) e* T) Y- do the above and press 'Yes', U; k9 p: q8 F0 b/ [$ G+ ^
- the BenQ flash should now be identified8 B$ D* M( U& g7 `1 t9 c
- go on like usual+ i# F& w. T$ `( \- K% J0 v2 O; I
) Q& J4 i: A/ h: S, O# c
- Z! U" m* ?5 s9 f1 zMagic28 BenQ unlock with DosFlash16 / DosFlash32 on any motherboard& _! q: M2 Q+ [, H
---------------------------------------------------------------------( T( D+ F) O% E0 Q6 y
- connect BenQ to your PC's power supply unit and SATA port
" p3 w& c9 D5 r) ?0 r: j- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash32
( b" O) n9 N% `) }- S: k. d- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
5 ~8 t* f$ r8 \9 L2 @- W- if you read the following:; S& E# i8 T) `6 t0 `
MTK Vendor Intro failed on port 0x????. Because there seems
2 N& _, s/ L5 B7 k to be a BenQ VAD6038 drive connected you should try the4 ~3 O4 V' A9 f) S; `" M. q
Magic28 unlock method.
& Q' y) @+ P4 [6 @& {/ U) E Do you want to send the Magic28 command?
# c6 \; y9 b% i" m$ X- press 'Yes'
4 t4 _% N7 f# X) Q- the BenQ flash should now be identified
: q6 O+ _' g# a& W- go on like usual
3 z! ~# E2 x% c z, C1 ~8 k* l% Z% g5 @) y
$ y/ t7 C- _5 p! a
Thanks to Redline99 and Tiros for help and support.
7 I0 }8 f; L ~4 y6 J, x! z- b8 m# u- p$ w4 H( `3 R
It's all about DOS!
' C3 Z/ Q q# y. H; p# q# ~8 UThanks guys for the excellent team work!
/ @- U& q5 n$ P: l5 p2 F" lGeremia, Modfreakz and Kai Schtrom7 {" t. h" N8 v; ^
. A, z6 m4 a! B
0 r9 \ o; g. |. p5 {8 ]+ _, H************************************************************************************************- [( s" G. n3 ?8 z c- g
( W1 S( a- R; I/ u* @6 T9 C
& P0 g p" d3 m( f, B( @0 z7 x& @# }DosFlash and DosFlash32 V1.4 Beta3 H: [. J% T1 L/ J) R. ~% I8 @# H8 n% ^
-----------------------------------, y/ J+ E) o$ ~' F- q# X- @
- DROM6316 flashing support
! w7 T& o7 r: G. g. A, Q; S. R- a flash erase is now always done with a chip erase and not a sector erase command, because
/ F2 w/ {0 ?5 ^ the sector erase gives problems for some Winbond flash chips including the DROM6316
9 h4 `5 ]7 W9 B- DosFlash.typ corrected and updated
5 ~9 ]: ~9 b1 v! h7 c3 v0 n- for a detailed explanation on the soft unlock look at the included file SoftUnlockByIriez.txt,
: F, m2 b8 s, f7 T. m8 L it contains a very good explanation by Iriez from XBS, thanks for that one!5 \2 o& f! r6 K) Z% a; m7 |8 F
. D; N# T! R6 i4 ]8 CThanks to Iriez, Jumba, Redline99 and Tiros for help and support.6 B, x% i0 h" s, x
: ?) M8 c, }: u9 D3 S- }
Happy DROM bricking!
g7 ?% L. }! H5 \' y" BTeam Modfreakz and Kai Schtrom& W7 B$ }( x; W
4 T3 P6 e" `6 _
( b/ J! `/ J4 ~* e" t************************************************************************************************! j% Q* ~- r! y+ k. k2 v6 H
/ X2 V) U& h. j% o! S! P
. L- ~) L$ H4 z D! v* c
DosFlash and DosFlash32 V1.3 Beta
0 I! v: w& w7 c Z-----------------------------------
/ i6 I6 U' s+ m4 M: `+ l( z1 D- BenQ optimization in unlocking the flash chip, it should now be possible to read/write/erase$ Q9 q& ?1 u2 Z; g+ T5 T% A
the flash without any soldering or wire tricks, the drive is polled for the correct mtk
2 N9 k8 F' R+ Z, B0 f7 \- t4 } unlocking status after power on, this only works for VIA cards and NForce boards atm
9 @+ v. O& J5 H$ |" O# S* }: B/ }- DosFlash32 has one additional parameter, if you start it with the parameter "EnableDrives"& Y. e. [: J) `5 f3 E) L
all the DVD-ROMs are enabled in device manager after flashing, this could give BSOD on some
