設為首頁收藏本站

黑皮論壇(手機維修/電玩維修/電腦維修)

 找回密碼
 立即註冊
12
返回列表 發新帖
樓主: ak475671
打印 上一主題 下一主題

360舊機軟改問題?

[複製鏈接]
16#
 樓主| 發表於 2011-8-21 17:46:22 | 只看該作者
^^版主你好
# V$ d3 n2 s: N我有按BENQ UNLOCK這個選項不過還是沒辦法解鎖不知道為什麼因為我是P4主機然後使用網路上所說的3112晶片的SATA轉接卡進行刷機布過可以讀到360的64930C卻無法解鎖想說會部會是需要主機板本身也有SATA介面的電腦後來試了有SATA的電腦後發現電腦系統是WIN7好像需要使用XP系統才可以進行刷機( p* o7 X; i0 c& Y. d; Q
因為WIN7好像會抓不到360的光碟機
17#
發表於 2011-8-21 21:08:07 | 只看該作者
ak475671 發表於 2011-8-21 17:46 2 s5 L/ c- r* g% A
^^版主你好$ n6 f6 G- o9 M) {( T' l  d/ c2 e
我有按BENQ UNLOCK這個選項不過還是沒辦法解鎖不知道為什麼因為我是P4主機然後使用網路上所說的 ...

% Z) ^3 ]: H/ i$ O8 `如果您在Windows下無法解鎖的話可以試試用純DOS的Dosflash工具,
- Q2 s) Q: ^. M1 K5 P不必像在Windows下要解鎖才能讀取,BENQ在DOS下取出韌體比較容易,
- g1 T' _8 h* q1 q2 ~$ \* M也比較不會挑主機板的SATA晶片組,DOS讀出來後再用JF開就行了。
18#
 樓主| 發表於 2011-8-21 22:10:48 | 只看該作者
Dosflash目前想要提取key使用哪個版本比較好呢^^* m4 n7 `7 m$ X8 ~' i/ ~: c1 _
19#
發表於 2011-8-22 12:01:38 | 只看該作者
ak475671 發表於 2011-8-21 22:10
" M/ Y4 A( l* w" w7 M! ?2 ]Dosflash目前想要提取key使用哪個版本比較好呢^^

8 t+ d6 d" x1 vDosflash v1.9版,它是取出整個韌體,
6 f* T7 N* I5 V2 V  ?* H不止是取DVDKEY而已。
20#
 樓主| 發表於 2011-8-22 13:03:21 | 只看該作者
版主你好
! C& J1 X9 p* s  f% ^版主知道哪裡有教學嗎使用DOS提KYE的過程不是很了解不知道有沒有教學可以參考的呢* J2 Y, {8 G+ }
另外你說他提取的是整個韌體而不只單單DVDKEY而已這個不太懂一\般向JF所提去的是單單只有KEY嗎如果Dosflash v1.9版把整個韌體包含DVDKEY整個提取那光碟機本身不就沒有任體了然後用JF把DVDKEY刷進光碟機裡布就變成只有DVDKEY沒有任體??8 o4 O- d$ ?8 s% @
% u  h0 Q% I- ?+ \3 u
再麻煩版主解答一下2 B0 [6 @' h- Q" ]) y# {! S+ w
! u, ?6 n+ K3 _+ ^6 q( _* a
謝謝版主~~
) i/ }& e. X8 d- {8 ^
21#
發表於 2011-8-22 13:31:06 | 只看該作者
ak475671 發表於 2011-8-22 13:03 9 B4 Y, S, v1 X+ t4 o1 W. J& Y1 w
版主你好
  @7 k, n: C7 z3 |版主知道哪裡有教學嗎使用DOS提KYE的過程不是很了解不知道有沒有教學可以參考的呢
3 p, ^9 v5 I$ e8 E另外你說他提取 ...

. ~, @4 W  G! N/ h4 g' v3 TDosFlash ReadMe.txt 說明文件
0 ~/ c! M7 W' r% R5 |0 B( N, a7 a. j/ `9 d! M- @
DosFlash V1.9 Release Date 01.01.2011
3 R. w3 V! u; A' V9 l2 J---------------------------------------+ p/ n- ~) M  e0 }) F' t
- SATA and IDE port scan improved in DOS and Windows
# c2 f5 z, o. {$ r! |" C  The ports are now enumerated with the CONFIG_ADDRESS and CONFIG_DATA register instead of using interrupts
; I" j. |# y8 n( i  in DOS and SetupDixx functions in Windows. This change will detect more ports in Windows than the old . T( X( q. h) c: v
  SetupDixx method.& U$ z0 O% F5 j9 k% v) V
- Settings saved to ini file for DosFlash32 and DosFlash64
$ A  W& v6 H' ?( o  m8 ?7 p  Settings like Port, Position, Task, COM Port, Enable Drives and DvdKey state are now saved to an ini file' u) e" e/ K( v
  inside the program folder. If the ini file is not present it is created after the first run. On the first; c0 N4 v/ n4 {9 W8 ~' ^0 |8 l# Y
  startup DosFlash will choose the most common and stable settings.
8 P! F0 o6 E* ]' j! f+ \) T' P- EnableDrives option included in dialog as a check box
1 q6 Y1 x, y5 Z6 e2 X" b& J8 g7 R  Due to high demand we removed the "Enabling CD-/DVD-ROMs" MessageBox on program termination and included
0 n$ s( Z, N# q5 C5 n: J  a check box "Enable Drives" inside the dialog. For security and more stability this is deactivated on the
5 M2 V: J/ U! T6 r( |% N  first run. If you enable it the checked state is saved to the ini file.4 C/ s& t- f4 W5 Y
- enabling drives in Windows caused some hangs from time to time, this is now fixed by a recoded enable
; O- b% X6 x3 {  drives function7 Z. j$ ]0 s, C, ]; ^1 j0 N
- port drivers portio32.sys and portio64.sys are now added to the executable and unpacked during runtime" o" v+ u9 f0 [% y1 q9 k4 E6 B& u
- PATA and SATA controllers list updated- H, V& k5 `9 b" k. d. c& U
- Fix for NForce motherboards in combination with drives like the "Samsung SH-D163C", "LG DH18NS40" or! d; c9 e  l& ~' T1 z8 ~
  "LiteOn iHDS118"
2 C0 w  |& O( x2 Y  Some drives have problems with flash identify, read, write and erase. This is clearly related to the
5 d* r0 T% `$ r: e+ L  R  NVidia NForce chipset. For manual mode in DosFlash16 an additional command line parameter is added called$ F. ^( V1 ?) W* E: n: c5 O
  "NFORCE FIX". This parameter should be set to 1 for NForce chipsets if you experience strange problems.
" s5 `, z: }  A/ k( U  In DosFlash32 and DosFlash64 we added a static control which shows if the NForce Fix is applied or not.  r3 S! L& `2 L) H) d( D
  Remember there is no need to activate this with every drive. It seems to be a combination between drive
4 M: o5 y& C& c2 ~5 H  and NForce chipset that causes the problem. The fix is automatically applied for DosFlash16 in auto mode,' i9 j  ]- w& M. {. P
  DosFlash32 and DosFlash64.
3 l0 L7 O1 N+ S- f, i- DosFlash32 and DosFlash64 are now DPI Aware for Windows7+ L* e3 ^& x$ k6 |1 p
- New task Verfiy Key/Inject Key added for verification/injection of drive keys& }+ w4 Q' ^, s4 M! u
  All DosFlash versions now have the possibility to validate drive keys against an XBOX360 drive and set
* ~- \6 a+ ^" i- _, H1 p" m8 p  the key for an XBOX360 drive. We use the same authentication method like the console to verify a key.
# J' m" C2 F/ g8 p% p  In the Windows versions you have the choice to paste the drive key from the clipboard to our custom hex/ q5 X6 |( x/ ]5 S6 i" T
  edit control or load a key file. To add a key simply click right inside the hex edit control and select. @$ k* W6 e1 H4 p% u4 |1 r0 a$ f
  your choice from the shortcut menu. In DosFlash16 you can enter the key in the format "1A-2B-3C" without
1 [* T! Z* v. e  quotes. Remember that a key has 16 bytes of data. The key file to import should also have 16 bytes of data
/ J6 a: i9 v6 T7 e+ H. ~$ n  like the key files exported by LiteOn Key functions.* `7 b* t2 j9 o6 W; ]0 y/ \3 t* l/ F
- Removed multiple key extractions for LiteOn Key functions, added Verify Key after extraction2 a- Z6 h. ]# @
  For LiteOn Key functions we removed the multiple extractions, because the key is now verified immediately
2 \( }' M% J' I4 Y- x+ U( ^  against the XBOX360 drive.2 P+ [: X+ r6 N7 \3 B
- LiteOn Key V1 and V2 now also extract the file Serial.bin and the 2nd inquiry file Inquiry2.bin  ]4 Z* P0 b' z, v
  We added the file Serial.bin and Inquiry2.bin to LiteOn Key functions. Inquiry2.bin is only generated for" W  G: E% P, g, |- A, ]3 A- a
  LiteOn drives V1 and V2.. ?. a/ n8 Y) G/ R, N( g
- The drive key of Maximus patched UART drives can be extracted by using the task "LiteOn Key V1 (DvdKey)"
4 S! f1 q; I* ?  D" e  C& L  The drive check has been removed from LiteOn Key functions. This way we can extract a key from an UART % Z4 ~" M( t% e! {- M" ]' ^% K9 Z
  patched drive firmware by Maximus.3 h0 [" P0 c! |, T# `/ s
- LiteOn files are now extracted to a destination folder instead of prompting the user for every file name.
4 J4 @- H: s) l% s5 A- LiteOn key extraction tasks separated per drive version in "LiteOn Key V1 (DvdKey)", "LiteOn Key V2 (FreeKey)"8 A" u! z: [" R
  and "LiteOn Key V3 (Tarablinda)"
6 ]2 A7 m  f+ @( O1 K% T- In DosFlash32 and DosFlash64 the number of installed COM ports in the system are now enumerated instead of* {" c  A9 Q: s
  adding port 1 to 4! b8 d1 h+ Z7 I! _" s- G$ d4 J
- For failing cdb commands the sense code is returned
! R0 z( ]/ y$ O) X- Geremia's Tarablinda functionality added
3 i- e. ]9 h* N$ t( O/ R  We added all Tarablinda tasks to every DosFlash version. You can extract the key by choosing the task7 n+ o5 W* P% g, [* M" X
  "LiteOn Key V3 (Tarablinda)". For read, write and erase of the flash simply use the standard functions.
" i6 Q( z% N7 C- |8 ]+ F  Pay attention that the "LiteOn Erase V1/V2" task is only available for older LiteOns and not for the Slim.
6 s* ~7 z2 ^' R2 l  You should use "Read Flash", "Write Flash" and "Erase Flash" for the Slim. "LiteOn Key V3 (Tarablinda)"
& B+ x. \1 {+ W' o/ {# f  extracts 1 additional file in comparison to Tarablinda v04b, this file is called Xtram.bin and contains8 p$ L5 M- v3 x7 Y! ]& s
  a dump of the XTRAM8000 area. This can differ in a few bytes from one dump to the next.. j) M1 \: [* N; e/ \: Y3 t/ a
- Device Reset in DosFlash16 manual mode is now done automatically, there is no option to turn it off anymore
) d& Y$ ~+ x9 \+ G- Code optimization to work with modern SATA2 controllers added, remember to set SATA controllers to IDE and- U* Z9 ?# }  m0 l/ x
  not AHCI mode otherwise Port I/O will not work4 N1 m. n" u2 P, F8 B" M+ ?% Q# |
- Warning: The read, write and erase of the Slim drive is considered risky in general! So pay attention and! [0 j" r4 A) X: b( l6 e
  always remember you use DosFlash on your own risk every time! Even during flash read the Slim gets flashed
' U" d$ x! t% @( ^: D6 S( L  with a patched firmware sector to retrieve the complete dump!! Q# [8 S) Q* f' z/ ]
- We had to change many command line arguments for DosFlash16 Manual Mode, because of the NForce Fix, added6 p% I% N7 W7 k' a
  Tarablinda support and splitting of LiteOn Key functions. To get a better understanding we added the example. P: o- c# X* Y, w0 y, [9 e
  section below.4 J- q4 C! d" O" ~5 {+ Q- F
# `8 q5 ?2 E- r) V3 P$ h; {

