[SOLVED]Help me! I'm very desperate wife!

Here for general support for B series TVs, request and problem solve area.
Post Reply

desperatewife
Posts: 2
Joined: Sun May 06, 2012 3:16 pm

[SOLVED]Help me! I'm very desperate wife!

Post by desperatewife »

Hi, I'm new the forum and the world samygo. I joined because my husband broke our tv samsung and now it's my turn to help him fix it! Model Code LE40B650T2WXXC.
1. He updated the TV firmware. Big mistake!
2. Fate has the FFB procedure, to go back
3. The TV is bricked
I'm following all the procedures for repair but I have these problems:
1.I run this:

Code: Select all

C:\Python27>python SamyGO.py ./T-CHL7DEUC
SamyGO Firmware Patcher v0.23 (c) 2010 Erdem U. Altinyurt

                   -=BIG FAT WARNING!=-
            You can brick your TV with this tool!
Authors accept no responsibility about ANY DAMAGE on your devices!
         project home: http://SamyGO.sourceforge.net

Firmware:  T-CHL7DEUC v2005.0

XOR Encrytped CI firmware detected.
Decrypting with  XOR Key :  T-CHL7DEUC
Crypto package not found, using slow XOR engine.
 %100

Applying Patches...
MD5 of Decrypted image is : fc6a69294d99aab1582bf44d34b910d8

Extracting exeDSP from image
FAT16 image type.!
FAT image analyzed - exeDSP location: 7811072  size: 37414044
exeDSP file created at :  C:\Python27\T-CHL7DEUC\image\exeDSP-T-CHL7DEUC-2005.0

Patching VideoAR Fix v1
CToolMmbDisplaySizeItem::GetToolItem() Adress : 0x13537D0
CToolMmbDisplaySizeItem::PressLeftRightKey() Adress : 0x1353AC8
VideoAR Fix v1 Compatibility NOT Found.
Skipped VideoAR v1 Fix.

Patching Big Subtitles
CMultimediaMovieInfo::UpdateCaptionTextSize() Adress : 0xDF5ECC
CMultimediaMovieInfo::InitCaption() Adress : 0xDF6C38
Big Subtitles Compatibility NOT Found.
Big Subtitles patch skipped.

Colorfull Subtitles ColorKey Adr 0xDF6D00 Color: 0xFFF0F0F0
Colorfull Subtitles Compatibility Found.
Want to Change Substitle Color ( y/N )? n
Colorfull Subtitles patch skipped.

Injecting modified exeDSP file to image
FAT16 image type.!
FAT image analyzed - exeDSP location: 7811072  size: 37414044
Injection Size :  37414044

Applying Telnet Patch...
Searching %99
Oops!: "#Remove engine logging." string not found on image.
Probably this firmware is already patched.
Telnet Patch not applied.

Calculated CRC : 0x174D4A99
Updating C:\Python27\T-CHL7DEUC\image\validinfo.txt with new CRC.

Encrypting with  XOR Key :  T-CHL7DEUC
Crypto package not found, using slow XOR engine.
 %100
Operation successfully completed.
Now you can flash your TV with ./T-CHL7DEUC directory.
but the extension of the file appdata.img and exe.img, in the T-CHL7DEUC folder, are still .enc!Instead find exeDSP-T-CHL7DEUC-2005.0
2. I copied the modified firmware directory to my USB flash device root and tv reboot and view:

Code: Select all

ONBOOT :: 0x59a50219 0x12821282 
[SERIAL INPUT MANAGE] Managed tty_struct(.name:ttyS1) Setup!!!
[SERIAL INPUT MANAGE] disable_serial : ~~bye(len:5)
[SERIAL INPUT MANAGE] enable_serial : debug(len: 5)

[28_64_512] Linux version 2.6.18_SELP-ARM (ksh921@sp) (gcc version 4.2.0 20070514 (GPL2) (SELP 4.2.0-3.0.5.custom 2007-10-31(14:53))) #81 PREEMPT Mon Jun 22 10:10:31 KST 2009
================================================================================
 SAMSUNG: v2.6.18_SELP_3.X_GA_bayhill+/A1(P24)
         (Detailed Information: /sys/selp/vd/lspinfo/summary)                   
================================================================================
[SERIAL INPUT MANAGE] Managed tty_struct(.name:ttyS1) is freed !!!
[SERIAL INPUT MANAGE] Managed tty_struct(.name:ttyS1) Setup!!!
[SERIAL INPUT MANAGE] disable_serial : ~~bye(len:5)
[SERIAL INPUT MANAGE] enable_serial : debug(len: 5)