8 C1 F* f6 E* F7 m7 E( |8 I1 l3 a systems, therefor you need to create a DosFlash32 link and add that parameter manual to use it# {# h; f6 O4 K' F5 p8 A
- DosFlash16 has one additional parameter "Send ATAPI Device Reset" in manual mode, this could
( _, w5 G, j) Y/ l! a give better chances for soft flashing on some VIA - motherboard combinations
0 ]2 d) m% B( C! i& m0 A8 T- better support of Intel chipsets, drives can now be flashed if the controller is not set to) c; v3 t: c2 e0 K' }$ i
native mode in the BIOS7 m$ @8 D4 B4 H) L' J- g
- the following controller list includes vendor and device IDs that are hardcoded to identify" g0 g) D- x( R5 B$ L' a; F
the controller type (IDE or SATA), this is needed if the BIOS uses IDE ports like 0x01F0 or
* i+ Q$ G4 j' i 0x0170 as SATA and not as IDE channels, this list is NOT related to soft flashing
5 n# f& T0 V5 h) y- the following chipset support is added
* a" y& G0 j X, \7 @' q) g - VIA cards
, m% J& l, O. g" ~ - all VIA cards with a 6420 chipset# T/ ~4 ], ^& e$ [- H5 X
- IDE Controllers
5 ]4 h$ t) q4 P. p( s# Z# g! E1 t - NVIDIA nForce 2 IDE Controller
+ |: k5 \. K* m: I; {) L3 c2 A+ | - NVIDIA nForce 4 IDE Controller
0 o) W3 e* F9 o$ [4 h - Intel ICH93 j4 R% R6 b4 G& Y( T4 D1 \3 M
- Intel ICH (i810,i815,i840)2 G2 P2 c W) p6 \+ q6 H C
- Intel ICH00 n. V5 n( U: d
- Intel ICH2M
- Y1 ~! ?! y; p2 O2 {- v- q - Intel ICH2 (i810E2,i845,850,860)
& D. M( z4 W3 h - Intel C-ICH (i810E2)6 b+ H6 u1 `, z5 j/ q' `! c& S
- Intel ICH3M
$ ?, z$ N P0 ? L7 G: q) g - Intel ICH3 (E7500/1)1 ?1 X; f8 f, Y$ ]6 r
- Intel ICH4 (i845GV,i845E,i852,i855)
) S3 r( [1 D% K! T! H - Intel ICH5
) q% U3 B8 |6 t$ R1 f& [ - Intel ESB (855GME/875P + 6300ESB)' C; @8 e6 ]0 d: e' J7 Y) a
- Intel ICH6 (and 6) (i915)5 `2 ^* ^" i+ R; T) S& w) }
- Intel ICH7/7-R (i945, i975)6 j, M3 K+ q1 O$ P* D
- Intel PIIX3 for the 430HX etc
6 h. ^: v J2 ?# {0 L1 F0 ` - Intel PIIX4/ d: z6 I" w* M% P
- Intel PIIX4 for the 430TX/440BX/MX chipset) e! ~6 M/ \$ D+ Q
- Intel PIIX+ ]9 D: i3 Z) b, {8 p; i8 b
- SATA Controllers. d3 y& m& y( |4 W/ A7 ^" n2 K
- NVIDIA nForce 4 SATA Controller
' |" k. y/ ?9 l, w2 _8 {' z - NVIDIA nForce 2 SATA Controller
2 o0 M+ |; C. D: F- o+ r# m - NVIDIA nForce 3 SATA Controller
: M$ g& S/ D$ K! E - NVIDIA nForce MCP04 SATA Controller
5 f( T. x& F: f2 g4 }. {+ q - NVIDIA nForce MCP51 SATA Controller. r* H( {3 g; E; D
- NVIDIA nForce MCP55 SATA Controller& y9 X1 K) d3 N% R
- NVIDIA nForce MCP61 SATA Controller
2 c6 W" T6 _# _2 c. U' H2 b! Q( p - Intel 82801EB (ICH5)3 s( I: p X( s5 {" \2 N
- Intel 6300ESB (ICH5)$ P4 ]* x: i" v( J; Z' Q
- Intel 82801FB/FW (ICH6/ICH6W)- N9 F8 t# {, t) }
- Intel 82801FR/FRW (ICH6R/ICH6RW)
% {$ C- |. V6 I) M. Y+ Y - Intel 82801FBM ICH6M3 D$ O/ j4 W2 e* ` H
- Intel Enterprise Southbridge 2 (631xESB/632xESB)
6 [% w8 K' }, m4 r$ r) A - Intel 82801GB/GR/GH (ICH7, identical to ICH6)7 Y6 d) N3 R; d' @
- Intel 2801GBM/GHM (ICH7M, identical to ICH6M)/ F* e/ t9 R* t5 i
- Intel SATA Controller IDE (ICH8), O& |& i9 J1 j# r2 ?/ C1 E; J
- Intel Mobile SATA Controller IDE (ICH8M)
0 p1 }) i, q2 b3 m6 p, L z/ {& p1 s - Intel SATA Controller IDE (ICH9)$ _' i1 W7 k6 [0 a1 L
- Intel SATA Controller IDE (ICH9M)
' `3 l6 D' `/ i; y3 W
' ]0 c" k1 M- p9 d* Y8 c* ^* f6 L# {! F# }- X$ @. e% T
The following only applies to a software flash on a locked flash. The methods have been tested
2 r: X9 t) Q& M- K& o9 D$ ?with the BenQ and the Sammy. The VCC trick will work on any motherboard, but you need to do 9 n( h* B/ I0 z$ J1 V# t; Q9 y4 i& m
some soldering and cut traces.