( R3 Q6 ]" `9 g5 iDosFlash16 Manual Mode Examples
1 F1 U) \% }+ s, y& r; n) }# z---------------------------------
- B( b/ f" e! z7 k/ H3 M9 y- Extract drive key on a "LDS DG-16D2S 74850C" over UART -> "LiteOn Key V1 (DvdKey)"' ~0 u' D8 f+ U0 d* D0 M
  DOSFLASH LITEON K V1 0970 A0 1
  Z8 P5 B; K/ V3 X: v5 F/ j7 |' D0 j% M+ t
- Extract drive key on a "LDS DG-16D2S 83850C" over SATA -> "LiteOn Key V2 (FreeKey)"
. l$ V$ w: x# C# D! w  DOSFLASH LITEON K V2 0970 A0/ z5 u" M; h( k, O% {" N! D. Y

" X, K* }. K: X9 ]  h- Extract drive key on a "LDS DG-16D4S 9504" over SATA -> "LiteOn Key V3 (Tarablinda)"
6 }9 S+ [( q4 a, t3 D$ M  DOSFLASH LITEON K V3 0970 A0
7 A5 {. z8 Y: }1 ]" j  \& h5 G% e
- Read firmware on a "LDS DG-16D4S 9504" -> "Read Flash" this is considered risky!
7 P' e+ m- ~" _  ?6 s1 T  DOSFLASH R 0970 1 A0 3 0 4 FWOUT.BIN 0
5 m) ~0 x0 X( s8 m4 E
' |, u  ]5 G) V/ J9 A- Write firmware on a "LDS DG-16D4S 9504" -> "Write Flash" this is considered risky!
; x; I7 u) M1 X) I* {& |8 j  DOSFLASH W 0970 1 A0 3 0 4 FWIN.BIN 00 Y) {! P( |% C5 }7 m; B3 I
- p+ l" a( y1 q. h/ \4 b  H- ]1 C2 F
- Erase firmware on a "LDS DG-16D4S 9504" -> "Erase Flash" this is considered risky!
/ u3 C& f' p2 c5 D4 p  DOSFLASH E 0970 1 A0 3 0 4 C7 0- p, n) h( X9 L% c! ]5 V

3 |- G9 U& z. |3 W- Erase firmware on a "LDS DG-16D2S 74850C" or a "LDS DG-16D2S 83850C" -> "LiteOn Erase V1/V2"" V3 a' ^/ W/ Q4 V% d
  DOSFLASH LITEON E 0970 A0+ N* f$ y/ Q$ f2 E

$ ?" F; V" ]* F" X9 n6 Z8 |8 q- Read firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Read Flash"
) Y4 \& M$ E/ y1 E& g/ D  DOSFLASH R 0970 1 A0 2 0 4 FWOUT.BIN 1
* `2 h! G# Z, a0 M3 D
- z7 m; R0 s1 D5 m$ i' r- Write firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Write Flash"9 c2 H0 L2 [- o# _* p8 u8 r
  DOSFLASH W 0970 1 A0 2 0 4 FWIN.BIN 1: x0 Y/ l) A. e+ N+ R: M; M- B$ ^/ R

) l& q$ h, B, I1 z8 b0 j- Erase firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Erase Flash"
8 s; V( D1 Y: e/ X% g' ^  DOSFLASH E 0970 1 A0 2 0 4 C7 19 s8 W; T4 {9 H

$ b7 T2 Y- ]* l$ J+ }- Verify drive key on a XBOX360 drive, enter the drive key manual
# }, m+ R0 T2 x  DOSFLASH V 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF" K! }9 P- U# \9 w9 P) s, J

2 m" A' @" T6 q/ Y3 o- Verify drive key on a XBOX360 drive, load a drive key file2 D4 R7 p' X) r8 ?
  DOSFLASH V 0970 A0 KEY.BIN: c8 [1 g5 I; c# n5 @1 v, l, A
& [% z  g" o( y- F' B
- Inject drive key on a XBOX360 drive, enter the drive key manual" j! t, u- B) n7 k) h, n# ^/ I
  DOSFLASH I 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF
, f( ?8 W; v0 d6 G# [9 |
) }9 G* X3 _4 h; Q' d5 z" y* |- Inject drive key on a XBOX360 drive, load a drive key file, t  S6 |* |" }. S5 |: O
  DOSFLASH I 0970 A0 KEY.BIN
& s/ P, H  _, [7 O/ _& F3 `  Q+ Z$ F, {* E' M) p; o
For DosFlash drives on which we can extract the key via UART are considered V1. Drives we get the key over2 t8 p6 v/ D7 Y
SATA are considered V2. The new Slim is considered V3 but only firmware version 9504 is supported atm.8 t. h, Q; M! A: n, Q
1 X' O' s1 c* |& P+ D
8 d7 m; `# F3 M% `/ L4 s
Many thanks to Geremia, Modfreakz, Redline99 and Tiros for their support. Special thanks to Geremia and: K2 Y; |8 Z9 }  ?9 y
Modfreakz for drive sponsoring, testing, coding and much more. It is always a pleasure to work with you! \. S6 t, x; }. d
professional guys! Respect to Maximus for his UART enable patch. I'm looking forward to your magic Lizard2 P7 n+ p7 K; R6 h( k/ i
hardware flasher!
$ g( f1 X0 V# o6 E' F/ {2 g4 |- F0 y9 [
Happy new year 2011!
0 d$ u+ m8 o! h2 d- zKai Schtrom% J8 G% R( D- g. C9 j9 y
6 N; e/ U* b1 C! F
************************************************************************************************
* S+ l2 d- ^' d. v" A" u( {- ?3 i/ r+ z$ N, O1 i
6 f, `$ Q. Q% C3 W9 M
DosFlash V1.8 Release Date 08.08.2009
  s1 ?2 l; s- \4 G5 R---------------------------------------- _+ [2 |, _7 ^6 A( V
- now supports LiteOn PLDS DG-16D2S 83850C V2 Geremia/Maximus LiteOn FreeKey method- ~3 d9 g2 J' {' d6 E+ j
- huge firmware read/write speed increase, especially if run from a floppy disk' C0 @4 V9 a- S% t6 }
- updated IDE/SATA motherboard chipset list
6 A5 h' E# K  e% }- E- new IDE/SATA detection for Windows and DOS' z- v1 b. Q. C* |$ s" @- A
- DosFlash.typ embedded in executable file5 V9 x  O4 X2 I3 y  T
- LiteOn V1 drive key is now extracted 10 times and compared against each other,% V$ j$ Q. O/ o; i3 l4 c
  after the extraction a summary is displayed sorted by the most common matches
/ i4 ]( V: X6 `4 t# ?: ?- LiteOn V2 drive key is extracted 2 times and compared+ u) e8 e* [5 Q& a# U/ K3 V1 R
- new BenQ unlock keys added to unlock all known BenQ drive firmwares: R, a* d4 `4 I% b( b! Y
- command line parameter "EnableDrives" removed, DosFlash asks the user on
: e( e9 @4 _$ d0 O" s, }% G  application close if he wants to enable the drives or not, during the tests it; P: v2 X) c2 R) a0 M) j
  seems that IDE drives have problems with the enable, SATA drives seem to
+ O& T9 \2 M0 z/ x! d  work fine
: a7 x8 z$ l0 c) z- new 64-bit DosFlash edition added called DosFlash64, because some driver! Z8 b. }# o- W; q* a5 k. P# Q4 K
  functions don't work as expected in the 32 bit compatibility mode on Windows x640 `- ]$ V& t3 g1 @' Z8 g
- Beta state removed
" M. {( F# D1 K$ Z- ready and tested on Windows7 X86 and x64) |1 x  k/ ?/ A: ]/ l1 u, B9 `7 i
: T0 ]5 E8 J# I" u% H' }

" `1 p% o' i6 |; E/ V& [+ OGeremia/Maximus FreeKey method with DosFlash167 S* {- f* A6 V( J% a4 j9 K
------------------------------------------------- L) p+ z$ R$ G7 j, l: {
We have added one cmd line parameter for DosFlash16 in manual mode. The COM port8 f$ D( M7 T6 H+ V7 b
is simply ignored and can have any value for the V2 drives.
% h( t! G( x1 t6 Y' E3 GUse the following command line to extract your free key from 83850C:5 ~: X- o2 f- G: L- c& m! j
- DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin enckey.bin
8 y, m9 z) W2 J# z: k9 w1 ^8 e3 B( S" P8 V4 C4 s' i. W' d
5 T6 ~4 b' o) u: V& ^; W
Tips for running DosFlash on Windows 7
& A$ F) w6 y" Q----------------------------------------
# i0 k3 |0 y' C; ], \" p, ]
4 B7 C6 X- h& R# t! Q( eSince Windows Vista 64 Bit and upwards it is necessary that every driver is signed. Because
+ y1 D- K+ B* I1 o& n* N# Zthe DosFlash driver will not be signed by MS due to some unknown reason we need to circumvent( C' f+ S, N" k. p5 i
this check. You have the following 2 possibilities to do this.
8 h: B& v" Z1 K0 c
3 m; i) M0 Z) a3 CSafe Way of Disabling Driver Signature Enforcement$ ~: e8 B+ Y9 x
1) On Windows 7 bootup press F8 to get to the extended boot options screen
- ?% D  m/ d( O5 J8 ^. e, B2) Choose "Disable Driver Signature Enforcement"
& C/ h8 ^0 z& L/ G3) To start DosFlash right click on it in Windows Explorer and choose& v& z0 z' z( a) A. [% G
   "Run as administrator" > answer the message box with "Yes"$ |' n  f) L/ i1 _. N+ |
4) Short after the program started a "rogram Compatibility Assistant" warning message# F! X/ l* n) F- Y) h- w/ \
   is displayed, you can simply ignore this by pressing the "Close" button
7 w7 q4 u) G( ^. _7 |% u" S( f& f" f2 s* o( m4 ]! |
Recommended Way of Disabling Driver Signature Enforcement
  o, X# Q1 t0 P. f1) Disable User Account Control (UAC)8 V: N: m& z6 S- U
   - go to "Start Menu" > "Control Panel" > "User Accounts and Family Safety" > "User Accounts"$ \5 @6 s3 ?* W3 v9 W/ `0 e8 O
   - click on "Change User Account Control settings"* G! ]; B5 B+ a4 k; @5 B
   - set the slider bar to the lowest value (Never notify) > click "OK"; A* @; L) K# `0 @& s& ~+ }
2) Sign the DosFlash driver+ m6 q  o- |' S3 n
   - download the "Driver Signature Enforcement Overrider" (DSEO) from4 u' _6 w! H; h" ^2 X1 K! O3 {
     http://www.ngohq.com/home.php?page=dseo
, w4 a0 q! U8 ~  Q) l   - start DSEO > click "Next" > "Yes" > choose "Sign a System File" > "Next" > enter the path to
9 a2 X$ c5 c1 l( Z* L- q     the used driver (portio32.sys or portio64.sys) > "OK" > "OK"7 b4 q6 f0 Q6 s* r9 U" M
3) Disable Driver Signature Enforcement) i/ U% K9 I* R; C  H1 ~
   - start DSEO > click "Next" > "Yes" > choose "Enable Test Mode" > "Next" > "OK"9 m3 q8 r5 e& ~
4) Restart the computer1 t$ d2 C, m6 [' [

