|
|
ak475671 發表於 2011-8-22 13:03 & ]8 h+ K( I! d. Y d) s) B
版主你好
; I' E" q* U& l版主知道哪裡有教學嗎使用DOS提KYE的過程不是很了解不知道有沒有教學可以參考的呢0 J% V0 s, ]; h4 k
另外你說他提取 ...
M* c! G! r. z7 f/ B4 @9 wDosFlash ReadMe.txt 說明文件, |6 d& N2 Z9 h/ a! U
% v# ^- A1 M+ c# U0 V
DosFlash V1.9 Release Date 01.01.2011+ X( F+ Q% y ]# l" [8 e
---------------------------------------6 A. X$ z1 E; H2 x- x1 ?
- SATA and IDE port scan improved in DOS and Windows
! _; y% ?& X" A! s9 Z- T/ N The ports are now enumerated with the CONFIG_ADDRESS and CONFIG_DATA register instead of using interrupts
& R5 u: z* O: z( z; U in DOS and SetupDixx functions in Windows. This change will detect more ports in Windows than the old 6 e$ ^) Q1 z+ }3 F8 ?7 S9 ^7 o
SetupDixx method.7 g# d6 i9 n- k; w8 s
- Settings saved to ini file for DosFlash32 and DosFlash64
' B) I4 ~4 s$ }' k: O/ c2 L- ~5 P Settings like Port, Position, Task, COM Port, Enable Drives and DvdKey state are now saved to an ini file- f) l& z. V. j, t6 R7 P9 k1 k9 U6 c
inside the program folder. If the ini file is not present it is created after the first run. On the first* X( s8 G1 \8 H6 N7 h
startup DosFlash will choose the most common and stable settings.
2 |# z, I" Z S1 u% z# v- EnableDrives option included in dialog as a check box
6 h9 G$ e- N/ U! e. h \ Due to high demand we removed the "Enabling CD-/DVD-ROMs" MessageBox on program termination and included3 u' C. ~) S% x, X& ~0 o7 ?
a check box "Enable Drives" inside the dialog. For security and more stability this is deactivated on the' V" G T# W% `# Y
first run. If you enable it the checked state is saved to the ini file.! @+ z9 O8 |7 B8 X4 k6 `
- enabling drives in Windows caused some hangs from time to time, this is now fixed by a recoded enable
) n4 a# N8 ]. C+ B drives function
/ L0 m; H$ Q% ?" W- port drivers portio32.sys and portio64.sys are now added to the executable and unpacked during runtime
% W; \8 Q. S q$ T) f6 J/ s- PATA and SATA controllers list updated
7 B i! m5 e+ N- Fix for NForce motherboards in combination with drives like the "Samsung SH-D163C", "LG DH18NS40" or+ J0 h# U" G1 ?- @
"LiteOn iHDS118"
) ~1 y0 I+ J3 C! P Some drives have problems with flash identify, read, write and erase. This is clearly related to the5 z& X- \# ^) s* I* |1 B
NVidia NForce chipset. For manual mode in DosFlash16 an additional command line parameter is added called
2 I( w. z" g& K6 J' `% b' }9 p "NFORCE FIX". This parameter should be set to 1 for NForce chipsets if you experience strange problems.
' a$ d& Z, P+ ?) W In DosFlash32 and DosFlash64 we added a static control which shows if the NForce Fix is applied or not.4 A3 S1 c) E7 u; \, E7 E1 R, |9 M6 B5 u
Remember there is no need to activate this with every drive. It seems to be a combination between drive0 s4 @; _& l* u4 r/ i# ^
and NForce chipset that causes the problem. The fix is automatically applied for DosFlash16 in auto mode,5 m6 d/ }# F4 A
DosFlash32 and DosFlash64.- |! H0 [+ o" B, ^- H
- DosFlash32 and DosFlash64 are now DPI Aware for Windows76 T2 u% @, ~! u" X& H2 T
- New task Verfiy Key/Inject Key added for verification/injection of drive keys
5 e* v' {0 u9 w) ]8 g% ~ All DosFlash versions now have the possibility to validate drive keys against an XBOX360 drive and set
+ P' x6 W8 k2 k% g- K U the key for an XBOX360 drive. We use the same authentication method like the console to verify a key.2 N- ]1 b" |/ y' @/ B6 `( L
In the Windows versions you have the choice to paste the drive key from the clipboard to our custom hex3 z% Y( r+ y3 ~3 n
edit control or load a key file. To add a key simply click right inside the hex edit control and select
9 d1 V1 _9 G3 }% _/ K# u S your choice from the shortcut menu. In DosFlash16 you can enter the key in the format "1A-2B-3C" without
* R0 m0 j5 S2 F8 } quotes. Remember that a key has 16 bytes of data. The key file to import should also have 16 bytes of data4 V6 L' Q5 `1 x! a# x
like the key files exported by LiteOn Key functions." a, q, G* t& R( ~6 m+ B
- Removed multiple key extractions for LiteOn Key functions, added Verify Key after extraction- G$ U( m4 g" E( q2 I. d8 [3 q3 o2 [
For LiteOn Key functions we removed the multiple extractions, because the key is now verified immediately$ g7 R" `: ~+ ? l
against the XBOX360 drive.
- d' n9 _1 }0 |( [9 K- LiteOn Key V1 and V2 now also extract the file Serial.bin and the 2nd inquiry file Inquiry2.bin
9 S7 c" E1 z3 O We added the file Serial.bin and Inquiry2.bin to LiteOn Key functions. Inquiry2.bin is only generated for$ K% _+ A& L* i0 Z7 |) |/ I; {
LiteOn drives V1 and V2.
& E3 q" d, @0 G- b$ n- The drive key of Maximus patched UART drives can be extracted by using the task "LiteOn Key V1 (DvdKey)"
. o* T! a$ | } The drive check has been removed from LiteOn Key functions. This way we can extract a key from an UART
5 r0 R; `; |: C3 v+ V% f patched drive firmware by Maximus.) _' G }4 J& U, L# M; e
- LiteOn files are now extracted to a destination folder instead of prompting the user for every file name.
! g/ t& Y9 j5 ^2 M& j& Q- LiteOn key extraction tasks separated per drive version in "LiteOn Key V1 (DvdKey)", "LiteOn Key V2 (FreeKey)"/ X- Y0 H8 {5 o& j+ [
and "LiteOn Key V3 (Tarablinda)"
+ }+ v4 k/ r9 C& C- In DosFlash32 and DosFlash64 the number of installed COM ports in the system are now enumerated instead of
6 R k3 f- H1 e0 U- o/ _ adding port 1 to 4
5 m! N, P) h9 ^. _& E) Z- For failing cdb commands the sense code is returned' j. R% ~6 H$ Z8 q2 V
- Geremia's Tarablinda functionality added; L( W( Q4 e8 f( g, Y
We added all Tarablinda tasks to every DosFlash version. You can extract the key by choosing the task$ v# i s; Y& ]( I2 X
"LiteOn Key V3 (Tarablinda)". For read, write and erase of the flash simply use the standard functions.
- s+ B. }' _8 C1 S3 e Pay attention that the "LiteOn Erase V1/V2" task is only available for older LiteOns and not for the Slim.
- a5 z2 u D4 M! V$ {4 r3 Y You should use "Read Flash", "Write Flash" and "Erase Flash" for the Slim. "LiteOn Key V3 (Tarablinda)"
' d3 O$ b$ D6 [# V, T( m3 S0 r extracts 1 additional file in comparison to Tarablinda v04b, this file is called Xtram.bin and contains0 ?& P( c' x2 ]+ A7 @2 |# o$ H; t# S
a dump of the XTRAM8000 area. This can differ in a few bytes from one dump to the next.$ t1 [6 ]" x, v6 u, w" Y
- Device Reset in DosFlash16 manual mode is now done automatically, there is no option to turn it off anymore: o0 O( ?, k# G9 B0 i% E* ^" _
- Code optimization to work with modern SATA2 controllers added, remember to set SATA controllers to IDE and
o8 w5 m( ~' Z0 S2 W not AHCI mode otherwise Port I/O will not work/ L: b3 K, g7 I% g# _+ D
- Warning: The read, write and erase of the Slim drive is considered risky in general! So pay attention and8 P2 r4 ^+ v* x
always remember you use DosFlash on your own risk every time! Even during flash read the Slim gets flashed" z" w! d: l7 t9 ?
with a patched firmware sector to retrieve the complete dump!
- ^8 t6 V, o2 P, W- We had to change many command line arguments for DosFlash16 Manual Mode, because of the NForce Fix, added1 k) p: @8 \; N+ B+ D
Tarablinda support and splitting of LiteOn Key functions. To get a better understanding we added the example
; [) ~+ N) ~ B* F ^9 x1 Z5 O. \0 W section below.
1 T0 R d7 b( m& h, w# m8 c& |6 v" g. g1 `
, a# E+ _+ F" r i3 C: i5 T
DosFlash16 Manual Mode Examples
; u5 c* A, g0 P$ d* s0 R8 b---------------------------------9 ^( M$ K y, R5 C# F9 V, M1 I/ s% K
- Extract drive key on a " LDS DG-16D2S 74850C" over UART -> "LiteOn Key V1 (DvdKey)"
- `2 ^8 s" o$ W- c7 o DOSFLASH LITEON K V1 0970 A0 11 p$ u. z3 |% {4 P9 ?! F6 J
1 J: G0 q0 k5 K) W& ~) }1 |
- Extract drive key on a " LDS DG-16D2S 83850C" over SATA -> "LiteOn Key V2 (FreeKey)"
# M/ g" A$ J( r- d! Y DOSFLASH LITEON K V2 0970 A0
) @+ h8 S+ _$ h. t5 e$ c( }( h5 T l( E% D. }3 ^
- Extract drive key on a " LDS DG-16D4S 9504" over SATA -> "LiteOn Key V3 (Tarablinda)"6 F7 w" s4 J& N# d+ E
DOSFLASH LITEON K V3 0970 A08 f+ J: u5 U( J' i, E
* j7 t% k, ~+ f K4 k2 ]- Read firmware on a " LDS DG-16D4S 9504" -> "Read Flash" this is considered risky!
% j" ]5 M' q d3 T. u DOSFLASH R 0970 1 A0 3 0 4 FWOUT.BIN 0
( ]0 |4 E8 c$ f5 y
0 o) o4 m8 N+ Z* y2 _- Write firmware on a " LDS DG-16D4S 9504" -> "Write Flash" this is considered risky!