4 A8 l+ u' ?5 l( v: P( A- W- a8 A3 ~) ?4 A0 U! J
# ~- a+ B C+ y2 [Soft Flashing the BenQ in DOS with a VIA card and DosFlash16 in manual mode5 G% Q b$ ]" l
-----------------------------------------------------------------------------
+ K* t U* c! {" f* M+ ^& X- l- first you need to know the port addresses of your VIA card, you can get these by starting
, j. |) z7 p( f! ^4 u8 l ^ msinfo32 on Windows XP and looking at the port listing for SCSI devices
+ R* Z4 [, v. D. e: `! E2 ^- for the 6421 the 1st port is internal SATA, 2nd is external SATA and 3rd is internal IDE, g2 {) X3 h, S3 T p# |1 t* y
- for the 6420 the 1st and 3rd port are internal SATA! }7 c* Y/ G2 c
- you need the starting address e.g. 0xD000 or 0x7000
% O8 e$ J2 Q+ e K- be warned that these addresses can change from computer to computer, they are assigned
; h. G" o0 K# Z e8 N8 U4 I3 X3 J at bootup, but Windows XP should display the ones you need for flashing in DOS
, C& t. n$ }/ r) K$ n- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
$ _0 N V3 j$ |! _' |( M5 M! R3 y- ]) q Xecuter Connectivity Kit)
1 n& P5 Y7 c8 _) V0 P% d' d- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we q$ F0 w9 F0 ~0 {
need to power the drive off and on during soft flashing& r) Q' {$ N* U+ W
- cold reboot or reset the computer
$ @4 J" S+ ^8 M6 s& R- boot from a DOS disk, I used a Windows XP MS-DOS startup disk- g& Q7 [9 P- s
- at the prompt type:
- Z0 @0 ^4 U+ L Q% k; [ DosFlash r 7000 1 a0 1 4 a:\orig.bin 0 " N+ V, }$ w' ]3 M# z" H
- instead of port 7000 use the starting address your VIA card uses% a% _( x3 i5 ]' j& ~
- press return0 {( A; \: N8 h3 j0 R& a
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes# q) Q& |6 R& x7 u1 M$ H
- after you pressed Yes the drive status is shown on the screen, it's something like 0x7F,/ X. C4 B+ X+ b; `/ I; ?$ h
this will change during the next few steps( B, I1 J, F; e
- turn on the BenQ psu and wait 2 or more seconds, status changes between 0x51 and 0xD1& U, \* n" } g! a
- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD1/ ^* L5 ]3 E l' {* y3 a) @3 e5 C
- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start
! |7 Y) F9 s7 W; M: C/ d# n" L0 W- this worked only one time after the computer is powered on or resetted for me
) n0 q2 ?8 A: e# H% _7 l- writing and erasing works the same way
" U: y( ?6 r% B" f. h6 P, |$ ?- for writing type:, g8 ^4 Y2 r3 U- e" E& c0 C E; }
DosFlash w 7000 1 a0 1 4 a:\ixtreme.bin 09 C3 X! Y N- p* h9 ^7 C
- for erasing type:
; X0 g( ~/ }5 X" z7 h+ a DosFlash e 7000 1 a0 1 4 D8 0 (D8 is the sector erase opcode for the BenQ flash, if you need
0 f1 n2 ~, x+ P to erase another drive, lookup the value in the datasheet or DosFlash.typ), K) _7 ?- n h" p" ?4 K& y. x
- if you experience any problems try to use 1 as the parameter to the ATAPI Device Reset, cause
! z6 |* j+ A0 {* s) c( a the same VIA card will react differently on another motherboard sometimes
5 t/ ~! I; e7 |7 ~+ H2 s. F; e5 L @, ^. l6 }$ W6 ^3 @
3 w4 F# m+ A$ j. }. A2 B( n
Soft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in manuel mode
8 G1 w6 ?' R4 G6 B) K5 y---------------------------------------------------------------------------------------5 C. N E2 ?' s! y. o
- first you need to know the port addresses of your NForce motherboard, you can get these by 1 \( C* K7 ~/ J* |( ]
starting msinfo32 on Windows XP and looking at the port listing for IDE devices% h; n9 A* g& m4 d- u) Q" t4 k* D
- on most motherboards the 1st and 3rd ports are used for SATA" I! G) S* O) Q$ M! i4 R
- you need the starting address e.g. 0x0970 or 0xE900; h0 l. l/ S5 ]4 G
- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
+ z$ F$ j: t' \" ^ Xecuter Connectivity Kit), h3 s) X$ X) B$ V) Q" T$ m
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
2 p9 _- t7 f3 h7 Y: G# v6 k need to power the drive off and on during soft flashing( N' [2 y. w7 B7 v6 f
- cold reboot or reset the computer
) P4 d; a0 W3 g- boot from a DOS disk, I used a Windows XP MS-DOS startup disk9 |0 x- c J0 f3 F% Y
- at the prompt type: 7 j. y% ]' H1 E9 ^
DosFlash r 0970 1 a0 1 4 a:\orig.bin 1
0 u3 ]9 m, e# i - instead of port 0970 use the starting address your NForce motherboard uses
, _3 t& l8 [) n0 V3 V- press return, F9 }6 }+ O9 C9 L9 F
