Eeprom Impresora
Eeprom Impresora
Eeprom Impresora
CrumProg
Conception
This project is the development of non-professionals. It spreads in condition "as is"
and the authors are not liable for any loss directly or indirectly connected with its
use. Concept of the Resetter is the following: a payment is made only once, and you
get only the features that are at the time of the purchase. If the software of the
Resetter will be updated and a new features will be added, you get them for free as
a bonus. Since the programs are not written by professionals, we can not guarantee
the program will work on all operating systems and all computers, but we constantly
improve them. To check the compatibility of our product with your computer, please
download and run the program. If the program is started without any errors, then
everything will work. The authors have no way to check the work of the Resetter on
a printer, and that is why we can not guarantee that we will teach you to reset
chips for using them in printers. We only provide you the tool to work with the
chips. It is assumed that you know how to modify the data in the chip for this
particular printer. However, our experience and your achievements allow us to add
specific instructions on resetting the printer and dumps of their chips. The Crum
Prog does not guarantee a support of emulators (compatible chips). We only
guarantee reprogramming of emulators of our production or those emulators, which
are stated as supported.
System requirements
To run the program You need to install NET Framework 4.0 or higher. You can
download it from the manufacturer site http://www.microsoft.com/ru-ru/download/details.aspx?id=17851
The program was tested and it runs on the following operating systems:
Windows XP 32 -64
Windows Vista 32 -64
Windows 7 32 -64
Windows 8.1 64
To check the compatibility with your operating system version, please download the
program and run it on your computer BEFORE purchasing our device. The program
is compact and does not require any installation. If the program starts without an
error, the device will run on your computer.
By GenaAlfa
www.resetkits.lv
1 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
2 56
04/2015
CrumProg
The device connects to a free USB 3.0/2.0/1.0 port and is recognized by the
computer as a Human Interface Device (HID) class. Such devices as a keyboard,
mouse, joysticks and other devices of communication of the computer and person
also belongs to HID class devices. Any Windows version contains all necessary
drivers for connection of any HID device. The present Resetter does not require any
special drivers to work with Windows.
After connecting the device to the computer, Windows finds the drivers and the
device is ready for work.
Each device has its own serial number, which You can see in a program window and
device manager. This serial number is linked with a licence file. A name of the file
can't be changed, the program will look for the license file on serial number and the
file name. It is possible to keep licenses from several Resetters in the folder and the
program will find the necessary. There is a complete list of all current and future
chips in the file of the license by default. When buying a Resetter you can buy a
specific list of concrete chips (economy version) and expand the list of the chips by
getting another license file later.
By GenaAlfa
www.resetkits.lv
3 56
04/2015
CrumProg
4
6
1
5
By GenaAlfa
www.resetkits.lv
4 56
04/2015
CrumProg
Hex editor
5
4
3
6
By GenaAlfa
www.resetkits.lv
5 56
04/2015
CrumProg
Tabs
There is an opportunity to set up a number of tabs for convenient work with dumps in
a program. 15 tabs are the maximum quantity of tabs. The system tab is always
added automatically and is used for recording the system messages.
Tabs with dumps
Each tab saves the selected chip model and code page. After activating any tab and
clicking Read, Save and Check button the Resetter will take an action with the
chip from this tab. Only one tab can be active at the same time. If the system tab is
selected than the last selected tab will be the active. An active tab is indicated in the
status bar (1). An active tab becomes visible by clicking on the symbol of the active
tab (1). Drag-and-drop function of a mouse works at tabs. It is possible to activate
the necessary tab and to drag the required file in it.
System tab
The system tab displays messages for the user. Also these messages parallely are
written in a log file (ErrorsLog.txt) of the programm`s directory for problem analysis.
The right mouse button functions (shortcut menu) do not work in a system tab, but
the text from it can be copied by a shortcut of Ctrl-C and the text can be pasted by
Ctrl-V combination.
The text inserted that way is not transferred to a log file. There are 3 types of text in
a system tab which differ on color.
Black text mean standard operation and serve for information.
Red text mean critical errors because of which it wasn't possible to perform the
specified operation.
Texts of other colors (there is only blue so far) mean warnings about any not
compliances or automatic actions. No corrections are required in case of these texts.