  V' G' g$ g4 _( \Keep in mind that with the recommended way the changes will have effect on every reboot without
* X/ _4 b9 _% ]doing anything manual. The first way needs to be done over and over again. In addition the second
8 H& ]8 |5 }. j. U0 y& r5 ], `2 Mway can be used to sign every driver that doesn't run natively on Windows 7.
- I9 j  t2 Y7 q  O
7 ]( H. p( o# Q6 f4 \For use of the VIA Cards in Windows 7 it is recommended to uninstall the VIA driver. This can be
+ l" _% y) W1 p7 ]done like follows:# R) V% G" P+ o" s
- start "Device Manager" > expand "Storage controllers" > right click on "VIA RAID Controller" >
8 J  H0 N1 y% u: }! u2 A. G1 P  choose "Uninstall" > "OK"
8 V  I/ @6 G$ }; h. g! Y- rename C:\Windows\inf\vsmraid.inf to vsmraid.inf_
( R; [5 z- ^4 d% F! O- rename C:\Windows\inf\vsmraid.PNF to vsmraid.PNF_
9 q& v: H; b# e6 [! o9 Y& Y/ f- rename C:\Windows\System32\drivers\vsmraid.sys to vsmraid.sys_
; a! e$ x* C- ?) r; j- l5 A- reboot computer' d+ ^# I2 {/ e* V3 @1 D
  E  ?' x  k: n9 Z

( l9 t, l" _% m; t1 DMuch respect and credits go to Geremia and Maximus for their money saving FreeKey app* [0 a+ ^  I4 C' [& _% \4 u
and their lightning like decryption speed!
1 P+ g, r8 S7 X) p
+ p) |/ ~3 z4 Q2 @In Dedication To The Birth Of FreeKey On August Fifth 2009
. J1 I: H3 {: c- G( zKai Schtrom0 N  }9 |- D1 \& B! _

2 n8 w8 m! D/ J# V# f. b% l7 }! z
************************************************************************************************6 h: [7 w( \4 k% Q3 d

1 x7 D' y5 k, i1 G0 y. I8 a) n
: D: B# c) |, L* M1 uDosFlash and DosFlash32 V1.7 Beta Release Date 23.12.2008
* \, z5 Z. C) @-----------------------------------------------------------/ j. {+ S0 G6 e4 g
- now supports LiteOn PLDS DG-16D2S 74850C and Geremia's LiteOn Erase and DvdKey method5 U  o, W. G; U8 y7 U4 c2 k
, P5 ]8 g; k# M+ w, j
0 [0 c& [; ~  b+ y# b
The following only applies to the new XBox360 LiteOn drive PLDS DG-16D2S 74850C.* b1 Y/ C& g: `2 Q  \

' D. c* t. F4 u+ q1 a& r8 U: c2 V+ V6 C4 \5 s+ d+ F
Geremia's DvdKey method with DosFlash16 with the PC's psu. S- T: K: H. X3 N8 o) V
-----------------------------------------------------------; `8 k' Z' p; u4 _
- disable CD-ROM boot option in BIOS
: K! ?0 G! u: e. E4 n* a# M- connect LiteOn to your PC's power supply unit and SATA port% F( r$ {( h4 @& [" |
- power up PC, wait until bootup is finished
! Q3 \) T7 R0 N+ H8 R$ H- eject tray of the LiteOn and shutdown PC completely
! y2 |1 b% D9 w: g4 w/ Z- push the LiteOn tray half in0 d8 I+ e- S. q
- power up PC and boot into DOS
9 p0 a" [/ E5 I9 R9 n' @9 e) J; r- run DosFlash16 in auto mode- g+ c7 n' `5 e
- if you read the following:$ k7 P) _6 D+ `$ c. {2 P6 ]1 m1 o
  MTK Vendor Intro failed on port 0x????.
( I, Y; @- b6 Y* Z$ d. }  If you choose to resend the command you should turn the drive off and on
% E5 w8 d# b2 U$ X  after you pressed "Yes".
: M  X1 ?- a6 x  Do you want to resend the command until the drive responds (Y/N)?
+ O7 A1 F1 _, x; n  ~$ ^) o9 [( Q- press 'N' for "No"
0 z  @$ R$ N: a# m- choose the number of your LiteOn ATAPI drive
  i8 y- e: g0 Y7 r- enter "LITEON K" to read the drive key
0 Q5 Y% f+ d7 H  B) l" m0 n- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files' t5 `9 I' v% c* @/ T; V) a# w
- enter the number of the COM port
. }* T! L7 i( B* y% |- if you read the following:; H2 H3 ~: @) l5 G! x
  To receive the drive key use Geremia's DvdKey method like follows:2 E! e8 O. A# n
  - Connect your drive with a serial cable to the COM port
& L* v" a' s# [& H" n  }0 }, u  - Eject drive tray* Y2 A0 s/ `: t" N
  - Power off drive  e, b( r1 i1 w0 U$ D
  - Push drive tray in until it is half open
0 z1 @! R9 ~+ P1 @" W3 L  - Power on drive  X, b6 J$ C) o/ P& `
  - Press "Yes" if you are ready' V+ |% j! B% A
    Are you ready (Y/N)?
) x6 U0 s# o) w6 S- simply press 'Yes' without doing anything of the above, because we
2 v- }; c0 l, i0 l1 J: c- o  already did that before2 J  g0 r6 @( Y' F' M' n* C
- after this DosFlash16 displays your DVD-Key and saves your key and identify data; Z9 {" Z. V3 F6 x  m: _! i6 _
- to do the above steps in manual mode use the following command line if your drive
8 }) G* Z) a8 l  is connected to port 0x0970 and serial cable is on COM port 16 K" K6 k& Y* A* q  I
  DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin' K# b+ x, a4 Y' r: J% Y

0 W/ P9 f$ E) ^
; N9 n. E; _" [3 P  K9 CGeremia's DvdKey method with DosFlash16 and 2nd psu
& r9 s6 H4 ?( q7 ^1 e# B9 [-----------------------------------------------------1 {- K! M1 _. t/ ^/ z
- connect a separate power supply unit to the LiteOn, don't turn it on yet- W) I! i! h" R" }9 ~
- power up PC and boot into DOS
( k( w) O$ p! M3 H' }+ E! |- turn on the LiteOn psu
$ o+ m# i4 d$ n' l2 X- f/ ]- run DosFlash16 in auto mode
9 f! _3 {/ H" ?" _3 D& L- if you read the following:
. O% j# Y, u3 z2 x# q7 N* F' j  MTK Vendor Intro failed on port 0x????." `& \: v" d4 n
  If you choose to resend the command you should turn the drive off and on5 B/ X4 o; l2 ]! K5 g$ d
  after you pressed "Yes".
' f7 l  I! `) p" B& V  Do you want to resend the command until the drive responds (Y/N)?& V# R5 h. x) ]. n6 l5 h6 |
- press 'N' for "No"
: y8 U6 S6 e) e8 D$ i# g- choose the number of your LiteOn ATAPI drive& E6 q( m. g+ p! k2 |
- enter "LITEON K" to read the drive key, i6 I) C% x) u1 ]# b' Q
- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files
0 X2 n) F/ t0 N  ~! U- enter the number of the COM port; L. B  O8 x# u$ G
- if you read the following:: B0 A, P, ^! o+ D9 g* |
  To receive the drive key use Geremia's DvdKey method like follows:
+ X; s3 Z, X9 A) m  - Connect your drive with a serial cable to the COM port7 m( w* A) w& P: G
  - Eject drive tray
6 H$ s5 Q+ `- R% F, x& ~  - Power off drive
2 I5 f. Q+ Y$ W8 e; v+ h  - Push drive tray in until it is half open
- V7 Q7 Q# J0 d/ X: B  - Power on drive: ?. w2 v" O$ w3 _( `) L' t- ~8 \
  - Press "Yes" if you are ready* @- A0 L* X3 w' j2 N- q; {
    Are you ready (Y/N)?
2 q) a- L4 ?7 |' t: p- do the above and press 'Yes'
; ?. N! |; Z2 |. S- after this DosFlash16 displays your DVD-Key and saves your key and identify data% X3 }9 t! j" t

  Q! F- H9 z: P6 ^8 e" M
( n) Z0 B, c, v# G3 X# O2 pGeremia's LiteOn Erase method with DosFlash16 and 2nd psu; W: P! C. C5 o  `, M
-----------------------------------------------------------# k% Q  l( m  F" O+ _9 S/ v
- connect a separate power supply unit to the LiteOn, don't turn it on yet
& b* {4 ]6 {7 G/ W( r6 O- power up PC and boot into DOS+ Z0 d, }" [/ X) X3 X9 q
- turn on the LiteOn psu
7 R+ [4 e6 ~, z- x# R. K- run DosFlash16 in auto mode
/ d  T  U5 ~2 M; X- if you read the following:0 V/ q( @' R; N# b* Y9 W; L! C
  MTK Vendor Intro failed on port 0x????.3 r. [& J; q  I: P" R7 p# o
  If you choose to resend the command you should turn the drive off and on
. A/ T0 J4 o1 _' R& G+ S: u( s  after you pressed "Yes".& F  W6 f# Z' s+ i4 `' I3 R" i
  Do you want to resend the command until the drive responds (Y/N)?. \8 D9 D5 `/ L- \* a
- press 'N' for "No"
& p. `0 w$ v/ U# |  M- choose the number of your LiteOn ATAPI drive5 E7 P, s% _- q% U1 K- b/ }
- Warning!!! Keep in mind that you will need the drive key before you erase the flash,6 O' d3 G" G, y: d
  without the drive key your XBox360 will not work anymore# K& P' x& b8 K$ x
- enter "LITEON E" to erase the flash
2 u# l8 B& K& |$ ~; [* C2 l. Z' v- the first time after the LiteOn Erase the drive needs to be repowered to give
, Y2 ^( y7 a  k, r  flash chip access, this can be achieved by repowering the drive before another# ?' L) x% Z& V$ P2 g  L5 _- z
  DosFlash16 start in auto mode or by doing a MTK Vendor Intro Power Brute$ `8 [) a+ H# L" ]5 ^0 `+ Z
- in my tests it did not work to power the drive with the PC's psu, because it will
. ^. [' x0 b- ^& T+ o3 o  always respond with busy status7 A( w. V; I& [7 u
- DosFlash16 can now read, write and erase the flash chip like usual2 |4 I3 c- [& v) a' k7 f) l3 \
- to do the above steps in manual mode use the following command line if your drive6 W: b' u4 t# J* E5 M2 @
  is connected to port 0x09704 ~& v- n4 Z5 w
  DosFlash LITEON E 09704 _3 L: x& Q8 Y* W6 K/ ^
0 |3 [' J6 T+ ]* S6 D5 r
9 c  e. n% p  z$ B+ o
Geremia's DvdKey method with DosFlash32 with the PC's psu
! {' A" e7 S5 {  }8 L5 S( W1 w-----------------------------------------------------------. r, P4 |* D8 G+ g  A4 Y
- disable CD-ROM boot option in BIOS
! F, Y! e  b5 d5 j- connect LiteOn to your PC's power supply unit and SATA port$ x( \5 z! I3 f( W3 e9 o* v! }
- power up PC, wait until bootup is finished( p0 F( Z( d" ?& I6 t9 g9 x( Q
- eject tray of the LiteOn and shutdown PC completely
! u8 P9 z; G0 ?! O; E3 o- push the LiteOn tray half in& L1 C$ d% s6 h+ }
- power up PC and boot into Windows
: g8 b$ t0 S: T* r% b0 N2 s- run DosFlash32- d  b! {0 H$ Y  Y! y* N
- if you read the following:9 g) `: }+ K) k# n1 v1 `
  MTK Vendor Intro failed on port 0x????.
$ t7 ^% t8 k2 a9 M7 m  If you choose to resend the command you should turn the drive off and on
' R+ w7 }! ?' p/ w4 o  after you pressed "Yes".
5 x+ J- ~) k  B( m  Do you want to resend the command until the drive responds?+ n* _7 g# U- v/ a/ j* ~
- press 'No'! A0 Q# ?/ ]5 w5 P, ^' o
- choose "LiteOn DvdKey" as flashing task+ Q6 ~7 g. }+ s+ J) e
- choose the COM port number. N2 E4 ]" ?$ T5 ^. I% D! Z
- press on "LiteOn DvdKey" button
. N5 J( @* W& c, @/ o- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files
5 ]; x# p+ v" Q) Y  d; @& k- if you read the following:0 Q7 h, Z( q5 c+ ?( D
  To receive the drive key use Geremia's DvdKey method like follows:; H8 j. K; r% h% L* q3 f: _
  - Connect your drive with a serial cable to the COM port  O" q& f1 ~* {: K
  - Eject drive tray6 f# E) L) i6 c9 F3 _
  - Power off drive
6 D5 U! R- ~) U- R* h  ?  - Push drive tray in until it is half open
; Q$ G* ]. r8 ]/ e8 p+ S  - Power on drive
7 g6 I8 ~* R: {1 g  - Press "Yes" if you are ready
7 r7 o' T- ?5 k$ r. Y    Are you ready?
: H. Y, U( Y$ l. o: _  p- simply press 'Yes' without doing anything of the above, because we' W5 ]# X8 X% E" p; O
  already did that before
9 ^' ?. e1 ]0 b+ z$ I- after this DosFlash32 displays your DVD-Key and saves your key and identify data
0 e5 P/ U" M- u) Z8 R% x/ X
) X5 ?. H  l6 r, W3 e9 U
) C2 V% Q4 |5 b! {% @8 w) XGeremia's DvdKey method with DosFlash32 and 2nd psu
  }0 G7 [! M4 C3 F3 ?# p( |-----------------------------------------------------2 i8 _: Q0 {& Y( H- U- d
- connect a separate power supply unit to the LiteOn, don't turn it on yet
* j) P$ A. ~  }( P1 M7 R! `- power up PC and boot into Windows
1 e0 k" @+ R  ]$ `; A6 f( K- turn on the LiteOn psu
7 {5 Q3 L" \4 N" Y! C% J- run DosFlash32& m6 t3 U, u- |* N. i: C/ p* B
- if you read the following:0 }" b4 b: e5 h$ }: _
  MTK Vendor Intro failed on port 0x????.
1 a5 |3 _# ?, w! z. H% J- D% d  If you choose to resend the command you should turn the drive off and on
" @0 Y' @2 ~9 J2 J  after you pressed "Yes".5 O6 U, t5 i, s1 _; r: I3 N6 w
  Do you want to resend the command until the drive responds?
1 z6 }! ^: ^* ]! ]+ q; G& P- press 'No'8 V/ T0 y& T( o: |# ?1 N
- choose "LiteOn DvdKey" as flashing task% h9 P8 B0 P: K6 q
- choose the COM port number
8 n) \5 \8 P: B. D+ u( @* }# w- press on "LiteOn DvdKey" button
% @! e4 n0 r! _, W- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files) X  n0 u3 M* W; h1 ^, U
- if you read the following:
) \4 d  \( y, C  To receive the drive key use Geremia's DvdKey method like follows:' n6 k+ b$ w1 f. d
  - Connect your drive with a serial cable to the COM port
/ y4 {5 `! P2 o  - Eject drive tray% T" N6 M; G- w
  - Power off drive7 I2 A. b/ Y5 }
  - Push drive tray in until it is half open/ C% e. x2 I* ?/ U
  - Power on drive+ E2 L; x: x2 T9 I& |! ]. s# ?  B
  - Press "Yes" if you are ready
) M* H! K; y) j) @, _    Are you ready?- G8 W# L" ~3 \4 G. f  v$ y5 a, h
- do the above and press 'Yes'
4 x! y3 j/ w0 R5 C) s1 s- after this DosFlash32 displays your DVD-Key and saves your key and identify data, B: m6 Q( ~: E7 m5 X* g( n