( w" j* Y3 x% [; o, C1 _9 D DOSFLASH W 0970 1 A0 3 0 4 FWIN.BIN 0; D1 O$ O: [, a5 b4 s
, b4 T- e0 \0 n& D7 U# @6 m& L- Erase firmware on a " LDS DG-16D4S 9504" -> "Erase Flash" this is considered risky!$ t- t5 {4 v8 E# ~6 r4 a& j- G ^* r" R
DOSFLASH E 0970 1 A0 3 0 4 C7 0- {% G* G* R, t8 k' ^
U, Y7 r/ Y! @+ O2 d! m3 U! t3 U- Erase firmware on a " LDS DG-16D2S 74850C" or a " LDS DG-16D2S 83850C" -> "LiteOn Erase V1/V2"
& u( b5 Z& L# U, q+ L8 b DOSFLASH LITEON E 0970 A05 {* e" X$ |5 M0 C5 o
- ]( h9 N7 x d9 N/ J- Read firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Read Flash"
( R8 D- H9 Q1 J/ Z% j1 B( n DOSFLASH R 0970 1 A0 2 0 4 FWOUT.BIN 17 l, j3 @0 k) `8 o7 p
" M) T% B" u3 C8 p( |. \$ ?
- Write firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Write Flash"2 f" o( q e. \, U, l6 K0 J. o
DOSFLASH W 0970 1 A0 2 0 4 FWIN.BIN 1 V0 b0 H& q5 b. N9 S, m/ u4 {
- K: T3 G3 @* s
- Erase firmware on a "Samsung SH-D163C", "LG DH18NS40" or "LiteOn iHDS118" and a NForce motherboard -> "Erase Flash"
5 G8 m; Q& Q: i; G/ x1 Y DOSFLASH E 0970 1 A0 2 0 4 C7 1$ m) |( b3 K5 X4 n$ g7 {* r
& A `; H+ J) A8 r) ]$ d" u- Verify drive key on a XBOX360 drive, enter the drive key manual
# [7 R& J8 {. |0 d4 y/ S5 e DOSFLASH V 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF) Z4 U i% m$ K) ~( ?
A/ d, i: M/ Q- Verify drive key on a XBOX360 drive, load a drive key file
M6 Z0 N- E2 {4 ?5 g DOSFLASH V 0970 A0 KEY.BIN
9 A8 V. L1 d9 Q- l# A6 ?
) X1 D7 k$ r; h" \% s8 Q. ~- Inject drive key on a XBOX360 drive, enter the drive key manual: P. a- ?. [' B7 |; u# `# E- @
DOSFLASH I 0970 A0 12-34-56-78-90-AB-CD-EF-12-34-56-78-90-AB-CD-EF6 F0 o* V% k! w0 z M' {
. m) H/ i9 f! V
- Inject drive key on a XBOX360 drive, load a drive key file4 j8 e; j0 _( P
DOSFLASH I 0970 A0 KEY.BIN
, ?8 F1 ^; M( l$ |8 C% p2 ]
: d. ]0 b6 ~+ [7 a0 SFor DosFlash drives on which we can extract the key via UART are considered V1. Drives we get the key over2 d: h" T1 }2 G1 ^
SATA are considered V2. The new Slim is considered V3 but only firmware version 9504 is supported atm.8 k4 p( L$ X7 A% ?
( {" t7 C( ^9 z/ A d3 Z! t) G2 R+ A: J+ f5 J4 R
Many thanks to Geremia, Modfreakz, Redline99 and Tiros for their support. Special thanks to Geremia and
0 \+ I# \$ g! w, `7 HModfreakz for drive sponsoring, testing, coding and much more. It is always a pleasure to work with you
" v9 [( q7 w! X3 _/ ^professional guys! Respect to Maximus for his UART enable patch. I'm looking forward to your magic Lizard
( ^( p* [ n0 }1 q& P6 Z: \hardware flasher!8 p! C; c' e8 I; P+ i# `4 k
+ X' {% A3 Z( @! b* E' K, vHappy new year 2011!& M: [1 i- r1 G. e- K4 z' A; M
Kai Schtrom; G! `9 D* N b. f" q3 M7 ~
+ x. q: v2 O6 {$ {7 _. w0 Y5 V************************************************************************************************
' R5 ?& N" n4 b6 _7 e( u5 z2 j# w ~' G/ i
, u) P7 g/ u* U* E7 I3 A
DosFlash V1.8 Release Date 08.08.2009
5 g9 `3 E$ i' o( i/ K1 [---------------------------------------: ?) B \$ o9 y4 `+ ]" E
- now supports LiteOn PLDS DG-16D2S 83850C V2 Geremia/Maximus LiteOn FreeKey method8 d8 C4 @4 y- F1 Z0 {- B
- huge firmware read/write speed increase, especially if run from a floppy disk
7 X( o& d/ N B" E! {0 S+ n- updated IDE/SATA motherboard chipset list; K9 |0 P9 [. K4 F( K' H
- new IDE/SATA detection for Windows and DOS! f0 T; i U7 [# |4 |5 {1 U6 Y# O
- DosFlash.typ embedded in executable file( z! O( N! ^9 f( i$ |- ^
- LiteOn V1 drive key is now extracted 10 times and compared against each other,8 x! a3 H( K, u$ R. B
after the extraction a summary is displayed sorted by the most common matches
6 q- l. W* A7 e' F- LiteOn V2 drive key is extracted 2 times and compared
% Q8 h; ^8 \* }! A% O. u) P- new BenQ unlock keys added to unlock all known BenQ drive firmwares
5 d8 I# W! X9 g- command line parameter "EnableDrives" removed, DosFlash asks the user on9 O- H& a. h0 {8 @$ v
application close if he wants to enable the drives or not, during the tests it- P; v5 X4 O4 n) F
seems that IDE drives have problems with the enable, SATA drives seem to ( j$ V7 Y/ G* o/ _" c
work fine+ Y: g5 P$ i) p; B9 V0 C A: r3 S. M
- new 64-bit DosFlash edition added called DosFlash64, because some driver, G$ x: y, W2 z# m T
functions don't work as expected in the 32 bit compatibility mode on Windows x64
& J2 i3 ~5 b. w, M; L- Beta state removed
- D+ I8 e+ y2 w- ready and tested on Windows7 X86 and x64) g8 Z7 B0 a: u' y" {4 ~$ ^
; c p' T5 k. S; W; i8 A" b, O; e5 }/ t3 l3 l( w$ ]" _
Geremia/Maximus FreeKey method with DosFlash16
6 s9 K1 |/ a6 n3 l------------------------------------------------0 I6 } t7 F* V Z! b6 n
We have added one cmd line parameter for DosFlash16 in manual mode. The COM port% a0 `; ?$ e( Z7 n% n/ R% w4 ?# X: M
is simply ignored and can have any value for the V2 drives.
* v- c8 ^. o3 [% L+ mUse the following command line to extract your free key from 83850C:# r& f( W. B, P3 ?
- DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin enckey.bin
9 A( k2 n, u# ]/ m3 R4 I9 z1 O+ a/ W9 u. C
+ o1 P, G0 h/ WTips for running DosFlash on Windows 7/ Z) }( J& y7 Z- T6 X& }# R! R7 W2 r' I
----------------------------------------% M, e4 m/ }6 K* L$ t7 h
8 S4 p$ d8 {- C. X/ D
Since Windows Vista 64 Bit and upwards it is necessary that every driver is signed. Because% P7 t7 C7 p# U7 T9 J
the DosFlash driver will not be signed by MS due to some unknown reason we need to circumvent5 k( _! ^' j4 K3 p) W G9 `0 P
this check. You have the following 2 possibilities to do this./ p7 @) A) n3 f: R) Y l
) ] p, ~2 l0 eSafe Way of Disabling Driver Signature Enforcement
% b9 _" [0 N4 m. L1) On Windows 7 bootup press F8 to get to the extended boot options screen2 c" X# U1 S7 V" P8 e# v* Z& b7 r
2) Choose "Disable Driver Signature Enforcement"1 H( j/ r9 M. {
3) To start DosFlash right click on it in Windows Explorer and choose
* q6 \4 j4 c. V) |5 Z" j "Run as administrator" > answer the message box with "Yes"
+ f9 a1 T4 m$ J. I+ a; S# T5 H) m4) Short after the program started a " rogram Compatibility Assistant" warning message" b7 {/ @; X& S- F M
is displayed, you can simply ignore this by pressing the "Close" button
7 _% R8 T0 G2 f0 o% U; p' S" k7 c# ~6 ^2 a' ^
Recommended Way of Disabling Driver Signature Enforcement
4 l! a6 s& g" V1 T1) Disable User Account Control (UAC)" w7 Y/ E' x" ]7 U5 Y' x
- go to "Start Menu" > "Control Panel" > "User Accounts and Family Safety" > "User Accounts": z0 J# D9 j: {! S1 X: @
- click on "Change User Account Control settings"
! `% j/ L% N8 n* i - set the slider bar to the lowest value (Never notify) > click "OK"+ u- A6 m' b2 W7 J% ?1 p( W; c
2) Sign the DosFlash driver
" F; g& E: x1 }; ` - download the "Driver Signature Enforcement Overrider" (DSEO) from4 T% x$ p( |& \6 ]' }; I
http://www.ngohq.com/home.php?page=dseo
+ Q" r% A) D! d3 Q. Y1 k4 i7 z - start DSEO > click "Next" > "Yes" > choose "Sign a System File" > "Next" > enter the path to
7 D. h8 U1 ~. [, U# Z7 _ the used driver (portio32.sys or portio64.sys) > "OK" > "OK". v- X @ b- P, H! s
3) Disable Driver Signature Enforcement
8 n6 W; s( l$ U0 m# b! D - start DSEO > click "Next" > "Yes" > choose "Enable Test Mode" > "Next" > "OK"
) z6 T7 t+ f( @# U* i9 ^4) Restart the computer8 a8 _# P* h3 S1 E" {4 X2 T- Z
; [8 z# d. G4 o1 I+ X
Keep in mind that with the recommended way the changes will have effect on every reboot without
% t S4 }: v8 q0 W. ?0 mdoing anything manual. The first way needs to be done over and over again. In addition the second
# ?/ G9 E" V% I$ l2 K4 _) j8 Vway can be used to sign every driver that doesn't run natively on Windows 7.
6 e* A8 o4 r$ m: z8 ^ y8 ]( u/ F1 f& q1 ^# [6 u1 R
For use of the VIA Cards in Windows 7 it is recommended to uninstall the VIA driver. This can be+ d/ Y& }0 c- D' p3 O( O5 [% Y( ^
done like follows:+ b" ?4 X5 y y4 z
- start "Device Manager" > expand "Storage controllers" > right click on "VIA RAID Controller" > ) l4 o9 j) n' |7 x: R5 x/ |
choose "Uninstall" > "OK"8 k1 ~7 T, h. U
- rename C:\Windows\inf\vsmraid.inf to vsmraid.inf_, B, u; N6 J; K- _& G- \% m
- rename C:\Windows\inf\vsmraid.PNF to vsmraid.PNF_# M1 y0 E1 g0 U- |$ l7 H$ K
- rename C:\Windows\System32\drivers\vsmraid.sys to vsmraid.sys_
; Q: t" Z) x, w4 \/ R) g- reboot computer8 ^8 O E$ i% d: g
7 o$ D- `8 }8 ^# x9 E; c
3 ^( Q, F$ d, P( i BMuch respect and credits go to Geremia and Maximus for their money saving FreeKey app6 a: [2 U) P0 N8 |5 g- e% s0 Z, x% L
and their lightning like decryption speed!
