設為首頁收藏本站

黑皮論壇(手機維修/電玩維修/電腦維修)

 找回密碼
 立即註冊
12
返回列表 發新帖
樓主: ak475671
打印 上一主題 下一主題

360舊機軟改問題?

[複製鏈接]
16#
 樓主| 發表於 2011-8-21 17:46:22 | 只看該作者
^^版主你好
! |+ X! E7 H' ?8 J. M: b# f) T我有按BENQ UNLOCK這個選項不過還是沒辦法解鎖不知道為什麼因為我是P4主機然後使用網路上所說的3112晶片的SATA轉接卡進行刷機布過可以讀到360的64930C卻無法解鎖想說會部會是需要主機板本身也有SATA介面的電腦後來試了有SATA的電腦後發現電腦系統是WIN7好像需要使用XP系統才可以進行刷機
' R/ ?& c( ~% u! q0 z1 O因為WIN7好像會抓不到360的光碟機
17#
發表於 2011-8-21 21:08:07 | 只看該作者
ak475671 發表於 2011-8-21 17:46
( U( a& Z, I/ @2 J* [^^版主你好& C- X- B$ M) r* ?" j, A
我有按BENQ UNLOCK這個選項不過還是沒辦法解鎖不知道為什麼因為我是P4主機然後使用網路上所說的 ...

7 r9 D% x6 x" M+ T. P% A如果您在Windows下無法解鎖的話可以試試用純DOS的Dosflash工具,6 K( N3 ]% t7 E+ W+ n; q
不必像在Windows下要解鎖才能讀取,BENQ在DOS下取出韌體比較容易,+ E/ Q5 s. E1 q& R) }+ D" J
也比較不會挑主機板的SATA晶片組,DOS讀出來後再用JF開就行了。
18#
 樓主| 發表於 2011-8-21 22:10:48 | 只看該作者
Dosflash目前想要提取key使用哪個版本比較好呢^^
) ^4 C  Z1 ?* e0 g% ^5 W. g* \
19#
發表於 2011-8-22 12:01:38 | 只看該作者
ak475671 發表於 2011-8-21 22:10
$ O" X, l0 H) i6 ]# rDosflash目前想要提取key使用哪個版本比較好呢^^
* n' j. a: Z7 D! u
Dosflash v1.9版,它是取出整個韌體,
( z; x  w( O  n& M, I不止是取DVDKEY而已。
20#
 樓主| 發表於 2011-8-22 13:03:21 | 只看該作者
版主你好$ ^! a7 s! F# l1 w
版主知道哪裡有教學嗎使用DOS提KYE的過程不是很了解不知道有沒有教學可以參考的呢
+ ^, e2 R( U% I. f) V( R" Z另外你說他提取的是整個韌體而不只單單DVDKEY而已這個不太懂一\般向JF所提去的是單單只有KEY嗎如果Dosflash v1.9版把整個韌體包含DVDKEY整個提取那光碟機本身不就沒有任體了然後用JF把DVDKEY刷進光碟機裡布就變成只有DVDKEY沒有任體??  ]0 l; ]4 k. G* i; M& ~

, I. o8 F# h4 b再麻煩版主解答一下6 x: m& c" e) n8 y4 K

& l1 U6 s) J6 o8 p) o9 Y謝謝版主~~
3 l6 `4 C4 _& J9 A4 p9 j' V  y
21#
發表於 2011-8-22 13:31:06 | 只看該作者
ak475671 發表於 2011-8-22 13:03 * `3 \, U" ]+ G. f: J  r3 r
版主你好
4 z4 I: ~- b4 I5 o3 M  A/ ?版主知道哪裡有教學嗎使用DOS提KYE的過程不是很了解不知道有沒有教學可以參考的呢
1 {1 ]# e' a' P0 L* S/ m( j另外你說他提取 ...

9 P& Y  i/ h. P: b; iDosFlash ReadMe.txt 說明文件* h( W9 o" K: k

! ^& k9 C; o5 @! R/ lDosFlash V1.9 Release Date 01.01.2011
5 x4 P, W' |2 N9 {---------------------------------------
8 z! G+ u) X, p/ Q* {% G! i- E- SATA and IDE port scan improved in DOS and Windows# E( T3 B. |/ W9 _. N
  The ports are now enumerated with the CONFIG_ADDRESS and CONFIG_DATA register instead of using interrupts
' w/ `, [$ Q, e# y  in DOS and SetupDixx functions in Windows. This change will detect more ports in Windows than the old
& m% z3 p  J2 F9 m% G  SetupDixx method.9 D1 H  o2 E; v) D
- Settings saved to ini file for DosFlash32 and DosFlash64; ]/ Q4 S# @4 z, n1 E% D
  Settings like Port, Position, Task, COM Port, Enable Drives and DvdKey state are now saved to an ini file+ k* R6 }5 r* k8 K  s. x* w
  inside the program folder. If the ini file is not present it is created after the first run. On the first
' |6 B7 V- M4 g4 I  U( x  startup DosFlash will choose the most common and stable settings.& h  J7 k" f/ g6 ^" F  F
- EnableDrives option included in dialog as a check box
8 t: i1 E! K2 G% y& f( @" w  Due to high demand we removed the "Enabling CD-/DVD-ROMs" MessageBox on program termination and included& c' Q( x, o0 t
  a check box "Enable Drives" inside the dialog. For security and more stability this is deactivated on the
! X! P: ?. T5 `$ N* b8 g  first run. If you enable it the checked state is saved to the ini file.
: X; ?' t" t( H" z& G/ H- enabling drives in Windows caused some hangs from time to time, this is now fixed by a recoded enable) [; b( R* z6 U4 _# G
  drives function
" v) y/ Z  ?+ s2 w4 R5 q) V- port drivers portio32.sys and portio64.sys are now added to the executable and unpacked during runtime
4 ^: C+ B) _1 g1 E2 D8 P- PATA and SATA controllers list updated
+ ~3 b0 p! ~. B: E' l5 I- Fix for NForce motherboards in combination with drives like the "Samsung SH-D163C", "LG DH18NS40" or
9 {! M' `" v+ S( v/ P5 H1 G7 C, E  "LiteOn iHDS118"
' z+ H! D9 C6 E4 x. L/ O9 Z  Some drives have problems with flash identify, read, write and erase. This is clearly related to the. Z( }- d2 B! B: J1 Q
  NVidia NForce chipset. For manual mode in DosFlash16 an additional command line parameter is added called
6 g& m9 `+ a% r0 l9 m& M( A& ?  "NFORCE FIX". This parameter should be set to 1 for NForce chipsets if you experience strange problems.8 j6 {  C1 Q; F% _( G7 ]: D' z
  In DosFlash32 and DosFlash64 we added a static control which shows if the NForce Fix is applied or not.4 z, {3 E- Q& E5 p0 C9 ^
  Remember there is no need to activate this with every drive. It seems to be a combination between drive
& V; w" }( d5 W7 z: }+ `  and NForce chipset that causes the problem. The fix is automatically applied for DosFlash16 in auto mode,
; V! k" _  e- X  DosFlash32 and DosFlash64.) t+ |( v/ L( S  P1 v3 J  B
- DosFlash32 and DosFlash64 are now DPI Aware for Windows78 @* z" C( _  Q. p3 A
- New task Verfiy Key/Inject Key added for verification/injection of drive keys5 e) u) p: \, m6 _
  All DosFlash versions now have the possibility to validate drive keys against an XBOX360 drive and set/ m# F! l/ d( ^+ R. Q' X/ a) q/ j3 B
  the key for an XBOX360 drive. We use the same authentication method like the console to verify a key.! W2 L5 I% `) ]) Y. Y
  In the Windows versions you have the choice to paste the drive key from the clipboard to our custom hex
2 T1 C5 M) D7 j3 |  edit control or load a key file. To add a key simply click right inside the hex edit control and select6 P5 C2 b9 @6 a* `$ o" p
  your choice from the shortcut menu. In DosFlash16 you can enter the key in the format "1A-2B-3C" without! e3 T& E5 s( I4 c
  quotes. Remember that a key has 16 bytes of data. The key file to import should also have 16 bytes of data
1 b! `: w( L7 W* Z) k+ c5 d  like the key files exported by LiteOn Key functions.
6 }8 E; E2 b" w, x) G7 S- Removed multiple key extractions for LiteOn Key functions, added Verify Key after extraction6 X" Y0 w: }9 t) R
  For LiteOn Key functions we removed the multiple extractions, because the key is now verified immediately5 v& X/ P9 e0 z6 J1 W' A% U$ D0 q
  against the XBOX360 drive.
) J$ `4 f' s% N8 f$ ^* X* p2 s- j- LiteOn Key V1 and V2 now also extract the file Serial.bin and the 2nd inquiry file Inquiry2.bin
- o! H" D. D# N  i" G3 M* S9 z' T. \  We added the file Serial.bin and Inquiry2.bin to LiteOn Key functions. Inquiry2.bin is only generated for
- W) ~. Q0 u) l  LiteOn drives V1 and V2.
3 {, `/ @4 I  e$ w( s2 D- The drive key of Maximus patched UART drives can be extracted by using the task "LiteOn Key V1 (DvdKey)"
" R  S8 G0 l5 Q' u/ M3 k  The drive check has been removed from LiteOn Key functions. This way we can extract a key from an UART
# K7 R) u( ?8 {6 I. S) t& p4 D! K  patched drive firmware by Maximus.
5 R- G0 A7 h' u- LiteOn files are now extracted to a destination folder instead of prompting the user for every file name.
, t! C" u0 F5 ~3 j: h9 S7 o- LiteOn key extraction tasks separated per drive version in "LiteOn Key V1 (DvdKey)", "LiteOn Key V2 (FreeKey)"
2 V' j, c& ^0 w% d5 q. \4 f  and "LiteOn Key V3 (Tarablinda)"
, ]  e) L5 G* j1 N- In DosFlash32 and DosFlash64 the number of installed COM ports in the system are now enumerated instead of" |) w, ~8 B& L, A7 c8 O. k
  adding port 1 to 47 x7 v9 Y* B* w* p$ \  B9 _
- For failing cdb commands the sense code is returned! u$ S; O7 A0 ^% L
- Geremia's Tarablinda functionality added
  w0 m9 `# |# o9 r  We added all Tarablinda tasks to every DosFlash version. You can extract the key by choosing the task
. i1 X+ t8 N7 p+ ?1 ^( p. a% ]4 _  "LiteOn Key V3 (Tarablinda)". For read, write and erase of the flash simply use the standard functions.2 @, B9 h- i0 d! h* `) G
  Pay attention that the "LiteOn Erase V1/V2" task is only available for older LiteOns and not for the Slim.& [2 P: a5 E2 H! f% d, f% e
  You should use "Read Flash", "Write Flash" and "Erase Flash" for the Slim. "LiteOn Key V3 (Tarablinda)"
" G4 k2 j: K% ]: ]. G& t' M5 N  extracts 1 additional file in comparison to Tarablinda v04b, this file is called Xtram.bin and contains
* j1 x; ^$ O) P- Y/ }. _3 b+ h  a dump of the XTRAM8000 area. This can differ in a few bytes from one dump to the next.
& P. ~5 p- s6 z7 s+ \1 a/ |- Device Reset in DosFlash16 manual mode is now done automatically, there is no option to turn it off anymore( G# H& F% {+ M# S
- Code optimization to work with modern SATA2 controllers added, remember to set SATA controllers to IDE and$ ?% n* o, b8 D% A7 g) @) v
  not AHCI mode otherwise Port I/O will not work
7 I# C2 q2 Y$ M" T& R' w2 |- Warning: The read, write and erase of the Slim drive is considered risky in general! So pay attention and
# w- G$ }! p; g* w4 D. e+ D  always remember you use DosFlash on your own risk every time! Even during flash read the Slim gets flashed
1 a4 U2 o9 V' h, M4 B  with a patched firmware sector to retrieve the complete dump!
4 c2 V* R9 |! e  ~6 r- We had to change many command line arguments for DosFlash16 Manual Mode, because of the NForce Fix, added& ~& J# W! y0 U: U
  Tarablinda support and splitting of LiteOn Key functions. To get a better understanding we added the example0 u5 N2 @* z& I2 w
  section below.
+ n3 s5 `$ |4 C. b+ _3 @
4 F/ m1 c" k5 [7 j" i+ K8 g( i( v4 d4 l4 E# ?( T- v
DosFlash16 Manual Mode Examples8 v" Z: Q) \- L1 c6 S
---------------------------------( b3 j% h( R: q& }9 V& T( ?
- Extract drive key on a "LDS DG-16D2S 74850C" over UART -> "LiteOn Key V1 (DvdKey)"
. t( u' _6 F* W  DOSFLASH LITEON K V1 0970 A0 1
9 Z! e" Q- D! B0 c3 k/ R
! g! a; J( _2 |; J2 M/ N4 U- Extract drive key on a "LDS DG-16D2S 83850C" over SATA -> "LiteOn Key V2 (FreeKey)"
& v7 t' k+ F' f& j3 w( b8 w) D  DOSFLASH LITEON K V2 0970 A09 D6 V3 X; @2 v6 _7 k$ p% {
  d2 \  a% S8 Q% E- {  w8 V! y1 D
- Extract drive key on a "LDS DG-16D4S 9504" over SATA -> "LiteOn Key V3 (Tarablinda)"
1 \8 l1 J* }- X. Y% ^: W  DOSFLASH LITEON K V3 0970 A0$ e- R0 a0 b8 R) |
8 s, B: X$ f: U+ Q; T
- Read firmware on a "LDS DG-16D4S 9504" -> "Read Flash" this is considered risky!( v5 t  p& l! D% G
  DOSFLASH R 0970 1 A0 3 0 4 FWOUT.BIN 0
- C+ _* V$ d2 p+ Q: C
( N0 S+ i, q9 L4 s9 S+ b  o- Write firmware on a "LDS DG-16D4S 9504" -> "Write Flash" this is considered risky!
1 D, ~- X/ U4 R  DOSFLASH W 0970 1 A0 3 0 4 FWIN.BIN 0
0 b$ N* [9 T) u7 L) F" `# T9 P
" [, o5 z" m( a- Erase firmware on a "LDS DG-16D4S 9504" -> "Erase Flash" this is considered risky!5 V- e  o3 U- t, q: c# e8 ]& y
  DOSFLASH E 0970 1 A0 3 0 4 C7 0
2 a/ N( U& Y1 w
" T2 @4 W0 V3 m$ s( D7 L& N6 o- Erase firmware on a "LDS DG-16D2S 74850C" or a "LDS DG-16D2S 83850C" -> "LiteOn Erase V1/V2"
1 w% c" L+ \- r* H  DOSFLASH LITEON E 0970 A0% |' L6 T! S. t/ N8 B