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes: t1 x4 M* Z- L C% R6 ?+ w
- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,4 i/ y9 v/ _3 w) h" m
this will change during the next few steps* {3 f9 @# V6 w# p+ |7 N
- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start9 Z; ^. D( L% Q0 u+ y7 q9 C
- writing and erasing works the same way
- W% s$ b3 R# @6 ?- for writing type:
3 b* X5 T1 `: Y" `7 A, g DosFlash w 0970 1 a0 1 4 a:\ixtreme.bin 1
- |7 l: {% e" h- for erasing type:5 k' A; x, m6 `: D P4 R3 d1 g9 i/ r
DosFlash e 0970 1 a0 1 4 D8 1 (D8 is the sector erase opcode for the BenQ flash, if you need
$ ]( {! V1 M( T, K# L( j l to erase another drive, lookup the value in the datasheet or DosFlash.typ)7 X U+ g( o# Z1 T$ g0 g
( T$ n$ |. A& r
& n9 ]. R5 v# Z$ H) W. J( F
Soft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in auto mode
) \' U, A* Y) Z1 g-------------------------------------------------------------------------------------
7 e) K8 n* w3 d0 h2 h. T5 X- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
% |0 u0 r# O/ A: u6 t' F6 b Xecuter Connectivity Kit) j, b7 j, r9 {# M; N
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we" _( ]# J9 i) u5 b: t6 Z8 l- M7 a
need to power the drive off and on during soft flashing( O1 c$ A, Y6 O. f. `, O
- cold reboot or reset the computer; G: k$ a6 z& K+ J! ]
- boot from a DOS disk, I used a Windows XP MS-DOS startup disk
5 Q) Z1 D4 J8 W/ [0 d h- wait until you are at the cmd prompt
! d+ o& V; t0 w @$ r" c) w' _1 H6 k- turn on the BenQ psu
; @- Z. k( t6 A$ O* e' C6 J- ~- at the prompt type:
7 `' s* B' I' _) h DosFlash
$ {3 {; G; k2 O9 f# C- press return
$ e, b* t9 @/ w) }! P5 A- during scann of the BenQ's port DosFlash16 will ask you if you wanna resend the mtk vendor
* \2 M. A2 p; {. ?2 W% I; U intro cmd, press Yes
! w* Q( y) {+ y. Y' G: S- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,7 U' k! \) j% l) q" X
this will change during the next few steps7 J6 V0 ~" C: n/ V' g
- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD1
* C @) h7 t7 y! U) W: [8 Y- turn on the BenQ psu, you should get a good drive status 0x73 and flash access is granted
' P9 I7 ]8 p% L5 M3 B# }- you can now continue as usual using DosFlash
; i3 y8 h- f( d" H1 e2 c( e' S- writing and erasing works the same way0 O* j* k' y. P
- if the ports are scanned there is the possibility that you'll get the resend question for
& e: J4 i O3 o6 y3 C other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,
( G( ?! ] M. f8 a if you know the NEC is at that port you should press No and press Yes only if the port of1 ~2 C+ ]+ O5 Q8 `. D# ^
the BenQ is shown or simply disconnect the NEC3 w4 ]- g8 ~& a
+ I! M7 f% n( }4 I5 v! @: M# d$ b+ w; V/ w( p3 P9 W7 S1 I
Soft Flashing the BenQ in Windows XP with a VIA card or NForce motherboard and DosFlash32
. ]5 T% N& y( i' B! Z-------------------------------------------------------------------------------------------" C8 l( V5 w& ], G
- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
$ D$ J; n6 ^, j# G. M) ] Xecuter Connectivity Kit)
$ X$ @- d8 ~- J- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we8 t4 V u+ r0 J) S
need to power the drive off and on during soft flashing7 O+ Z% [' D! ^" x9 Z/ Y9 V1 g2 d
- cold reboot or reset the computer4 E4 L! D! ^1 v, r
- turn on the BenQ psu when you are in Windows XP- ]3 y1 Z1 }: [0 M' g( U, b. X( ]! p
- start DosFlash32$ z) r1 k5 a/ _. R% I8 \3 y
- DosFlash32 will ask you if you wanna resend the mtk vendor intro cmd, press Yes- @# v& l9 f7 J0 Q# x
- turn off the BenQ psu and wait 2 or more seconds
) |; }! U3 ?3 K- turn on the BenQ psu, the DosFlash32 dialog should show up6 [( @0 p4 `0 U
- the flash should be recognized by DosFlash321 x. P" H2 u8 r) J
- you can now read, write or erase the flash
! i! Y, a. D# i# p/ \( p% O- you should be able to do the flashing more than one time in Windows, only do the power
; B" ?, a4 j! q! ~ off/on trick again1 ?2 _- W9 [0 ]/ W" s
- if the ports are scanned there is the possibility that you'll get the resend question for' X4 D6 ^5 j I/ P
other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,5 H* }4 X2 Z% a; W3 D' n$ O9 u
if you know the NEC is at that port you should press No and press Yes only if the port of