[SERIAL INPUT MANAGE] Managed tty_struct(.name:ttyS1) is freed !!!
[SERIAL INPUT MANAGE] Managed tty_struct(.name:ttyS1) Setup!!!
[SERIAL INPUT MANAGE] disable_serial : ~~bye(len:5)
[SERIAL INPUT MANAGE] enable_serial : debug(len: 5)

init started:  SELP-BusyBox(GPL2) v1.2.2-Samsung.Common.Linux (2008.12.24-18:59+0000) multi-call binary
Starting pid 24, console /dev/ttyS1: '/etc/rcS'
/etc/rc.local start!!!!
boot script rc.local start!!!
=====================================================
  ROOTFS VERSION : 24_64_512-25 T-CHL7DEUC
  BOOT VERSION   : 24_64_512-31
=====================================================
/mtd_rwarea/PartitionSwitch_1_0  is detected...
2nd Partition is selected...
Unable to handle kernel paging request at virtual address d345403c
pgd = cc380000
[d345403c] *pgd=6bef6011, *pte=00000000, *ppte=00000000
Internal error: Oops: 7 [#1]
Modules linked in: rfs fsr_stl fsr
CPU: 0
PC is at sys_init_module+0xb84/0x1770
LR is at 0x28
pc : [<c005d864>]    lr : [<00000028>]    Tainted: P     
sp : cc33fee0  ip : cc33fec8  fp : cc33ffa4
r10: d3345b28  r9 : d30a1000  r8 : d335de60
r7 : bf191544  r6 : bf37bba0  r5 : cc33e000  r4 : 00000000
r3 : d3454030  r2 : 000005d0  r1 : 0000fff2  r0 : 0000fff1
Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  Segment user
Control: C5387F
Table: 6C380000  DAC: 00000015
Process insmod (pid: 41, stack limit = 0xcc33e250)
Stack: (0xcc33fee0 to 0xcc340000)
fee0: c026176c c006f590 bf37bbac c06a94e0 00000000 00000000 00000000 00000000 
ff00: 00000000 00000000 00000000 00000000 00000f66 00000000 00000000 00000f64 
ff20: 00000000 00000000 d33bb418 cc19a700 d338a9d8 d3387080 00000eb8 00000000 
ff40: 0000309f 0000005d bf190f74 00001001 cc33e000 d334afe8 cc33ff74 d335de88 
ff60: d335de60 c0151620 d338aa00 000011e3 00000000 c026176c 00000002 00000008 
ff80: 00000000 00000000 00000080 c001ffe8 cc33e000 00000000 00000000 cc33ffa8 
ffa0: c001fe40 c005ccec 00000008 00000000 40000000 00377b78 00153158 00000004 
ffc0: 00000008 00000000 00000000 00000080 00153140 00124398 00000002 00151c9c 
ffe0: bede07b8 bede07a8 000183cc 000a9840 00000010 40000000 ffdffd7f fedfffff 
Backtrace: 
[<c005cce0>] (sys_init_module+0x0/0x1770) from [<c001fe40>] (ret_fast_syscall+0x0/0x2c)
Code: e3530000 13a0e028 05962160 1023839e (1593200c) 
 Segmentation fault

----------- Kernel  Loading End------------

Application is started..
##### System Execution!!! #####
~~[SSPF] [FastBoot.cpp] Initialize, FAST INIT
TDaStore Building...
TDaTuner0 Building...
TDaDemodulator0 Building...
TDaTuner1 Building...
TDaDemodulator0 Building...
TDaTuner2 Building...
TDaDemodulator1 Building...
TDaTuner Building...
TDaDemodulator Building...
TDaTuner Building...
TDaDemodulator Building...
TDaAudioAmp0 Building...
TDaAudioAmp1 Building...
TDaSystem Building...
TDaAudioProcessor Building...
TDaScaler0 Building...
TDaScaler1 Building...
TDaAnalogVideoProcessor Building...
TDaDemux 0 Building...
TDaDemux 1 Building...
TDaMpeg Building...
TDaCompProcessor Building...
TDaHdmiProcessor Building...
TDaPcProcessor Building...
TDaHdmiSwitch Building...
TDaCommonInterface Building...
TDaFeeder Building...
TDaImage Building...
TDaTeleText Building...
TDaRecorder Building...
TDaAnalogVideoSwitch Building...
TDaStore PC DDC Building...
TDaStore HDMI1 DDC Building...
TDaStore HDMI2 DDC Building...
TDaStore HDMI3 DDC Building...
TDaStore HDMI4 DDC Building...
FRCQ TDaPanel0[LCD] Building...
TDaVideoEnhancer0[LCD] Building...
TDaPanel1[PDP] Building...
TDaVideoEnhancer1[PDP] Building...