0 Q; d4 r7 t. {2 [6 @" C/ T7 L
" j$ ^/ p: L2 ?5 Q2 u  hGeremia's LiteOn Erase method with DosFlash32 and 2nd psu3 q7 e3 w! m5 i+ `  l- S+ K* E
-----------------------------------------------------------
7 |- {) l: B9 Q; H, C# J! }6 Q- connect a separate power supply unit to the LiteOn, don't turn it on yet
1 ~0 e) i) z2 N5 m- power up PC and boot into Windows
( _6 r# Z! t1 y# B5 x) u* O$ [- turn on the LiteOn psu& M3 K  |2 p: q5 q5 P
- run DosFlash32
) [; |( h+ x, ?" z( @- if you read the following:
" v' T, G  T* Y% n0 |  MTK Vendor Intro failed on port 0x????.
0 [$ V4 [4 n: E  {" |* U  If you choose to resend the command you should turn the drive off and on7 P9 a8 X' N" {1 F
  after you pressed "Yes".. |! z8 S% w& w' c1 [5 M1 K4 h
  Do you want to resend the command until the drive responds?
7 {6 l- Y5 @% |+ J9 m- press 'No'
( V6 V( q  I. [" j8 x, Q- the LiteOn flash is not identified
- I4 S7 p. Z( d2 l- choose "LiteOn Erase" as flashing task
/ d9 g8 D& X5 p) U2 l! ~: H- C- Warning!!! Keep in mind that you will need the drive key before you erase the flash,$ ]% M& ?2 T# k" s# w3 I$ n1 N
  without the drive key your XBox360 will not work anymore
" C! A+ g4 A+ j, [- press on "LiteOn Erase" button
0 l. w$ L7 D* l, `9 I3 v- the first time after the LiteOn Erase the drive needs to be repowered to give
% Q. [1 d" \7 p  flash chip access, this can be achieved by repowering the drive before another. |+ \7 v3 F* P3 N
  DosFlash32 start or by doing a MTK Vendor Intro Power Brute
% t% f  Z7 G9 b  t3 y( k; q- in my tests it did not work to power the drive with the PC's psu, because it will
% j! K. C; L% _" C! W; X6 D  always respond with busy status/ r0 M  s7 q0 ?. z) V  b* H( F% H
- DosFlash32 can now read, write and erase the flash chip like usual4 V1 _- L& f3 z% h5 U, ]

( _% V- O) `3 {0 e* _" E" v5 O3 f* h9 M) d, r: M  a
Respect to Geremia, Modfreakz, Podger, Redline99 and Tiros.) L0 N2 e4 K9 R( S% i
; Q5 h; f  o+ n0 v. M
Like a wise man said: "0x2E is the MTK Intro of Death"
. a$ s6 p7 ~% WKai Schtrom
- v, U5 A2 s  M, |2 q/ f: E' K- t( h# Y, _) k" E  V0 i
1 w+ c2 N  l$ l7 @6 w
************************************************************************************************3 u& z# X4 ]/ D* U
) g2 w9 D  Q  V! i: Y
$ F" n1 y; r8 @& ~5 S) U" b) C
DosFlash and DosFlash32 V1.6 Beta5 [& I* Y" F2 z  O* ]0 W& d
-----------------------------------7 y# `+ w4 R$ r( `3 z
- fixed power brute unlock bug for VIA cards, this can stop your VIA from working0 Y; |& r) a0 U, C1 b- V
  with the power brute unlocking in Version 1.5. {, v$ W0 I) Q: S7 i
- for DosFlash16 in auto mode on DOS my VIA card works best if I do a cold boot
% D. N5 ]* R$ a, [, F* C4 ?+ Z+ J  and power up the drive short before or with the PC
" Z. O+ m1 S0 L. z- for DosFlash32 on Windows my VIA card works best if I power up the drive short7 |7 W# Y. ^) I' S7 w
  before starting DosFlash32( Z% L# ?. f0 Z4 Q; T4 g6 ]6 [
- for me the VIA works with internal and external connectors on DOS and Windows: ~% w6 l% z! x

, Z  F1 h/ R7 G# Q8 o5 ^! JSorry for the trouble!
/ x! G! g; |8 }8 SKai Schtrom7 F1 p6 L9 e& y9 X. W
  H  Z$ \, ?& p3 g8 H* }) r

4 _9 l4 `5 X0 a; m) `************************************************************************************************, }% L" @, U' `* Y  r1 o