If a record in a system tab differs from black color, the program automatically
transfers focus to a system tab to pay attention of the user to warning. The active tab
to which this warning works, still remains active and its name is shown in a status
bar (1).
By GenaAlfa
www.resetkits.lv
6 56
04/2015
CrumProg
Some chips have more than one region of memory. The basic region of memory
that is displayed in the tabs of dumps of the program is called EEPROM memory
(Electrically Erasable Programmable Read-Only Memory). The main work with the
chip memory is carried out in this region. However chips with difficult algorithms of
access have additional regions of memory, such as Configuration of the chip
(Configuration Mermory), serial numbers, authorization data, passwords,
administrative areas of memory, one-time programmable areas of memory (OTP)
and others.
If the knowledge of contents in these areas of memory can be useful for the user,
the Resetter can show additional regions of memory from this chip. Additional
regions of memory are displayed in additional windows (a picture). Information in
these areas is for information only and can not be edited or rewritten into the chip.
Additional windows are closed themselves when next reading/writing the chip.
Saving a data from additional windows isn't provided. If the user wants to save this
information, the shortcut menu works in additional windows. The dump can be
selected and copied in another tab and then save the tab in the file.
It is possible to turn off the popups of additional windows in the setup file of the
Program CrumProg.ini
By GenaAlfa
www.resetkits.lv
7 56
04/2015
CrumProg
Bus scan
1
2
4
3
Bus scanning (search of the address of the chip by searching of all possible
addresses) can be started either by pressing a button (1) or automatically in this
Programmer. A procedure of automatic search of the chip runs in the case when no
chip was selected on the active tab and one of control buttons of the Resetter
"Read", "Write" or "Compare" is pressed.The range of scanned addresses(00 -255)
is presented in hexadecimal 0x00-0xFF way in the Resetter. The scan result will be
showed in the System Tab (2), thus the System Tab will be activated. The active
tab (3), which the scanning was made for, will be marked on the Status Bar.
Clicking on the name of the dump on the status bar (3), an active tab opens.
If the found address (or some addresses) uniquely identify a specific supported
chip, this chip is automatically selected in the active tab (4).
Some chips can't be identified by the found addresses, then it is necessary to
select a model of the chip manually. For example 24s02, X-01, 24s512 and
Kyocera chips may have the same address on 0hA0 bus. If the automatic choice
sets 24c02 chip, instead of H-01, then H-01 chip will be permanently damaged. If
You select 24c02 chip instead of 24512, then 24c512 chip won't be read
completely. Thus an automatic choice will set the H-01 chip in order not to damage
anything. If this choice differs from the type of your chip, select the type manually,
based on the given-out addresses of scanning and on the surface of the chip.
Scanning will have a result for the chips with I2C protocol only, accordingly all the
chips with another protocol (for example 1-Wire) can not be recognized by the
program. If you are sure that the chip is I2C, but its address was not identified by
scanning, it is likely that there is a problem with connecting the chip.
By GenaAlfa
www.resetkits.lv
8 56
04/2015
CrumProg
Comparing
There are two types of comparing the dumps at the moment:
1. Comparing a dump in a programm and a dump in a chip,
2. Comparing a dump in a programm and a dump from the file
By GenaAlfa
www.resetkits.lv
9 56
04/2015
CrumProg
For comparing an active dump with a file it is necessary to open a tab with a dump
which You want to compare, then open the System Tab and drag a file for
comparing there. Or to click File/Compare in the menu of the program and to
specify a path to the file for comparing. The names of the files which were
compared and the differences between them (1) will be written in a System Tab
after comparing process. An active dump is specified on the Status Bar (2). If You
open an active tab, the differences (3) will be highlighted there.