, B( e* ~' z7 F" {3 [ B7 e the BenQ is shown or simply disconnect the NEC
5 S$ q# K7 _/ E) ?
' y; m$ H* T4 B) z- ?* c1 K. `
- o* q" D6 u8 B* X, l; K( V$ ]Many thanks to jumba for the great idea of BenQ polling!) G: X2 [3 e8 @. _) Q! y" `3 U4 _
Thanks to Iriez, Jumba, Redline99, TeamModfreakz, Tiros and all the IRC people for testing
% f) J$ U- W% r- m$ [6 Xand support.
4 M1 w% m5 S+ n$ [/ ?6 P6 Z, t4 P9 D5 O' ?; p1 g c* x6 y. l
Join us on IRC efnet at the channel #dosflash for support." X- _2 N- s5 I" P0 @- ^
9 m L2 U$ s& `. ]& B: J
Don't brick your BenQ!
. B: A: j" z2 ]+ U1 _Kai Schtrom
. F/ `' g6 r6 i8 j- Y' ?1 n
5 U- R. E. Z0 ^6 o; W9 |2 j! D) @! i" j8 B; ]
************************************************************************************************
8 |- G5 @" r! p) W$ @" A. U5 e) x3 j8 r5 X" p0 x( |6 t/ @
& f( R. \, a8 E K+ Y7 v& P# V J
DosFlash and DosFlash32 V1.2 Beta
7 t2 F, b) y4 {4 x2 {" c$ S-----------------------------------
! c! k/ h2 T' R9 B- bug fix for BenQ recognition
. v2 }" U8 y6 R! I" v5 ]! k$ L# u - manufacturer and device id are sometimes 0x00 for a correct installed switch+ }( I5 R+ L% i- }: V D2 X$ b
- this issue is fixed with an additional ATAPI device reset before the mtk vendor intro is sent
3 U; W1 C) H, z1 q0 X
/ Z8 x4 x% Q; {- M, a# kThanks to Redline99 who fixed my buggy code by adding one line! : p# v, x5 n8 [4 V( L* Y' j+ A) W
# r" `/ O# V$ u% S/ x* J) H. f
4 D# a2 k& S# G
************************************************************************************************: p+ K' ^! V2 a8 Z
- F; m. j9 G/ y+ x+ A( u2 l
5 C% T6 }" b( f& C& X- r+ v$ ?DosFlash and DosFlash32 V1.1 Beta" w; v, }; \/ Z9 s; A
-----------------------------------/ h' c- p7 x1 Y2 @
- DosFlash.typ modified for better BenQ support
" Z4 r; @0 P: X( L, X- DosFlash16 Flash Manufacturer and Device ID screen output restructured& Z' f! m# r/ e2 h7 f1 v6 L" h, {
- flash chips are first erased before writing starts
* Q8 |2 q2 Z5 Z8 k. y- DosFlash32 no reenable of DVD-ROMs in device manager after flashing, this means you can't see the drive
; Y/ W/ h+ I0 f. E9 o5 P and maybe have to activate it manually again in device manager, this could give better compatibility and# a; ?% t$ Y. Y6 l$ I5 j1 s
hopefully no more blue screens8 Q! E, @: Y: R
" Q, a9 n/ m) ^1 ?
Many thanks to Jumba, Redline99, TeamModfreakz and Tiros for inspiration and help!
/ S1 o( c# ^' q9 Q9 M. q4 W0 ? d m4 H, {; ]. @+ F
7 G% {4 Q. m9 {) F. y************************************************************************************************" i* H0 x4 b: z& Z& Z C
4 Q6 x# V" s$ I2 n9 z! G
, [' ~; Z$ s# C& c0 V1 K; O D& @4 oDosFlash and DosFlash32 V1.0 Beta
$ _0 k; V( I: _3 ]0 G-----------------------------------
2 v; h' f/ r, [ T* c3 @DosFlash can be used to read/write/erase the flash chips of most CD/DVD-ROM drives3 X) Z) J1 B/ D' h
that have a mediatek chipset installed. DosFlash is for DOS flashing, DosFlash32
6 Q' C% v3 _7 l4 v s. N! ]1 Ufor Windows flashing.9 f" L/ ~1 k/ G% ?/ j
% ^+ k# L8 r+ ~' s H) i
2 `7 |' @0 T4 z4 w7 ~ E, q, A
Features:' \5 Y1 Z I) B6 [; f: Q, g
-----------# h" m4 B0 `- p# a0 f2 ?