3 F5 {. l$ M4 h- ]. {. _2 f& w" k5 n4 W. n. q
DosFlash and DosFlash32 V1.5 Beta
8 D! a5 Y2 P6 J8 U-----------------------------------$ b4 X6 Z4 J: i" C1 {. D
- now supports serial flash chip MT1309E with mediatek status 0x72 like the SH-D163B, SH-D162D,
( w+ W$ W  V3 A0 Q; l" K# c9 E  Asus DVD-E616A3, Asus DVD-E818A3, Sony Optiarc DDU1671S2 d2 v% K1 C; t, x
- SST25LF020A and SST25LF040A chip support added
3 f- q; A4 T' p- j% L9 _- DosFlash32.exe ported from MFC to plain Windows API, exe size is now 22 KB
& A/ P4 r7 a  ^9 M$ g# B* E- new port i/o driver, because giveio.sys can't be compiled for 64 Bit Windows1 B2 c- k% m! S
- DosFlash16 changed slighly in manual mode, one parameter is added to support SST25LF020A and) R/ I3 `0 U2 L. `" D0 U6 w
  SST25LF040A
# P( d* E: c2 A( ?( s6 l4 B) H- two new methods of BenQ soft unlock are now possible on all motherboards with only one power
1 p+ y% i' S% W  supply unit
0 N+ {4 O! j1 f1 n- 1st method is powered by Geremia's unlock core, thanks for the complete idea, concept and
7 ~+ K, R, }! o' P  source to Geremia, M: v) {0 r% c+ |) F4 K
- 2nd method is the Magic28 key send, this only works on BenQ VAD6038 firmware, thanks to$ A, k! e- [3 ~1 Y/ r! V8 A
  c4eva and podger for the initial idea
9 K; [: H* N4 F. @1 M+ \0 u" b5 c! c3 \- the two unlock methods are send one after the other if the drive is a possible unlock
5 o) L+ c* Y9 K. Z7 w/ }  candidate, first the Magic28 command, then Geremia's unlock commands and after that the4 E& Z( W9 R% ]
  already known power brute unlock is send to the drive, you can cancel any of these methods$ n- ]" }5 m* b
  before they are send to the target, this only applies to BenQ drives with a locked flash
6 H: [# l! n" ^, |1 P- DosFlash.typ updated( L' F. z, W; k7 i
- other minor improvements3 s& T3 R3 H+ |% C9 R
- DosFlash32 is now ready for* y1 M% }' Z, K& ~4 G
  - Windows 2000/ s) ~, M) t4 U% Y8 o
  - Windows XP 32 Bit; [2 _* f8 \# c2 `0 ?! _
  - Windows XP 64 Bit
( ?+ k5 q$ q4 Q  - Windows Server 2003 32 Bit
6 J# p: @8 L- F2 P1 W  - Windows Server 2003 64 Bit4 c# {/ z! b5 n  [. O4 r  V8 ~
  - Windows Vista 32 Bit
3 a& |6 v8 ^6 T9 P. [+ t  - Windows Vista 64 Bit
0 q. E9 ^! |/ w/ h- Warning: Drivers for Windows Vista 64 Bit need to be signed, because we can't afford the
' o% H2 T: z. |0 z7 s  money to let portio64.sys sign you need to do the following:" ?4 C/ m+ r4 y/ F( R- m' X
  1) Log on as Administrator; {$ T, `) f' f
  2) Enter the following command in a Dos-Box:# \3 T4 V5 v' }- K
     "bcdedit -set loadoptions DDISABLE_INTEGRITY_CHECKS"
4 y0 }( j% D5 o. X     (we made sure there are no typos in the line above) 1 l9 h" Z: ^( `( V0 V$ ^' I* }
  3) Press enter and reboot your PC: h1 r2 `! J# K1 Z* b. o" ^
  4) Press F8 key upon initial system boot up% g, ?  t( @* {4 Q* @- F0 l1 m% Z
  5) Choose to disable forced driver signing enforcement for that boot session
- @3 `# P9 X2 e. O& t
9 }" k! e+ x/ N
0 w8 H" m) }4 f& A! E% cThe following only applies to drives with a locked BenQ flash.
3 y6 W3 x& m3 u4 w% W5 u' G( H1 A- N/ M2 r& t1 l5 Z  ?3 z5 R
. Z$ I0 M; Y# A
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with the PC's psu7 T( o+ o* L% b7 h6 o
-----------------------------------------------------------------------------------------3 X% O8 w# N! I1 C
- disable CD-ROM boot option in BIOS
% S5 o1 n2 Q2 G) Z- W- connect BenQ to your PC's power supply unit and SATA port( ]# F: z( }  f" B8 @* j' R
- power up PC, wait until bootup is finished
+ Q3 L- X, {. s& A, I6 B* y* H- ^- eject tray of the BenQ and shutdown PC completely  C9 h& M( }% r- r2 y
- push the BenQ tray half in* s" J) \4 I) @$ M
- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash32' h' L) n8 k9 \) q2 f' D
- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
2 q9 @( b, f; c- if you read the following:
# P8 l4 J; p$ m! y/ n  MTK Vendor Intro failed on port 0x????. Because there seems: l" b- o! J6 B' ^7 F) J5 l
  to be a BenQ drive connected you should try Geremia's1 p9 `; w: Y" U/ X9 j3 {8 _
  unlock method.
! e0 u2 l$ i8 W  - Eject drive tray: x# m4 Q8 ]5 D7 `" A: i
  - Power off drive  b  v$ A: y; W1 ]8 {
  - Push drive tray in until it is half open
" E' {8 M- n/ r+ t  - Power on drive( t1 B  U/ }8 F3 Y5 s
  - Press "Yes" if you are ready
* f9 Q1 V1 E6 P0 h8 H0 A1 j+ E    Are you ready (Y/N)?
- Z0 g( b8 Y1 `5 S. }! }& M- simply press 'Yes' without doing anything of the above, because we1 ]& R5 L  S& _# p, ^5 `7 S
  already did that before starting DosFlash16 / DosFlash32
$ N  J' c/ w( H4 \- the BenQ flash should now be identified
7 M: f3 i6 z  s' p2 a" N- go on like usual6 G0 u7 C, V+ Q
: a8 B/ ]0 Q. ~& m
4 W1 _. M  W3 v  E, y6 j
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with 2nd psu
7 k  R' w6 c, T: }+ q5 @4 Q& j- H  C------------------------------------------------------------------------------------% t/ q! C% M- c1 Q4 m
- connect a separate power supply unit to the BenQ, don't turn it on yet
& z9 \' J3 M1 H0 C' F6 }0 n- power up PC and boot into DOS6 l; [6 e! T! f4 j$ W# B
- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
7 F- L* R' d4 j8 H- if you read the following:& F( W4 u  y/ s7 H/ _6 N
  MTK Vendor Intro failed on port 0x????. Because there seems0 R) t8 S5 J2 @' x
  to be a BenQ drive connected you should try Geremia's
' U+ e4 H6 V) l: G8 i  unlock method.
  r! N4 L% @0 S) a; O% W/ t! c  - Eject drive tray
3 x# A: x, j, e# m/ C6 i: ?  - Power off drive  m$ {# y7 X9 g2 A: _( r
  - Push drive tray in until it is half open% r% o+ Y. T; s
  - Power on drive
% G; P/ g% g5 |# a' \) }/ Q& |  - Press "Yes" if you are ready
  ^  l7 j  Z6 f) o; Z4 m7 b7 S    Are you ready (Y/N)?
( S8 g- w' h% r) e* T) Y- do the above and press 'Yes', U; k9 p: q8 F0 b/ [$ G+ ^
- the BenQ flash should now be identified8 B$ D* M( U& g7 `1 t9 c
- go on like usual+ i# F& w. T$ `( \- K% J0 v2 O; I

) Q& J4 i: A/ h: S, O# c
- Z! U" m* ?5 s9 f1 zMagic28 BenQ unlock with DosFlash16 / DosFlash32 on any motherboard& _! q: M2 Q+ [, H
---------------------------------------------------------------------( T( D+ F) O% E0 Q6 y
- connect BenQ to your PC's power supply unit and SATA port
" p3 w& c9 D5 r) ?0 r: j- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash32
( b" O) n9 N% `) }- S: k. d- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
5 ~8 t* f$ r8 \9 L2 @- W- if you read the following:; S& E# i8 T) `6 t0 `
  MTK Vendor Intro failed on port 0x????. Because there seems
2 N& _, s/ L5 B7 k  to be a BenQ VAD6038 drive connected you should try the4 ~3 O4 V' A9 f) S; `" M. q
  Magic28 unlock method.
& Q' y) @+ P4 [6 @& {/ U) E  Do you want to send the Magic28 command?
# c6 \; y9 b% i" m$ X- press 'Yes'
4 t4 _% N7 f# X) Q- the BenQ flash should now be identified
: q6 O+ _' g# a& W- go on like usual
3 z! ~# E2 x% c  z, C1 ~8 k* l% Z% g5 @) y
$ y/ t7 C- _5 p! a
Thanks to Redline99 and Tiros for help and support.
7 I0 }8 f; L  ~4 y6 J, x! z- b8 m# u- p$ w4 H( `3 R
It's all about DOS!
' C3 Z/ Q  q# y. H; p# q# ~8 UThanks guys for the excellent team work!
/ @- U& q5 n$ P: l5 p2 F" lGeremia, Modfreakz and Kai Schtrom7 {" t. h" N8 v; ^

. A, z6 m4 a! B
0 r9 \  o; g. |. p5 {8 ]+ _, H************************************************************************************************- [( s" G. n3 ?8 z  c- g

( W1 S( a- R; I/ u* @6 T9 C
& P0 g  p" d3 m( f, B( @0 z7 x& @# }DosFlash and DosFlash32 V1.4 Beta3 H: [. J% T1 L/ J) R. ~% I8 @# H8 n% ^
-----------------------------------, y/ J+ E) o$ ~' F- q# X- @
- DROM6316 flashing support
! w7 T& o7 r: G. g. A, Q; S. R- a flash erase is now always done with a chip erase and not a sector erase command, because
/ F2 w/ {0 ?5 ^  the sector erase gives problems for some Winbond flash chips including the DROM6316
9 h4 `5 ]7 W9 B- DosFlash.typ corrected and updated
5 ~9 ]: ~9 b1 v! h7 c3 v0 n- for a detailed explanation on the soft unlock look at the included file SoftUnlockByIriez.txt,
: F, m2 b8 s, f7 T. m8 L  it contains a very good explanation by Iriez from XBS, thanks for that one!5 \2 o& f! r6 K) Z% a; m7 |8 F

. D; N# T! R6 i4 ]8 CThanks to Iriez, Jumba, Redline99 and Tiros for help and support.6 B, x% i0 h" s, x
: ?) M8 c, }: u9 D3 S- }
Happy DROM bricking!
  g7 ?% L. }! H5 \' y" BTeam Modfreakz and Kai Schtrom& W7 B$ }( x; W
4 T3 P6 e" `6 _

( b/ J! `/ J4 ~* e" t************************************************************************************************! j% Q* ~- r! y+ k. k2 v6 H
/ X2 V) U& h. j% o! S! P
. L- ~) L$ H4 z  D! v* c
DosFlash and DosFlash32 V1.3 Beta
0 I! v: w& w7 c  Z-----------------------------------
/ i6 I6 U' s+ m4 M: `+ l( z1 D- BenQ optimization in unlocking the flash chip, it should now be possible to read/write/erase$ Q9 q& ?1 u2 Z; g+ T5 T% A
  the flash without any soldering or wire tricks, the drive is polled for the correct mtk
2 N9 k8 F' R+ Z, B0 f7 \- t4 }  unlocking status after power on, this only works for VIA cards and NForce boards atm
9 @+ v. O& J5 H$ |" O# S* }: B/ }- DosFlash32 has one additional parameter, if you start it with the parameter "EnableDrives"& Y. e. [: J) `5 f3 E) L
  all the DVD-ROMs are enabled in device manager after flashing, this could give BSOD on some
8 C1 F* f6 E* F7 m7 E( |8 I1 l3 a  systems, therefor you need to create a DosFlash32 link and add that parameter manual to use it# {# h; f6 O4 K' F5 p8 A
- DosFlash16 has one additional parameter "Send ATAPI Device Reset" in manual mode, this could
( _, w5 G, j) Y/ l! a  give better chances for soft flashing on some VIA - motherboard combinations
0 ]2 d) m% B( C! i& m0 A8 T- better support of Intel chipsets, drives can now be flashed if the controller is not set to) c; v3 t: c2 e0 K' }$ i
  native mode in the BIOS7 m$ @8 D4 B4 H) L' J- g
- the following controller list includes vendor and device IDs that are hardcoded to identify" g0 g) D- x( R5 B$ L' a; F
  the controller type (IDE or SATA), this is needed if the BIOS uses IDE ports like 0x01F0 or
* i+ Q$ G4 j' i  0x0170 as SATA and not as IDE channels, this list is NOT related to soft flashing
5 n# f& T0 V5 h) y- the following chipset support is added
* a" y& G0 j  X, \7 @' q) g  - VIA cards
, m% J& l, O. g" ~    - all VIA cards with a 6420 chipset# T/ ~4 ], ^& e$ [- H5 X
  - IDE Controllers
5 ]4 h$ t) q4 P. p( s# Z# g! E1 t    - NVIDIA nForce 2 IDE Controller
+ |: k5 \. K* m: I; {) L3 c2 A+ |    - NVIDIA nForce 4 IDE Controller
0 o) W3 e* F9 o$ [4 h    - Intel ICH93 j4 R% R6 b4 G& Y( T4 D1 \3 M
    - Intel ICH (i810,i815,i840)2 G2 P2 c  W) p6 \+ q6 H  C
    - Intel ICH00 n. V5 n( U: d
    - Intel ICH2M
- Y1 ~! ?! y; p2 O2 {- v- q    - Intel ICH2 (i810E2,i845,850,860)
& D. M( z4 W3 h    - Intel C-ICH (i810E2)6 b+ H6 u1 `, z5 j/ q' `! c& S
    - Intel ICH3M
$ ?, z$ N  P0 ?  L7 G: q) g    - Intel ICH3 (E7500/1)1 ?1 X; f8 f, Y$ ]6 r
    - Intel ICH4 (i845GV,i845E,i852,i855)
) S3 r( [1 D% K! T! H    - Intel ICH5
) q% U3 B8 |6 t$ R1 f& [    - Intel ESB (855GME/875P + 6300ESB)' C; @8 e6 ]0 d: e' J7 Y) a
    - Intel ICH6 (and 6) (i915)5 `2 ^* ^" i+ R; T) S& w) }
    - Intel ICH7/7-R (i945, i975)6 j, M3 K+ q1 O$ P* D
    - Intel PIIX3 for the 430HX etc
6 h. ^: v  J2 ?# {0 L1 F0 `    - Intel PIIX4/ d: z6 I" w* M% P
    - Intel PIIX4 for the 430TX/440BX/MX chipset) e! ~6 M/ \$ D+ Q
    - Intel PIIX+ ]9 D: i3 Z) b, {8 p; i8 b
  - SATA Controllers. d3 y& m& y( |4 W/ A7 ^" n2 K
    - NVIDIA nForce 4 SATA Controller
' |" k. y/ ?9 l, w2 _8 {' z    - NVIDIA nForce 2 SATA Controller
2 o0 M+ |; C. D: F- o+ r# m    - NVIDIA nForce 3 SATA Controller
: M$ g& S/ D$ K! E    - NVIDIA nForce MCP04 SATA Controller
5 f( T. x& F: f2 g4 }. {+ q    - NVIDIA nForce MCP51 SATA Controller. r* H( {3 g; E; D
    - NVIDIA nForce MCP55 SATA Controller& y9 X1 K) d3 N% R
    - NVIDIA nForce MCP61 SATA Controller
2 c6 W" T6 _# _2 c. U' H2 b! Q( p    - Intel 82801EB (ICH5)3 s( I: p  X( s5 {" \2 N
    - Intel 6300ESB (ICH5)$ P4 ]* x: i" v( J; Z' Q
    - Intel 82801FB/FW (ICH6/ICH6W)- N9 F8 t# {, t) }
    - Intel 82801FR/FRW (ICH6R/ICH6RW)
% {$ C- |. V6 I) M. Y+ Y    - Intel 82801FBM ICH6M3 D$ O/ j4 W2 e* `  H
    - Intel Enterprise Southbridge 2 (631xESB/632xESB)
6 [% w8 K' }, m4 r$ r) A    - Intel 82801GB/GR/GH (ICH7, identical to ICH6)7 Y6 d) N3 R; d' @
    - Intel 2801GBM/GHM (ICH7M, identical to ICH6M)/ F* e/ t9 R* t5 i
    - Intel SATA Controller IDE (ICH8), O& |& i9 J1 j# r2 ?/ C1 E; J
    - Intel Mobile SATA Controller IDE (ICH8M)
0 p1 }) i, q2 b3 m6 p, L  z/ {& p1 s    - Intel SATA Controller IDE (ICH9)$ _' i1 W7 k6 [0 a1 L
    - Intel SATA Controller IDE (ICH9M)
' `3 l6 D' `/ i; y3 W
' ]0 c" k1 M- p9 d* Y8 c* ^* f6 L# {! F# }- X$ @. e% T
The following only applies to a software flash on a locked flash. The methods have been tested
2 r: X9 t) Q& M- K& o9 D$ ?with the BenQ and the Sammy. The VCC trick will work on any motherboard, but you need to do 9 n( h* B/ I0 z$ J1 V# t; Q9 y4 i& m
some soldering and cut traces.
4 A8 l+ u' ?5 l( v: P( A- W- a8 A3 ~) ?4 A0 U! J