By GenaAlfa
www.resetkits.lv
10 56
04/2015
CrumProg
Installing updates
By GenaAlfa
www.resetkits.lv
11 56
04/2015
CrumProg
3.3v Rx ->
3.3v Tx <GND
Printer
CrumProg
Tx
Rx
Rx
Tx
GND
GND
Jumpers
Tx
By GenaAlfa
www.resetkits.lv
Rx
GND
12 56
04/2015
CrumProg
Debug (UART)
1
In some cases it is useful to connect to the printer through the service connector on
the motherboard of the printer (formatter). This connection is required in a case
when the printer stops connecting (communicate) throuh USB. In this case, the
processor of the printer continues to communicate with the programmer via the
service connector for debugging CPU microcode. This connector on the printer is
called "DEBUG" or "TERMINAL". Some printers provide service jumpers for
DEBUG connection with the processor. As a part of this manual, we do not give
their location, but acquaint with their possible presence.
Connection to the processor is at "low level", it means that the connected has full
access to all processes of the printer without any "protection against the fool". All
your actions will be immediately accepted to execution and they can't be cancelled.
Having such rights, you can easily damage something in the printer and You won't
always even note what exactly killed the printer.
We don't give the description what exactly it is necessary to do with the printer
through this connection to it, we just give You the tool for this connection. All
responsibility for consequences of Your actions lays down on You. Connection is
made through 3 wires: "TX", "RX" and "GND". Voltage levels are already
coordinated for connection to 3.3 V formatter (check how many volt is applied to the
chip of the cartridge, and it will be the voltage of the formatter, but I think that all the
printers have 3.3 V).
To enter DEBUG mode press Mode/Debug in the programm. Resetter will change
USB settings of connections after that and the programm stops to see the
hardware. LED on the resetter will start blinking another way. There will be a new
device COM-X port in Device Manager of the computer, where X is a free COM
number. Maybe it will be necessary to specify a path to the driver (is applied) in
Windows. To exit the DEBUG mode it is necessary to disconnect the Resetter from
USB and to connect it again. When connecting the Resetter it always starts in a
Resetter mode.
I choosed quite a good programm (Terminal) to work with DEBUG. I will shortly
describe a work with it below.
By GenaAlfa
www.resetkits.lv
13 56
04/2015
CrumProg
Terminal
4
7
6
Before you run the Terminal program, make sure that the Resetter passed into the
DEBUG mode and the LED on a board blinks rare short flashouts. Also make sure
that the computer connected all necessary drivers (it can be made in Hardware
Manager) and computer has an additional COM port (I do not describe it cause it is a
standart procedure).
After starting the program choose a number of Your COM port in a window (1). If
you run the program earlier than the computer set drivers, press ReScan (2) button
and the program will revise the list of the connected ports. After that make necessary
installations of the port for connection to the printer, they are shown on the picture
(3). When everything is ready press the Connect button (4). If the port is connected
successfully, the Connect button will change on Disconnect (4).
I didn't connect the printer but just connected two wires on the Resetter TX and RX
together for this demonstration. Resetter received the sent messages. You can do
so to check a work of DEBUG mode also. After You made all the settings and
connected a port, connect a printer to power supply. The printer will give out some
message lines in a window (5) (there is no messages in my example cause the
printer isn't connected). Printer will ask You to send any symbol to the port within a
second, so be ready for it. If You don`t send the symbol, the printer will load a
firmware and won`t enter the DEBUG mode. The required symbol (most likely any
symbol) should be entered into a field (6) for sending and to send it using button (7).
Enter a symbol in advance (before connecting the printer), otherwise You will not
have time to send it in a set time. If the printer accepts a symbol from You, it will give
out some more lines in a window (5) and will confirm readiness to accept commands
of control from You. Try to enter the help command, as it is shown in an example
(6). The printer will give You out the system of commands in reply. Shortly it is
everything.
By GenaAlfa
www.resetkits.lv
14 56
04/2015
CrumProg
File formats
1
1
The program can work with three file formats: *.hex, *.bin, *.e2p. Files of other
formats can also be opened in the program for their editing, but files of other
formats are loaded as a binary array and will be stored in the same form. Files of
other formats cannot be a source for writing in the chip. If, however, you wish to use
these files to write to the chip, then copy the part of the file from its tab to the tab, in
which your chip is selected (copy/paste).
The main file format of this programmer is the format *.hex. If you do not specify a
different file extension, the program will save files as *.hex.
The format *.e2p by the company http://www.lancos.com also stores information
about the type of the chip selected. If you save the file in this format, the next time
you open the file, the chip type will be selected automatically (1). Other formats do
not contain data on the type of the chip selected.