/ u! B7 h. R6 G* O) q: @3 e- Read firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Read Flash"
& z- X/ J) }2 M- }  DOSFLASH R 0970 1 A0 2 0 4 FWOUT.BIN 1
7 D* V( K2 H; A
8 Q" a; l  P4 B4 ], T- e! w- Write firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Write Flash"
- s& K- _7 M  g  DOSFLASH W 0970 1 A0 2 0 4 FWIN.BIN 1, t! Y- i  `+ C6 s
' E* o6 @2 _! `) e1 s5 b
- Erase firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Erase Flash"# N* G: v3 F' i; \# }
  DOSFLASH E 0970 1 A0 2 0 4 C7 1
: }% X1 u4 y& v$ J: j* {/ K7 i+ k$ ?0 Y
- Verify drive key on a XBOX360 drive, enter the drive key manual+ B# H  C8 b0 w& Y8 ?5 [* O
  DOSFLASH V 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF" L3 u/ s2 g* N
0 a* T' B  A6 |$ [7 O6 G
- Verify drive key on a XBOX360 drive, load a drive key file) ]2 l; e+ r* S! L" e
  DOSFLASH V 0970 A0 KEY.BIN
* I" v$ J1 F7 a7 T, I
4 \9 q  _2 L- e  ~$ K& B. i# @- Inject drive key on a XBOX360 drive, enter the drive key manual
* X9 o3 B9 |4 d1 F* p. D  DOSFLASH I 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF/ r/ J! l" h) r  D

0 m, o% J4 S  }* x- Inject drive key on a XBOX360 drive, load a drive key file
3 I- y. h% a/ T6 W- Z) v  DOSFLASH I 0970 A0 KEY.BIN9 t: j- r5 z; ~( ?0 j4 H

9 h. l5 G; B4 s3 ?9 J1 hFor DosFlash drives on which we can extract the key via UART are considered V1. Drives we get the key over
5 ?4 t  N- v  n3 B8 _& G( NSATA are considered V2. The new Slim is considered V3 but only firmware version 9504 is supported atm.
: o4 d* D: J# R' Z) u' [! \
1 R7 q3 o( {+ @9 Y  ]: W% D: R2 Z! g; Y# C& o, `2 E
Many thanks to Geremia, Modfreakz, Redline99 and Tiros for their support. Special thanks to Geremia and
! b+ A" m9 F5 l! S0 m# mModfreakz for drive sponsoring, testing, coding and much more. It is always a pleasure to work with you! a& @2 L# {4 x7 a' e& R) E7 T# T
professional guys! Respect to Maximus for his UART enable patch. I'm looking forward to your magic Lizard
% d# z5 w: v8 y/ S4 Ghardware flasher!6 M5 @( I7 }( o4 e' u* d8 [

6 ^& z3 T0 ~5 u0 d! hHappy new year 2011!2 M, n( z' L" o7 z2 i5 [3 a1 ^$ d' Z
Kai Schtrom
4 @7 C5 N+ L- l8 a/ @: o, r4 G/ o6 O6 G1 ]9 \
************************************************************************************************# q0 h& U  t4 k; u0 i

& Y, }4 B# G5 Y  L6 H, \" Q- B3 f# ]6 |$ U
DosFlash V1.8 Release Date 08.08.20096 m# W2 }* V& ]; Z  k/ B9 p8 P, d
---------------------------------------
- x. _( Y- F: p& D- now supports LiteOn PLDS DG-16D2S 83850C V2 Geremia/Maximus LiteOn FreeKey method
4 ~; ~# d1 E, y. N" G' y$ [4 @% ]- huge firmware read/write speed increase, especially if run from a floppy disk
$ @4 [- v% R) z4 P- updated IDE/SATA motherboard chipset list3 `+ o: B9 y* J4 \6 e$ w$ \5 ?+ k6 D
- new IDE/SATA detection for Windows and DOS
+ A$ e( N' x" y# D6 @- ]- DosFlash.typ embedded in executable file  W3 B. d1 D% L" B& N' [
- LiteOn V1 drive key is now extracted 10 times and compared against each other,3 A; O( s3 l6 K$ Q6 I9 J
  after the extraction a summary is displayed sorted by the most common matches
0 q2 G+ O8 ^( Z5 ?7 ?4 F6 I+ W/ W- LiteOn V2 drive key is extracted 2 times and compared0 N  y3 n' u2 H: s  S
- new BenQ unlock keys added to unlock all known BenQ drive firmwares
- Q/ a+ o" X& D- command line parameter "EnableDrives" removed, DosFlash asks the user on
8 Z5 J" D9 D+ u# V; M, k& Z  application close if he wants to enable the drives or not, during the tests it2 v& E4 V4 Y! P. p' J. [8 G# L6 L
  seems that IDE drives have problems with the enable, SATA drives seem to ) x* z2 \1 N- |9 O5 v
  work fine
8 h5 W. n8 m* d- new 64-bit DosFlash edition added called DosFlash64, because some driver
! b/ u4 E( X: M/ S8 K; r' r6 R- H  functions don't work as expected in the 32 bit compatibility mode on Windows x64" m3 ?4 d  h3 d% j* R# |
- Beta state removed
* c4 @2 |) u2 s; W9 s4 X0 u- ready and tested on Windows7 X86 and x64
2 W. P0 n! Z5 e* U+ P: e( m: F& {1 x+ f+ H
( N) Y! a2 v! ^& ?
Geremia/Maximus FreeKey method with DosFlash16
6 m3 G9 s& f$ b2 R- ]2 S------------------------------------------------1 ]+ Z! a0 |" l$ g) G
We have added one cmd line parameter for DosFlash16 in manual mode. The COM port
, j& c1 I; g* F3 a' @: [5 |% mis simply ignored and can have any value for the V2 drives.
) U8 {- F0 ]1 H9 u' i" `* g7 kUse the following command line to extract your free key from 83850C:
1 M# _$ D, V- J- DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin enckey.bin
9 F( q4 G7 p/ B4 e/ d5 z4 w7 D2 ?5 x+ q! W

! d7 Z9 }$ G5 V2 p- a) GTips for running DosFlash on Windows 7" r4 P( l" N! @  k
----------------------------------------: S) s8 _$ Y/ Y4 h
9 ]2 q9 _' C+ C; m
Since Windows Vista 64 Bit and upwards it is necessary that every driver is signed. Because/ U: }$ [  V& j4 T  B) e5 t
the DosFlash driver will not be signed by MS due to some unknown reason we need to circumvent
* r" M1 a  e3 r7 M8 t$ bthis check. You have the following 2 possibilities to do this.
4 v; ~" l5 B8 y7 A* [" ]
+ |% [: d/ @, p/ K4 SSafe Way of Disabling Driver Signature Enforcement7 w2 A7 V& ^% P5 ?
1) On Windows 7 bootup press F8 to get to the extended boot options screen
) A" B# r( R* k& _) t+ x2) Choose "Disable Driver Signature Enforcement"
. S$ H& E- ~/ f! F- e( [7 a3) To start DosFlash right click on it in Windows Explorer and choose/ I* t7 S! {- ^/ b$ U+ l! O
   "Run as administrator" > answer the message box with "Yes", ^3 }/ A0 O* ?7 v
4) Short after the program started a "rogram Compatibility Assistant" warning message3 k/ _4 q" q% o: L5 a
   is displayed, you can simply ignore this by pressing the "Close" button1 t6 ~0 C% H: n! ?

