RIFF JTAG – RIFF JTAG Manager v1.24, RIFF Box Firmware v1.18 released
10.02.2011 RIFF JTAG Manager v1.24, RIFF Box Firmware v1.18
Firmware 1.18
---------------------------
- PXA270 debug is now available in ARM/Thumb modes (use the GDBServer for this);
JTAG Manager 1.24
---------------------------
- In case when Resurrector has no DCC Loader the JTAG Manager will now report it correctly and will not allow DCC Read/Write features
- (SDK): more functions are now available (exported) for future Resurrector DLLs;
- Usefull Plugins Enabled
---------------------------
Qualcom FullFlash Image Processing Tool:
This plugin works with NAND image files which have generic Qualcomm layout
With help of this plugin you can do:
- Disassemble a full NAND image file previously obtained with JTAG Manager (DCC Read/Write Page);
- Inspect each partition contents (main zone and spare zone) simultaneously;
- Save separate partitions to HDD (only main zone, only spare zone, or both zones);
- Write a chosen partition directly into phone;
- Read a chosen partition directly from the phone and substitute old partition contents to new ones;
Please note, direct read/write operations from/to the phone will require proper resurrector to be set (Resurrector Settings: thus before clicking the Activate Plugin button make sure compatible model is selected as well as other settings like TCK/RTCK frequencies).
You can access it from "Usefull Plugins" TAB.
16.02.2011 HTC HD7 Unbrick, Unlock, IMEI Repair and CID Update supported
16.02.2011 HTC HD7 Unbrick, Unlock, IMEI Repair and CID Update supported
Please start JTAG Manager and click “Check for Updates” button. You’ll be notified about new DLL, download it and restart the software.
“HTC_HD7.dll” contains pinout, instructions and required repair files for HTC HD7 Unbrick, Unlock, IMEI Repair and CID Update.
http://www.jtagbox.com/wp-content/up.../htc_hd7_2.jpg
RIFF JTAG - HTC P3300 (HTC ARTE100, ARTE110) Unbrick - Boot Repair Supported
18.02.2011 HTC P3300 (HTC Artemis 100) Unbrick – Boot Repair Supported
Please start JTAG Manager and click “Check for Updates” button. You’ll be notified about new DLL, download it and restart the software.
“HTC_Artemis.dll” contains pinout, instructions and required repair files for HTC P3300 (HTC Artemis 100) Unbrick – Boot Repair.
- Important :
There are 7 devices with Artemis code name. Check Your phone back sticker, if You see "ARTE100" or "ARTE110" You can repair Your phone.
"ARTE200" is NOT tested !.
RIFF Box – JTAG Revolution
RIFF JTAG - Updates from Yesterday :D
10.03.2011 HTC Tattoo A3232 (HTC Click 1100) Unlock, Unbrick, IMEI repair, CID Update supported
Resurrecting HTC Click is easy. Phone is auto powered on with USB Data Cable connected to the PC while battery is inside.
There are two different hardware versions exist – one based on the MSM7225 chipset (CLIC10000) and other – on the ESM7225 chipset (CLIC11000). In resurrector settings you can select a desired version.
Resurrector will reflash radio’s boot zone and will re-write PDA’s SPL to 0.52.0001 SPL version.
As well, you can change CID – for this make sure ‘Repair Custom ID’ field is checked in the Resurrection Guide dialog.
To resurrect HTC Click:
* Solder JTAG cable to HTC Click JTAG pads;
* Make sure HTC Click is selected in the list of models;
* Click Resurrect button;
* Wait till software signals a successful operation completion;
* Disconnect power supply, de-solder JTAG wires;
Now phone is in bootable condition, that is, even if it does not start up normally, you can flash it using known flashing methods.
To Unlock HTC Click :
* Solder JTAG cable to HTC Click JTAG pads;
* Make sure HTC Click is selected in the list of models;
* Click Resurrect button;
* Select “Unlock Settings” TAB
* Select Unlock method
* Click “Unlock”
10.03.2011 HTC Desire DLL Update – Unlock Code reading supported
New HTC Desire DLL has additional option to select between reading NCK Code, or direct unlock.
This should also solve “error 0×45″ problem with some of the HW revisions.