To save the file in a format other than *.hex, select in the program menu File/Save
As and the file type to be saved.
By GenaAlfa
www.resetkits.lv
15 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
16 56
04/2015
CrumProg
24Cxxx. Connection
Vcc
DAT
CLK
WP, GND
A0, A1, A2
A0
A1
A2
GND
A0
A1
A2
GND
Vcc
WP
CLK
DAT
Vcc
WP
CLK
DAT
24
Chips in this series consist entirely of EEPROM memory. You can change their
memory as you like. Addressing these chips on the bus i2c may vary from 0xA0 to
0xAE. The exact address of the chip depends on two factors: the model of the chip
and connected address pins of the chip. One chip responds only to two adjacent
addresses simultaneously - even and not even (A0 and A1 or A2 and A3, etc.).
By GenaAlfa
www.resetkits.lv
Vcc
DAT
CLK
GND
GND
CLK
DAT
Vcc
AT88SC0204C(A). Connection
17 56
04/2015
CrumProg
88SC0204
1
2
3
1
2
By GenaAlfa
www.resetkits.lv
18 56
04/2015
CrumProg
88SC0204
Chips in this series are protected by cryptography. In the chip there are two
memory zones: data zone and the zone of the chip configuration. In the
configuration zone the information on the chip is stored, which serves for the correct
operation of the chip. This programmer does not modify the configuration zone of
the chip, but can read it for users information. The printer stores its information in
the data zone of the chip. To access the data zone, the chip is required to provide
the correct passwords. Different printers have different passwords in their chips,
thats why it is important to select the correct printer model from the list of these
chips. Every attempt to read the chip with unfamiliar passwords reduces the counter
of incorrect login attempts. Totally it is possible to make 7 attempts to read the chip
with incorrect passwords before the chip is locked. The programmer has a function
of reading the chip without passwords. In so doing, only the configuration zone (1)
is read from the chip, in which you can keep track of login attempts counters (3), or
other service information. You can find information about the chip from the
manufacturer here: www.atmel.com/Images/doc8664.pdf . Dont toy with
passwords. No need to press Read several times if the data does not open
perhaps this password is from another CRUM. Remember that the incorrect
password counters are ticking... The programmer has only one protection against
counters it does not allow you to use the last password. The last attempt will
never be used. If the counter (3) reaches the penultimate attempt (you will see an
error message), you should insert the CRUM back into the printer and turn on. The
printer will enter the correct password and the counter will reset. You can read the
counter values in the mode "Read Without Present Of Passwords (Safe Mode)" in
the configuration zone (1). Counters can only have these values ($FF, $FE, $FC,
$F8, $F0, $E0, $C0, $80, $00). FF number of attempts not spent, 00 - the chip is
locked dead. Just 7 attempts, and the chip is locked up.
By GenaAlfa
www.resetkits.lv
19 56
04/2015
CrumProg
88SC0204
Printers Xerox-3600 and Xerox-3635 have the OTP zone, which is stored as the
number 0x56 at 0x20 in the configuration zone (2). If the programmer meets this
configuration in the chip, before attempting to write to the OTP zone it will make an
automatic attempt to reset the protection, whereby the programmer will store the
value 0x57 at 0x20 (2). Lock removing can be successful only to the original chips.
If, after entry into the chip the value 0x56 does not vary to 0x57, then the attempt to
reset the protection failed. Unsuccessful attempt to reset the protection means that
the chip is not original.
Unlike other printers, Xerox 3635 remembers the last 10 serial CRUM numbers (1)
(the exact number is not known), and the printer remembers the additional marker
in the firmware (2). To reset the chip in this printer you need to change the serial
number (1) and change the marker (2). The serial number may have only numerical
values (in the right part of the editor) and the marker may have any values from 0 to
9 (in the left side of the editor).
By GenaAlfa
www.resetkits.lv
20 56
04/2015
CrumProg
By GenaAlfa
GND
CLK
Vcc
DAT
GND
CLK
DAT
Vcc
Vcc
DAT
CLK
GND
www.resetkits.lv
21 56
04/2015
CrumProg
S3CC912, S3CC921
Chip address space is divided into two zones - EEPROM (1) and OTP (2).