# ~- a+ B  C+ y2 [Soft Flashing the BenQ in DOS with a VIA card and DosFlash16 in manual mode5 G% Q  b$ ]" l
-----------------------------------------------------------------------------
+ K* t  U* c! {" f* M+ ^& X- l- first you need to know the port addresses of your VIA card, you can get these by starting
, j. |) z7 p( f! ^4 u8 l  ^  msinfo32 on Windows XP and looking at the port listing for SCSI devices
+ R* Z4 [, v. D. e: `! E2 ^- for the 6421 the 1st port is internal SATA, 2nd is external SATA and 3rd is internal IDE, g2 {) X3 h, S3 T  p# |1 t* y
- for the 6420 the 1st and 3rd port are internal SATA! }7 c* Y/ G2 c
- you need the starting address e.g. 0xD000 or 0x7000
% O8 e$ J2 Q+ e  K- be warned that these addresses can change from computer to computer, they are assigned
; h. G" o0 K# Z  e8 N8 U4 I3 X3 J  at bootup, but Windows XP should display the ones you need for flashing in DOS
, C& t. n$ }/ r) K$ n- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
$ _0 N  V3 j$ |! _' |( M5 M! R3 y- ]) q  Xecuter Connectivity Kit)
1 n& P5 Y7 c8 _) V0 P% d' d- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we  q$ F0 w9 F0 ~0 {
  need to power the drive off and on during soft flashing& r) Q' {$ N* U+ W
- cold reboot or reset the computer
$ @4 J" S+ ^8 M6 s& R- boot from a DOS disk, I used a Windows XP MS-DOS startup disk- g& Q7 [9 P- s
- at the prompt type:
- Z0 @0 ^4 U+ L  Q% k; [  DosFlash r 7000 1 a0 1 4 a:\orig.bin 0 " N+ V, }$ w' ]3 M# z" H
  - instead of port 7000 use the starting address your VIA card uses% a% _( x3 i5 ]' j& ~
- press return0 {( A; \: N8 h3 j0 R& a
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes# q) Q& |6 R& x7 u1 M$ H
- after you pressed Yes the drive status is shown on the screen, it's something like 0x7F,/ X. C4 B+ X+ b; `/ I; ?$ h
  this will change during the next few steps( B, I1 J, F; e
- turn on the BenQ psu and wait 2 or more seconds, status changes between 0x51 and 0xD1& U, \* n" }  g! a
- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD1/ ^* L5 ]3 E  l' {* y3 a) @3 e5 C
- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start
! |7 Y) F9 s7 W; M: C/ d# n" L0 W- this worked only one time after the computer is powered on or resetted for me
) n0 q2 ?8 A: e# H% _7 l- writing and erasing works the same way
" U: y( ?6 r% B" f. h6 P, |$ ?- for writing type:, g8 ^4 Y2 r3 U- e" E& c0 C  E; }
  DosFlash w 7000 1 a0 1 4 a:\ixtreme.bin 09 C3 X! Y  N- p* h9 ^7 C
- for erasing type:
; X0 g( ~/ }5 X" z7 h+ a  DosFlash e 7000 1 a0 1 4 D8 0 (D8 is the sector erase opcode for the BenQ flash, if you need
0 f1 n2 ~, x+ P  to erase another drive, lookup the value in the datasheet or DosFlash.typ), K) _7 ?- n  h" p" ?4 K& y. x
- if you experience any problems try to use 1 as the parameter to the ATAPI Device Reset, cause
! z6 |* j+ A0 {* s) c( a  the same VIA card will react differently on another motherboard sometimes
5 t/ ~! I; e7 |7 ~+ H2 s. F; e5 L  @, ^. l6 }$ W6 ^3 @
3 w4 F# m+ A$ j. }. A2 B( n
Soft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in manuel mode
8 G1 w6 ?' R4 G6 B) K5 y---------------------------------------------------------------------------------------5 C. N  E2 ?' s! y. o
- first you need to know the port addresses of your NForce motherboard, you can get these by 1 \( C* K7 ~/ J* |( ]
  starting msinfo32 on Windows XP and looking at the port listing for IDE devices% h; n9 A* g& m4 d- u) Q" t4 k* D
- on most motherboards the 1st and 3rd ports are used for SATA" I! G) S* O) Q$ M! i4 R
- you need the starting address e.g. 0x0970 or 0xE900; h0 l. l/ S5 ]4 G
- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
+ z$ F$ j: t' \" ^  Xecuter Connectivity Kit), h3 s) X$ X) B$ V) Q" T$ m
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
2 p9 _- t7 f3 h7 Y: G# v6 k  need to power the drive off and on during soft flashing( N' [2 y. w7 B7 v6 f
- cold reboot or reset the computer
) P4 d; a0 W3 g- boot from a DOS disk, I used a Windows XP MS-DOS startup disk9 |0 x- c  J0 f3 F% Y
- at the prompt type: 7 j. y% ]' H1 E9 ^
  DosFlash r 0970 1 a0 1 4 a:\orig.bin 1
0 u3 ]9 m, e# i  - instead of port 0970 use the starting address your NForce motherboard uses
, _3 t& l8 [) n0 V3 V- press return, F9 }6 }+ O9 C9 L9 F
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes: t1 x4 M* Z- L  C% R6 ?+ w
- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,4 i/ y9 v/ _3 w) h" m
  this will change during the next few steps* {3 f9 @# V6 w# p+ |7 N
- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start9 Z; ^. D( L% Q0 u+ y7 q9 C
- writing and erasing works the same way
- W% s$ b3 R# @6 ?- for writing type:
3 b* X5 T1 `: Y" `7 A, g  DosFlash w 0970 1 a0 1 4 a:\ixtreme.bin 1
- |7 l: {% e" h- for erasing type:5 k' A; x, m6 `: D  P4 R3 d1 g9 i/ r
  DosFlash e 0970 1 a0 1 4 D8 1 (D8 is the sector erase opcode for the BenQ flash, if you need
$ ]( {! V1 M( T, K# L( j  l  to erase another drive, lookup the value in the datasheet or DosFlash.typ)7 X  U+ g( o# Z1 T$ g0 g
( T$ n$ |. A& r
& n9 ]. R5 v# Z$ H) W. J( F
Soft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in auto mode
) \' U, A* Y) Z1 g-------------------------------------------------------------------------------------
7 e) K8 n* w3 d0 h2 h. T5 X- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
% |0 u0 r# O/ A: u6 t' F6 b  Xecuter Connectivity Kit)  j, b7 j, r9 {# M; N
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we" _( ]# J9 i) u5 b: t6 Z8 l- M7 a
  need to power the drive off and on during soft flashing( O1 c$ A, Y6 O. f. `, O
- cold reboot or reset the computer; G: k$ a6 z& K+ J! ]
- boot from a DOS disk, I used a Windows XP MS-DOS startup disk
5 Q) Z1 D4 J8 W/ [0 d  h- wait until you are at the cmd prompt
! d+ o& V; t0 w  @$ r" c) w' _1 H6 k- turn on the BenQ psu
; @- Z. k( t6 A$ O* e' C6 J- ~- at the prompt type:
7 `' s* B' I' _) h  DosFlash
$ {3 {; G; k2 O9 f# C- press return
$ e, b* t9 @/ w) }! P5 A- during scann of the BenQ's port DosFlash16 will ask you if you wanna resend the mtk vendor
* \2 M. A2 p; {. ?2 W% I; U  intro cmd, press Yes
! w* Q( y) {+ y. Y' G: S- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,7 U' k! \) j% l) q" X
  this will change during the next few steps7 J6 V0 ~" C: n/ V' g
- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD1
* C  @) h7 t7 y! U) W: [8 Y- turn on the BenQ psu, you should get a good drive status 0x73 and flash access is granted
' P9 I7 ]8 p% L5 M3 B# }- you can now continue as usual using DosFlash
; i3 y8 h- f( d" H1 e2 c( e' S- writing and erasing works the same way0 O* j* k' y. P
- if the ports are scanned there is the possibility that you'll get the resend question for
& e: J4 i  O3 o6 y3 C  other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,
( G( ?! ]  M. f8 a  if you know the NEC is at that port you should press No and press Yes only if the port of1 ~2 C+ ]+ O5 Q8 `. D# ^
  the BenQ is shown or simply disconnect the NEC3 w4 ]- g8 ~& a