7 I) `7 B! H( ~! ~" g) YRecommended Way of Disabling Driver Signature Enforcement
% n4 l: U7 y4 g# F. o/ X7 }1) Disable User Account Control (UAC)1 w( i, j( ?3 @' s4 R) |
   - go to "Start Menu" > "Control Panel" > "User Accounts and Family Safety" > "User Accounts"  l3 U$ N3 h2 Y; l- F
   - click on "Change User Account Control settings"
( C1 _: g' W5 }' G   - set the slider bar to the lowest value (Never notify) > click "OK"
6 i  Z' M: g' z0 ~2) Sign the DosFlash driver9 U. ^9 ]6 K- l2 L
   - download the "Driver Signature Enforcement Overrider" (DSEO) from
! A( F& A  u2 n' U8 }  Y+ ?! M     http://www.ngohq.com/home.php?page=dseo
* I9 N  B2 q9 D2 ^   - start DSEO > click "Next" > "Yes" > choose "Sign a System File" > "Next" > enter the path to
; T% O# i- N) q$ I0 z! q     the used driver (portio32.sys or portio64.sys) > "OK" > "OK"- {4 u  S+ k4 y
3) Disable Driver Signature Enforcement4 I# k2 T+ U3 m$ q
   - start DSEO > click "Next" > "Yes" > choose "Enable Test Mode" > "Next" > "OK", b: j) e% E; U/ `
4) Restart the computer
: [) B! s1 J, [$ T- o
5 S. X. h  g7 }* w& f9 S/ rKeep in mind that with the recommended way the changes will have effect on every reboot without% P; T- H; ^5 o
doing anything manual. The first way needs to be done over and over again. In addition the second1 q- t. K3 T0 ^) \2 j! c
way can be used to sign every driver that doesn't run natively on Windows 7.
& X& X# p" C* t) d. q
; D" n% T/ P8 o% w3 m7 A4 QFor use of the VIA Cards in Windows 7 it is recommended to uninstall the VIA driver. This can be
$ K# I, `9 s3 V% ~; J0 r8 Hdone like follows:
+ a1 q, O- n- R9 M- start "Device Manager" > expand "Storage controllers" > right click on "VIA RAID Controller" > 4 C7 {6 H) b9 T* [& {) Q, B
  choose "Uninstall" > "OK"# q: v" C1 {! K! p. B9 Z
- rename C:\Windows\inf\vsmraid.inf to vsmraid.inf_
7 V; f- Q! |; T2 X, ^" S. O/ |  P9 X- rename C:\Windows\inf\vsmraid.PNF to vsmraid.PNF_2 P* J' `! Y% N8 }7 q, e/ y
- rename C:\Windows\System32\drivers\vsmraid.sys to vsmraid.sys_) E! I$ d* E# R2 B4 c  t- \1 e
- reboot computer
  c7 D" `: r4 u; q' O* N% P
5 o( r( e0 I3 h! o6 x5 }+ a. I1 M  H0 a0 S
Much respect and credits go to Geremia and Maximus for their money saving FreeKey app0 R, X1 u) M: t
and their lightning like decryption speed!4 o% Q" j; b0 b- k! N
( C3 V* R' H2 V5 u
In Dedication To The Birth Of FreeKey On August Fifth 2009
" t: W8 Z7 U; V8 P" ^/ P8 u+ IKai Schtrom: v. k$ Q& f7 y" `8 D. F, ^% {

; v" [- C/ a) Y  A
2 S% H* }# _9 D9 s************************************************************************************************& s6 L+ |9 O: m# \" T
2 w1 q* I$ p0 `& e9 I

# x% e% \" H+ L8 `" aDosFlash and DosFlash32 V1.7 Beta Release Date 23.12.2008
: M, ?& H  Q5 _: I- e; J) ~-----------------------------------------------------------, a5 y, q/ q# {0 g
- now supports LiteOn PLDS DG-16D2S 74850C and Geremia's LiteOn Erase and DvdKey method
& Q6 {2 Y& p: e# l; J1 T
/ C" }4 b# a0 r% v1 K9 l9 _- L' L
8 F; I; H( H5 t* `" j$ qThe following only applies to the new XBox360 LiteOn drive PLDS DG-16D2S 74850C.
+ Q6 R$ C& m8 R8 Z8 s6 J
. Y# m: K$ _0 e  C- F; ]7 l7 W) R, o5 {* N
Geremia's DvdKey method with DosFlash16 with the PC's psu
" e2 q& v- b9 G) |) z4 E  Y, y, h" b-----------------------------------------------------------0 W% z9 B1 X: l7 _' U, K& ?
- disable CD-ROM boot option in BIOS
$ }5 H) K1 Z/ s  a) [- connect LiteOn to your PC's power supply unit and SATA port- j- M" A1 `3 L3 @2 u! s
- power up PC, wait until bootup is finished7 u: V3 O  d6 ~
- eject tray of the LiteOn and shutdown PC completely
/ ?8 |8 k0 L6 s  @1 P- push the LiteOn tray half in! b3 V# ^& ~" c% [3 p* v. ^
- power up PC and boot into DOS8 m, H1 h; z* Z5 K
- run DosFlash16 in auto mode
; Q! ]# }% h  a2 A9 z3 _- if you read the following:9 p3 W6 Y0 t7 ~) G9 X6 f) Q: ~6 W4 I1 M
  MTK Vendor Intro failed on port 0x????.9 D0 ~, w' e4 a: S2 x& a/ {$ v+ g% p
  If you choose to resend the command you should turn the drive off and on
; O; j6 k* t, e! S  after you pressed "Yes".
5 a+ L3 X! U8 T" e6 a  Do you want to resend the command until the drive responds (Y/N)?
- f3 i, z* j8 l& m- press 'N' for "No"7 k/ d4 q3 z6 k) u( F! s* ^
- choose the number of your LiteOn ATAPI drive1 |6 m) ^; n# ^% o7 L* q
- enter "LITEON K" to read the drive key
+ F0 Y& @# p% P# ?9 R- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files
8 J- T; v  l) @3 j# C$ p- enter the number of the COM port
- U* Y2 V1 W1 q- N* Z8 g6 N& V- if you read the following:3 z4 W; J: R8 m; \
  To receive the drive key use Geremia's DvdKey method like follows:$ D% O( \# L( I) a* z& s  b- D
  - Connect your drive with a serial cable to the COM port9 X6 p0 F7 D+ S4 @! J: H5 M
  - Eject drive tray
: _$ [% K) g5 y5 [& g6 @  - Power off drive: S  @! ]# [! V7 Q
  - Push drive tray in until it is half open
" u1 u) M3 \  P& J- a  - Power on drive$ I2 K/ o$ D6 n, _- f$ [! m  W
  - Press "Yes" if you are ready: G/ J5 U, r0 ?; v  X; ~
    Are you ready (Y/N)?
0 |. g& q7 T/ h5 e3 T' v- j3 ^. f- simply press 'Yes' without doing anything of the above, because we
5 s" Y$ C  b; G* Q1 Q  N  already did that before
1 t# r* Z, |* \$ T- after this DosFlash16 displays your DVD-Key and saves your key and identify data( b) x1 x4 g. {/ s( n
- to do the above steps in manual mode use the following command line if your drive
) X" c0 M! j. O# c1 w. k& a  is connected to port 0x0970 and serial cable is on COM port 1
' M+ W" p6 X1 M! j( q  DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin
" }& G: U( G& w- U2 K" w; S0 _6 g: I

, n7 K% [' h4 n# ZGeremia's DvdKey method with DosFlash16 and 2nd psu
) @% U! q8 X7 D1 t; W# p: A-----------------------------------------------------* U. }, Y5 v* X
- connect a separate power supply unit to the LiteOn, don't turn it on yet! u* b- S1 Q2 N5 y" O: o
- power up PC and boot into DOS
' i) |# Y. b! q% h# b* J* C4 B2 V- turn on the LiteOn psu
% g% [6 s* e& P5 s$ K$ b- run DosFlash16 in auto mode8 s4 P( R, Q7 _: z" z# W
- if you read the following:6 F. j# @: j' r# I0 |& i
  MTK Vendor Intro failed on port 0x????.
9 S/ b  K. z7 W  z6 f  If you choose to resend the command you should turn the drive off and on- P* X8 i3 Y! k
  after you pressed "Yes".
0 o8 i# b7 Q$ d+ Y  M; Z  Do you want to resend the command until the drive responds (Y/N)?; `9 U7 c* `& u
- press 'N' for "No"$ [, N7 a1 h* F
- choose the number of your LiteOn ATAPI drive
9 J# H7 Y. {1 ?6 E( g2 @+ Y2 B- enter "LITEON K" to read the drive key$ `4 W0 M4 z' f5 y( q7 `' V
- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files2 h4 ]3 J/ b" ~# ~) e0 X7 m
- enter the number of the COM port, V0 V) M* t7 C3 j
- if you read the following:
9 ~9 V4 b1 L  N, Z! R& X; d  ?7 U! [4 Z  To receive the drive key use Geremia's DvdKey method like follows:
- e( S1 _9 n5 \& p9 r  - Connect your drive with a serial cable to the COM port
0 Y7 m- e# V% ^; a  - Eject drive tray
- t! r; m; f, z  l  - Power off drive
8 M( ^+ L! [) `( J* F2 w  - Push drive tray in until it is half open
3 i5 \+ [, }6 `  M* P  - Power on drive( ]5 D  j. Q0 d! u
  - Press "Yes" if you are ready
+ u1 @9 K- L2 C* q( K2 _    Are you ready (Y/N)?+ s& s3 _- O# ~3 y' d  }: D
- do the above and press 'Yes'4 g: Q; B8 w8 S  {# R3 v
- after this DosFlash16 displays your DVD-Key and saves your key and identify data$ u7 t! b( v1 K2 z
7 v# r  ]+ y, s% ^) w1 h

# g+ G) }* k2 S& z# ]; B4 A1 D+ ZGeremia's LiteOn Erase method with DosFlash16 and 2nd psu
- \# x, n  q! H$ b! P' J4 @-----------------------------------------------------------
7 B* o6 Z8 l4 o6 o- connect a separate power supply unit to the LiteOn, don't turn it on yet( f3 X, q: G& ?- [4 G
- power up PC and boot into DOS6 L9 t& {# B5 O
- turn on the LiteOn psu
  D" W5 i2 ^* C3 w- run DosFlash16 in auto mode
, n4 ^  s" c- i% ~% h9 x( g8 h: @- if you read the following:
/ t0 I% A* M$ Y) W% G4 h6 c3 W7 @  MTK Vendor Intro failed on port 0x????.7 }( p2 E' q1 c  G) w
  If you choose to resend the command you should turn the drive off and on. V  x$ }( H+ ?' ]) R$ j0 i! J! _3 @6 P
  after you pressed "Yes".5 k+ H% s( g, ~
  Do you want to resend the command until the drive responds (Y/N)?  U4 k4 ?) y+ O; H! B
- press 'N' for "No"
: J# k0 w7 J* m- choose the number of your LiteOn ATAPI drive5 d$ K/ e! [$ @, u  B; r
- Warning!!! Keep in mind that you will need the drive key before you erase the flash,
7 K: z% f) a3 y+ e  without the drive key your XBox360 will not work anymore
. ^; T4 }1 d2 X$ h1 a8 u( G3 L- a; B- enter "LITEON E" to erase the flash
$ }  H4 R8 u. t) e- s% b4 c, n/ }- the first time after the LiteOn Erase the drive needs to be repowered to give: M, w' G. c' D' r5 M  O
  flash chip access, this can be achieved by repowering the drive before another
- [3 P9 R" @" m4 J7 U  DosFlash16 start in auto mode or by doing a MTK Vendor Intro Power Brute. x9 r4 W* |' _4 Y2 r8 t0 |
- in my tests it did not work to power the drive with the PC's psu, because it will
5 s9 g( S: r: G4 y& z  always respond with busy status1 [5 g$ C9 [$ \
- DosFlash16 can now read, write and erase the flash chip like usual
# _, a9 \+ t' {2 O0 h. B- to do the above steps in manual mode use the following command line if your drive( q0 q2 x8 A7 {2 m1 M
  is connected to port 0x0970  [' ^7 l: A& S" M
  DosFlash LITEON E 0970
3 S$ y3 ]- K+ Z+ N" W/ Y( d! D( s3 u) Z- F1 t8 s& R

' K( L) r+ a9 |Geremia's DvdKey method with DosFlash32 with the PC's psu  X/ E/ ]$ z) _5 L
-----------------------------------------------------------
! S/ j$ H0 w, Q+ p! Z+ _- disable CD-ROM boot option in BIOS, c2 P' L! g9 ]
- connect LiteOn to your PC's power supply unit and SATA port
" L* L7 M2 |6 K- power up PC, wait until bootup is finished
/ g+ _7 n" H, `/ b) `; T& w) S' O- eject tray of the LiteOn and shutdown PC completely
/ `6 Z9 H6 B/ U- push the LiteOn tray half in
/ C% s9 y+ i# }, D- power up PC and boot into Windows9 B9 v3 X4 I6 q4 o  M% Q8 |: x) P
- run DosFlash32& `2 J. b, @; L; G
- if you read the following:7 b3 _" D; ~* n9 j& B; ~
  MTK Vendor Intro failed on port 0x????.
8 f# a% `( `7 M& `  If you choose to resend the command you should turn the drive off and on
- Y( C- I" z+ ]; ^2 G" C  after you pressed "Yes".
* g/ o# y% z4 g  Do you want to resend the command until the drive responds?# c* i0 v4 S. O7 m. X
- press 'No'/ L" r1 u" }6 T* F
- choose "LiteOn DvdKey" as flashing task
/ N% I1 k4 _' w7 Y- choose the COM port number
1 g# w5 s! ], l4 ?, r- press on "LiteOn DvdKey" button
- J: W1 K7 {: M- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files3 `: s0 B- w/ n) t) Y; L  Q
- if you read the following:
2 ]( V% K' j! P3 v3 s  To receive the drive key use Geremia's DvdKey method like follows:7 E, R# q. y/ |5 H
  - Connect your drive with a serial cable to the COM port/ Z' D' Y( T9 t! d! N! e
  - Eject drive tray" _3 u. T8 R6 ]" y+ o7 {
  - Power off drive6 o. M5 D) W3 t' A8 T& t
  - Push drive tray in until it is half open* P+ P5 g0 m6 B, F+ J
  - Power on drive  P6 A/ m4 }8 x1 S- P& U' \. T
  - Press "Yes" if you are ready" O/ Q4 ~/ S9 u
    Are you ready?) J( U; t' E: p* }9 \, X
- simply press 'Yes' without doing anything of the above, because we
, _) J; s+ J8 U+ s0 V8 q/ _  already did that before
  O) O2 J! f9 {. r5 n' h5 t- after this DosFlash32 displays your DVD-Key and saves your key and identify data  V+ P' ^" Z6 h% h