EEPROM zone is located at the addresses from 00h to FFh. In the original chips
this area can be changed as you like, and in this zone there are main counters that
must be reset. Multiple reading and writing of data is possible. It should be noted
that the memory area from C0 to FF still has not been used in printers, and it
contains different data in different chips, so we advise to leave this zone
unchanged. Perhaps in this zone there are the keys or data that will be used by
next versions of printer firmware.
OTP (One Time Programmable) zone is located at the addresses 100h - 17Fh. It
is an area for a single programming. It is readable, but it is available as a singly
programmable. This means that the entry of any byte is possible only to memory
cells which contain the value 0xFF. In this block there are mostly constants:
CRUM-number, capacity and type of cartridge, release date and more. This area
also has several important singly programmed data. They are the flag Exhaust
toner (0x14C), the flag to ignore toner Clear toner (0x14D), 16-byte field
Progress Bar (0x160-0x16F). Flags are initially equal 0xFF, and upon activation
of flags the printer usually writes the number "01". The field Progress Bar in the
new cartridge contains 0x10 byte with the value 0xFF.
By GenaAlfa
www.resetkits.lv
22 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
23 56
04/2015
CrumProg
Solution: just as in the case of the progress bar, it is also possible to occupy this
byte earlier than the printer will do it. If you store a value other than 01 (e.g. store
00) in it, the printer will never be able to change your value to 01 and the chip will
not be locked.
Region lock of the chip is just as important. Each printer has a regional anchor.
The cartridge bought in China (region CHN) will not work in the printer from
Latvia (region EUR). When exchanging chips from another printer, check the
coincidence of chips region locks.
S3CC921 series supports the following cartridges:
MLT-D103: Samsung ML-2950/2951/2955, SCX-4727/4728/4729
MLT-D104: Samsung ML-1660/1665/1667, SCX-3200/3205/3207/3217
MLT-D105: Samsung ML-1910/1915/2525/2580, SCX-4600/4623, SF-650
MLT-D106: Samsung ML-2245
MLT-D108: Samsung ML-1640/1641/1645/2240/2241
MLT-D109: Samsung SCX-4300
MLT-D205: Samsung ML-3310/3710, SCX-4833/5637
MLT-D209: Samsung ML-2855, SCX-4824/4828
CLT-407: Samsung CLP-320/325, CLX-3185
CLT-409: Samsung CLP-310/315, CLX-3170/3175
CLT-508: Samsung CLP-620/670, CLX-6220/6250
CLT-609: Samsung CLP-770
Xerox3140/3155/3160
Xerox WC 3210/3220
Xerox WC 3550 05/2014
By GenaAlfa
www.resetkits.lv
24 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
25 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
26 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
27 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
28 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
29 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
30 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
31 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
32 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
33 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
34 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
35 56
04/2015
CrumProg
By GenaAlfa
www.resetkits.lv
36 56
04/2015
CrumProg
Xerox 3140/3155/3160
By GenaAlfa
www.resetkits.lv
37 56
04/2015
CrumProg
Xerox WC 3210/3220
By GenaAlfa
www.resetkits.lv
38 56
04/2015
CrumProg
Xerox WC 3550
By GenaAlfa
www.resetkits.lv
39 56
04/2015
CrumProg
A0
A1
A2
GND
By GenaAlfa
Vcc
Vpp
CLK
DAT
A0
A1
A2
GND
www.resetkits.lv
Vcc
Vpp
CLK
DAT
40 56
04/2015
CrumProg
"Secret" zone
zone
Xerox-01 (XC-01) chips use I2C data-exchange protocol and have an address on
the bus 0xA0 0xAE depending on cartridge color. In general, their protocol is fully
conformant 24C02 chips, but an attempt to read/write this chip as 24C02 will
destroy it. The chip XC-01 is damaged as a consequence of attempts to access to
its "Secret" zone. "Secret" supposedly is bytes of chip configuration and their
reading/change is not acceptable. Never try to read the chip XC-01 in the menu
24Cxx. Also the chip XC-01 has the OTP zone. To change the data in this area you
should connect the programmers Vpp pin to the 7th pin of the chip. A high-voltage
synchronous writing pulse is formed on this pin during writing in the OTP zone. If
the Vpp pin is not connected, then the entry in the OTP zone is not possible. The
rest of the chip memory is occupied by conventional EEPROM memory.