10.03.2011 ASUS P526 Unbrick, Dead Boot repair supported
Resurrection of ASUS P526 is slightly complicated. JTAG pads are very small and sensitive thus extreme care must be taken when soldering wires to the board. Battery must be connected in order to establish JTAG connection.
Current resurrector re-flashes only the IPL area, and will not re-write MDOC XLOADER area (though write of this area is supported too).
Please note: DiskOnChip G4 memory has security features, due to which there is a risk of permanently blocking the access to the flash memory while re-flashing the XLOADER areas. Current resurrector will not touch the XLOADER zone, but it is possible you’re already holding such killed device in hands. If it is so you will see this error:
************************************************** **************
Detected a Not Initialized FLASH1 Chip ID: 0×0400/0xFBFF
ERROR: Selected FLASH Chip was not initialized by the DCC Loader
************************************************** **************
This can happen due to unknown protection keys used or due to permanently blocked MDOC chip. If latter is true we advise you to solder a new flash memory chip or throw this phone away to the trash bin.
To resurrect ASUS P526:
* Solder JTAG cable to ASUS P526 JTAG pads;
* Insert battery and connect USB cable to phone and PC;
* Make sure ASUS P526 is selected in the list of models;
* Click Resurrect button;
* Wait till software signals a successful operation completion;
* Disconnect USB cable, de-solder JTAG wires;
Now phone is in bootable condition, that is, even if it does not start up normally, you can flash it using known flashing methods.
If phone not enters download mode after resurrection then it means XLOADER was damaged too but memory chip is still usable. In this case repeat resurrection using RAM Downloader Mode and when USB connection is established reflash the phone with official firmware.
To enter download mode:
* Disconnect PC cable;
* Insert battery;
* Move ‘Lock’ slider down, hold ‘OK’ key (on the left) and press ‘Power ON’ button. In few seconds you should see TriColor picture.
Additional info:
* Phone has DiskOnChip G4 memory type, which has security features. It has two password protected partitions (Password1 = 12345678, Password2 = 00000000);
* XLOADER re-flash is not performed in this resurrector on purpose. While re-flashing the XLOADER area there is a risk of permanently blocking the memory chip.
* Any write access (Erase or Write) on MDOC NAND memory range 0×00000000 to 0x0017FFFF is rejected by the DCC Loader
10.03.2011 CDMA ZTE F285 Repair supported
Resurrecting ZTE F285 is simple. Phone is auto powered on with USB Data Cable connected to the PC. Battery presence is not required; connection can be established with detached board. Resurrector re-flashes only firmware zone of the phone (0×000000 to 0x60FFFF).
To resurrect ZTE F285:
* Solder JTAG cable to ZTE F285 JTAG pads;
* Insert USB Data cable into board and PC;
* Make sure ZTE F285 is selected in the list of models;
* Click Resurrect button;
* Wait till software signals a successful operation completion;
* De-solder JTAG wires;
10.03.2011 RIFF JTAG Manager v1.27, RIFF Box Firmware v1.19
Whats new :
RIFF JTAG Manager v1.27
* Fixed access violation bug upon JTAG Manager startup if there is no RIFF Box detected and Cancel button is clicked.
* (SDK): more functions are now available (exported) for future Resurrector DLLs;
* Added flags for JTAG Manager to be able to retrieve memory chip size from the DCC Loader.
* Fixed initialization bug for NOR-related DCC Loadererss
* ScriptEngine: added options pocessing ‘/byte’, ‘/word’, ‘/long’ to data.save.binary instruction: thus it’s possible now to read memory through script using desired bus access width (8-,16-, or 32-bit widths). For example: “data.save.binary c:\myfile.bin 0×00..0x11FF /word” – will read 0×1200 bytes from memory into myfile.bin file starting from address 0×00 using 16-bit bus accesses.
Note: “Read Memory” button on the JTAG Read/Write page reads memory using 32-bit bus accesses only.
RIFF Box Firmware v1.19
* Added more H/W script (*.has) instructions;
* Added HTC security processing functions;
Please click “Check For Updates” button in order to download and apply new files. Closing all running application before starting update process is recommended.
11.03.2011 CDMA Huawei C5005 Unbrick – Repair supported
11.03.2011 CDMA Huawei C5005 Unbrick – Repair supported
Resurrecting Huawei C5005 is simple. Phone is auto powered on with USB Data Cable connected to the PC. Battery presence is not required; connection can be established with detached board.