+ I! M7 f% n( }4 I5 v! @: M# d$ b+ w; V/ w( p3 P9 W7 S1 I
Soft Flashing the BenQ in Windows XP with a VIA card or NForce motherboard and DosFlash32
. ]5 T% N& y( i' B! Z-------------------------------------------------------------------------------------------" C8 l( V5 w& ], G
- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
$ D$ J; n6 ^, j# G. M) ]  Xecuter Connectivity Kit)
$ X$ @- d8 ~- J- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we8 t4 V  u+ r0 J) S
  need to power the drive off and on during soft flashing7 O+ Z% [' D! ^" x9 Z/ Y9 V1 g2 d
- cold reboot or reset the computer4 E4 L! D! ^1 v, r
- turn on the BenQ psu when you are in Windows XP- ]3 y1 Z1 }: [0 M' g( U, b. X( ]! p
- start DosFlash32$ z) r1 k5 a/ _. R% I8 \3 y
- DosFlash32 will ask you if you wanna resend the mtk vendor intro cmd, press Yes- @# v& l9 f7 J0 Q# x
- turn off the BenQ psu and wait 2 or more seconds
) |; }! U3 ?3 K- turn on the BenQ psu, the DosFlash32 dialog should show up6 [( @0 p4 `0 U
- the flash should be recognized by DosFlash321 x. P" H2 u8 r) J
- you can now read, write or erase the flash
! i! Y, a. D# i# p/ \( p% O- you should be able to do the flashing more than one time in Windows, only do the power
; B" ?, a4 j! q! ~  off/on trick again1 ?2 _- W9 [0 ]/ W" s
- if the ports are scanned there is the possibility that you'll get the resend question for' X4 D6 ^5 j  I/ P
  other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,5 H* }4 X2 Z% a; W3 D' n$ O9 u
  if you know the NEC is at that port you should press No and press Yes only if the port of
, B( e* ~' z7 F" {3 [  B7 e  the BenQ is shown or simply disconnect the NEC
5 S$ q# K7 _/ E) ?
' y; m$ H* T4 B) z- ?* c1 K. `
- o* q" D6 u8 B* X, l; K( V$ ]Many thanks to jumba for the great idea of BenQ polling!) G: X2 [3 e8 @. _) Q! y" `3 U4 _
Thanks to Iriez, Jumba, Redline99, TeamModfreakz, Tiros and all the IRC people for testing
% f) J$ U- W% r- m$ [6 Xand support.
4 M1 w% m5 S+ n$ [/ ?6 P6 Z, t4 P9 D5 O' ?; p1 g  c* x6 y. l
Join us on IRC efnet at the channel #dosflash for support." X- _2 N- s5 I" P0 @- ^
9 m  L2 U$ s& `. ]& B: J
Don't brick your BenQ!
. B: A: j" z2 ]+ U1 _Kai Schtrom
. F/ `' g6 r6 i8 j- Y' ?1 n
5 U- R. E. Z0 ^6 o; W9 |2 j! D) @! i" j8 B; ]
************************************************************************************************
8 |- G5 @" r! p) W$ @" A. U5 e) x3 j8 r5 X" p0 x( |6 t/ @
& f( R. \, a8 E  K+ Y7 v& P# V  J
DosFlash and DosFlash32 V1.2 Beta
7 t2 F, b) y4 {4 x2 {" c$ S-----------------------------------
! c! k/ h2 T' R9 B- bug fix for BenQ recognition
. v2 }" U8 y6 R! I" v5 ]! k$ L# u  - manufacturer and device id are sometimes 0x00 for a correct installed switch+ }( I5 R+ L% i- }: V  D2 X$ b
  - this issue is fixed with an additional ATAPI device reset before the mtk vendor intro is sent
3 U; W1 C) H, z1 q0 X
/ Z8 x4 x% Q; {- M, a# kThanks to Redline99 who fixed my buggy code by adding one line! : p# v, x5 n8 [4 V( L* Y' j+ A) W
# r" `/ O# V$ u% S/ x* J) H. f
4 D# a2 k& S# G
************************************************************************************************: p+ K' ^! V2 a8 Z

- F; m. j9 G/ y+ x+ A( u2 l
5 C% T6 }" b( f& C& X- r+ v$ ?DosFlash and DosFlash32 V1.1 Beta" w; v, }; \/ Z9 s; A
-----------------------------------/ h' c- p7 x1 Y2 @
- DosFlash.typ modified for better BenQ support
" Z4 r; @0 P: X( L, X- DosFlash16 Flash Manufacturer and Device ID screen output restructured& Z' f! m# r/ e2 h7 f1 v6 L" h, {
- flash chips are first erased before writing starts
* Q8 |2 q2 Z5 Z8 k. y- DosFlash32 no reenable of DVD-ROMs in device manager after flashing, this means you can't see the drive
; Y/ W/ h+ I0 f. E9 o5 P  and maybe have to activate it manually again in device manager, this could give better compatibility and# a; ?% t$ Y. Y6 l$ I5 j1 s
  hopefully no more blue screens8 Q! E, @: Y: R
" Q, a9 n/ m) ^1 ?
Many thanks to Jumba, Redline99, TeamModfreakz and Tiros for inspiration and help!
/ S1 o( c# ^' q9 Q9 M. q4 W0 ?  d  m4 H, {; ]. @+ F

7 G% {4 Q. m9 {) F. y************************************************************************************************" i* H0 x4 b: z& Z& Z  C
4 Q6 x# V" s$ I2 n9 z! G

, [' ~; Z$ s# C& c0 V1 K; O  D& @4 oDosFlash and DosFlash32 V1.0 Beta
$ _0 k; V( I: _3 ]0 G-----------------------------------
2 v; h' f/ r, [  T* c3 @DosFlash can be used to read/write/erase the flash chips of most CD/DVD-ROM drives3 X) Z) J1 B/ D' h
that have a mediatek chipset installed. DosFlash is for DOS flashing, DosFlash32
6 Q' C% v3 _7 l4 v  s. N! ]1 Ufor Windows flashing.9 f" L/ ~1 k/ G% ?/ j
% ^+ k# L8 r+ ~' s  H) i
2 `7 |' @0 T4 z4 w7 ~  E, q, A
Features:' \5 Y1 Z  I) B6 [; f: Q, g
-----------# h" m4 B0 `- p# a0 f2 ?
- flashes IDE and SATA drives+ J' U2 N. Q# I" Y" q( f7 D
- supports parallel and serial flash chips
7 {; d3 K8 m1 ]- flash drives in Windows with direct port access0 z: C3 |3 B# v4 F
- no vendor cdb flashing commands are used& ~: E( @7 {! i( }5 i1 Z. g! Z
- tested with the following drives:8 \0 [! e/ ~& Z; M) }1 ~
  - TS-H943A MS25, MS28
, r+ o1 d# X% b8 \6 A7 Q  - SH-D162C. n  K* d; A0 O# ^0 z
  - SH-D163A
, Q; C% A( A. |  - and some other drives like Liteon, Hitachi, ...7 d' D' a) V: U& j  `/ x- Y
- NEC drives are not supported, cause they have no mediatek chipset installed
( W! L: v9 T! A: ~# V 4 }! c: x) u5 b- ?) ?
, R& ?8 x3 f8 P: I- q
DosFlash6 p" n# T$ d7 {$ ?6 p4 \! p
----------
# }6 h$ o! ^" [, M" }( q) tDosFlash supports two flashing modes, Auto and Manual. If you type DOSFLASH at a DOS prompt it4 s8 o) P& i; n
will start in Auto mode. All drives and the corresponding flash chips are detected automatically.; u% D" a3 J4 V. H- Z% L' m, E, ?
If you can't get a flash chip recognized due to a bad flash or other problems you should use the
7 m* B+ e  F& q& ?' [! `) _  ~/ @Manual mode. In Manual mode you can enter all the parameters used for flashing by hand. The# n" ~' U* H; E# n9 R
following help screen is displayed if you start DosFlash with a wrong number of parameters:
$ t& @" J! i) @4 u; ]5 l( A9 o+ h& @* [" c
" d8 i8 @4 S6 a3 u  b2 w
DOSFLASH by Kai Schtrom, 08/05/2007 (Ver 1.0 Beta)- s2 K: ]! @) P* F* ~: M) R! D, M
DOSFLASH [R|W|E] [PORT] [PORT TYPE] [DRIVE POS] [FLASH TYPE]
* P. n1 A) Y( c' O- P) {; E' \+ P% D         [FLASH SIZE] [FLASH SECTOR ERASE OPCODE] [FILE NAME]
8 A! B, G8 V1 b1 z. ]) H% g                        R: Read FLASH, ^, q! Y& ~! O, c, K
                        W: Write FLASH1 S0 x' G8 z1 H2 |& J+ l# M# ]) y
                        E: Erase FLASH
) C$ T# c& t$ c& @                     PORT: Port to send command to
3 [- q+ J  l3 C* L# [# J                PORT TYPE: 0 for IDE, 1 for SATA- D9 n3 y9 E+ J/ n5 j$ }: f
                DRIVE POS: A0 for Master, B0 for Slave
6 j2 d8 U  A4 S               FLASH TYPE: 0 for parallel flash, 1 for serial flash" p0 b. l7 V6 s
               FLASH SIZE: size of flash chip in number of banks
$ }' G2 t! x$ e/ J# \3 h( o) y$ DFLASH SECTOR ERASE OPCODE: individual sector erase opcode command byte9 b6 y4 E8 v8 U
                           this is only needed for erasing a serial flash
2 i* F1 X" N7 X2 f% I                FILE NAME: name of the file to read/write from/to flash4 c& S$ b+ Q2 X8 Y  d: Q' D, R
All numbers are intepreted as hex values!
3 e$ G- `' b7 {- G% W( `
( G- E: F* k; s! Y- y  h' X, kExample Usage:! p! O) I) g1 B
"DOSFLASH R 01F0 0 A0 1 4 C:\flash.bin"" p- ]$ k' ~. E, _
=> Read serial flash with a size of 4 bank (262144 bytes) from Master Device0 ~3 y. R3 w# J7 o6 W) k
   on IDE port 0x01F0
  S( m( D- w2 K# N3 H"DOSFLASH E C000 1 A0 1 4 D8"0 b- }# a" A% A( S* x: G7 B
=> Erase serial flash with opcode 0xD8 and a size of 4 banks (262144 bytes)
% y& X: A  s$ _0 @   from Master Device on SATA port 0xC000- |  h9 k2 N# A
   
* y8 {# g4 P9 m+ L- V   4 U; D. [/ w* t( v; x9 w
Explanation of the Parameters:
. e' `" E& _9 |5 F- B3 ^--------------------------------
$ Q8 R4 o: ]) _" M* x8 i
( S, i. l/ D( N[R|W|E]! I0 ^3 j: I0 _/ S8 [% E
---------
: B  o* W/ t1 @2 H' e' I- o- this will set the mode of flashing, it is recommended to first try read on any! n: _# `6 u, P
  drive, if the read will fail, it is highly unlikely that a write or erase will
) Z; G2 J0 x( d3 R# ~" r9 ?$ F3 ?  succeed7 i3 [. z3 f1 }) _8 K

2 V1 g( y3 V; r  R0 E: P[PORT]
- Q. a1 {2 {/ X9 z" s% V$ F& k& w--------
& h; \2 L$ {$ _, y- the port to which the drive is connected, a port number should always be entered
! W1 @1 E% b* [% a( s+ V& o) w! f  in hexadecimal and have 4 hex digits, valid ports are: 01F0, 0170, C000, C800- c0 v! j1 e& e  \
- this option can be used if your PCI adapter card or on board IDE/SATA ports are
: t, O& s+ d# x8 p3 w+ ]  not identified by the auto mode: T4 X$ W! t2 t8 S

/ @+ ]* \' g6 f7 \# F$ J' e[PORT TYPE]6 ?8 P- [! T5 q  B& _* s" U$ C. e) e
-------------
) |3 ?0 S1 L) f; M- the port type tells DosFlash what type of port is installed on the before entered" _' T0 M6 e! o( K  d3 d" [) N
  port address/ }( I. o+ B# F! s7 ?
- valid values are 0 for IDE and 1 for SATA1 W, }& U6 L7 u; a9 X
- make sure you never mix the wrong port with the wrong port type, this could give
  L6 Y; e6 O. r2 W  strange results or in the worst case a bricked drive" g5 |- ]: m6 f$ |: S
  ) d5 w/ Q8 o5 F3 F& g% K% q
[DRIVE POS]
# V4 G. S. B' X- [+ C7 L-------------* N; e2 U! G% l( t
- old style IDE channels have the possibility to connect two drives at one IDE6 c! E4 h( d) Q' X) G9 u
  channel, the first drive is called the master, the second drives is called the
& T/ t+ O, P/ w; G3 E7 J" y  slave3 t% D+ y8 O1 s, n7 Y
- you can select which drive should be flashed on the channel, A0 selects Master,
; t1 V) L. G. K( B  B0 selects Slave
/ d: Z& H, m: h/ ~- on SATA ports this value is always A0, cause you can only connect one drive to( s$ ~, \2 i) F( C  @
  a SATA port, so for SATA you will always type A0 here- z3 h: F- G4 C( L6 }( y. w
- it is not recommended to flash IDE drives with another drive connected to the
4 K/ X9 \# m2 q1 x  same IDE channel, this could be risky if something in the Master/Slave selection  l  U1 |, W; N' {( ?" r
  fails2 @' {) H8 L. r
  & D/ P$ g; Y6 X. D! ^' V) `* A' J
[FLASH TYPE]
/ x5 ]3 j: _4 Y. W% J, h. X--------------
6 R& V0 M+ j! g! V( H! T- z( p- there are two types of flash chips out for CD/DVD-ROM drives atm
3 W4 d8 r0 d" p0 H4 J- the older type is parallel flash, which is also supported by mtkflash for example& }6 D5 \' Z2 d5 C+ s6 Z
- the newer type is serial flash, which is supported by flashers like XSF9 ]3 Y8 H3 K/ ^5 s
- the problem here is that no tool is out that can flash serial flash chips on
( W1 f8 f& p6 |/ D! L  SATA ports- z. D+ R- G: H7 M
  
