Just spent 5 hours screwing with this
9504 slim OFW updated and locked to 0272 (13599 dash)
I had a previous dump already, and replacement PCB on the way. I kept getting a 'dump failed' when verifying the write. This is bad as it has to continue to do more sector modification after the write to lock the drive down as it was supposed to be.
Method for me is a bit different than posted, for me to make a good write or read, I have to disable the switch.
1. Cut trace, connect 12ohm resistor and switch between via and GND.
2. Turn on DVD drive and open JF 0.1.85 MTK32 tab
3. hit CTRL + F7 to refresh device, once info found power off drive.
4. hit device ID/intro, select YES and while the .... are going across probe MPX01 point with GND. power cycle drive until 0x72 status (my PMT cap was socketed between 3.3v and GND. I pinned the GND wire from this socket) once 0x72 found remove probe.
5. run the unlock program, enter port in window, hit unlock. should come up with 2 russian words. the 2nd should start with a p. if so your unlocked! (CTRL + C the popup and translate it if you need to)
AT THIS POINT I REMOVE RESISTOR! I don't know why I had to do this, but I had to!
6. flip switch to off (remove resistor)
7. in JF hit Slim UnLock - should do some unlocking and end result is read FW and dump. This may require the LTPlus-0272 file in the firmware folder if you are on 0272 firmware and need a key. (I already had dump, but after LT was wrote this is how I could obtain the key)
8. gen new LT firmware
- maybe not needed, but I did an outro, and an intro and it found 0x72 flash without MPX01 probe - this could be important for successful write)
9. erase and flash as you normally would. It should write, verify, erase a few sectors, authorised! and continue until it says successful!
Again, this took trial and error to figure out the finer points. It does work however!
If you get dump failed errors, or can't dump the key - try screwing with the switch. This may also be true for those with Winbond chipsets. Since I have no 0225 or winbond devices here I'll let someone else figure that out. Guess TX really did their research on how to bypass the SPi lock.
This post has been edited by ruciz: Jul 21 2011, 06:35 AM