( f$ V( |3 o2 U7 b- o' A
- C2 B; N  f& z# m, B: XGeremia's DvdKey method with DosFlash32 and 2nd psu
7 G! `" k% P5 ~4 X' z-----------------------------------------------------+ n7 x( r$ b+ I! G" p: t
- connect a separate power supply unit to the LiteOn, don't turn it on yet: ]+ `- Y9 J6 c: m
- power up PC and boot into Windows  o" U+ H) K# ], S( Y; u+ i* }
- turn on the LiteOn psu( {* Y) E& g4 I5 |/ {6 @
- run DosFlash32
# _+ h0 K6 a' S( _% q# v- S' f- if you read the following:# P5 d2 `9 b& r
  MTK Vendor Intro failed on port 0x????.5 `$ A/ T1 O; `" h. |, h  G# `
  If you choose to resend the command you should turn the drive off and on" S* \* K5 e; ?4 E$ E# {" ]* ?
  after you pressed "Yes".; l& ^+ Z4 B9 `; b7 Y7 ^4 O
  Do you want to resend the command until the drive responds?# q$ m3 ~9 C; t9 }1 u
- press 'No'/ a- v; r, l( |) o4 u5 z) A0 q
- choose "LiteOn DvdKey" as flashing task1 A) i; O2 P' j6 W! J
- choose the COM port number6 F& d+ U( c1 u  B3 K+ `' X2 N* _
- press on "LiteOn DvdKey" button0 y) r6 ?1 M# l, f
- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files1 F0 o! |! g: w$ f9 j
- if you read the following:# b" d. M3 G! ^6 R. ~
  To receive the drive key use Geremia's DvdKey method like follows:
4 d8 o+ i# ^) Q' ~4 @  - Connect your drive with a serial cable to the COM port- Z8 p- h1 g) U" E7 D$ Z! A7 m
  - Eject drive tray
. r5 _) A8 Y4 K+ f" `6 }- _  - Power off drive* ]: R  f! W& d5 H" V
  - Push drive tray in until it is half open1 l; x7 s5 I+ j
  - Power on drive' ^- z+ w9 u0 D& `( I# E
  - Press "Yes" if you are ready
. }, ^9 Y/ n5 e- y    Are you ready?
6 Y# H" }1 i* M  \9 u& C- do the above and press 'Yes'
) B# H6 ^+ e& e+ R9 x, j6 n- after this DosFlash32 displays your DVD-Key and saves your key and identify data
& h/ F& j' t$ h8 \8 v$ R3 ]# }) P4 l* t7 y# Q

% i1 `' h' _$ v. W4 `2 cGeremia's LiteOn Erase method with DosFlash32 and 2nd psu
$ q7 B  ^1 ?/ `-----------------------------------------------------------8 h- c# y" p% X4 }  m
- connect a separate power supply unit to the LiteOn, don't turn it on yet6 ~" i. F. }. p
- power up PC and boot into Windows
, p; L  E. G/ v% p) U- turn on the LiteOn psu
8 W: X8 Q. `6 |& s0 V- run DosFlash32
- Y/ X1 L. z6 L; g6 `) }- if you read the following:
" ~3 Q" _$ c3 x. Q2 {0 {$ j6 a/ W  MTK Vendor Intro failed on port 0x????.
9 A6 S/ u8 B9 X% Y$ c, H  If you choose to resend the command you should turn the drive off and on. c; Y$ i7 v9 S% U4 w& D
  after you pressed "Yes".
" d" [3 y8 U$ U/ c  Do you want to resend the command until the drive responds?
; b; k6 G. }6 g9 {) A! o+ X% f- press 'No'! r8 v7 e1 H4 G5 f% P% L0 Y
- the LiteOn flash is not identified
7 Y, H# e1 ?7 R5 w3 u- choose "LiteOn Erase" as flashing task  u7 q& K4 t0 f" X5 b
- Warning!!! Keep in mind that you will need the drive key before you erase the flash,
6 z/ ~# G  q& i1 O; M4 }: J  without the drive key your XBox360 will not work anymore/ H, h$ Y9 L* G
- press on "LiteOn Erase" button5 w0 d) C2 L! ]6 W
- the first time after the LiteOn Erase the drive needs to be repowered to give, Z2 V0 z$ ^  N4 d
  flash chip access, this can be achieved by repowering the drive before another
' v8 ?) a; e, A3 X; X5 Z3 h  DosFlash32 start or by doing a MTK Vendor Intro Power Brute* ~/ ^$ d" b; D. L, Y: R
- in my tests it did not work to power the drive with the PC's psu, because it will# U3 X3 d" T$ d6 \3 n
  always respond with busy status
6 X% U  X5 o6 K; S% L  H7 J- DosFlash32 can now read, write and erase the flash chip like usual* q7 m* _" o9 c: [& u( s
( i2 D8 \3 u5 B5 _
. K- [2 Y# ?. x, q. U. u
Respect to Geremia, Modfreakz, Podger, Redline99 and Tiros.
5 O8 E5 E1 `1 J
7 I3 M4 h. }' k( a; t6 oLike a wise man said: "0x2E is the MTK Intro of Death"
! U/ W5 _6 ^. k- hKai Schtrom1 C5 N; ]1 A7 t& E* Y, ~* e# Y

* g3 |0 C0 l6 F) A' G* t5 y% q, Y* k, w% ]5 I/ T
************************************************************************************************
# N! F9 G" ^$ L1 e. M; O# ^2 }+ \5 I1 P0 U( q) ]! x' l& d
, R, q+ d% D2 d' M8 Z4 Q' R
DosFlash and DosFlash32 V1.6 Beta
) m$ V8 u; [5 o-----------------------------------8 N1 L3 P5 A* u, l: V8 Q
- fixed power brute unlock bug for VIA cards, this can stop your VIA from working# M1 w& D4 p% }! t" e: j) S
  with the power brute unlocking in Version 1.51 q$ Z1 @9 k- P# B! }
- for DosFlash16 in auto mode on DOS my VIA card works best if I do a cold boot4 ~* J6 C5 D* w# A8 a& o; |6 n
  and power up the drive short before or with the PC
' z- f# E/ V! x1 i0 T2 {4 J- for DosFlash32 on Windows my VIA card works best if I power up the drive short+ \& p, I1 ]' b) H7 Y
  before starting DosFlash327 \5 Q) q: {: S  {
- for me the VIA works with internal and external connectors on DOS and Windows5 M5 @( C" A2 A) B, X. g  ?# [

# n0 f2 A% j0 M8 R3 ]& Z% `6 CSorry for the trouble!
" H; E6 @. V! Y* r1 w: K8 ?Kai Schtrom
! x' N9 v  d  K& ]5 ?* B. \) V, U5 q+ }5 W5 l( }* [
! G, Z) ?  ^8 b
************************************************************************************************' c2 C1 s7 i0 i% i& I

% [3 k* `6 u6 z9 T
) p( Y- I' j4 f  t* D0 r2 YDosFlash and DosFlash32 V1.5 Beta
3 R) E; H" \# }9 C-----------------------------------0 U8 a5 ~8 a$ j; t# N' x- w5 J" V
- now supports serial flash chip MT1309E with mediatek status 0x72 like the SH-D163B, SH-D162D,+ G* u0 H1 a2 {( ~* P3 ^* _8 {
  Asus DVD-E616A3, Asus DVD-E818A3, Sony Optiarc DDU1671S2 u6 `% j' A) y: W( }% V7 I2 ]3 I
- SST25LF020A and SST25LF040A chip support added
9 a" Y, s" H; w4 w# c% m; _2 x8 ^- DosFlash32.exe ported from MFC to plain Windows API, exe size is now 22 KB3 q2 G  y6 }- t% C
- new port i/o driver, because giveio.sys can't be compiled for 64 Bit Windows
+ o* M. [% _$ {* M- DosFlash16 changed slighly in manual mode, one parameter is added to support SST25LF020A and; n" U# i" @7 ~
  SST25LF040A
& D+ G! s; d: B1 X- two new methods of BenQ soft unlock are now possible on all motherboards with only one power
, h2 s1 S2 f) l; p/ Q3 t+ C5 r8 W  supply unit6 Q& c5 J& g$ m2 {. d& K
- 1st method is powered by Geremia's unlock core, thanks for the complete idea, concept and
/ D$ K) b* U' A  source to Geremia# V: f& T4 ?8 ~! ]9 c3 w: \
- 2nd method is the Magic28 key send, this only works on BenQ VAD6038 firmware, thanks to
/ i2 D3 B% I, z5 W4 F+ Y( n0 a6 n/ J  c4eva and podger for the initial idea
! I% }: I0 b1 z* k1 N" _- the two unlock methods are send one after the other if the drive is a possible unlock4 f7 F, q/ q+ i4 ~
  candidate, first the Magic28 command, then Geremia's unlock commands and after that the
$ ^7 {% Y$ t2 U" s  already known power brute unlock is send to the drive, you can cancel any of these methods
6 W  f% \6 e# n  before they are send to the target, this only applies to BenQ drives with a locked flash
6 E7 m0 A0 Z2 \8 J7 s* A- DosFlash.typ updated
7 F) p& v+ A( p# @$ H9 G7 L' G4 m- other minor improvements
! K. f# c" ?' Y- P) X( l- DosFlash32 is now ready for4 S( k3 ?7 z2 I7 v
  - Windows 2000
: k( p8 U. C% e! c. i$ `8 j  - Windows XP 32 Bit' J5 o+ `/ b# I6 }
  - Windows XP 64 Bit
& l) F0 m" E8 @% n, |* u  - Windows Server 2003 32 Bit, H1 h% {1 f: s
  - Windows Server 2003 64 Bit/ k- Y+ j1 C( ^4 O8 q' o
  - Windows Vista 32 Bit
# }& p  z! s# @  - Windows Vista 64 Bit' Y# \' C! H6 g+ }
- Warning: Drivers for Windows Vista 64 Bit need to be signed, because we can't afford the8 @3 V$ S% }  I
  money to let portio64.sys sign you need to do the following:
0 T* Q' a8 i( x9 x7 w  1) Log on as Administrator" i; f* F2 c8 X  K* Z! Y
  2) Enter the following command in a Dos-Box:
5 s5 Y9 L' z- X( Q( D) d* A     "bcdedit -set loadoptions DDISABLE_INTEGRITY_CHECKS"
. _6 c: B/ D( L/ m     (we made sure there are no typos in the line above) 2 A+ a8 m3 f# q8 @7 m% u
  3) Press enter and reboot your PC% ~: {2 O1 t( ~2 N; d  J
  4) Press F8 key upon initial system boot up8 U3 g' l! a* C( ]! Q, G: Y
  5) Choose to disable forced driver signing enforcement for that boot session7 A1 u0 c: f6 x1 [