6 r$ M0 v j1 {- d
% I* p' i/ e4 f* j7 L; c! L) qIn Dedication To The Birth Of FreeKey On August Fifth 2009
7 H& F+ n( Y, }" ]; bKai Schtrom$ e6 p( y! h; j
% y( ?0 s$ e' I. ]
7 g* E' J4 F" z# c************************************************************************************************
0 \( e! U' R' t& l/ K+ H5 R# p. U
7 `: Q/ {& S5 y- P- I" ]DosFlash and DosFlash32 V1.7 Beta Release Date 23.12.2008: d t# _1 j1 j, q8 G( F; ?7 R
-----------------------------------------------------------/ d# h5 v# n5 A/ @" c0 M9 O x
- now supports LiteOn PLDS DG-16D2S 74850C and Geremia's LiteOn Erase and DvdKey method
) Q4 L* D9 @1 `* J/ M0 W w! H
, j+ X- j* w7 i# Q0 a3 B. W* J$ c" J$ X4 G- c( g6 w
The following only applies to the new XBox360 LiteOn drive PLDS DG-16D2S 74850C.7 h5 o8 x# d0 R
1 {) J1 ]7 U' I, g d
o+ z0 w' R& _" K+ }5 X' a+ j- W# i
Geremia's DvdKey method with DosFlash16 with the PC's psu/ ?9 s; J6 M/ `/ j
-----------------------------------------------------------* J# `: q6 {& g! N# q& f+ n& _
- disable CD-ROM boot option in BIOS
$ I! C- T% p. b |* M- V8 ?" k- connect LiteOn to your PC's power supply unit and SATA port' ^2 [& N5 }) C7 P- m9 p
- power up PC, wait until bootup is finished3 m6 j* j( D; g- Z. `
- eject tray of the LiteOn and shutdown PC completely
$ k9 i1 v4 x, q1 A2 M6 f- push the LiteOn tray half in1 e' {' J) F5 g B. u. M0 M
- power up PC and boot into DOS
$ t1 n" c# P! J# ^* o9 n- run DosFlash16 in auto mode
5 `! {. Z' V' ?5 _- if you read the following:, j7 q, ~$ Y* ?& R" f- n3 Q1 [
MTK Vendor Intro failed on port 0x????.* D8 _: E( \ D
If you choose to resend the command you should turn the drive off and on( r& I; V* g- q" B6 K: v; n0 e
after you pressed "Yes".
$ n# T' ?$ t. @2 \8 L+ V Do you want to resend the command until the drive responds (Y/N)?# K, u" `/ ?) ` H& l
- press 'N' for "No"% J% J2 \; \2 g6 P" Q, n4 Q
- choose the number of your LiteOn ATAPI drive. j; i" H1 i( ?* C
- enter "LITEON K" to read the drive key
* V( `6 Y* y+ P C h- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files
, x. ]5 L6 f9 [! P* ^! r- A- enter the number of the COM port; v" r+ f. }" u8 S1 r \$ t& w ^
- if you read the following:. N1 e% `0 n; R6 v
To receive the drive key use Geremia's DvdKey method like follows:
7 E! R) z B, b - Connect your drive with a serial cable to the COM port& v4 H% B9 h4 q8 O
- Eject drive tray. r V* S/ |3 ]. _0 h
- Power off drive
1 I9 T( `) j/ f/ G5 v - Push drive tray in until it is half open
1 ~0 q! B I' R- h - Power on drive& ~3 x g e. p; U; r8 f8 q
- Press "Yes" if you are ready" r, J( Q& z' |- p+ n) D
Are you ready (Y/N)?: y8 Z8 y) I6 E) U- |" e
- simply press 'Yes' without doing anything of the above, because we
; `% B7 a1 {- O- |4 S, L0 O- \. B already did that before
; D9 E- h- Y* S$ F. z- after this DosFlash16 displays your DVD-Key and saves your key and identify data
( B$ L, M! e1 j( i+ L- to do the above steps in manual mode use the following command line if your drive. u% J f# Y& o4 B, ~: m2 e
is connected to port 0x0970 and serial cable is on COM port 1
2 d' K7 C7 f( A. a) g DosFlash LITEON K 0970 1 inquiry.bin identify.bin key.bin dummy.bin
# @2 J# e( ?. l" C- |1 V' Z5 t. Q: l7 Y$ W$ u
! q0 ~6 G9 W6 l+ e g6 `- qGeremia's DvdKey method with DosFlash16 and 2nd psu( G' Q% b1 o; C/ M, S$ G
-----------------------------------------------------# ?2 o+ R6 _* G. B# ~
- connect a separate power supply unit to the LiteOn, don't turn it on yet G1 r8 j6 B. K% g
- power up PC and boot into DOS8 o# M6 z2 b. c5 A3 d! w& K( W
- turn on the LiteOn psu
' k% P4 b# r+ B; D( h& f4 U- run DosFlash16 in auto mode% y4 s; L2 g' a8 E5 c9 H) `! Y( V
- if you read the following:6 P- _* O. _3 J& P
MTK Vendor Intro failed on port 0x????.
$ b" Q/ o9 E) Z% ?& { If you choose to resend the command you should turn the drive off and on4 e8 F `: _2 h/ U Q( n5 m: T
after you pressed "Yes".
# M6 d+ k \2 r Do you want to resend the command until the drive responds (Y/N)?
% ]; Z- p2 J# j" ?- press 'N' for "No"
8 D5 M# F( f7 y0 ^. y! F% {- choose the number of your LiteOn ATAPI drive
; z; ~7 ~) }& W1 x. _# [9 E- enter "LITEON K" to read the drive key
# t. F* ]* V, f" G! s- type the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files3 Q$ n4 F; e$ B/ X, Z
- enter the number of the COM port8 ?, C" o+ ^# P) a
- if you read the following:
5 d1 l# d9 q8 u8 B0 U. Q To receive the drive key use Geremia's DvdKey method like follows:6 M& `0 {2 q3 S( E
- Connect your drive with a serial cable to the COM port0 ~# }; K0 J- G) a H) T# _, f" r- T
- Eject drive tray
$ w$ ]- ? m3 p& A - Power off drive/ f8 m6 o3 U* o. y: U& e' M) X0 ^
- Push drive tray in until it is half open" D6 e8 o" Q3 R, y7 e* S- H( Y
- Power on drive
% e3 J0 ?. e2 Z/ J - Press "Yes" if you are ready# C+ F- v) m# @ M' b9 W
Are you ready (Y/N)?" r. L8 u! V+ E* ^
- do the above and press 'Yes'+ U' p) I; h4 d% Y4 p
- after this DosFlash16 displays your DVD-Key and saves your key and identify data, Q8 a5 J! d2 y, ^6 ~9 q" r0 R
9 D; Z2 O6 h7 J6 `; p6 Z0 p/ K8 G& \8 J3 y8 ?; I. E! S, Z
Geremia's LiteOn Erase method with DosFlash16 and 2nd psu
5 ~% I% [9 ?% Y# X* N-----------------------------------------------------------
9 {; C* ?+ d. `( r% v6 k7 D- connect a separate power supply unit to the LiteOn, don't turn it on yet2 S" Z) E! [& `0 d. H( c3 N
- power up PC and boot into DOS
9 y) o/ C0 X4 L- turn on the LiteOn psu
+ J, A5 Z; H" O5 U) K# q- run DosFlash16 in auto mode
$ q/ S P" \: s9 [% `# a- if you read the following:* o4 }. J! w% F9 s5 w
MTK Vendor Intro failed on port 0x????.
4 `* S' f# i" E; J( o4 L If you choose to resend the command you should turn the drive off and on/ g" q! _. ]. v7 \0 b5 {- q) G# @3 o
after you pressed "Yes".6 E1 h$ y8 v1 Z9 Y2 ^
Do you want to resend the command until the drive responds (Y/N)?6 }! j6 A% x/ [8 E& |& Y
- press 'N' for "No"
! `. ^+ @. \. }# g/ c# f9 G- choose the number of your LiteOn ATAPI drive' i% C. Z' ?( P1 f& ^* a4 B
- Warning!!! Keep in mind that you will need the drive key before you erase the flash,
8 ]& @+ Y0 C- |$ z without the drive key your XBox360 will not work anymore
4 s5 C4 R" b" U$ D& x3 H: E- enter "LITEON E" to erase the flash" V4 ~/ ]8 w' L s1 j1 V
- the first time after the LiteOn Erase the drive needs to be repowered to give
: A/ a# l- A+ v( x: t flash chip access, this can be achieved by repowering the drive before another
1 N) B5 [3 C3 _5 V9 s, T$ s( m DosFlash16 start in auto mode or by doing a MTK Vendor Intro Power Brute) I0 i8 G u7 J+ p) T% u8 O5 O6 C
- in my tests it did not work to power the drive with the PC's psu, because it will
: Z/ ^' Y; F }4 q/ g6 s) n always respond with busy status
' U3 o4 u5 D3 m% s# q- DosFlash16 can now read, write and erase the flash chip like usual
& \# x! }9 I$ A9 q$ A" t" A8 e6 }- to do the above steps in manual mode use the following command line if your drive
: g' g7 y: t( I: V is connected to port 0x0970
& R" Z/ b3 ]- R$ m DosFlash LITEON E 09709 S5 a/ e' ]# K/ U6 Y8 K! f0 `0 A
/ i. X. o- f5 V- d* c# J: m- I2 x3 q' ^$ @
Geremia's DvdKey method with DosFlash32 with the PC's psu6 S' @( |1 D0 b+ j
-----------------------------------------------------------0 y& }4 L" }6 }- t
- disable CD-ROM boot option in BIOS
6 d. D+ R: C/ |+ I- connect LiteOn to your PC's power supply unit and SATA port
; R+ |% |* ^8 c5 f- power up PC, wait until bootup is finished
- N3 L2 C+ T# l0 w- eject tray of the LiteOn and shutdown PC completely
/ f6 i4 f; f0 T6 \ t5 O' Y7 m# b- push the LiteOn tray half in7 W ^" g$ G: X" r: {
- power up PC and boot into Windows
7 c6 L) A! u* E2 N" C( y9 W- run DosFlash32/ a# L& h3 i4 O0 J0 k
- if you read the following:; K* u" D) W2 D) C4 |
MTK Vendor Intro failed on port 0x????.& H, Q4 I- l1 r5 ^
If you choose to resend the command you should turn the drive off and on3 r9 ?5 Q, G* H3 E- v% f
after you pressed "Yes".; p: V! i4 h2 \# u# v
Do you want to resend the command until the drive responds?. w; P: j, ?0 Z4 R& u
- press 'No'4 K6 E$ ]1 \3 A! I
- choose "LiteOn DvdKey" as flashing task
. g7 d9 h9 W B. H, W. p+ N( ^) B0 V- choose the COM port number1 d- H: V& e& Z7 I, H) \* N; W
- press on "LiteOn DvdKey" button
: s- M. ^7 [+ p6 @( E- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files9 k3 @. q- c0 [- y; Q
- if you read the following: O) r- H4 [0 e, o, N
To receive the drive key use Geremia's DvdKey method like follows:* y/ v* c" _6 z