Resurrector re-flashes only firmware zone of the phone (0×000000 to 0xBFFFFF).
To resurrect Huawei C5005:
Solder JTAG cable to Huawei C5005 JTAG pads;
Insert USB Data cable into board and PC;
Make sure Huawei C5005 is selected in the list of models;
Click Resurrect button;
Wait till software signals a successful operation completion;
De-solder JTAG wires;
Please click “Check For Updates” button in order to download and apply new files. Closing all running application before starting update process is recommended.
http://www.jtagbox.com/wp-content/up...1/03/c5005.jpg
RIFF JTAG - Samsung i607 Blackjack PDA, CDMA Huawei C5005, OMAP 1710 Support added
12.03.2011 Samsung SGH-i607 BlackJack PDA Unbrick, Dead Boot repair supported
Resurrecting Samsung i607 PDA part is easy. Phone requires battery presence in order to establish JTAG connection. If you additionally connect charger the phone will be auto powered on and there will be no need to press Power on key.
In case you experience connection problems, de-power phone completely, disconnect charger (if it was used), then insert battery, click Resurrection button in the JTAG Manger and immediately (within 0…1 seconds) press Power On key.
To unbrick Samsung i607 PDA part:
Solder JTAG cable to Samsung i607 PDA JTAG pads;
Make sure Samsung i607 PDA is selected in the list of models;
If only battery is connected – press Power On key shortly;
Click Resurrect button;
Wait till software signals a successful operation completion;
Disconnect power supply, de-solder JTAG wires;
Now phone is in bootable condition, that is, even if it does not start up normally, you can flash it using known flashing methods.
11.03.2011 CDMA Huawei C5005 Unbrick – Repair supported
Resurrecting Huawei C5005 is simple. Phone is auto powered on with USB Data Cable connected to the PC. Battery presence is not required; connection can be established with detached board.
Resurrector re-flashes only firmware zone of the phone (0×000000 to 0xBFFFFF).
To resurrect Huawei C5005:
Solder JTAG cable to Huawei C5005 JTAG pads;
Insert USB Data cable into board and PC;
Make sure Huawei C5005 is selected in the list of models;
Click Resurrect button;
Wait till software signals a successful operation completion;
De-solder JTAG wires;
OMAP 1710 Support added :
OMAP 1710 Specs,
OMAP 1710 based devices.
Please click “Check For Updates” button in order to download and apply new files. Closing all running application before starting update process is recommended.
RIFF JTAG - Toshiba Portege G900 Unbrick, Dead Boot repair supported
14.03.2011 Toshiba Portege G900 Unbrick, Dead Boot repair supported
Resurrection of Toshiba Portégé G900 PDA part is not hard. Battery is required for successful HALT operation. If USB Data Cable is connected phone is auto powered on when battery is inserted.
If during connect operation (“Establish communication with the phone…”) after 2-3 passes there is still no success (progress bar keeps running from 0 to 100% and so on) then remove battery and insert it again. If USB cable is not connected then press and hold Power On key.
Current resurrector re-flashes only the EBOOT and secondary EBOOT area, and will not re-write IPL area (though write of this area is supported too).
Please note: DiskOnChip G4 memory has security features, due to which there is a risk of permanently blocking the access to the flash memory while re-flashing the IPL areas. Current resurrector will not touch the IPL zone, but it is possible you’re already holding such killed device in hands. If it is so you will see this error:
************************************************** **************
Detected a Not Initialized FLASH1 Chip ID: 0×0400/0xFBFF
ERROR: Selected FLASH Chip was not initialized by the DCC Loader
************************************************** **************
This can happen due to unknown protection keys used or due to permanently blocked MDOC chip. If latter is true we advise you to solder a new flash memory chip or throw this phone away to the trash bin.
To resurrect Toshiba G900 PDA part:
* Solder JTAG wires to the Toshiba G900 PDA pads;
* Connect USB cable to phone and PC;
* Make sure Toshiba G900 PDA is selected in the list of models;
* Insert battery and click Resurrect button;
* Wait till software signals a successful operation completion;
* Disconnect USB cable, de-solder JTAG wires;
Now phone is in bootable condition, that is, even if it does not start up normally, you can flash it using known flashing methods.