' t, Q& }) f5 |. O0 z9 J5 w/ Q( B" L: \  @9 F
The following only applies to drives with a locked BenQ flash.
8 }  O, K( L+ q' L. u8 Q* t( i8 C1 S0 l0 v" `" \5 W) }5 M* B
2 j% [8 E5 q8 }: y' n% F4 }
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with the PC's psu7 J# N3 p* B3 l! I) x
-----------------------------------------------------------------------------------------
5 p; }) x6 C0 |+ y/ e- disable CD-ROM boot option in BIOS4 @7 t1 P. T! v  [$ A" V( ~* w% x
- connect BenQ to your PC's power supply unit and SATA port, U- t( z2 c. C' U- H
- power up PC, wait until bootup is finished. p8 p* Q) U  i: C) m
- eject tray of the BenQ and shutdown PC completely1 G/ l3 J7 Y6 f+ }5 F
- push the BenQ tray half in" N+ M' I" U* ~3 o
- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash32
0 M( M3 h5 a# K9 [" F+ E4 d3 l/ z- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows' P- S& W3 u- b9 J
- if you read the following:: P+ b. Z# t% c1 p- S
  MTK Vendor Intro failed on port 0x????. Because there seems
4 T7 I3 Q) p6 y5 f, n% f1 j5 v7 P  to be a BenQ drive connected you should try Geremia's
# R$ ~$ g7 `0 v: n4 I  unlock method.
- A# ~1 m1 ~3 m# h8 v5 U6 w4 ]' H  - Eject drive tray# c% r# d" M2 t
  - Power off drive
# s* x" p0 b" R  - Push drive tray in until it is half open
2 ?# s7 ?4 @# `1 w* I( a0 z  - Power on drive4 |, M# R1 e/ o9 N' ?- w9 f
  - Press "Yes" if you are ready
% B* S6 i5 }9 ~9 N6 |) E2 h    Are you ready (Y/N)?
# p( I$ v% B$ i1 T. U& `  G- simply press 'Yes' without doing anything of the above, because we
( f5 h5 ~2 q8 u5 r( x2 i  already did that before starting DosFlash16 / DosFlash32
/ h5 ~% J! n9 ?4 i+ p8 Z. O- the BenQ flash should now be identified! b% E4 v4 X+ B+ U# F  }- ]
- go on like usual' }" k# }$ x' n+ J
9 |+ y+ \+ v/ D! @' C) m# ]  L
# G) i/ v# {/ W9 V5 z" g# d
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with 2nd psu* n; g& e/ D2 {$ o
------------------------------------------------------------------------------------
7 {; ~* Z1 W9 E* @- C& v9 B% G2 w# ?- connect a separate power supply unit to the BenQ, don't turn it on yet& a2 j1 H8 ~' K/ n5 w7 v- @8 R2 G7 [
- power up PC and boot into DOS5 m) ]5 f' e; T% n" g; X
- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows; {0 |% ~4 J  X1 O; j0 D& O* }. {4 H
- if you read the following:! `/ ?% n1 w+ y
  MTK Vendor Intro failed on port 0x????. Because there seems
6 e: D& H! U8 R( h8 W4 `$ N* q* ~  to be a BenQ drive connected you should try Geremia's! q+ ~; B7 Q, Q4 _
  unlock method.
8 D$ Y$ K( L6 h8 }4 ~# M  - Eject drive tray6 Y8 q. ~: O- a* `  \
  - Power off drive
! r, Q5 K- `* }. S! R% J  - Push drive tray in until it is half open+ p* d. ^5 j# E  C! m
  - Power on drive
6 V. Y7 ~5 a$ R0 N) p+ E  - Press "Yes" if you are ready
- F3 C0 s1 w  o' j    Are you ready (Y/N)?- I# b$ P% R+ g3 ?8 M1 y- S6 k# y
- do the above and press 'Yes'; @( z, ]6 L- k6 B" H
- the BenQ flash should now be identified
. B0 Z. S' |; T* U" g5 X2 ?- go on like usual/ x9 [% \+ l5 m! G4 A* j6 D
2 X8 g$ c8 y5 |- v# d) o/ k. q
$ J- |3 w( Y) n! i5 c; d9 w5 g! n
Magic28 BenQ unlock with DosFlash16 / DosFlash32 on any motherboard
, v" O8 v8 x( B' [---------------------------------------------------------------------, v# g5 M% I4 f5 M& F2 L$ z
- connect BenQ to your PC's power supply unit and SATA port
4 c. x  @, `+ P( w6 U( y- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash32
: Y0 b2 ]+ X! E3 A* r- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows2 i0 H# m0 ]; Z: f! w4 b/ p
- if you read the following:8 k" y$ b& o, J7 ~0 D
  MTK Vendor Intro failed on port 0x????. Because there seems
" V1 A% r+ D" M& X  to be a BenQ VAD6038 drive connected you should try the
9 C/ v$ F% v% p  C  Magic28 unlock method.! O3 q8 }+ k& m" F7 J
  Do you want to send the Magic28 command?
4 |0 N0 h, B: U5 b3 w) Y) f- press 'Yes'$ V- _( O3 f; B
- the BenQ flash should now be identified
5 L. J/ }3 B6 K  ^0 t7 N- go on like usual3 P  J1 ]6 v) @  z# a5 q3 K3 g: B

# i5 k+ E$ S) w1 A2 h5 Q6 j( m
Thanks to Redline99 and Tiros for help and support.
, |1 F, U8 {; O# s+ w5 s' s- D$ u8 `6 W" H# l$ Y& o
It's all about DOS!+ d; ]& q4 s* L# a- u1 i! O
Thanks guys for the excellent team work!* V5 i) v( m, m$ t6 ?9 K% |0 \( B6 O
Geremia, Modfreakz and Kai Schtrom; f) `" y+ h, V" f0 T, }! c

$ w. I) |& X0 p9 f7 ]1 j5 {6 Y' o% ^: {0 \9 j0 K5 U5 q
************************************************************************************************6 T% m6 p0 _& a" @/ ?4 A
2 T+ e- d6 V0 H6 N( X
9 Q! K5 D% n6 n6 x# e- z$ h
DosFlash and DosFlash32 V1.4 Beta
$ N  a. k2 ^5 l1 K/ o: h; q0 ?-----------------------------------
- O" J; n" R) _2 ]- DROM6316 flashing support! t' i+ t( }" i* ^
- a flash erase is now always done with a chip erase and not a sector erase command, because5 ^! X' {$ ]$ m; K
  the sector erase gives problems for some Winbond flash chips including the DROM6316; G% ~& h& _( {0 D: T# V
- DosFlash.typ corrected and updated
( r! x1 c. @& i% T# j- for a detailed explanation on the soft unlock look at the included file SoftUnlockByIriez.txt,% x8 X  I) _4 Y2 }4 ]; E- O$ W
  it contains a very good explanation by Iriez from XBS, thanks for that one!
9 ~1 R+ E  }2 M8 A% R
5 a9 B  a: z+ O, LThanks to Iriez, Jumba, Redline99 and Tiros for help and support.
/ m* {5 ^, {$ T; Y" @6 f7 \: M9 [9 B" V
Happy DROM bricking!
/ J+ j9 ^) [. g' a6 o; o4 gTeam Modfreakz and Kai Schtrom/ ~! M: r( f0 v+ F, Z

, ?. Y' b* H9 Y6 S; K
( ?* `$ v- |3 X1 f; j+ g************************************************************************************************
! t. e4 e; W6 J1 x  P. ^% w' F0 O: @5 n9 T& l" o, f

2 [" w& A4 d6 c9 p( R( m6 ]8 Y* aDosFlash and DosFlash32 V1.3 Beta+ ?! D0 U6 A  b/ c- {3 i4 d( f
-----------------------------------
1 J- x5 ~6 _' w0 w7 ~$ i! ~- BenQ optimization in unlocking the flash chip, it should now be possible to read/write/erase& x4 s! R; n- f( H2 U; ^1 q6 ^
  the flash without any soldering or wire tricks, the drive is polled for the correct mtk3 J" x0 `$ L4 D; d3 s3 C* J
  unlocking status after power on, this only works for VIA cards and NForce boards atm
1 T3 p* Z/ x6 i7 T3 w+ h1 [: v- DosFlash32 has one additional parameter, if you start it with the parameter "EnableDrives"$ c) ~" p8 t/ y/ u* F. E1 y% \
  all the DVD-ROMs are enabled in device manager after flashing, this could give BSOD on some
, j, P- W/ d( B  systems, therefor you need to create a DosFlash32 link and add that parameter manual to use it
! d6 q% Y0 s- T$ m- DosFlash16 has one additional parameter "Send ATAPI Device Reset" in manual mode, this could
! q3 i* J( r: g( I, J& v  give better chances for soft flashing on some VIA - motherboard combinations9 s/ ?  e. ]" s9 `
- better support of Intel chipsets, drives can now be flashed if the controller is not set to: |0 D6 |. C8 R+ u% N9 D2 [
  native mode in the BIOS: m5 y4 D8 Q# G. `& r6 i
- the following controller list includes vendor and device IDs that are hardcoded to identify$ `4 @( |2 x/ Z9 i* m
  the controller type (IDE or SATA), this is needed if the BIOS uses IDE ports like 0x01F0 or2 F; I. N! ]* \: C; E
  0x0170 as SATA and not as IDE channels, this list is NOT related to soft flashing
# z7 m7 \) [; N3 G9 a- the following chipset support is added( \1 D. ~4 x4 r3 _: A
  - VIA cards
8 x" ]# v4 ^5 J  X/ b/ K6 v# B    - all VIA cards with a 6420 chipset
8 O9 w+ k0 e# Y$ y  - IDE Controllers
) e% e7 G8 G/ W- A+ d4 M$ z3 a3 M) }    - NVIDIA nForce 2 IDE Controller
0 W% @- R$ @8 {; `9 x+ I3 D    - NVIDIA nForce 4 IDE Controller/ F; }7 q$ W1 I7 u/ O0 _
    - Intel ICH9; H2 i/ v8 g/ u% _; [. I* Z
    - Intel ICH (i810,i815,i840)
& k. f$ ^. B& L: G$ v    - Intel ICH01 N: w- u0 i6 A" y/ F- {
    - Intel ICH2M3 k0 N- r; P( e: l4 J/ ?. R
    - Intel ICH2 (i810E2,i845,850,860)
) t- f  {# x  {" U9 Y# m    - Intel C-ICH (i810E2)
; H4 e2 B: t' }  h2 x    - Intel ICH3M
$ g: P* {! c  C# A0 o    - Intel ICH3 (E7500/1)3 F$ z. G# d% }4 v0 \4 `, Y# Y
    - Intel ICH4 (i845GV,i845E,i852,i855)0 v$ z- ~7 Q, N4 `. X' w
    - Intel ICH5
% z4 @3 ^# n  P9 F& i! k# ~    - Intel ESB (855GME/875P + 6300ESB)) a  Y! w/ l" M# S
    - Intel ICH6 (and 6) (i915)8 y8 d4 ?! h6 R
    - Intel ICH7/7-R (i945, i975)
; K- d6 P4 J/ L6 J: b6 N    - Intel PIIX3 for the 430HX etc  M4 {3 S4 h; z) j" C
    - Intel PIIX46 a' a+ T8 E/ A
    - Intel PIIX4 for the 430TX/440BX/MX chipset
1 v2 ]8 I3 V" r! _# f: g: |8 [    - Intel PIIX
. z- @- t2 y% }3 q1 L! i" o5 ~  - SATA Controllers
; Y3 W' n9 N% ?$ ?9 K, B! s    - NVIDIA nForce 4 SATA Controller/ Z  j" R9 H4 Z, z% V7 |. N
    - NVIDIA nForce 2 SATA Controller) h- a4 p& w" r. d1 N! {
    - NVIDIA nForce 3 SATA Controller
' c6 ~  Q7 [6 f' R, X    - NVIDIA nForce MCP04 SATA Controller- Q) L, q2 `+ k" I! G
    - NVIDIA nForce MCP51 SATA Controller
" Y! u3 y0 H+ m( K) h5 Z2 t; `    - NVIDIA nForce MCP55 SATA Controller, v. M: S* x* ?. F; {" p
    - NVIDIA nForce MCP61 SATA Controller* {: `( e  {6 j
    - Intel 82801EB (ICH5)) b6 H. R, @$ \# B2 a/ t- X
    - Intel 6300ESB (ICH5): x: M* T7 ~' ?3 g& E, N# D2 u
    - Intel 82801FB/FW (ICH6/ICH6W)
% [8 |2 d% {* f    - Intel 82801FR/FRW (ICH6R/ICH6RW)
0 S- @5 i9 ~, g, a3 z  j    - Intel 82801FBM ICH6M: m! I8 W- j# }
    - Intel Enterprise Southbridge 2 (631xESB/632xESB)
5 I0 ], L1 z6 X% t! `    - Intel 82801GB/GR/GH (ICH7, identical to ICH6)
! V/ P! N( ?( ]9 w7 u. O    - Intel 2801GBM/GHM (ICH7M, identical to ICH6M)
2 C9 P' D  K2 \    - Intel SATA Controller IDE (ICH8)
) J6 r7 F: `8 L& t, \1 D0 q    - Intel Mobile SATA Controller IDE (ICH8M)  G/ o. L6 q3 Z! c2 r
    - Intel SATA Controller IDE (ICH9)
) }8 W( Y. p$ Q9 Z    - Intel SATA Controller IDE (ICH9M)
- a) n( L* Z7 K3 ]6 H! |, w, p: h/ f3 {) S2 O$ F