- Connect your drive with a serial cable to the COM port
5 Z0 B+ j2 s7 E( W - Eject drive tray( F5 @, V- i6 c; b K' C# o
- Power off drive. N% T# {, X0 e0 ]' y
- Push drive tray in until it is half open b- k1 R& X2 a8 V2 E* z9 b9 n
- Power on drive
" ]& u) W! v' P( n% Z7 N% L- E1 U; { - Press "Yes" if you are ready
3 X- E1 i9 v9 P+ T Are you ready?
- R9 N8 }" j/ B/ R% H- simply press 'Yes' without doing anything of the above, because we
% D, |0 C, s: O$ d already did that before
$ ]* C4 }2 T: B" X* X- after this DosFlash32 displays your DVD-Key and saves your key and identify data# p6 P2 o* D# @4 V( W$ L) w
2 e- u9 r+ ]5 B" ~0 E4 N8 \) m
0 }* O- f, o6 q. y6 X: gGeremia's DvdKey method with DosFlash32 and 2nd psu
S) I# E3 o( S! p( `1 C-----------------------------------------------------' ^/ E: t3 e! k5 G$ n9 ? M2 ]
- connect a separate power supply unit to the LiteOn, don't turn it on yet3 D3 [) d7 A: G# @; J4 X7 i
- power up PC and boot into Windows* }3 d) Y. y5 C" j8 n2 u
- turn on the LiteOn psu, h. C @: H5 K; o/ G) K
- run DosFlash32
6 D1 r0 C$ s4 n% i2 @) i9 O9 n- if you read the following:' c8 v( S8 b9 b( U
MTK Vendor Intro failed on port 0x????.
: L/ O" i' A2 X' c, E& ] If you choose to resend the command you should turn the drive off and on5 ^1 c }: n7 U5 W
after you pressed "Yes"./ X7 t! S, ~ a2 a R. [! }) N
Do you want to resend the command until the drive responds?$ X) @: B& L4 Q. r+ ]; i0 @+ w
- press 'No'3 y! P1 q' J' m; F/ [5 i2 l9 T8 l0 Z8 z
- choose "LiteOn DvdKey" as flashing task
2 b2 B% w# j& \- choose the COM port number
" x3 A* {4 {0 y, {- press on "LiteOn DvdKey" button
, b/ e+ K1 S! ^$ v$ J- enter the names of inquiry.bin, identify.bin, key.bin and dummy.bin output files7 ~8 `8 B" Y S8 b1 L
- if you read the following:
+ L) y4 Y, j% L' P, |& r To receive the drive key use Geremia's DvdKey method like follows:
" \. P* _6 W. ^6 S8 f6 ~5 \- P - Connect your drive with a serial cable to the COM port
& L! T5 D2 n/ n4 V' l- P - Eject drive tray3 s3 i4 ~! y. m" g% y/ p4 \
- Power off drive2 w0 r" V0 |0 i% c: B' @
- Push drive tray in until it is half open# R# l/ ]" ^0 J, P
- Power on drive$ a$ D/ `+ f4 {, p: g; J
- Press "Yes" if you are ready3 L& q: A% N: g5 V" _
Are you ready?
% V% e k+ j9 g- @$ o6 X; G- do the above and press 'Yes'
. x& [, U b/ u6 V- after this DosFlash32 displays your DVD-Key and saves your key and identify data' z. E, ^% N+ f9 G1 B
8 X8 G; w0 t2 H3 s* i
1 N" P; {6 N$ V
Geremia's LiteOn Erase method with DosFlash32 and 2nd psu
# k! q. c) @# }' S: U( C% \-----------------------------------------------------------
/ Q- {( c3 |0 C* ^. z4 s R- connect a separate power supply unit to the LiteOn, don't turn it on yet
% h+ V+ M# ?' Z- power up PC and boot into Windows
$ F* E3 ?! |) z9 Q9 t" I3 v/ B: ]- turn on the LiteOn psu
u% f$ I3 V0 v) X5 Z& d- run DosFlash321 m1 U# @7 O: Y6 C" o" ?! r9 K/ a
- if you read the following:2 r( n+ i$ E- ]' j4 o
MTK Vendor Intro failed on port 0x????.5 }8 z9 T+ [5 m# P
If you choose to resend the command you should turn the drive off and on. F0 B, g! e% x1 b
after you pressed "Yes".7 k' Q0 D# ?! D9 @4 j; Q; l
Do you want to resend the command until the drive responds?
) i$ |3 Z/ T, \0 z5 }- press 'No'
$ O9 U, N5 @9 G* \- {6 T- the LiteOn flash is not identified
$ p; c9 |6 [9 A; u- choose "LiteOn Erase" as flashing task
0 G& H1 g# r3 K+ t) ~* l" K4 g, m" p- Warning!!! Keep in mind that you will need the drive key before you erase the flash,! w5 G# d$ a% u M/ g
without the drive key your XBox360 will not work anymore0 [" l- p) a3 D8 ^
- press on "LiteOn Erase" button) H) f4 S# C; q5 Y) \8 H
- the first time after the LiteOn Erase the drive needs to be repowered to give1 n7 ]+ S& s5 D
flash chip access, this can be achieved by repowering the drive before another& Q8 F) [, @9 m& _
DosFlash32 start or by doing a MTK Vendor Intro Power Brute
3 N2 R+ a$ n5 v$ Q' T: U- in my tests it did not work to power the drive with the PC's psu, because it will
. b* x# P6 w1 s. v always respond with busy status! f) P- a: D9 l0 ?3 W
- DosFlash32 can now read, write and erase the flash chip like usual
9 P; w' q1 b$ t; _! k
6 e3 D: S& t7 B0 | {" Y/ l: k7 G1 ]+ W' \
Respect to Geremia, Modfreakz, Podger, Redline99 and Tiros.& E* g/ z: \0 C1 j. F9 M/ u
- b+ v; Q# C* t- w
Like a wise man said: "0x2E is the MTK Intro of Death"
, d8 }4 U7 R6 j7 L+ H: a5 iKai Schtrom7 e7 t; Q/ A/ T4 F0 d {+ j
; a t" f- }0 E8 Z) W [4 Y# e! P0 O* c. J2 j, H
************************************************************************************************+ t1 Y+ F; r( N; i
3 }5 F6 h |: j. }! Y" {) x6 E: l T. i
DosFlash and DosFlash32 V1.6 Beta
/ U& Q1 G0 t J-----------------------------------
0 Y# v" }8 O x4 p+ k/ N! N9 l- fixed power brute unlock bug for VIA cards, this can stop your VIA from working
) {1 ]' B+ U. O8 J with the power brute unlocking in Version 1.58 ]- ? |" s: d- w
- for DosFlash16 in auto mode on DOS my VIA card works best if I do a cold boot
7 p P8 M; F: j# S/ L' L and power up the drive short before or with the PC) [& `1 F* v; P; F
- for DosFlash32 on Windows my VIA card works best if I power up the drive short2 V! r$ O" ?$ e5 Z- x' q5 J" a
before starting DosFlash32
# _( A8 |- |1 I0 M5 ^' J- for me the VIA works with internal and external connectors on DOS and Windows1 m' |/ D+ M4 p$ e
, s- g% O' k5 k4 I) @Sorry for the trouble!
2 v: i, ]( |* A/ V5 m/ h, BKai Schtrom
- e( p7 m n( H8 ]" i
5 V6 |: \% Z6 ]0 `& a9 y1 e( z& e) t; F* Z0 e% c% g; |
************************************************************************************************
6 d I" Z, v: U% Q' I3 J0 Z( l0 r
' f' Q9 `) A, a" R5 P- Q7 C7 l7 R. r% J& n, {8 i! }4 g& i
DosFlash and DosFlash32 V1.5 Beta L8 e) G& L$ U, A) x
-----------------------------------
: n ]7 N6 Z8 E/ C1 S( ]! Y- now supports serial flash chip MT1309E with mediatek status 0x72 like the SH-D163B, SH-D162D,
: ^% L# |8 o2 f* @# R6 C Asus DVD-E616A3, Asus DVD-E818A3, Sony Optiarc DDU1671S6 Q6 V: c( e$ T `# k
- SST25LF020A and SST25LF040A chip support added
( i3 K0 h% N1 Z- DosFlash32.exe ported from MFC to plain Windows API, exe size is now 22 KB
- d6 _0 g8 S: p' v% G- new port i/o driver, because giveio.sys can't be compiled for 64 Bit Windows
- c$ w6 e: V. W3 Z- DosFlash16 changed slighly in manual mode, one parameter is added to support SST25LF020A and G6 D7 F S# h! {, Z
SST25LF040A
. _* y: o/ G" d- two new methods of BenQ soft unlock are now possible on all motherboards with only one power
) k" K5 l8 F G- g, e0 f supply unit
1 o0 l+ \. k# y3 V- 1st method is powered by Geremia's unlock core, thanks for the complete idea, concept and
) i0 L5 K% S r- h2 }% E* A4 ` source to Geremia" l3 y2 y$ ?; ^% D
- 2nd method is the Magic28 key send, this only works on BenQ VAD6038 firmware, thanks to2 F; q$ e. v) @& p5 p
c4eva and podger for the initial idea
4 {+ B8 P6 a/ u8 z. t* Z3 Z7 a. s- the two unlock methods are send one after the other if the drive is a possible unlock- F) Q7 [& T5 v9 e$ }
candidate, first the Magic28 command, then Geremia's unlock commands and after that the n) T* A3 Z; }8 J1 e+ [
already known power brute unlock is send to the drive, you can cancel any of these methods
* n$ C+ S7 K) [9 M% _7 o; u4 ^ before they are send to the target, this only applies to BenQ drives with a locked flash+ q/ c* C4 F7 V" X! ]) n
- DosFlash.typ updated
' o7 Z- n P. Q( H% b3 |- other minor improvements1 s' W% `0 C" |1 C
- DosFlash32 is now ready for
- Q& D# L* v, [. }/ L: \& P8 C# j - Windows 2000
& i# P& e7 J: |4 a: }% @6 W/ q - Windows XP 32 Bit
4 X6 a/ o2 t3 ^$ g: r - Windows XP 64 Bit
' G9 q% u4 \# n! S6 ` - Windows Server 2003 32 Bit$ J6 f" o" A% \% P6 w0 C2 c
- Windows Server 2003 64 Bit
" T p. E5 Y+ E O, k1 m- M - Windows Vista 32 Bit( Y# _' o1 r6 a1 v- s4 Q' A5 Z4 P
- Windows Vista 64 Bit
; Z3 R0 V$ Q- G8 K- Warning: Drivers for Windows Vista 64 Bit need to be signed, because we can't afford the
3 h) }( g& f7 h5 K+ H$ B1 c money to let portio64.sys sign you need to do the following:/ r1 { E$ Z2 Y- m4 e4 S. O
1) Log on as Administrator. J( t1 |7 }. Z( @, w* E9 n
2) Enter the following command in a Dos-Box:
X0 }/ G* m) c; Z. v( G$ o "bcdedit -set loadoptions DDISABLE_INTEGRITY_CHECKS"
# k& Q; M* H8 S (we made sure there are no typos in the line above) 
y% K# w+ k o" r5 W 3) Press enter and reboot your PC
, R$ Y" R) z& i7 z3 s 4) Press F8 key upon initial system boot up$ @% C7 Z& W- y5 J( C
5) Choose to disable forced driver signing enforcement for that boot session
6 X8 I8 f: f6 O! e/ f: F- A5 C% M3 [2 D
~/ ^7 ]/ B3 s3 B L9 R
The following only applies to drives with a locked BenQ flash.