To enter USB download mode:
* Disconnect PC cable;
* Insert battery;
* Hold ‘Left soft’ key (which is exactly above the Dial key) and press ‘Power ON’ button. In few seconds you should see red download screen.
To enter SD-card download mode:
* Disconnect PC cable;
* Insert battery;
* Hold ‘D’ key and press ‘Power ON’ button.
Additional info:
* Phone has DiskOnChip G4 memory type, which has security features. It has two password protected partitions (Password1 = 12345678, Password2 = 00000000);
* IPL re-flash is not performed in this resurrector on purpose. While re-flashing the IPL area there is a risk of permanently blocking the memory chip.
* Any write access (Erase or Write) on MDOC NAND memory range 0×00000000 to 0x0017FFFF is rejected by the DCC Loader. For full image writing convenience access to that range will not rise any error, data will just be ignored and reported as if it was written successfully, thus you still can write full image files using ‘Auto FullFlash Size’ checked.
Please click “Check For Updates” button in order to download and apply new files. Closing all running application before starting update process is recommended.
RIFF JTAG - Huawei E153U Broadband modem unbrick – dead boot repair supported
17.03.2011 Huawei E153U Broadband modem unbrick – dead boot repair supported
Resurrecting Huawei E153U is simple. Just make sure you solder all JTAG signals and insert modem into a USB port for it to get powered.
If modem is not detected by RIFFBOX JTAG, disconnect JTAG connector, re-insert modem into USB and then connect back the JTAG connector.
There are secured (QCSBL is signed) and non-secured (QCSBL is not signed) modem revisions exist. Resurrector will automatically detect board revision and will select proper data to be flashed.
No matter what h/w revision is you can select which partitions are to be flashed during resurrection process.
To resurrect Huawei E153U:
* Solder JTAG cable to Huawei E153U JTAG pads;
* Insert Huawei E153U modem into any USB port for power;
* Make sure Huawei E153U is selected in the list of models;
* Click Resurrect button;
* Wait till software signals a successful operation completion;
* De-solder JTAG wires;
Please click “Check For Updates” button in order to download and apply new files. Closing all running application before starting update process is recommended.
RIFF Box – JTAG Revolution
RIFF BOX - ROVER PC EVO V7, MARVELL PXA3XX Generic NAND DCC Loader
21.03.2011 RoverPC EVO V7 Unbrick – Dead boot repair supported
RoverPC Evo V7 resurrection is simple. Phone is auto powered on with USB Data Cable connected to the PC. Battery presence is not required; connection can be established with detached board.
To resurrect RoverPC Evo V7:
-Solder JTAG cable to RoverPC Evo V7 JTAG pads;
-Connect USB cable to phone and PC;
-Make sure RoverPC Evo V7 is selected in the list of models;
-Make sure a fixed TCK frequency is selected;
-Click Resurrect button;
-Wait till software signals a successful operation completion;
-Disconnect USB cable, de-solder JTAG wires;
-Now phone is in bootable condition, that is, even if it does not start up normally, you can flash it using original firmware downloader software to restore it to the working state.
To enter download mode:
-Disconnect PC cable;
-Insert battery;
-Hold both ‘Volume Down’ and ‘Camera’ keys and press Power-On.
21.03.2011 MARVELL PXA3XX NAND Generic DLL Released
Resurrector PXA3XX contains only NAND DCC Loader, thus it is to be used only for operations on DCC Read/Write page in the JTAG Manager.
Embedded DCC Loader is designed to work inside of MCU's internal RAM memory, thus it is not sensitive to external SDRAM configuration or availability or its physical state.
21.03.2011 - RIFF Box Firmware v1.21
Firmware 1.21
---------------------------
Added RX-polling feature (debugger-to-target) for PXA3XX DCC transfers.
RIFF BOX firmware is able now to wait (if resurrector DLL will request so) for PXA3XX target to be ready to accept
next packet over DCC: this feature slows down a little the JTAG-to-Target DCC
transfers but guaranties no packets loss for slow clocked targets;
Please click “Check For Updates” button in order to download and apply new files. Closing all running application before starting update process is recommended.