- flashes IDE and SATA drives+ J' U2 N. Q# I" Y" q( f7 D
- supports parallel and serial flash chips
7 {; d3 K8 m1 ]- flash drives in Windows with direct port access0 z: C3 |3 B# v4 F
- no vendor cdb flashing commands are used& ~: E( @7 {! i( }5 i1 Z. g! Z
- tested with the following drives:8 \0 [! e/ ~& Z; M) }1 ~
- TS-H943A MS25, MS28
, r+ o1 d# X% b8 \6 A7 Q - SH-D162C. n K* d; A0 O# ^0 z
- SH-D163A
, Q; C% A( A. | - and some other drives like Liteon, Hitachi, ...7 d' D' a) V: U& j `/ x- Y
- NEC drives are not supported, cause they have no mediatek chipset installed
( W! L: v9 T! A: ~# V 4 }! c: x) u5 b- ?) ?
, R& ?8 x3 f8 P: I- q
DosFlash6 p" n# T$ d7 {$ ?6 p4 \! p
----------
# }6 h$ o! ^" [, M" }( q) tDosFlash supports two flashing modes, Auto and Manual. If you type DOSFLASH at a DOS prompt it4 s8 o) P& i; n
will start in Auto mode. All drives and the corresponding flash chips are detected automatically.; u% D" a3 J4 V. H- Z% L' m, E, ?
If you can't get a flash chip recognized due to a bad flash or other problems you should use the
7 m* B+ e F& q& ?' [! `) _ ~/ @Manual mode. In Manual mode you can enter all the parameters used for flashing by hand. The# n" ~' U* H; E# n9 R
following help screen is displayed if you start DosFlash with a wrong number of parameters:
$ t& @" J! i) @4 u; ]5 l( A9 o+ h& @* [" c
" d8 i8 @4 S6 a3 u b2 w
DOSFLASH by Kai Schtrom, 08/05/2007 (Ver 1.0 Beta)- s2 K: ]! @) P* F* ~: M) R! D, M
DOSFLASH [R|W|E] [PORT] [PORT TYPE] [DRIVE POS] [FLASH TYPE]
* P. n1 A) Y( c' O- P) {; E' \+ P% D [FLASH SIZE] [FLASH SECTOR ERASE OPCODE] [FILE NAME]
8 A! B, G8 V1 b1 z. ]) H% g R: Read FLASH, ^, q! Y& ~! O, c, K
W: Write FLASH1 S0 x' G8 z1 H2 |& J+ l# M# ]) y
E: Erase FLASH
) C$ T# c& t$ c& @ PORT: Port to send command to
3 [- q+ J l3 C* L# [# J PORT TYPE: 0 for IDE, 1 for SATA- D9 n3 y9 E+ J/ n5 j$ }: f
DRIVE POS: A0 for Master, B0 for Slave
6 j2 d8 U A4 S FLASH TYPE: 0 for parallel flash, 1 for serial flash" p0 b. l7 V6 s
FLASH SIZE: size of flash chip in number of banks
$ }' G2 t! x$ e/ J# \3 h( o) y$ DFLASH SECTOR ERASE OPCODE: individual sector erase opcode command byte9 b6 y4 E8 v8 U
this is only needed for erasing a serial flash
2 i* F1 X" N7 X2 f% I FILE NAME: name of the file to read/write from/to flash4 c& S$ b+ Q2 X8 Y d: Q' D, R
All numbers are intepreted as hex values!
3 e$ G- `' b7 {- G% W( `
( G- E: F* k; s! Y- y h' X, kExample Usage:! p! O) I) g1 B
"DOSFLASH R 01F0 0 A0 1 4 C:\flash.bin"" p- ]$ k' ~. E, _
=> Read serial flash with a size of 4 bank (262144 bytes) from Master Device0 ~3 y. R3 w# J7 o6 W) k
on IDE port 0x01F0
S( m( D- w2 K# N3 H"DOSFLASH E C000 1 A0 1 4 D8"0 b- }# a" A% A( S* x: G7 B
=> Erase serial flash with opcode 0xD8 and a size of 4 banks (262144 bytes)
% y& X: A s$ _0 @ from Master Device on SATA port 0xC000- | h9 k2 N# A
* y8 {# g4 P9 m+ L- V 4 U; D. [/ w* t( v; x9 w
Explanation of the Parameters:
. e' `" E& _9 |5 F- B3 ^--------------------------------
$ Q8 R4 o: ]) _" M* x8 i
( S, i. l/ D( N[R|W|E]! I0 ^3 j: I0 _/ S8 [% E
---------
: B o* W/ t1 @2 H' e' I- o- this will set the mode of flashing, it is recommended to first try read on any! n: _# `6 u, P
drive, if the read will fail, it is highly unlikely that a write or erase will
) Z; G2 J0 x( d3 R# ~" r9 ?$ F3 ? succeed7 i3 [. z3 f1 }) _8 K
2 V1 g( y3 V; r R0 E: P[PORT]
- Q. a1 {2 {/ X9 z" s% V$ F& k& w--------
& h; \2 L$ {$ _, y- the port to which the drive is connected, a port number should always be entered
! W1 @1 E% b* [% a( s+ V& o) w! f in hexadecimal and have 4 hex digits, valid ports are: 01F0, 0170, C000, C800- c0 v! j1 e& e \
- this option can be used if your PCI adapter card or on board IDE/SATA ports are
: t, O& s+ d# x8 p3 w+ ] not identified by the auto mode: T4 X$ W! t2 t8 S
/ @+ ]* \' g6 f7 \# F$ J' e[PORT TYPE]6 ?8 P- [! T5 q B& _* s" U$ C. e) e
-------------
) |3 ?0 S1 L) f; M- the port type tells DosFlash what type of port is installed on the before entered" _' T0 M6 e! o( K d3 d" [) N
port address/ }( I. o+ B# F! s7 ?