/ k2 c( M5 v+ KThe following only applies to a software flash on a locked flash. The methods have been tested
. i3 |" Z+ X  i/ E- l) z( Q' ^9 ]with the BenQ and the Sammy. The VCC trick will work on any motherboard, but you need to do
7 p( u& Z) \9 I0 s, Tsome soldering and cut traces.
, U2 _% C( r1 k! y0 |' D% `$ b; z* ~& ?
8 X6 u3 {+ Z0 t- H8 q/ j" j$ `9 W
Soft Flashing the BenQ in DOS with a VIA card and DosFlash16 in manual mode
3 o( A7 [/ j1 v1 l- S& l-----------------------------------------------------------------------------
- R1 k/ r7 Q; v- g$ Y; t3 B% g- first you need to know the port addresses of your VIA card, you can get these by starting
3 H# ]* w. {7 J4 r. `. N: @4 n3 c  msinfo32 on Windows XP and looking at the port listing for SCSI devices/ t! F4 h6 B& ?4 a- w3 q
- for the 6421 the 1st port is internal SATA, 2nd is external SATA and 3rd is internal IDE& I5 i( x2 u4 j5 C3 F5 W% z
- for the 6420 the 1st and 3rd port are internal SATA
7 w5 M% S' U4 X  r& ?! F- you need the starting address e.g. 0xD000 or 0x7000
( O- A! K0 M' K: k8 H8 E5 u3 d, z- be warned that these addresses can change from computer to computer, they are assigned9 P* |" ~% k& w/ l
  at bootup, but Windows XP should display the ones you need for flashing in DOS
' Y6 P1 g' w, c% f! X5 u- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
' j$ J8 _; ^8 v) [7 k% i" K% r  Xecuter Connectivity Kit)) l9 e' ]: ~/ A* a6 l
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
3 r% n+ J; b7 a$ k( u  need to power the drive off and on during soft flashing
/ \- y( x: R! @6 e% O- cold reboot or reset the computer
0 w& I- ]& w, e3 d! I- boot from a DOS disk, I used a Windows XP MS-DOS startup disk4 N# s) G1 s- i" E* ?' _* N# X
- at the prompt type:
9 e8 P, `5 D7 j2 p9 |. C/ q  DosFlash r 7000 1 a0 1 4 a:\orig.bin 0
! ]8 Q3 |3 p9 }4 z& q2 |  - instead of port 7000 use the starting address your VIA card uses8 Q) O/ P& k1 w! H
- press return9 ^  F  |9 p7 B" w: n; V! L  ~
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes
, s2 }- S+ S; o" O5 B! R. J2 a- after you pressed Yes the drive status is shown on the screen, it's something like 0x7F,3 `, P7 q% H' L6 w+ g
  this will change during the next few steps
/ n9 P$ {, E! K3 Z$ |; b) N; C  a- turn on the BenQ psu and wait 2 or more seconds, status changes between 0x51 and 0xD1, n0 f$ l/ [1 H( m) K
- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD17 O, D* {/ \- X) p1 {4 K
- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start% D2 O! W* \8 S
- this worked only one time after the computer is powered on or resetted for me* q) d2 ~9 n2 P1 U% v
- writing and erasing works the same way, }* O+ O- }3 I
- for writing type:) L( |9 c: e/ x7 r5 d+ I+ j3 `- M
  DosFlash w 7000 1 a0 1 4 a:\ixtreme.bin 0
' C5 ~- M) }) [2 p2 t0 w# Y- for erasing type:( t" q" t/ Z/ o/ I1 g8 }% ]8 L" |, @
  DosFlash e 7000 1 a0 1 4 D8 0 (D8 is the sector erase opcode for the BenQ flash, if you need0 }( j( c4 Z# ~) B& X. S
  to erase another drive, lookup the value in the datasheet or DosFlash.typ)$ t  D4 f" l4 B/ Q& F( E( h* i
- if you experience any problems try to use 1 as the parameter to the ATAPI Device Reset, cause& l' F! o; Z1 H, y* E
  the same VIA card will react differently on another motherboard sometimes
9 {3 f* v, g0 @% h, B- R- l$ Q' R. ?

# c- j9 M0 Z- {$ i1 \- [7 dSoft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in manuel mode) e1 C- n2 h; Q1 B3 x
---------------------------------------------------------------------------------------
: I- E  ]2 J: e0 i- first you need to know the port addresses of your NForce motherboard, you can get these by 5 x9 L4 Y' j& R1 q2 n+ Y
  starting msinfo32 on Windows XP and looking at the port listing for IDE devices$ K( i2 J1 M0 h2 M4 k
- on most motherboards the 1st and 3rd ports are used for SATA
$ |, U. G, U+ I# e2 s2 v, g  c- you need the starting address e.g. 0x0970 or 0xE900
4 g2 {+ r+ Q8 n  f7 ~0 k2 q- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or + A9 F. I% V, ]" A& d
  Xecuter Connectivity Kit)
9 f8 [# |- o3 @/ O, D6 O  i  f- }4 @- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we0 t( }% K# R1 e. z1 `4 Y& t: a
  need to power the drive off and on during soft flashing& N" a( q/ B9 U# \, K8 x- A* A
- cold reboot or reset the computer
4 ~. I5 C; @6 m0 x8 I4 E- boot from a DOS disk, I used a Windows XP MS-DOS startup disk0 J( `5 o1 c8 {3 T& j" w  A
- at the prompt type: / K( C% p3 B; i' s" H* a
  DosFlash r 0970 1 a0 1 4 a:\orig.bin 1 7 \6 a2 v/ ^# x0 V9 R- ~
  - instead of port 0970 use the starting address your NForce motherboard uses$ S3 ?$ _/ p5 H! M2 ^8 ]! O
- press return5 [$ [8 k; \$ C. B/ f, p+ q" c( }
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes% v/ D% G( d3 }  U, Y& n; x4 |0 a# j
- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,7 o7 t; h6 K5 p4 ?3 F4 j
  this will change during the next few steps  i  c, C2 a7 }! k3 X. ?
- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start
  k, ~# i; N- ]- writing and erasing works the same way
  G4 _3 `5 t- Y' x1 R' t# B; f- for writing type:; Q  O  c- s- w3 i' S7 ~. \! }
  DosFlash w 0970 1 a0 1 4 a:\ixtreme.bin 1' M( i, B1 v( m8 G
- for erasing type:
3 L  @: P" e1 ^/ @: E1 [! n& m7 P, e9 d  DosFlash e 0970 1 a0 1 4 D8 1 (D8 is the sector erase opcode for the BenQ flash, if you need
* g3 Y5 v7 W# u7 E4 x- l6 Z  to erase another drive, lookup the value in the datasheet or DosFlash.typ)
2 T! u6 Q: A6 N  Y5 y
: A0 H) t0 z& O* {4 M! S# v& p0 \2 t% B, I$ z; z
Soft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in auto mode
1 a. G4 x" R& n1 c-------------------------------------------------------------------------------------; o3 w3 R2 k# N. H
- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or . E; L+ J& h) Y8 n& s' a
  Xecuter Connectivity Kit)
) E  \* ?3 m; g- z5 m. }- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
' r+ ], r! E* e& Q/ O  need to power the drive off and on during soft flashing5 s. b, Q2 }6 z7 X* y8 |. v
- cold reboot or reset the computer% P% d7 P/ T, p" n' D
- boot from a DOS disk, I used a Windows XP MS-DOS startup disk
# R& {( X! b6 _4 w$ @1 m- wait until you are at the cmd prompt
$ [- r8 x! p: r/ _0 \- turn on the BenQ psu
$ r# _) [% C, {! I. c  O& O+ m* s- at the prompt type:
7 s8 r1 d& N( ^0 Y) I: J4 W  DosFlash
6 \) p9 o' g& z& f& {- press return* _# f( q5 p. I
- during scann of the BenQ's port DosFlash16 will ask you if you wanna resend the mtk vendor
+ B0 E$ T* [4 _- R  intro cmd, press Yes3 ~- Y- X# S- M! \! `# v" {
- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,# `  @& t) m0 s+ T6 V. R& x- U
  this will change during the next few steps& _7 D5 w" |& Q+ m' Q" y0 Z# }/ Z' q
- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD1
& O0 T' k7 p1 f  O( J! j4 [9 Q- turn on the BenQ psu, you should get a good drive status 0x73 and flash access is granted+ e# V0 h7 ?% G3 h! I
- you can now continue as usual using DosFlash
/ q& E0 C3 ^. p* _- B- writing and erasing works the same way3 b9 _4 |8 }! t8 r
- if the ports are scanned there is the possibility that you'll get the resend question for8 W6 p* p) H9 R# ?& ]. b
  other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,3 G" R2 _; i: Y; Y6 v! i% y9 o( r9 Y
  if you know the NEC is at that port you should press No and press Yes only if the port of: q5 D9 ~) K: ~8 ]
  the BenQ is shown or simply disconnect the NEC
2 J$ m( |3 A9 f2 O" A# l3 d3 O! q2 j" @2 \
5 |( E& Q2 o7 t6 `% D1 w
Soft Flashing the BenQ in Windows XP with a VIA card or NForce motherboard and DosFlash323 f& d2 p  A6 D; S  {- h. ]
-------------------------------------------------------------------------------------------
1 e# o* O- u5 }4 C) Q- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
. M' _" T, x" n  Xecuter Connectivity Kit)% B6 \. K) X5 I4 W/ R! P
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
( M2 V1 |, @) t( N. u# H  need to power the drive off and on during soft flashing
; M/ A0 R: t6 p" t* a3 Q' B- cold reboot or reset the computer
) S& v; M& W1 Z8 Y1 i' h4 u- turn on the BenQ psu when you are in Windows XP3 e5 }0 x3 H( U. S
- start DosFlash32* k  o5 s5 e4 w0 Z" S4 ^# }# d6 N
- DosFlash32 will ask you if you wanna resend the mtk vendor intro cmd, press Yes
4 u* l4 w3 _5 e% X7 Z- turn off the BenQ psu and wait 2 or more seconds' F, L8 N! J, y& ?- N, r! B
- turn on the BenQ psu, the DosFlash32 dialog should show up% y, V1 W$ \7 X( X0 \
- the flash should be recognized by DosFlash32
0 b  c# N) ^' M0 ^- you can now read, write or erase the flash
! h( q6 n6 q- I3 p3 @) J- you should be able to do the flashing more than one time in Windows, only do the power 9 I0 y; N8 n  _
  off/on trick again# x& P. ^$ n( k: _6 @* D& ^- D
- if the ports are scanned there is the possibility that you'll get the resend question for' Q, W' W9 y0 w: [% W0 U
  other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,
7 E6 N! [5 D- K& _) q( `  if you know the NEC is at that port you should press No and press Yes only if the port of
& \$ g8 |% _+ ~% [) ~  the BenQ is shown or simply disconnect the NEC# a0 R( o8 f% M- }5 Y/ G  Q