5 v l' |6 l) d( y$ R% C( ~' N) X- }2 C# p# f" A
4 `2 t }$ |1 J1 o, `5 R
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with the PC's psu# K! c: D5 H% \& G4 Y# I$ N
-----------------------------------------------------------------------------------------3 `% |7 ^3 _4 @) W( s2 ] s
- disable CD-ROM boot option in BIOS0 r$ S5 r0 N! A# n, g1 I
- connect BenQ to your PC's power supply unit and SATA port9 ?0 z7 {. k1 i+ y5 x
- power up PC, wait until bootup is finished
6 z* B3 h$ `6 M- ]- eject tray of the BenQ and shutdown PC completely4 a' j# y6 l0 h& z: F
- push the BenQ tray half in
T+ V9 W0 m% a, B" w9 e' p- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash32
5 z6 e% e, O: l0 M$ s7 J- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
2 a( p8 c7 y" F, D4 C/ @- if you read the following:
: ^! ]) r1 G4 I. \ MTK Vendor Intro failed on port 0x????. Because there seems
' J$ q- q9 J1 K8 {' I1 ~) [) F( I to be a BenQ drive connected you should try Geremia's; J% d" [; w- \; C) [
unlock method.: }/ N+ \8 k7 _6 n8 ] x/ [
- Eject drive tray
+ y6 R3 V* _& x; ^8 u - Power off drive, f9 C1 \! \* x" J
- Push drive tray in until it is half open4 r) H- K+ ~' X O2 j( U" P) P
- Power on drive5 x* d" U. ~/ y+ F& f" y' t
- Press "Yes" if you are ready
' ~3 X: p; x# r3 x6 l& R3 Z; P2 N Are you ready (Y/N)?$ ?7 o4 @- G; D( H) [ p% i( @7 f% b
- simply press 'Yes' without doing anything of the above, because we7 v1 u d9 o, ]. n
already did that before starting DosFlash16 / DosFlash32& \( k; _( I, z4 w& k2 F3 K
- the BenQ flash should now be identified) k2 f) E; G. O X" E
- go on like usual
6 {$ B9 C1 n7 I- v8 t: x! p6 f3 ]" _( X7 L4 a0 E
5 T5 l. b- @! w
Geremia's BenQ unlock with DosFlash16 / DosFlash32 on any motherboard with 2nd psu
$ h: W" m! G: s2 {6 u------------------------------------------------------------------------------------
- ?# p* t7 f$ I- connect a separate power supply unit to the BenQ, don't turn it on yet
; U3 v- X& ^$ J% Z! r- power up PC and boot into DOS/ L* }' \0 k7 b4 m
- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
0 {" |2 F( C1 ~- if you read the following:5 `4 [% p( [ S! s( s3 P6 f9 f: q
MTK Vendor Intro failed on port 0x????. Because there seems
; L( C" E0 A* |7 ?5 c+ Q' D% u to be a BenQ drive connected you should try Geremia's
' [( N6 Y! u% u. X unlock method.* Q) x; m0 F" y9 A; V
- Eject drive tray
. m7 W2 `( A3 N! r$ x; E2 }" Y - Power off drive
8 o2 |/ F: U3 O# p0 Y - Push drive tray in until it is half open$ j- [: K/ [ X) S
- Power on drive1 j0 ~% N& Y/ b5 y% R7 u
- Press "Yes" if you are ready
% u$ x- i: X3 ]0 K" y! | Are you ready (Y/N)?
& p8 z8 X7 @7 A- do the above and press 'Yes'
1 Z- ^, ^ ]' V* ~- the BenQ flash should now be identified
5 z x; I" f& p4 v& D- go on like usual4 P/ a0 O2 r; I/ U% {
, B5 {* F8 _: R# h! h
; ]5 t8 A7 U& J. Q. b
Magic28 BenQ unlock with DosFlash16 / DosFlash32 on any motherboard
! F# Z/ U3 u" h$ {---------------------------------------------------------------------; [0 E" {$ p: B" d3 ~
- connect BenQ to your PC's power supply unit and SATA port2 v) F% L3 E+ R! N# ^! V+ a# v v
- power up PC and boot into DOS for DosFlash16 or Windows for DosFlash325 B) p5 u* _. q0 [
- run DosFlash16 in auto mode for DOS or DosFlash32 for Windows
+ Y! P) j) I9 ?9 ]+ J- if you read the following:
2 Y; W/ Z% ^* ^ MTK Vendor Intro failed on port 0x????. Because there seems
3 E) |% h# Y8 R3 J9 Z4 `4 f! j to be a BenQ VAD6038 drive connected you should try the2 C( l) b* A' @. v9 Q( A0 H
Magic28 unlock method.
[3 }$ ^% C& E; P9 n& ]% l b, a Do you want to send the Magic28 command?0 M8 ^; i1 B7 U. g+ C6 J) g- r/ A
- press 'Yes'2 y. f! N9 e/ T) f7 e2 v+ ]2 x) Q
- the BenQ flash should now be identified
4 n0 O- {7 K4 f. ~! C( V" K- go on like usual
q2 M+ C- H8 S! o# I- K1 S" [) e1 e& A
& K+ \# c1 y9 f6 KThanks to Redline99 and Tiros for help and support.
% b* r. ?& J$ u0 U' d8 `- _7 X. B4 q9 k1 W* l" \
It's all about DOS!
) B R5 X/ E9 \3 ~Thanks guys for the excellent team work!
2 k/ k! `) ?( U0 H7 G* UGeremia, Modfreakz and Kai Schtrom2 u7 m1 I& ~! t5 Q* y; [1 m
( ?' v! F4 I2 D/ x0 x" b( V- Y
" K- n. c7 S! y0 A8 S************************************************************************************************) _1 i% M& o' D. }0 v! a' |
1 x5 `( b# n. ]1 ^% _8 @: A
% i6 ~* K' t2 v7 ?3 S l3 {DosFlash and DosFlash32 V1.4 Beta: V4 R# G/ H& n
-----------------------------------
, @1 X, d$ ?1 l1 O) n5 j- DROM6316 flashing support& v5 Z. Z! W4 C7 E. u* O
- a flash erase is now always done with a chip erase and not a sector erase command, because
; x- Y: N7 B9 r, A1 {! F! q the sector erase gives problems for some Winbond flash chips including the DROM6316
" F0 Z, p0 s) c" E9 ]- DosFlash.typ corrected and updated$ c4 e3 T; u! l: L
- for a detailed explanation on the soft unlock look at the included file SoftUnlockByIriez.txt,
/ q, |' T# q% S& H$ `, P it contains a very good explanation by Iriez from XBS, thanks for that one!
! }: I+ x1 b- m) e3 u2 l( ]" |5 P3 ]' {" a
Thanks to Iriez, Jumba, Redline99 and Tiros for help and support.
$ n% ]: Y. C4 l: g+ v s# b% k2 q0 B% m- f0 ?) \) s6 l6 u7 ~
Happy DROM bricking!
- u* d! V) L: CTeam Modfreakz and Kai Schtrom/ O% R: t+ |: q- ~% w; x
; i2 X3 E' ^" z9 f" w1 d
% s( R$ J0 `9 H( k1 D) ^
************************************************************************************************% B( s, L: c# a
6 e" }6 B& ^- h" _8 p7 m, ?
2 n/ f9 V. q0 O3 V8 q) `/ @. X8 |DosFlash and DosFlash32 V1.3 Beta) \5 Z/ m2 C' Q. K0 p( U7 [8 q
-----------------------------------# u8 a9 _+ C, |* L3 |( g* d9 C
- BenQ optimization in unlocking the flash chip, it should now be possible to read/write/erase
; @% y7 \* g# ]* G the flash without any soldering or wire tricks, the drive is polled for the correct mtk3 V9 A$ J; A7 r/ l! l; z
unlocking status after power on, this only works for VIA cards and NForce boards atm" \; v/ B k: _
- DosFlash32 has one additional parameter, if you start it with the parameter "EnableDrives"
# ~$ g3 Y' N" [6 s F! o- Z all the DVD-ROMs are enabled in device manager after flashing, this could give BSOD on some
2 w! [; U. Y" q' G& | systems, therefor you need to create a DosFlash32 link and add that parameter manual to use it
$ ^' ]) _ y0 R5 R- DosFlash16 has one additional parameter "Send ATAPI Device Reset" in manual mode, this could
' r0 `/ D: G1 N5 o7 S give better chances for soft flashing on some VIA - motherboard combinations3 f$ B% w# M% W3 Z0 [/ D1 K: o
- better support of Intel chipsets, drives can now be flashed if the controller is not set to4 R% @9 r) i+ Z$ m2 P' b `1 J1 I8 R- p
native mode in the BIOS& z' V. ~- g' s
- the following controller list includes vendor and device IDs that are hardcoded to identify# I F) V7 n1 U; U3 S8 S- c& B
the controller type (IDE or SATA), this is needed if the BIOS uses IDE ports like 0x01F0 or, f3 {/ ~# O r, C. V' H% j
0x0170 as SATA and not as IDE channels, this list is NOT related to soft flashing2 P1 L9 v0 k t' q1 i
- the following chipset support is added
+ v+ T. V# p M$ E+ [+ T. c - VIA cards
2 O5 s$ u- J) Q1 \# D$ R - all VIA cards with a 6420 chipset7 }! U3 ?" F3 S, R- g* ]
- IDE Controllers: J- r* ?8 J7 ?) L I
- NVIDIA nForce 2 IDE Controller* M" ~0 ?5 X* u. J
- NVIDIA nForce 4 IDE Controller9 Q# U' L8 V4 C: W4 N
- Intel ICH9/ E9 V' V" V) h0 L: U% ]6 t: V9 W* ?