& X9 ]% \  `7 b1 \& G6 g/ ][FLASH SIZE]  J- U: i' R( H. W( ]9 w. i9 ?- D
--------------6 \4 ^# j+ W. L
- this is specifies the flash chip size in banks
8 K, v5 p% B. J# h1 Z% M' `- one bank is always 65.536 bytes in size5 u, e& C2 |  o- B- X  C, @  U
- if you know your drive has a flash chip of 262.144 bytes in size you need to enter 4& j+ X3 y! g$ Y% _8 j# n+ y4 _
! l9 _  f4 T7 f
[FLASH SECTOR ERASE OPCODE]
0 x: G" q. x9 x- w-----------------------------* _: d. z  V2 ]* Q
- the opcode used in the flash chips datasheet for erasing
8 `$ _$ @* a6 }, d- X- for serial chips this command can be different from the standard and needs to be
3 Q( |; v" v1 ?1 H5 L  entered for flash erase
' M( c# }0 H' }; B) j2 c- for parallel flash chips you can enter a dummy cmd byte, the integrated command
+ k4 G. n4 e! ^3 f. ~  should work on all parallel flash chips without a prob, R& K7 W5 q+ b* Q) m" m
  
" v  b* k1 c: [3 u( j[FILE NAME]0 @; v0 H4 f, H; U0 G
-------------
% N. r2 R6 I; L/ b0 G0 P- c- name of the file that should be used for flashing" \, K9 C" i/ X$ D- M; a4 \- ^
- for reading operations this should be the output file
  Z4 x  \" f0 ~; T- for writing operations this should be the input file
8 [7 \& p& e$ S; G7 h3 z: B$ x& l6 U  V& ~& o
' i9 a5 R' N- M) q% Y/ Q" D& x
Hints and Warnings
, H; c& H- n4 u4 Q5 k--------------------
) W/ `* @% t7 f4 r9 e/ H- read, write erase TS-H943A MS28 after the firmware stealth has been disabled with Enable0800 disc
& i# ~1 Y) s& j! i" ^  - this only works one time, after the first mtk vendor specific intro cmd is send2 @& j) p; h, [
  - if the mtk vendor specific outro cmd is send the chip goes back to stealth mode and you need
/ {. d4 ]3 F  ~5 O8 s! F$ `! O    again the Enable0800.iso to disable it& O: Q' Q, u" O9 k& o. ~; ^7 h" ^6 H
  - therefor the mtk vendor specific intro is send at program start to all present devices and the
- ~) b) S" o7 J- N4 }4 r) z! T% {% ?+ J    mtk outro is sent at program end1 F$ `$ f6 E, S
  - if you have a chip manufacturer id of 0x02 and a chip device id of 0x02 for the TS-H943A
! G# ?& d" \+ y5 S. V: f    the flash chip is in stealth mode and won't give access to any reading, writing, erasing
( V/ H, e- S- e- always have a look at the DataSum generated, this is exactly the DataSum of mtkflash
$ {8 M+ \2 h" u; N8 }  - the DataSum is calculated as the sum of all bytes of the firmware in a short integer/ \( ]. d# o4 t' n/ d0 [/ a
  - to make 100% sure that the flash is written right compare that DataSum to a known one
' [7 H6 ]+ e. A6 I8 M- this tool has not been tested on all drives out there, the typ list is simply copied from well
1 @0 z# O, w( v; n3 {  known programs like mtkflash and XSF
* Y4 H9 l0 v$ ?  - always try a flash read on a not yet tested drive before doing anything else
1 K, P* ^. h- o2 f! z  - if the read doesn't succeed it is highly unlikely that a write or erase will
# `3 W& J; j) \8 U+ y- @$ T( O- some LiteOn drives seem to have probs to write the firmware correct, this prob seems to be
7 I5 N. T- X) E% n$ _' p, z# m8 H  related to windows register flashing, cause even an assembler app can't do this error free
3 T0 Z- E  P6 A) [3 }  - if you get errors on LiteOn drives, write the flash two times in a row4 E" T( Z" _, U- G8 C8 I9 i
- for direct port I/O in windows the givoio.sys driver is used, this driver is loaded at DosFlash32; Z9 S+ ~$ L3 T  j. f8 n" H5 o  `
  start and unloaded at program end, be warned, this driver can possibly make your system unstable,
* e  z- \* _( o3 ^  it's intention is to let privileged assembler instruction like in and out pass, even in windows,
* E. Z+ o6 ~$ A  if this driver is not used you will not be able to get direct access to port registers8 p- q. i' _% u+ p/ a9 P8 R3 K
- DosFlash was tested on MS-DOS 6.22 and later, you can easily copy it on a MS-DOS boot disk created
, F7 S1 `  Z9 g5 Y5 c: y# n) T8 j  in Windows XP and start DosFlash directly from the disk
: X5 w: F6 P9 e( p9 }( ?  {$ V- don't forget to also copy the DosFlash.typ file, it has all the informations about flash chips- L+ D' q" N0 c( V' X0 d) s0 d, |2 f/ e
  for auto mode flashing
6 B# X, W; h& B& y2 e/ L4 h" f- DosFlash32 was tested without a prob on Windows XP SP2, you'll need also the typ file for the # O9 i/ }7 g& X% W
  win version
8 k* s/ C9 p, H- DosFlash32 will deactivate all CD-ROMs in device manager at startup, this is better for flashing,
0 J; {* ~" w5 t+ ^  cause Windows seems to poll the drives all the time and this could result in a bad fw file or
$ d" W0 X2 r* [  a program hang, the drives are activated again at program end2 k3 u7 g8 k( \+ |& A, ?
- you should make sure that the flash is not in an erased state at program end, cause device manager- e8 a) j. q. A% g
  don't like drives that do not respond to the inquiry command
4 Z. `) i% E- F4 H7 D- deactivating all CD-ROMs could take a few seconds, so please be patient at program start7 t. x# h3 |, \% f! P: I# N8 \: V
- DosFlash and DosFlash32 will try to scan for the VIA 6421L Raid Controller card, based on vendor
$ B* M' H' |" V( C% S. {( X9 M  id 1106 and device id 3249, it doesn't matter if the card driver is installed or not6 Q" z7 @7 G) L5 b( G. T6 Y
' u2 ^3 C7 i5 H4 ]9 `3 M& d
* V* r1 y' q" x/ S4 D+ p; X
Many thanks to Dale Roberts and his Direct Port I/O driver giveio.sys!& k& P, @, }2 l$ f  X; I

6 o$ d8 ^% r% r, {  D) m( J% F4 eAvoid a bad flash!
9 x. p0 [; Z! W7 Z4 cKai Schtrom
22#
 樓主| 發表於 2011-8-23 00:02:15 | 只看該作者
版主你好^^; n# s  l& O- Y: [4 }: `
非常感謝版主的用心貼這個給小弟^^只是小弟技術還沒有到那裡有看沒有懂^^|||在試著找看看如何使用dos介面下提取dvdkey雖然有找到一些訊息不過還是有看沒有等以小弟的目前的能力還需要多看多參考^^
& H( i8 m  _  B! n感謝版主的耐心回覆小弟在多上網找看看看有沒有新的發展如果可以成功自己刷機因該會很有成就感^^
23#
發表於 2011-8-23 12:08:02 | 只看該作者
ak475671 發表於 2011-8-23 00:02
% A3 F& d; u: A& J3 k8 I% W版主你好^^
& z* c, i& j7 S' e: ~$ Y非常感謝版主的用心貼這個給小弟^^只是小弟技術還沒有到那裡有看沒有懂^^|||在試著找看看如何使 ...
, x' t1 T- E+ X5 W7 z4 F2 L
以下是實際圖片示範:
# _6 U- s  u. |* ~* X* T7 e& t% F7 K: y/ J/ M  H5 m
在DOS模式下輸入DOSFLASH並開啟XBOX360光碟機插上電腦SATA,就能抓到以上資訊6 b1 Q3 d7 n6 L  R
9 W1 o# {4 R; `
接下來它會問你要幹什麼,這裡我們要取得它的韌體,按R讀取( G6 f0 `* U( \: Y

+ y3 ?' ^# u5 g8 }) a上圖就是取出test.bin韌體名稱,您可以任意取其它名字* ?) b! m" q' `% r( |6 I

" h) b& i2 @" o  g! |6 J+ L& s再使用16進位編輯器去開test.bin檔,可以在其中一行找到DVDKEY,至於其它韌體的DVDKEY位址不一定像上圖一樣,有可能在其它位址。
# j. Q( w- d0 l8 m, t$ V9 g
24#
 樓主| 發表於 2011-8-23 23:28:34 | 只看該作者
感謝版主還這麼用心幫小弟找圖片教學謝謝版主我再去試看看
/ V2 c1 `% N. L: Q2 L
# g& I* |5 G/ b& h) T; X( u8 P^^謝謝版主了^^
: ]% @) @: J/ Y3 S# S* L
25#
 樓主| 發表於 2011-8-25 00:26:07 | 只看該作者
版主你好* Z7 d9 v9 E7 r" f- M+ |+ j
請問要進到dos去提key是要開機就直接進到DOS還是附屬應用程式裡面的DOS就可以進行提KEY了5 a# B% m' y  C4 g& m; w2 @
另外我下載了DOSFLASH1.9版裡面有DOSFLASH16    DOSFLASH32    DOSFLASH64   這樣檔案是正確的嗎
! ]6 |! j( f% m$ e我有看了16的點了跳出畫面右不見了然後32的點了出現視窗因該是可以讀取DVDKEY的東西  那我可以直接從32那邊去提KEY嗎   或是需要進到DOS去才識正確的提KEY方式3 L/ W( r1 w/ ^' e
26#
發表於 2011-8-25 12:18:27 | 只看該作者
ak475671 發表於 2011-8-25 00:26
3 }$ C3 M. T* a( D( ~) m4 w  D版主你好) _" J& ~5 x7 R. Q2 h' E
請問要進到dos去提key是要開機就直接進到DOS還是附屬應用程式裡面的DOS就可以進行提KEY了3 I) f$ L8 \' H# j: ^  N
另外我 ...

8 {; K& l" e$ s$ B1 Q. R" ODosflash16純DOS模式使用(早期的Windows 95、98或更早的DOS 6.22開機使用)3 [# a3 ?: r9 v- U5 }
Dosflash32在Windows作業系統32位元使用  a/ Y$ A, v$ o( i8 p
Dosflash64在Windows作業系統64位元使用2 m- h* G2 h- O. o; a9 B' r. n
建議使用純DOS來執行,其實可以不必這麼麻煩用DOS下的16進位去找DVDKEY,
' [7 I% V: I2 g4 Q$ X! L可以使用DOS讀出韌體後再進到Windows下,使用JF去開您讀出來的韌體檔就能取得DVDKEY。
您需要登錄後才可以回帖 登錄 | 立即註冊

本版積分規則

小黑屋|Archiver|黑皮維修站    

GMT+8, 2026-8-2 03:25 , Processed in 0.096232 second(s), 15 queries .

Powered by Discuz! X3.2

© 2001-2013 Comsenz Inc.

快速回復 返回頂部 返回列表