7 E3 O( C" c4 ?9 n$ Q
) r2 E. r5 M3 ~, O3 ]$ ?2 T. |Many thanks to jumba for the great idea of BenQ polling!- W! ~2 o) H8 j
Thanks to Iriez, Jumba, Redline99, TeamModfreakz, Tiros and all the IRC people for testing
; c/ B4 B* d- _. Q0 Jand support.
  d& H/ P& C7 A' l3 ]. a& B  H. R
Join us on IRC efnet at the channel #dosflash for support.- A$ ]. L; w, S" u
; p8 Q  a1 v- |
Don't brick your BenQ!; B" M- [$ m- d1 m( E/ j0 ^4 Y7 T
Kai Schtrom1 ]9 h. V3 k" S

5 U; e) E# r5 u  I. s) e" e1 Q
" R' a# X8 d8 v7 C6 K************************************************************************************************
% ~, B* y2 J7 `8 Q2 M/ K+ h; g0 `
& _8 j+ [# ~/ T8 `( ~! P. E1 I
DosFlash and DosFlash32 V1.2 Beta3 d( y5 K4 E/ E# p
-----------------------------------
& {: i9 S3 h$ R! {- bug fix for BenQ recognition
0 r/ ]8 T) ^" {% r  - manufacturer and device id are sometimes 0x00 for a correct installed switch
- a& v' G0 R5 g$ b8 b* K4 `& \  - this issue is fixed with an additional ATAPI device reset before the mtk vendor intro is sent
) W2 H3 I  R4 }" j; W
" Y0 A4 d& D6 }, a# l8 a0 UThanks to Redline99 who fixed my buggy code by adding one line! & Z& {$ v( e1 j' A, w

4 `1 G2 K! h. |- m% {8 [3 g; x3 b* I% @$ w* l
************************************************************************************************
7 ^8 N" m* q: t; g+ n/ f
5 J$ X$ ]% N( [. m: @" X' Y0 ?7 E9 s& ?" P0 w2 L
DosFlash and DosFlash32 V1.1 Beta0 P$ K0 P( d6 e% d8 Y
-----------------------------------' l% A+ q1 T. I: w/ g
- DosFlash.typ modified for better BenQ support + j# F8 S% C1 M  H
- DosFlash16 Flash Manufacturer and Device ID screen output restructured* G5 R/ v( r* }
- flash chips are first erased before writing starts
3 s9 F" ~$ S% n( e: t! @# j, h- DosFlash32 no reenable of DVD-ROMs in device manager after flashing, this means you can't see the drive
- f2 E. f* ^% Q0 ?0 [  and maybe have to activate it manually again in device manager, this could give better compatibility and
- i: [4 I2 B& ^  hopefully no more blue screens
7 G0 @) J+ d: m( ^# z( g, ]( L
4 C3 b9 j9 L) B& E: l  _) Z6 CMany thanks to Jumba, Redline99, TeamModfreakz and Tiros for inspiration and help!
) Y' d, H- i/ w- f
3 N$ u) |# K- c- C# z0 z& ^
, [* L6 v" g8 i: H************************************************************************************************  D0 j4 X" I$ ]* k+ b

0 W7 \9 |% c: ]) n, T! ]3 y
9 F$ z; |, y6 I3 g' c3 W5 [8 vDosFlash and DosFlash32 V1.0 Beta7 Z: ?3 @4 U( `8 O0 C
-----------------------------------1 r  O& O. _3 t! j  T: @/ C
DosFlash can be used to read/write/erase the flash chips of most CD/DVD-ROM drives
# Y. ]6 C+ P2 G2 f9 i' g9 |1 e  z' Hthat have a mediatek chipset installed. DosFlash is for DOS flashing, DosFlash326 X8 ?+ ^5 b* l/ u) Z  p
for Windows flashing.  C# O: q- l- Q2 C1 @) _
; R# H# z+ H  K, U' w
* U. N( I' ?& _6 `& i+ q' q
Features:
1 `2 J3 \0 X% d0 H/ o3 X6 @! }-----------+ w5 P9 b8 H7 L: U
- flashes IDE and SATA drives1 p% a( a3 T- Q: q# |0 v7 R
- supports parallel and serial flash chips
  A0 V) H6 w5 J! @8 I+ S9 |, m- flash drives in Windows with direct port access
1 }( t/ A  x6 s- no vendor cdb flashing commands are used
( x: z* {# L7 ^/ f1 o1 G- b, v6 Q- tested with the following drives:
. y# V' h; ~2 ~6 x, o5 _- ]0 `  - TS-H943A MS25, MS28' V" R2 s$ G6 v; S) h2 H& H' A' q
  - SH-D162C
2 [& C8 ~* N1 [3 Z  - SH-D163A
/ {4 }5 t8 |5 ]  - and some other drives like Liteon, Hitachi, ...
" }: H2 G/ p& ^  ^' S" i0 {2 W- NEC drives are not supported, cause they have no mediatek chipset installed$ ~4 E6 }0 m, _1 J
3 t; Q3 S; E4 C+ v, m

, S# Z! R7 U" E+ [( r& jDosFlash1 S; ~0 o& c+ N. ~- I/ k3 U
----------
  E8 P* }; P$ r7 SDosFlash supports two flashing modes, Auto and Manual. If you type DOSFLASH at a DOS prompt it
5 K! x9 U1 W8 ^1 O& Zwill start in Auto mode. All drives and the corresponding flash chips are detected automatically.
( j$ u9 R  i8 d% o$ |9 K5 o/ r, h4 oIf you can't get a flash chip recognized due to a bad flash or other problems you should use the
5 ^! {2 {1 E9 @Manual mode. In Manual mode you can enter all the parameters used for flashing by hand. The
- p  Y' G9 Q; t2 O4 @- o! F( Ffollowing help screen is displayed if you start DosFlash with a wrong number of parameters:
$ s0 r4 a% M: p: T- E; ?1 \3 s3 e0 a. D2 T3 ]0 ~* [0 s/ n& ~

$ [/ v0 B. N6 c$ l6 `DOSFLASH by Kai Schtrom, 08/05/2007 (Ver 1.0 Beta)' [' G* j1 x9 }/ v8 R
DOSFLASH [R|W|E] [PORT] [PORT TYPE] [DRIVE POS] [FLASH TYPE]0 [8 ?( g0 L% T/ Y( ], @5 T
         [FLASH SIZE] [FLASH SECTOR ERASE OPCODE] [FILE NAME]8 B9 N/ i: Q! M/ A* a8 l# t
                        R: Read FLASH
5 [) L8 P! ~, ?9 e* @- e                        W: Write FLASH
- b0 Z; b8 R- r! x7 \; V1 L                        E: Erase FLASH
% L9 E$ n- E( H  W% o                     PORT: Port to send command to
/ k( ?& |" h$ k+ {                PORT TYPE: 0 for IDE, 1 for SATA. F! _5 y- O! T' n6 M3 b( P
                DRIVE POS: A0 for Master, B0 for Slave
, l9 A5 r/ c/ ]               FLASH TYPE: 0 for parallel flash, 1 for serial flash
, N( T6 \# v4 I' ^. w5 j               FLASH SIZE: size of flash chip in number of banks3 {, l5 q3 Z6 i$ X& i& V5 G5 I, h
FLASH SECTOR ERASE OPCODE: individual sector erase opcode command byte2 ^  N+ b( \; x! Q4 _* \
                           this is only needed for erasing a serial flash# _! I" G% l0 W
                FILE NAME: name of the file to read/write from/to flash
- `# p! O. b5 s9 J- b8 P; wAll numbers are intepreted as hex values!, Q1 {' V+ M  `
3 j3 \' D) @8 O" w! ^4 \
Example Usage:# ^* G/ ^. I, G5 W: `. Z$ R7 l
"DOSFLASH R 01F0 0 A0 1 4 C:\flash.bin"9 m) M% c2 ?- S3 N  C- J) D
=> Read serial flash with a size of 4 bank (262144 bytes) from Master Device
4 [' E# j# l. ]' q- U9 `$ F   on IDE port 0x01F0
& ~5 A4 P$ q3 p. U$ B"DOSFLASH E C000 1 A0 1 4 D8"+ h: ?/ i3 t2 z' E( h; ^. ^- U: o
=> Erase serial flash with opcode 0xD8 and a size of 4 banks (262144 bytes)
' R( z; z7 s: E3 V. n: W( r% f   from Master Device on SATA port 0xC000& m1 v/ Z) \5 d! b* ~
   
+ P. \0 I( \% C  e& @: G0 H   3 Q' f! a$ T" _0 ^, e
Explanation of the Parameters:7 w+ ^' m; J8 \: u2 @4 e
--------------------------------
0 p7 T9 |1 b. x8 h% y+ p+ T6 A5 T0 N
% ~/ ^$ ~% H$ W4 k0 ?! e; E[R|W|E]
9 q2 L4 I- c2 t) Z---------
/ G& e: X& b1 P- @- _# @5 E- this will set the mode of flashing, it is recommended to first try read on any
. h' |) s, r' Z! j  drive, if the read will fail, it is highly unlikely that a write or erase will5 G, e5 o3 U: ]4 P, z1 w
  succeed6 N* f( u! H" ^! q
& k6 [+ e9 \4 D' B" Z( r
[PORT]; s0 i4 I0 x& c) w6 ]0 ^
--------6 W( Q) a) o1 P
- the port to which the drive is connected, a port number should always be entered
  a9 I' z# u+ s  in hexadecimal and have 4 hex digits, valid ports are: 01F0, 0170, C000, C800
( r) V( R1 W9 C, U1 ]+ {5 n- this option can be used if your PCI adapter card or on board IDE/SATA ports are
6 {% U& r8 c; p. _# t4 l! T3 Y  not identified by the auto mode% F9 d% |: h3 n; i( X0 [: W% y
7 }" G6 x# z& R' j
[PORT TYPE]
9 }7 ~5 I: V7 o5 X-------------7 T) L3 M  v/ N0 h4 g6 \" H* A
- the port type tells DosFlash what type of port is installed on the before entered2 n' j2 J1 f; B9 Y0 d3 K5 ?! v
  port address
% f+ `( D+ ]8 ~) B. Q/ q7 s- valid values are 0 for IDE and 1 for SATA4 H" X6 u! @5 b9 G# A
- make sure you never mix the wrong port with the wrong port type, this could give! g4 z" `( d  f! _+ P% a4 k+ L5 ^
  strange results or in the worst case a bricked drive2 g) ~9 M$ Y- G/ ?: ]
  