- Intel ICH (i810,i815,i840)
" k( q) u" O5 ^2 {- a - Intel ICH0
6 h+ c5 s7 p, `4 |& P- `6 C' C9 x - Intel ICH2M
' M' k$ I, \9 e, D& ]2 c - Intel ICH2 (i810E2,i845,850,860)" T$ h; `; [6 M; p" f% _" y
- Intel C-ICH (i810E2)
. y. j2 a f, B Y - Intel ICH3M G+ V/ I5 |6 E' a! D2 k
- Intel ICH3 (E7500/1)
) z1 ^) r0 Q$ s' r( ]- B) ?5 `; ] - Intel ICH4 (i845GV,i845E,i852,i855)
& r) X: G% f* t- h3 K - Intel ICH5
1 Q, D7 w3 M9 u0 t* g) ^ - Intel ESB (855GME/875P + 6300ESB)2 g) R4 ]( |, ?& ~! p* Q0 b
- Intel ICH6 (and 6) (i915)- H! S3 }+ r- H+ J) r8 y; v
- Intel ICH7/7-R (i945, i975)
9 W4 C' K8 w- ?& Y - Intel PIIX3 for the 430HX etc
% j$ n) `& C4 ?8 l - Intel PIIX49 \6 Q; }, D, s* p# a; J
- Intel PIIX4 for the 430TX/440BX/MX chipset; b' w+ q5 W) E. U, b
- Intel PIIX b' ` u' b3 o* j( t# g J: T
- SATA Controllers7 {5 V8 u" B7 Z5 ?, w- [8 I' z: H
- NVIDIA nForce 4 SATA Controller
! ]8 _; F! H4 _- o8 z2 A - NVIDIA nForce 2 SATA Controller3 z3 m7 E) `! E5 [" u
- NVIDIA nForce 3 SATA Controller
. q& y6 ?: d' V& Q$ Z- h2 L/ J - NVIDIA nForce MCP04 SATA Controller
* n* l$ b) \; b" c. g. y# n - NVIDIA nForce MCP51 SATA Controller
. l: l7 B3 y7 h9 [' ^% g% Z, b - NVIDIA nForce MCP55 SATA Controller
" F1 m- h2 n2 |6 W - NVIDIA nForce MCP61 SATA Controller
! M8 x2 |& b1 I2 d' R - Intel 82801EB (ICH5)
/ D' L7 c$ S: S* a1 N4 z5 e - Intel 6300ESB (ICH5)3 [1 n9 w. e. k4 {( m' Z
- Intel 82801FB/FW (ICH6/ICH6W)8 f4 {9 h! |- M6 J. p- b) a
- Intel 82801FR/FRW (ICH6R/ICH6RW)
; I8 g/ p/ w7 b3 C6 S - Intel 82801FBM ICH6M
2 P. e0 j9 E! M$ S; {. ]# s9 W - Intel Enterprise Southbridge 2 (631xESB/632xESB)# t D3 J" @3 F' \
- Intel 82801GB/GR/GH (ICH7, identical to ICH6)
' e9 O: D1 Z/ R8 T6 p' E - Intel 2801GBM/GHM (ICH7M, identical to ICH6M)" T1 g$ z, p* _% n( U* N
- Intel SATA Controller IDE (ICH8)& @! x. p* q' e) ^! W$ n
- Intel Mobile SATA Controller IDE (ICH8M)# f/ [8 L% L t: V% }5 P
- Intel SATA Controller IDE (ICH9)
7 b# t/ Y* c# B+ ^1 b - Intel SATA Controller IDE (ICH9M)
3 n. o0 D0 {( |" \7 q7 _8 I3 d& e6 q- U! o, i% P
# m6 m& s) e4 f: yThe following only applies to a software flash on a locked flash. The methods have been tested8 C; h. [ H0 C* E6 S% q0 i
with the BenQ and the Sammy. The VCC trick will work on any motherboard, but you need to do
" E8 s g! A6 [2 ]2 esome soldering and cut traces.
$ W- L- c2 c1 N+ r$ D6 a5 ^+ O! Q2 ]9 C/ {0 N( g
: e9 `% I h7 c& g( h- [' k, l0 l
Soft Flashing the BenQ in DOS with a VIA card and DosFlash16 in manual mode
]7 u9 i' X: }6 Z: M-----------------------------------------------------------------------------
6 d5 p) q+ h; J3 b2 r& S- first you need to know the port addresses of your VIA card, you can get these by starting5 `) } a/ d: `
msinfo32 on Windows XP and looking at the port listing for SCSI devices
' `1 a) d6 p$ r6 Y9 \- for the 6421 the 1st port is internal SATA, 2nd is external SATA and 3rd is internal IDE, ?9 ^7 x7 b5 d4 g3 m6 H `
- for the 6420 the 1st and 3rd port are internal SATA$ M5 H- J. m1 ~( T
- you need the starting address e.g. 0xD000 or 0x7000
1 ^1 x. o+ e+ \. M5 }- be warned that these addresses can change from computer to computer, they are assigned
8 w2 y/ h- L y4 N at bootup, but Windows XP should display the ones you need for flashing in DOS
% k( u% ?/ v9 ^/ e9 B" w- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or * e5 W- v8 c; \) q; o8 O
Xecuter Connectivity Kit)$ @2 J1 ]# @: ~6 A9 @- `
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
' s o# a$ R! V4 b need to power the drive off and on during soft flashing' c: ], Z: ~$ n9 A- o" x! T9 \9 x
- cold reboot or reset the computer6 ]- F" x) P v; ^
- boot from a DOS disk, I used a Windows XP MS-DOS startup disk
' H: Q. Z# K% Q! Z- at the prompt type:
6 m! v- G! k, D- W7 _; I DosFlash r 7000 1 a0 1 4 a:\orig.bin 0 & S+ G- Y, v i- O4 K2 ]
- instead of port 7000 use the starting address your VIA card uses6 B% T; @0 f$ A- S) l& a" B
- press return1 l% H% M1 j" Y$ N% m
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes7 I! z* e, D8 g* n' A2 g5 p
- after you pressed Yes the drive status is shown on the screen, it's something like 0x7F,% }. f0 n6 @8 ^) P- Y# v0 E# K
this will change during the next few steps- X, P3 q9 I4 X0 N, T
- turn on the BenQ psu and wait 2 or more seconds, status changes between 0x51 and 0xD1
' n3 A* O* W; d0 B. I6 i8 @; u- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD1
- _- ^1 V* o8 o# t* d- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start
; D0 m! r @$ S. G- this worked only one time after the computer is powered on or resetted for me/ [: q2 s* P/ w8 y; p3 D8 B
- writing and erasing works the same way
6 U3 x# H/ p! V" S- for writing type:
- J* E8 [; d1 n, O DosFlash w 7000 1 a0 1 4 a:\ixtreme.bin 0$ Z, @/ f! X% l2 o
- for erasing type:. S6 t. p# k5 K! w q1 q
DosFlash e 7000 1 a0 1 4 D8 0 (D8 is the sector erase opcode for the BenQ flash, if you need
) I, I) H) @* ] to erase another drive, lookup the value in the datasheet or DosFlash.typ)
, R( {% n$ \! X) w: h0 w% e- if you experience any problems try to use 1 as the parameter to the ATAPI Device Reset, cause
' ~* O$ ]% I0 `1 P' A: g, K6 { the same VIA card will react differently on another motherboard sometimes% Q. {5 A+ n1 e. {
8 ?1 m! V0 u/ o6 @1 v% [8 D( \# E6 @
Soft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in manuel mode
: H) Q8 N2 V) Y! V---------------------------------------------------------------------------------------
! S3 }& I! m. l0 H6 R5 E- first you need to know the port addresses of your NForce motherboard, you can get these by
7 I; F2 Q2 t% F9 s starting msinfo32 on Windows XP and looking at the port listing for IDE devices
! ^- w. ^" z% G: |# `, N# S- on most motherboards the 1st and 3rd ports are used for SATA
# p# `3 V$ Z; }0 B- you need the starting address e.g. 0x0970 or 0xE900$ O& M/ P+ V$ O# J2 ?; R- F
- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
5 G* E6 O' X* r! }3 Q Xecuter Connectivity Kit)
! h7 ]2 Z' C @: c+ k* {4 b9 m9 M- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
! H1 m& I$ \0 U, A& O" E need to power the drive off and on during soft flashing
/ `1 v7 s7 p0 T6 Y0 P/ ?- cold reboot or reset the computer. {$ Z G3 r7 H$ `# V& H- f) a
- boot from a DOS disk, I used a Windows XP MS-DOS startup disk; x4 v) e. L6 E% y: @
- at the prompt type: O& c: p. h, W) ^
DosFlash r 0970 1 a0 1 4 a:\orig.bin 1
/ I1 ]% |& [' O% I' [; T - instead of port 0970 use the starting address your NForce motherboard uses1 t1 T" I$ H% f3 W# ]
- press return, u0 _: Y+ `- s M/ ]5 }; ?
- DosFlash16 will ask you if you wanna resend the mtk vendor intro cmd, press Yes
! ?, D: K$ n" h( ?6 e8 o- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,9 Y1 N" ?% o% x& ]& X/ ^
this will change during the next few steps
5 Y! k9 O7 {. Z' y# U; N ]6 [- turn on the BenQ psu, you should get a good drive status 0x73 and flashing should start
( S& w! [) ?! O& T* g4 @7 }% {- writing and erasing works the same way% w! z/ m" ^. y$ {
- for writing type:6 E* A$ q3 ~4 ^8 `3 {! b" R
DosFlash w 0970 1 a0 1 4 a:\ixtreme.bin 1
3 g2 ~6 c$ m5 H- for erasing type:: b* A" h0 ^1 n0 Q5 ?+ \5 b {' ?
DosFlash e 0970 1 a0 1 4 D8 1 (D8 is the sector erase opcode for the BenQ flash, if you need. _2 [' L4 @/ d0 z1 O6 }
to erase another drive, lookup the value in the datasheet or DosFlash.typ)* v/ `8 C. f/ B
1 |, \' N; Y5 e/ T% P5 [
2 n6 T2 v2 X* M: R- Y
Soft Flashing the BenQ in DOS with a NForce motherboard and DosFlash16 in auto mode3 K j% L- f) N: Z, t. c: I; T# ]
-------------------------------------------------------------------------------------8 C7 a7 u% K' B2 D+ `) X0 ^1 Y
- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or
/ n* G9 a1 K" f1 v3 q/ i! p Xecuter Connectivity Kit)
. R. _( d8 ^+ o: `6 C- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we6 X) N3 k2 f+ E5 Q4 Z; j
need to power the drive off and on during soft flashing: y+ O, J U/ |1 Q8 {2 r
- cold reboot or reset the computer
; q- P/ p, v$ E- boot from a DOS disk, I used a Windows XP MS-DOS startup disk* d( `; u+ K" O5 G
- wait until you are at the cmd prompt
% x7 F; E0 ?& H+ w3 P# V" g- turn on the BenQ psu
. K( w! I$ l, L! k- at the prompt type: 7 Y- y( L0 E9 d+ c! `" Q) d
DosFlash3 z! u/ `! F9 \, T$ V/ o1 N
- press return+ o R3 o2 a4 C. G; B6 m* J; _
- during scann of the BenQ's port DosFlash16 will ask you if you wanna resend the mtk vendor. D7 t2 Z0 \! \+ l
intro cmd, press Yes
" Z9 d3 l6 T# o7 i- j- after you pressed Yes the drive status is shown on the screen, it's something like 0xD1,
3 h5 C9 j. N; g3 u9 S7 p this will change during the next few steps
! h9 Z0 O5 f$ D D `- turn off the BenQ psu and wait 2 or more seconds, status will stay at 0xD13 d* w$ r8 o6 C/ H( E: D: K2 V
- turn on the BenQ psu, you should get a good drive status 0x73 and flash access is granted5 k: n; Z2 ~* P& m* ^
- you can now continue as usual using DosFlash
& p+ [0 ~8 x* l8 i8 I3 ?7 h; n- writing and erasing works the same way/ U( A7 h0 X" l
- if the ports are scanned there is the possibility that you'll get the resend question for
( d8 \; G7 ]& I+ `: r% L other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,
3 F4 x3 ^, I/ D" X' { if you know the NEC is at that port you should press No and press Yes only if the port of0 t/ o( {2 Q4 E: Y `3 B( B+ z
the BenQ is shown or simply disconnect the NEC/ U2 k) }; {8 b, ?