- valid values are 0 for IDE and 1 for SATA1 W, }& U6 L7 u; a9 X
- make sure you never mix the wrong port with the wrong port type, this could give
L6 Y; e6 O. r2 W strange results or in the worst case a bricked drive" g5 |- ]: m6 f$ |: S
) d5 w/ Q8 o5 F3 F& g% K% q
[DRIVE POS]
# V4 G. S. B' X- [+ C7 L-------------* N; e2 U! G% l( t
- old style IDE channels have the possibility to connect two drives at one IDE6 c! E4 h( d) Q' X) G9 u
channel, the first drive is called the master, the second drives is called the
& T/ t+ O, P/ w; G3 E7 J" y slave3 t% D+ y8 O1 s, n7 Y
- you can select which drive should be flashed on the channel, A0 selects Master,
; t1 V) L. G. K( B B0 selects Slave
/ d: Z& H, m: h/ ~- on SATA ports this value is always A0, cause you can only connect one drive to( s$ ~, \2 i) F( C @
a SATA port, so for SATA you will always type A0 here- z3 h: F- G4 C( L6 }( y. w
- it is not recommended to flash IDE drives with another drive connected to the
4 K/ X9 \# m2 q1 x same IDE channel, this could be risky if something in the Master/Slave selection l U1 |, W; N' {( ?" r
fails2 @' {) H8 L. r
& D/ P$ g; Y6 X. D! ^' V) `* A' J
[FLASH TYPE]
/ x5 ]3 j: _4 Y. W% J, h. X--------------
6 R& V0 M+ j! g! V( H! T- z( p- there are two types of flash chips out for CD/DVD-ROM drives atm
3 W4 d8 r0 d" p0 H4 J- the older type is parallel flash, which is also supported by mtkflash for example& }6 D5 \' Z2 d5 C+ s6 Z
- the newer type is serial flash, which is supported by flashers like XSF9 ]3 Y8 H3 K/ ^5 s
- the problem here is that no tool is out that can flash serial flash chips on
( W1 f8 f& p6 |/ D! L SATA ports- z. D+ R- G: H7 M
& X9 ]% \ `7 b1 \& G6 g/ ][FLASH SIZE] J- U: i' R( H. W( ]9 w. i9 ?- D
--------------6 \4 ^# j+ W. L
- this is specifies the flash chip size in banks
8 K, v5 p% B. J# h1 Z% M' `- one bank is always 65.536 bytes in size5 u, e& C2 | o- B- X C, @ U
- if you know your drive has a flash chip of 262.144 bytes in size you need to enter 4& j+ X3 y! g$ Y% _8 j# n+ y4 _
! l9 _ f4 T7 f
[FLASH SECTOR ERASE OPCODE]
0 x: G" q. x9 x- w-----------------------------* _: d. z V2 ]* Q
- the opcode used in the flash chips datasheet for erasing
8 `$ _$ @* a6 }, d- X- for serial chips this command can be different from the standard and needs to be
3 Q( |; v" v1 ?1 H5 L entered for flash erase
' M( c# }0 H' }; B) j2 c- for parallel flash chips you can enter a dummy cmd byte, the integrated command
+ k4 G. n4 e! ^3 f. ~ should work on all parallel flash chips without a prob, R& K7 W5 q+ b* Q) m" m
" v b* k1 c: [3 u( j[FILE NAME]0 @; v0 H4 f, H; U0 G
-------------
% N. r2 R6 I; L/ b0 G0 P- c- name of the file that should be used for flashing" \, K9 C" i/ X$ D- M; a4 \- ^
- for reading operations this should be the output file
Z4 x \" f0 ~; T- for writing operations this should be the input file
8 [7 \& p& e$ S; G7 h3 z: B$ x& l6 U V& ~& o
' i9 a5 R' N- M) q% Y/ Q" D& x
Hints and Warnings
, H; c& H- n4 u4 Q5 k--------------------
) W/ `* @% t7 f4 r9 e/ H- read, write erase TS-H943A MS28 after the firmware stealth has been disabled with Enable0800 disc
& i# ~1 Y) s& j! i" ^ - this only works one time, after the first mtk vendor specific intro cmd is send2 @& j) p; h, [
- if the mtk vendor specific outro cmd is send the chip goes back to stealth mode and you need
/ {. d4 ]3 F ~5 O8 s! F$ `! O again the Enable0800.iso to disable it& O: Q' Q, u" O9 k& o. ~; ^7 h" ^6 H
- therefor the mtk vendor specific intro is send at program start to all present devices and the