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 0

        >>[ERR:TDcChelseaGpio.cpp] Read():129 GPIO_GetIn() returns error -1! GPIO Port : 1

        >>[ERR:TDcChelseaGpio.cpp] Read():129 GPIO_GetIn() returns error -1! GPIO Port : 2

        >>[ERR:TDcChelseaGpio.cpp] Read():129 GPIO_GetIn() returns error -1! GPIO Port : 3

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 5

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 6

        >>[ERR:TDcChelseaGpio.cpp] Read():129 GPIO_GetIn() returns error -1! GPIO Port : 7

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 256

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 257

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 258

        >>[ERR:TDcChelseaGpio.cpp] Read():129 GPIO_GetIn() returns error -1! GPIO Port : 259

        >>[ERR:TDcChelseaGpio.cpp] Read():129 GPIO_GetIn() returns error -1! GPIO Port : 260

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 261

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 262

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 1287

~~[SSPF] [FastBoot.cpp] Initialize, [ResetBoard] Thread_ID=0x40cab490 : CREATE
~~[SSPF] [FastBoot.cpp] ResetBoard, Called...
############## Find Factory.dat File in mtd_exe ##################

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 5

        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 5

=== USE BSP RESET ===
~~[SSPF] [FastBoot.cpp] ResetBoard, m_semReset.Give

                FixedId : Nvram[94] vs File[94] 

                WBId : Nvram[70] vs File[70]

                EERId : Nvram[360] vs File[359]
*************EERId is different !!!!!!!!!!! saved[360] new[359]
        
        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 258
       
        >>[ERR:TDsEepromStore.cpp] Write():395 Nvram Write Error...
      
         >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 258
       
        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 258
      
        >>[ERR:TDsEepromStore.cpp] Write():417 Nvram Write Error...
     
        >>[ERR:TDcChelseaGpio.cpp] Write():161 GPIO_SetOut() returns error -1! GPIO Port : 258
          
     FACId : Nvram[89] vs File[89]
=== Chelsea register = 0x27106c0 is CHELSEA2
then go to menu debug, then ctrl + c and find:

Code: Select all

Starting pid 47, console /dev/ttyS1: '/bin/sh'
-sh: id: not found
# sh + x / sbin / usb_start.sh
sh: Can't open x
I do not know what to do at this point. where I'm wrong? is the usb port that does not work anymore? Anyone can help me, thank
sorry for my imperfect English[/off]
Last edited by desperatewife on Mon May 07, 2012 5:57 pm, edited 2 times in total.
User avatar
juusso
SamyGO Moderator
Posts: 10129
Joined: Sun Mar 07, 2010 6:20 pm

Re: Help me! I'm very desperate wife!

Post by juusso »

What about this: (no gaps between charachters!)

Code: Select all

rm -f /mtd_rwarea/PartitionSwitch_1_0
touch /mtd_rwarea/PartitionSwitch_0_0
/mtd_boot/MicomCtrl 143
This activates your previuos firmware. I see you got errors in patcher. SO i suggest to use original not patched firmware, decrypted and dexored.
Your command is wrong, you left free spaces between characters and this is wrong. Right command is:

Code: Select all

sh +x /sbin/usb_start.sh
Could you please attach logs left by FFB? thanks.
LE40B653T5W,UE40D6750,UE65Q8C
Have questions? Read SamyGO Wiki, Search on forum first!
FFB (v0.8), FFB for CI+ . Get root on: C series, D series, E series, F series, H series. rooting K series, exeDSP/exeTV patches[C/D/E/F/H]

DO NOT EVER INSTALL FIRMWARE UPGRADE
desperatewife
Posts: 2
Joined: Sun May 06, 2012 3:16 pm

Re: Help me! I'm very desperate wife!

Post by desperatewife »

Thank you for having responded to me
SO i suggest to use original not patched firmware, decrypted and dexored.
I downloaded a firmware from samygo the 2005 version, but do not know how to decrypted and dexored without patcher.
There are other ways to do this?


What do you mean by
Could you please attach logs left by FFB? thanks.

Unfortunately I'm ignorant on the subject, I follow only the guides and help me with research on google!
User avatar
juusso
SamyGO Moderator
Posts: 10129
Joined: Sun Mar 07, 2010 6:20 pm

Re: Help me! I'm very desperate wife!

Post by juusso »

To decrypt use SamyGO patcher v 0.30 (latest version from svn).
save as SamyGO.py, place script next to the T-CHL7DEUC directory of original extracted from archive firmware and:

Code: Select all

./SamyGO.py decrypt_all ./T-CHL7DEUC
...or...just check PM...


Edit: problem solved over ExLink cable and u-boot.
LE40B653T5W,UE40D6750,UE65Q8C
Have questions? Read SamyGO Wiki, Search on forum first!
FFB (v0.8), FFB for CI+ . Get root on: C series, D series, E series, F series, H series. rooting K series, exeDSP/exeTV patches[C/D/E/F/H]

DO NOT EVER INSTALL FIRMWARE UPGRADE

Post Reply

Return to “[B] Support”