1 f0 D8 c) S. t) o2 G; F
+ A, r& R* v( F8 U/ I ~Soft Flashing the BenQ in Windows XP with a VIA card or NForce motherboard and DosFlash32
8 l: P/ I# s% O! H5 j4 X: q; M-------------------------------------------------------------------------------------------
" b( J( ]2 A- t- b- connect a separate power supply unit to the BenQ, don't turn it on yet (can be XBOX360 or 5 t4 a/ ?( n$ ]$ K: F- i$ H
Xecuter Connectivity Kit), D0 U1 ^6 P1 O4 ^, D- A
- don't use the Xecuter Kit to power the drive with the same psu as your computer, cause we
% ^$ T$ A" K0 i, R l$ T need to power the drive off and on during soft flashing6 Z' C7 E$ P6 n
- cold reboot or reset the computer- H9 t$ M! i5 p: R5 E; C1 k
- turn on the BenQ psu when you are in Windows XP7 e( V n' i4 O# K% u
- start DosFlash32
K' @1 V7 Q( K5 Q- DosFlash32 will ask you if you wanna resend the mtk vendor intro cmd, press Yes
) R, a+ A7 q* y- turn off the BenQ psu and wait 2 or more seconds7 P# g5 [7 O3 j2 l3 ]
- turn on the BenQ psu, the DosFlash32 dialog should show up
* N1 q7 p, U& N" v- the flash should be recognized by DosFlash32' ?! t2 |& m# d7 ~- y
- you can now read, write or erase the flash
! b4 Y& M- r: E; t- you should be able to do the flashing more than one time in Windows, only do the power
8 P, y: b1 V$ h off/on trick again
# n: |9 u. c+ l0 g- B- if the ports are scanned there is the possibility that you'll get the resend question for" q, t% ]0 f/ ?: Z( [( B
other drives like a NEC, this is because the NEC has no MTK chip and returns a bad status,0 [. N5 }5 J$ E+ w
if you know the NEC is at that port you should press No and press Yes only if the port of
7 s W2 J& T' K& m, D the BenQ is shown or simply disconnect the NEC
/ E9 J7 U4 @1 m( p8 j* J4 ~9 h* L+ i1 x2 j% L. f: n* R4 G
- f5 |5 u3 H, ~! M) P! }$ `Many thanks to jumba for the great idea of BenQ polling!
2 m8 c( y$ k8 H6 q: o2 n6 PThanks to Iriez, Jumba, Redline99, TeamModfreakz, Tiros and all the IRC people for testing
. H/ i/ e2 z7 q1 Y. r7 i& Jand support.
: ]( N) I+ z2 B4 Z1 v
, Y4 G1 _, ~; |5 pJoin us on IRC efnet at the channel #dosflash for support.- B! |$ b2 S% V& _
6 |8 M; Y% c# ^$ KDon't brick your BenQ!# d3 D, [: c7 e; Z3 z }
Kai Schtrom
; a" S" {7 J. o' T5 ^" F+ e7 u3 @$ D1 ?
, s# p" M! r6 Y- G6 U
************************************************************************************************
3 Y1 q! k+ G& u( |
. v0 q4 R3 e: q
1 S* b, ^) z! `DosFlash and DosFlash32 V1.2 Beta
6 F) p/ x, ]6 V6 G' F-----------------------------------
! U. B: P$ Y4 @8 d, B% V- bug fix for BenQ recognition5 j; o7 l8 O$ Y# }* Q& x, W% t
- manufacturer and device id are sometimes 0x00 for a correct installed switch$ w, {6 J+ y! U7 S. x3 M. M) R
- this issue is fixed with an additional ATAPI device reset before the mtk vendor intro is sent/ @1 Z+ T- `, I6 F# q' I! D# U
# J2 U1 ?5 [. E0 sThanks to Redline99 who fixed my buggy code by adding one line! 
6 c9 L0 k/ q' w* M b4 |
$ s" \# z: [- Y2 a* }" U! A, q' a" S# M- p) j
************************************************************************************************% B) F" }+ _) W: X. _4 m' g4 {
% F8 d$ d. Q( T4 V0 I
4 d9 ^/ k0 G4 |4 Y. i. SDosFlash and DosFlash32 V1.1 Beta( h! p# Q' e/ {0 ?9 m# H; T1 h! v
----------------------------------- k+ q- c" \8 R$ k) E8 R8 T- r1 Z
- DosFlash.typ modified for better BenQ support
& i) v. ^$ n. }- DosFlash16 Flash Manufacturer and Device ID screen output restructured' @3 j6 c3 ^/ l8 C1 I9 w: n
- flash chips are first erased before writing starts$ G5 J9 p p% f' A/ q! L
- DosFlash32 no reenable of DVD-ROMs in device manager after flashing, this means you can't see the drive( f4 }3 S; h$ K* r2 }5 A/ Y% s
and maybe have to activate it manually again in device manager, this could give better compatibility and
' z! ~. E' {7 l. u. `/ P: k hopefully no more blue screens* O# V$ I- S6 c) G+ @( D
0 [6 w( q# v, I2 e6 S
Many thanks to Jumba, Redline99, TeamModfreakz and Tiros for inspiration and help!' U& k% W0 f! m$ t
3 j; u; R; g5 i5 i) V' b8 W
5 e4 c; x+ W7 {4 S0 B5 t************************************************************************************************
5 X/ V, I4 M' K6 L) n: A" X O) K: Q
4 }. Z7 C/ P; O( w( a# d F+ R. n+ N% z ]: |6 X) Q: i
DosFlash and DosFlash32 V1.0 Beta
! h8 _4 b. T; o+ d; [$ T6 M) i-----------------------------------
: \5 j* M) x% jDosFlash can be used to read/write/erase the flash chips of most CD/DVD-ROM drives
. r- M, j- C1 ?8 k! Y9 u; |that have a mediatek chipset installed. DosFlash is for DOS flashing, DosFlash32
; X' x9 d# h, pfor Windows flashing.% v2 q2 i" p( l p g1 h
1 ?0 V9 I, n" V2 t
9 @8 J! h+ M% @/ b# X" }) D1 q* ]Features:
0 h8 U$ I9 O' A' X- \-----------
& b5 M3 H F; \! b" \- flashes IDE and SATA drives
" p# h, @: m1 ]% |; P+ c- supports parallel and serial flash chips0 f$ E/ t7 q. B8 d! R& x$ ~
- flash drives in Windows with direct port access! u5 |" s- G6 E( V I# D0 j% J
- no vendor cdb flashing commands are used1 _$ y. f4 f5 }
- tested with the following drives:+ `" N5 d; c# |. d/ G1 i8 O
- TS-H943A MS25, MS28
d, I- X% S2 K; L - SH-D162C
) o9 m$ y. c6 v X - SH-D163A
3 ^/ f' o- T/ H3 s' u# U - and some other drives like Liteon, Hitachi, ...9 f/ K* p( Z) z3 D' g$ C( z
- NEC drives are not supported, cause they have no mediatek chipset installed) }/ d, W# U3 [& D
5 {6 U9 F; E5 `! |" r/ B6 i
2 }0 @7 T, B, l: vDosFlash! n! o9 w# ?' V0 V4 r, ~
----------3 T$ _, x! Q7 f1 D
DosFlash supports two flashing modes, Auto and Manual. If you type DOSFLASH at a DOS prompt it$ w- D6 v$ u( C
will start in Auto mode. All drives and the corresponding flash chips are detected automatically.
3 K @ M5 R8 C8 ?If you can't get a flash chip recognized due to a bad flash or other problems you should use the
$ t( N& I8 _; ]( W2 F6 VManual mode. In Manual mode you can enter all the parameters used for flashing by hand. The* j: t- v. x7 v) ^ r
following help screen is displayed if you start DosFlash with a wrong number of parameters:
$ d+ |1 s! V4 N' i# X2 d3 Y; W* N8 q4 i& q8 M4 K' ~$ R5 o
+ `, l T, h) | e) [" v+ [# ]DOSFLASH by Kai Schtrom, 08/05/2007 (Ver 1.0 Beta)
# @6 f. Y% F2 T( Q h2 T0 J3 jDOSFLASH [R|W|E] [PORT] [PORT TYPE] [DRIVE POS] [FLASH TYPE]
% W0 [ D# o; R. o) x6 [ G- r g3 u [FLASH SIZE] [FLASH SECTOR ERASE OPCODE] [FILE NAME]
) `0 |3 b5 O8 ]* b4 E! F R: Read FLASH
% Z9 }, B; s/ l3 L3 B W: Write FLASH
5 D7 L; g, W6 a5 ?3 x' K" V E: Erase FLASH
) N0 d/ u w$ Q$ L& [ PORT: Port to send command to
1 h! }5 m! r9 Z) O5 p8 w3 ~ PORT TYPE: 0 for IDE, 1 for SATA
+ y$ e1 p L$ t3 v DRIVE POS: A0 for Master, B0 for Slave
J+ r/ R4 p! w, C( U& c; } FLASH TYPE: 0 for parallel flash, 1 for serial flash4 A! ]) ]% }: P* N. n9 U
FLASH SIZE: size of flash chip in number of banks
, J% d6 B% B" Q! x v3 kFLASH SECTOR ERASE OPCODE: individual sector erase opcode command byte- s7 }0 y/ q1 s; ]5 q
this is only needed for erasing a serial flash
. }2 o( k0 @3 Y# T FILE NAME: name of the file to read/write from/to flash6 d* ^" V. e, B( i
All numbers are intepreted as hex values!