# D4 n' W- Q# V1 n. Y% u* ~[DRIVE POS]% ]/ k% @. B5 E. v/ l8 l) a
-------------) ]( h6 P6 H% ?
- old style IDE channels have the possibility to connect two drives at one IDE1 }. _' i2 M/ s* [4 r( j
  channel, the first drive is called the master, the second drives is called the
& H, l8 i$ y  _# p# d! i  slave
7 }& U2 v" w( X  F6 R% D- you can select which drive should be flashed on the channel, A0 selects Master,$ E' n* w& r7 y/ t2 Z4 H
  B0 selects Slave) N9 m# m6 q9 T0 Y7 K$ w1 X  E
- on SATA ports this value is always A0, cause you can only connect one drive to
% R, ?3 V& e/ J4 V0 T- M  a SATA port, so for SATA you will always type A0 here$ I" i, |- G) U( u, O( @. U
- it is not recommended to flash IDE drives with another drive connected to the
5 \/ @- w3 E$ l) y$ r0 L  same IDE channel, this could be risky if something in the Master/Slave selection7 H8 T4 N* {0 D  [8 y0 Z- e5 ]
  fails! ]7 ?# }1 U; l) h3 f
  1 W6 Z( O7 u0 s( ]+ n+ Z; N7 ^
[FLASH TYPE]; d  u2 D, v+ z% _, ]/ d/ @: b
--------------
* ?6 C) k, A' ~. R- there are two types of flash chips out for CD/DVD-ROM drives atm
: q# C& o  \$ K" O- the older type is parallel flash, which is also supported by mtkflash for example
1 _0 M" R" X8 m0 Z) P1 s- the newer type is serial flash, which is supported by flashers like XSF& n" Z9 u1 y5 l. K0 v
- the problem here is that no tool is out that can flash serial flash chips on 6 q+ i7 ^- f( _% o: I* b0 e
  SATA ports
$ y& U! O1 O: J  
) m& G" @: j( ?. ?2 w" U+ _/ Z6 R[FLASH SIZE]
5 L' i& m- J" G3 J; e. V, k* f--------------
8 Z' I& D- |2 d- this is specifies the flash chip size in banks
! y& ]" D6 }1 f' P' R3 o7 c- one bank is always 65.536 bytes in size+ k# B- A$ I9 @; A8 \8 z
- if you know your drive has a flash chip of 262.144 bytes in size you need to enter 4
: ~& D, R' t0 J' v
3 O+ @: ~/ U8 v/ i[FLASH SECTOR ERASE OPCODE]+ B. r- V% F; T' Y7 G: M1 R
-----------------------------' H) V, ^- D8 F4 x" T
- the opcode used in the flash chips datasheet for erasing. [0 b( H. p+ y. _  ]/ f# p0 b: F3 Q) R
- for serial chips this command can be different from the standard and needs to be
" Z9 s! y- k; G  entered for flash erase' a3 v% T8 B5 `) u# L/ D
- for parallel flash chips you can enter a dummy cmd byte, the integrated command
/ g% ~  _4 b4 l0 b  should work on all parallel flash chips without a prob
: x- l3 @. m8 z0 y/ V. F  6 e" W* H2 X% P0 v( G
[FILE NAME]$ \4 d3 Y7 E9 }' P/ B
-------------# P, G: l- q8 q
- name of the file that should be used for flashing& u4 G7 W7 g5 l# U5 `
- for reading operations this should be the output file
; W6 |4 T: s+ P2 Y& L9 p, k) ?- for writing operations this should be the input file
( S' K, `0 h4 r! p2 b- V5 I* Z! l6 e/ L1 v" P9 L1 f8 s

2 c! ?0 A8 D& I' ^Hints and Warnings7 t* H1 a4 f- i
--------------------
: O1 V3 {' Q. e& e7 F* q9 g- read, write erase TS-H943A MS28 after the firmware stealth has been disabled with Enable0800 disc; R& c1 Z8 V: }6 z) G% z" f
  - this only works one time, after the first mtk vendor specific intro cmd is send
5 W) s4 |$ u% E2 I6 E9 a  B  - if the mtk vendor specific outro cmd is send the chip goes back to stealth mode and you need2 ]+ Q  p# t" H
    again the Enable0800.iso to disable it
. D4 H- q. q3 j. u  - therefor the mtk vendor specific intro is send at program start to all present devices and the" @( E3 \0 d" d" X" ]+ i0 s
    mtk outro is sent at program end9 W/ A% F* L# H- s( e  S
  - if you have a chip manufacturer id of 0x02 and a chip device id of 0x02 for the TS-H943A
& U; e: j5 b( r: k1 E% f    the flash chip is in stealth mode and won't give access to any reading, writing, erasing* R  x  X! n; I
- always have a look at the DataSum generated, this is exactly the DataSum of mtkflash
0 U( |( l0 K; I4 a6 Z0 E  - the DataSum is calculated as the sum of all bytes of the firmware in a short integer
5 ~2 ^" Y! j3 `) p  - to make 100% sure that the flash is written right compare that DataSum to a known one% E0 K, S$ l, @
- this tool has not been tested on all drives out there, the typ list is simply copied from well
4 @$ J4 N# `: [1 s  known programs like mtkflash and XSF
& D, G9 p1 a0 m# M; V  - always try a flash read on a not yet tested drive before doing anything else$ I2 h3 z$ Z+ m' C% m* Q9 p
  - if the read doesn't succeed it is highly unlikely that a write or erase will7 S. n  _4 G" Y3 s$ }3 _* X
- some LiteOn drives seem to have probs to write the firmware correct, this prob seems to be
; ^* o! H5 B: U: s# w  related to windows register flashing, cause even an assembler app can't do this error free
- ~9 k8 a5 W5 M! B  - if you get errors on LiteOn drives, write the flash two times in a row
- Z0 p+ \* g; K; `* X2 n2 q6 W$ _- for direct port I/O in windows the givoio.sys driver is used, this driver is loaded at DosFlash32
/ {9 @2 k( l# d+ g4 A+ `2 f  start and unloaded at program end, be warned, this driver can possibly make your system unstable,
3 P4 \& ~' e0 T# ^  it's intention is to let privileged assembler instruction like in and out pass, even in windows,
8 m4 r& L! O- {/ E0 [  y  if this driver is not used you will not be able to get direct access to port registers* C( s+ B4 G8 X+ Q
- DosFlash was tested on MS-DOS 6.22 and later, you can easily copy it on a MS-DOS boot disk created
* S0 P/ g" T: O1 B- ~. U  L, F. w  in Windows XP and start DosFlash directly from the disk
9 g; P4 F" Q6 a2 k' w% r- don't forget to also copy the DosFlash.typ file, it has all the informations about flash chips
; R# I2 {! P" \2 X  for auto mode flashing
& l) p9 A2 w+ |( ~9 L, m- DosFlash32 was tested without a prob on Windows XP SP2, you'll need also the typ file for the 0 {, u2 z7 \/ c# |5 B! d
  win version
: R8 o: x! B& {5 x  f; k% ^- U- DosFlash32 will deactivate all CD-ROMs in device manager at startup, this is better for flashing,
8 `6 |' ], [, e8 a' ]' _: s  cause Windows seems to poll the drives all the time and this could result in a bad fw file or: b& N6 P( I3 S  g
  a program hang, the drives are activated again at program end/ h5 I# M( |* v' a+ M. p/ a
- you should make sure that the flash is not in an erased state at program end, cause device manager
; E& i5 O* J1 p5 k9 R  don't like drives that do not respond to the inquiry command
) L6 W: c) T3 q$ g- p  c- deactivating all CD-ROMs could take a few seconds, so please be patient at program start% a2 ^$ B; r" H; e& H% X
- DosFlash and DosFlash32 will try to scan for the VIA 6421L Raid Controller card, based on vendor
8 e! o; A: `8 c- B3 R/ |( Y' B$ X  id 1106 and device id 3249, it doesn't matter if the card driver is installed or not7 d* Q& j% C' ~( S2 D7 C  @

' |- q0 I  Y" j6 h/ x9 i7 ^
8 E. w. E) j# g# z: `Many thanks to Dale Roberts and his Direct Port I/O driver giveio.sys!- E/ V# w' h$ t- ]' W. K

. R) u4 F1 K, ^6 `Avoid a bad flash!% R/ S- Y! A" X; ?, q
Kai Schtrom
22#
 樓主| 發表於 2011-8-23 00:02:15 | 只看該作者
版主你好^^
2 |& q7 Y. s# ^- `9 d# u( Z非常感謝版主的用心貼這個給小弟^^只是小弟技術還沒有到那裡有看沒有懂^^|||在試著找看看如何使用dos介面下提取dvdkey雖然有找到一些訊息不過還是有看沒有等以小弟的目前的能力還需要多看多參考^^6 {' r6 d1 }! Y# R; y7 v% l5 P
感謝版主的耐心回覆小弟在多上網找看看看有沒有新的發展如果可以成功自己刷機因該會很有成就感^^
23#
發表於 2011-8-23 12:08:02 | 只看該作者
ak475671 發表於 2011-8-23 00:02
% R( m& m5 H: }- H0 e5 J版主你好^^
$ ?( _8 p" J* N+ X" @, k非常感謝版主的用心貼這個給小弟^^只是小弟技術還沒有到那裡有看沒有懂^^|||在試著找看看如何使 ...

6 C) U4 c- I9 P) U# V6 F以下是實際圖片示範:! N7 {+ L( z  Z4 t
1 n: u# O" u  V: a# y& h3 B' O+ C7 e
在DOS模式下輸入DOSFLASH並開啟XBOX360光碟機插上電腦SATA,就能抓到以上資訊
; [! y3 w  w5 Q$ z
& J! ]2 y9 Y. r: G  Y/ F接下來它會問你要幹什麼,這裡我們要取得它的韌體,按R讀取
. T: j: w& G+ v! w7 C7 x
1 ]- |% U* E4 X5 k  L上圖就是取出test.bin韌體名稱,您可以任意取其它名字
0 H& \$ B! g9 k6 S3 H
9 X$ F8 q6 L  `& j1 b, n" t9 ?1 \再使用16進位編輯器去開test.bin檔,可以在其中一行找到DVDKEY,至於其它韌體的DVDKEY位址不一定像上圖一樣,有可能在其它位址。
  U4 |( s$ y& B% v" _# I- S2 Z
24#
 樓主| 發表於 2011-8-23 23:28:34 | 只看該作者
感謝版主還這麼用心幫小弟找圖片教學謝謝版主我再去試看看
: Q' V7 v1 S, ~/ B5 N$ c5 w9 z
# X" q2 A* x  i( l8 h# ~^^謝謝版主了^^
/ l$ C9 A0 C  F" R# _* ]6 K
25#
 樓主| 發表於 2011-8-25 00:26:07 | 只看該作者
版主你好! j  H1 @# G. R
請問要進到dos去提key是要開機就直接進到DOS還是附屬應用程式裡面的DOS就可以進行提KEY了8 F) K/ n! ?( c: p
另外我下載了DOSFLASH1.9版裡面有DOSFLASH16    DOSFLASH32    DOSFLASH64   這樣檔案是正確的嗎
; h3 d' _4 \8 t: s: n$ m我有看了16的點了跳出畫面右不見了然後32的點了出現視窗因該是可以讀取DVDKEY的東西  那我可以直接從32那邊去提KEY嗎   或是需要進到DOS去才識正確的提KEY方式
: }( C' E" O0 F, k3 Z2 w$ f
26#
發表於 2011-8-25 12:18:27 | 只看該作者
ak475671 發表於 2011-8-25 00:26
% U# S" ^, g3 o7 g( j1 _' O版主你好
6 s$ i. v. v8 B/ W& y+ W2 K; p請問要進到dos去提key是要開機就直接進到DOS還是附屬應用程式裡面的DOS就可以進行提KEY了  z3 t4 R- ^4 D- n
另外我 ...
; t; L- }8 K9 |8 T4 P1 |$ r
Dosflash16純DOS模式使用(早期的Windows 95、98或更早的DOS 6.22開機使用)( u+ S0 `0 f1 e3 o
Dosflash32在Windows作業系統32位元使用2 z8 E. b% _6 u) A$ H4 ?" k
Dosflash64在Windows作業系統64位元使用" Y+ G/ D' h! A  X2 X, Z
建議使用純DOS來執行,其實可以不必這麼麻煩用DOS下的16進位去找DVDKEY,- ^0 n* ?0 y) i1 j( H! v; n- ]
可以使用DOS讀出韌體後再進到Windows下,使用JF去開您讀出來的韌體檔就能取得DVDKEY。
您需要登錄後才可以回帖 登錄 | 立即註冊

本版積分規則

小黑屋|Archiver|黑皮維修站    

GMT+8, 2026-9-18 19:29 , Processed in 0.102695 second(s), 14 queries .

Powered by Discuz! X3.2

© 2001-2013 Comsenz Inc.

快速回復 返回頂部 返回列表