- ~) b) S" o7 J- N4 }4 r) z! T% {% ?+ J mtk outro is sent at program end1 F$ `$ f6 E, S
- if you have a chip manufacturer id of 0x02 and a chip device id of 0x02 for the TS-H943A
! G# ?& d" \+ y5 S. V: f the flash chip is in stealth mode and won't give access to any reading, writing, erasing
( V/ H, e- S- e- always have a look at the DataSum generated, this is exactly the DataSum of mtkflash
$ {8 M+ \2 h" u; N8 } - the DataSum is calculated as the sum of all bytes of the firmware in a short integer/ \( ]. d# o4 t' n/ d0 [/ a
- to make 100% sure that the flash is written right compare that DataSum to a known one
' [7 H6 ]+ e. A6 I8 M- this tool has not been tested on all drives out there, the typ list is simply copied from well
1 @0 z# O, w( v; n3 { known programs like mtkflash and XSF
* Y4 H9 l0 v$ ? - always try a flash read on a not yet tested drive before doing anything else
1 K, P* ^. h- o2 f! z - if the read doesn't succeed it is highly unlikely that a write or erase will
# `3 W& J; j) \8 U+ y- @$ T( O- some LiteOn drives seem to have probs to write the firmware correct, this prob seems to be
7 I5 N. T- X) E% n$ _' p, z# m8 H related to windows register flashing, cause even an assembler app can't do this error free
3 T0 Z- E P6 A) [3 } - if you get errors on LiteOn drives, write the flash two times in a row4 E" T( Z" _, U- G8 C8 I9 i
- for direct port I/O in windows the givoio.sys driver is used, this driver is loaded at DosFlash32; Z9 S+ ~$ L3 T j. f8 n" H5 o `
start and unloaded at program end, be warned, this driver can possibly make your system unstable,
* e z- \* _( o3 ^ it's intention is to let privileged assembler instruction like in and out pass, even in windows,
* E. Z+ o6 ~$ A if this driver is not used you will not be able to get direct access to port registers8 p- q. i' _% u+ p/ a9 P8 R3 K
- DosFlash was tested on MS-DOS 6.22 and later, you can easily copy it on a MS-DOS boot disk created
, F7 S1 ` Z9 g5 Y5 c: y# n) T8 j in Windows XP and start DosFlash directly from the disk
: X5 w: F6 P9 e( p9 }( ? {$ V- don't forget to also copy the DosFlash.typ file, it has all the informations about flash chips- L+ D' q" N0 c( V' X0 d) s0 d, |2 f/ e
for auto mode flashing
6 B# X, W; h& B& y2 e/ L4 h" f- DosFlash32 was tested without a prob on Windows XP SP2, you'll need also the typ file for the # O9 i/ }7 g& X% W
win version
8 k* s/ C9 p, H- DosFlash32 will deactivate all CD-ROMs in device manager at startup, this is better for flashing,
0 J; {* ~" w5 t+ ^ cause Windows seems to poll the drives all the time and this could result in a bad fw file or
$ d" W0 X2 r* [ a program hang, the drives are activated again at program end2 k3 u7 g8 k( \+ |& A, ?
- you should make sure that the flash is not in an erased state at program end, cause device manager- e8 a) j. q. A% g
don't like drives that do not respond to the inquiry command
4 Z. `) i% E- F4 H7 D- deactivating all CD-ROMs could take a few seconds, so please be patient at program start7 t. x# h3 |, \% f! P: I# N8 \: V
- DosFlash and DosFlash32 will try to scan for the VIA 6421L Raid Controller card, based on vendor
$ B* M' H' |" V( C% S. {( X9 M id 1106 and device id 3249, it doesn't matter if the card driver is installed or not6 Q" z7 @7 G) L5 b( G. T6 Y
' u2 ^3 C7 i5 H4 ]9 `3 M& d
* V* r1 y' q" x/ S4 D+ p; X
Many thanks to Dale Roberts and his Direct Port I/O driver giveio.sys!& k& P, @, }2 l$ f X; I
6 o$ d8 ^% r% r, { D) m( J% F4 eAvoid a bad flash!
9 x. p0 [; Z! W7 Z4 cKai Schtrom |
|