; u, f! Z' a$ h! X1 H" p! l: Q; x" [+ l& _! R/ \. P( V y
Example Usage:
5 a1 C! f6 p: [: Q, }"DOSFLASH R 01F0 0 A0 1 4 C:\flash.bin"+ d6 G( Y* j/ p
=> Read serial flash with a size of 4 bank (262144 bytes) from Master Device
: V; V, `8 N3 I on IDE port 0x01F0
! f! ^/ [5 h1 | s: H, Y$ A' R"DOSFLASH E C000 1 A0 1 4 D8": i' o: n# i4 l
=> Erase serial flash with opcode 0xD8 and a size of 4 banks (262144 bytes)7 k) |. B' o; k$ J2 L8 S! H( ~& s0 E
from Master Device on SATA port 0xC000
3 v A+ k3 x# u& | % z: R! h( L' T+ C
( @# t5 s) j) @7 b; `( D9 K
Explanation of the Parameters: E3 [' a! C( F2 e
--------------------------------
+ ~( J+ n. Q! B. b
5 B+ w9 |* E8 C! |1 V. P[R|W|E]
% R! R* T) ?) I' x9 {) n---------
* Q( y* Z) ~* q6 B- this will set the mode of flashing, it is recommended to first try read on any
+ Z v- j+ s6 x1 e( | drive, if the read will fail, it is highly unlikely that a write or erase will7 n6 S3 k1 x* R3 q
succeed( j, b/ K, n1 q, ?. a
: D- z5 B2 M: c8 F[PORT]
1 Z* c/ ]: Z( X2 S--------
# s' G2 V4 m& Y+ @1 S7 E- the port to which the drive is connected, a port number should always be entered
, g& T% C0 ~0 R3 |( }' Z4 k9 s4 [ in hexadecimal and have 4 hex digits, valid ports are: 01F0, 0170, C000, C800/ |3 m$ H9 P5 S( J. U6 {( ?3 K. c
- this option can be used if your PCI adapter card or on board IDE/SATA ports are
0 D' w5 |7 G; [ D* W! n7 _; S: l not identified by the auto mode- J+ h/ D( a K! O. d! t2 j& h; [
5 L9 i% z6 T& c. B
[PORT TYPE]
# C8 ?5 @. B# S4 [& N/ g% J% V-------------
( |1 M0 r, L4 S" f7 f( W- the port type tells DosFlash what type of port is installed on the before entered
3 X4 H1 A0 Y& `7 a+ ~ L3 } port address
; K: \8 _4 ^# ~' \4 b9 X; Q; M- valid values are 0 for IDE and 1 for SATA: X5 N- e0 \1 }% k, g+ i9 g
- make sure you never mix the wrong port with the wrong port type, this could give
+ A2 c$ ~# y3 Z; ^ strange results or in the worst case a bricked drive1 _) [. o% n/ f$ _# C' g
$ t, }& T2 b. |1 i
[DRIVE POS]
! G1 t6 p+ W" E) J0 ]' N; U) o-------------
% _6 k k9 ~5 @4 p6 q5 @# v- old style IDE channels have the possibility to connect two drives at one IDE. t! u1 w4 n: J8 H
channel, the first drive is called the master, the second drives is called the% K0 }" Q/ W: Z- H/ n8 U7 w
slave
2 `$ k' N8 \, q4 J4 e Q- A1 W- you can select which drive should be flashed on the channel, A0 selects Master,
7 Y* Q3 w' n4 {$ ~, u B0 selects Slave8 ^& W% \4 e0 o7 U6 L0 [
- on SATA ports this value is always A0, cause you can only connect one drive to
( R' O4 J' p4 D% @) o: h a SATA port, so for SATA you will always type A0 here% B% n% f6 o' g' X G/ ^
- it is not recommended to flash IDE drives with another drive connected to the( |2 T+ ]% w* I
same IDE channel, this could be risky if something in the Master/Slave selection3 d0 e; |, S% R+ T( r6 p0 o% I
fails
# Q2 R2 a/ _ `% r: G6 @
8 Z7 P( O' \ x. ^9 g* Q8 g[FLASH TYPE], E/ u5 T% s) S: i/ q9 D( j8 O
--------------
; h2 S. S! o" T7 m% g- there are two types of flash chips out for CD/DVD-ROM drives atm6 }* y( @7 W) p9 c- I7 i1 R0 `
- the older type is parallel flash, which is also supported by mtkflash for example
+ w0 @7 Z) c6 I9 Z/ X- the newer type is serial flash, which is supported by flashers like XSF
+ Z8 i3 {, T% l7 k0 y: s- the problem here is that no tool is out that can flash serial flash chips on
5 y$ S- d* t/ s* Y& q& l( q5 ^ SATA ports
' c# T' X* A( r* X, p7 `! h; v 6 C7 U5 h3 i/ P) e! L: v
[FLASH SIZE]' J7 Z: Y* l, M3 e0 _7 l
--------------
9 j2 ?0 r$ S* g4 }/ S" v. ?- this is specifies the flash chip size in banks8 J8 [) p1 x# m4 \
- one bank is always 65.536 bytes in size
. t% z/ J. \$ t* B6 z5 D) b- if you know your drive has a flash chip of 262.144 bytes in size you need to enter 4, R( W' L# T1 }2 g5 S1 H. @
$ u& h8 R1 }: t( T[FLASH SECTOR ERASE OPCODE]
) f3 d: i. R' V-----------------------------/ F; E+ n0 c. E- H8 p6 n. j+ s
- the opcode used in the flash chips datasheet for erasing5 P2 p" @5 m5 J L$ g/ c. y# a5 d( u! Z
- for serial chips this command can be different from the standard and needs to be
6 n) w! o& Y ]* u7 I9 I1 S entered for flash erase
* Q8 p, `& H' e6 z( e( H" q8 M; d ~! X- for parallel flash chips you can enter a dummy cmd byte, the integrated command
) w+ F, O; d0 Z0 {6 J( j' ]. d should work on all parallel flash chips without a prob' C6 L0 b' W/ X& Z+ Y
2 [' ?4 Y' E" g8 V+ k: e
[FILE NAME]
3 m h) Q9 j( w4 B. V4 ?-------------# V" f' E# c# F' l$ O, |3 H
- name of the file that should be used for flashing
4 R3 q; K0 ?! |6 l- for reading operations this should be the output file
3 ~6 t# r/ d+ B* {) I; \8 E6 N- for writing operations this should be the input file
4 t. _; t5 `) c* S5 k, O. O6 b* t# ]! f6 t% O; D
# J$ L9 P! X7 f6 P
Hints and Warnings
9 y$ E& u, A7 I' n4 v; E7 ^6 h--------------------
W( _- v; n6 I* u J8 A- read, write erase TS-H943A MS28 after the firmware stealth has been disabled with Enable0800 disc
% j4 g; z o( O0 U/ C! y - this only works one time, after the first mtk vendor specific intro cmd is send
4 D E, P4 q) H" ?9 D1 H - if the mtk vendor specific outro cmd is send the chip goes back to stealth mode and you need
) U% U; t _! _1 k; b/ B again the Enable0800.iso to disable it5 t" x, _" ?4 q1 F
- therefor the mtk vendor specific intro is send at program start to all present devices and the9 C+ V/ t& j$ M+ ~# k
mtk outro is sent at program end
2 k, Q# y6 Z* i2 c - if you have a chip manufacturer id of 0x02 and a chip device id of 0x02 for the TS-H943A- C$ h) ~) K, [
the flash chip is in stealth mode and won't give access to any reading, writing, erasing# E6 m8 c# j- z2 T
- always have a look at the DataSum generated, this is exactly the DataSum of mtkflash5 U+ Q; S* r0 V. c \) N
- the DataSum is calculated as the sum of all bytes of the firmware in a short integer* ?% r, H! Z I/ y: T+ m# c/ N
- to make 100% sure that the flash is written right compare that DataSum to a known one. Z2 r# V; E$ y9 y3 a. ] V
- this tool has not been tested on all drives out there, the typ list is simply copied from well9 N. o% [4 K3 A( M T
known programs like mtkflash and XSF
0 N) W# l2 U( `4 F' Q# X: q - always try a flash read on a not yet tested drive before doing anything else
: ` S3 B, n% ~+ d! n - if the read doesn't succeed it is highly unlikely that a write or erase will
* m. E) u# J- T+ S3 O n6 t! T {- some LiteOn drives seem to have probs to write the firmware correct, this prob seems to be
3 o @- X- ~, }1 g8 N9 `* C+ n5 H related to windows register flashing, cause even an assembler app can't do this error free
. o% ]/ `) I: @% k$ M - if you get errors on LiteOn drives, write the flash two times in a row2 O- N2 P) W" \# G/ S: K/ w
- for direct port I/O in windows the givoio.sys driver is used, this driver is loaded at DosFlash329 P7 b! T ]9 I! [# s- A# K7 {
start and unloaded at program end, be warned, this driver can possibly make your system unstable,
9 q2 v/ V# v6 W5 A it's intention is to let privileged assembler instruction like in and out pass, even in windows,
! f9 U: v0 v% C' P if this driver is not used you will not be able to get direct access to port registers
3 _# \% Q: d4 o3 ^9 _- Q5 u- DosFlash was tested on MS-DOS 6.22 and later, you can easily copy it on a MS-DOS boot disk created: C- ^5 Z+ j% ~( s# ^
in Windows XP and start DosFlash directly from the disk! x& ?4 o- t( |& Q9 m* O
- don't forget to also copy the DosFlash.typ file, it has all the informations about flash chips2 ^2 }* S! x0 `! V
for auto mode flashing
; [4 t& o3 k) F, x- DosFlash32 was tested without a prob on Windows XP SP2, you'll need also the typ file for the
6 W0 l* {" J4 m win version
. p# a) k/ ]! y% `# p- DosFlash32 will deactivate all CD-ROMs in device manager at startup, this is better for flashing,
5 K9 t' u# M& h) K( M' i& E cause Windows seems to poll the drives all the time and this could result in a bad fw file or
% k$ `4 l! ~7 D5 k5 @ a program hang, the drives are activated again at program end
3 h2 {& M& _6 R" |" h- you should make sure that the flash is not in an erased state at program end, cause device manager
4 _: V1 `) J8 \2 g don't like drives that do not respond to the inquiry command
$ E F. i8 s. T0 u- deactivating all CD-ROMs could take a few seconds, so please be patient at program start% f$ L: Q e1 \" J
- DosFlash and DosFlash32 will try to scan for the VIA 6421L Raid Controller card, based on vendor1 C" a p8 q& f, b6 ~* i" G# x
id 1106 and device id 3249, it doesn't matter if the card driver is installed or not( P4 k" ^& |; A/ t% a( E3 {5 N8 S
6 T. \. s9 H: s( I
* _* \; G# C& j2 B* g- [, BMany thanks to Dale Roberts and his Direct Port I/O driver giveio.sys!* ^: n* _& h% g4 ?- z
8 G! K( @5 F4 u* f8 t' k
Avoid a bad flash!6 H' h8 ~4 t5 l! u
Kai Schtrom |
|