By GenaAlfa
www.resetkits.lv
41 56
04/2015
CrumProg
Vcc
DAT
SCL
GND
By GenaAlfa
www.resetkits.lv
Gnd
Vcc
Clk
Dat
Supported
Supported
DAT
Vcc
Not supported
CLK
GND
DAT
CLK
Vcc
GND
42 56
04/2015
CrumProg
"Secret" zone
32-bit zone.
EEPROM
ROM
By GenaAlfa
www.resetkits.lv
43 56
04/2015
CrumProg
"Secret" zone. In this area nothing is stored and nothing from there can be read. If
you fill in the dump with the values in this area, the programmer will display an error
when checking.
OTP zone. This zone is organized as 7 32-bit numbers with the Little-endian
sequence of bytes. This means that in the 32-bit number the leftmost byte is LSB,
and the rightmost - Senior. If in the dump we see 65 43 21 00, this sequence
corresponds to a 32-bit number 0x00214365. The arithmetic OTP zone is made
according to the rules of availability of change of a smaller number to the bigger
one. If we have the number 0x00214365 stored, it can be replaced by 0x00214366
or 0x05214365 and cannot be replaced by 0x00214364 or 0x00114365.
EEPROM zone changes whatever you like.
ROM zone is programmed once at the factory and is not altered in any way.
Due to the presence of OTP and ROM zones in the original chip, this chip cannot
be reset. However, many manufacturers of emulators do not protect their
chips by OTP zones and the chips can be reset. Below are photos of known chip
and the possibility to reset them.
6 - black
0 - yellow
2 - magenta
4 - cyan
EE - black
E8 - yellow
EA - magenta
EC - cyan
By GenaAlfa
www.resetkits.lv
44 56
04/2015
CrumProg
93Cxx. Connection
PE, Vcc
DI
CS
ORG
DO
CLK
GND
standart
CS
CLK
DI
DO
By GenaAlfa
Vcc
PE
ORG
GND
PE
Vcc
CS
CLK
turned
1
www.resetkits.lv
ORG
GND
DO
DI
DO
GND
DI
Vcc
CS
CLK
45 56
04/2015
CrumProg
93
These chips utilize the Microwire communication protocol and are connected via
four-wire. Also, some chips have an additional pin for switch between 8-bit and 16bit memory organization. The choice of the proper memory organization is a reason
of major difficulty in work with this series of chips.
Memory organization can be either fixed or has an additional output to select
between the two organizations, 8-bit and 16-bit. Organization of the chip can be
found only in the documentation for a particular chip. The difference between 8-bit
and 16-bit organization lies in a method of obtaining data from the chip. When 8-bit
organization, the chip will output 1 byte of information at a time, when 16-bit
organization - 2 bytes. Accordingly, communication protocols are different for
different organizations and if make the wrong choice, you will get distorted data.
Even if the chip supports switching of memory organization, physical data can be
stored in different memory cells, and they (the data) are assembled from memory
and glued in the chip just before sending to the bus. For example, the chip HOLTEK
HT93LC46 stores the even bytes in the Upper Memory Area, and odd ones in the
LMA. After writing to it in the 16-bit mode, when reading the chip as an 8-bit, you'll
get a valid set of bytes, but all of them will be scattered in the memory in a different
order. For this reason, all of the chips must be read exactly in the mode in which
they were written, even those chips that support both types of organization. Chip
protocols do not allow you to find out chip organization through the data exchange,
the organization must be chosen on ones own and not to be mistaken with it. What
to do if you do not have documentation on the chip and no way to know the
organization? My advice is: read the chip 2 times by different organizations and
save the data in two files. Then write any value in the first two memory cells by both
ways and check what is written in the chip. If you are right with the choice of
organization, the chip will store your data, if not, it will write garbage or will not write
anything. Do not forget to remove the wrong file of the two saved ones and do not
forget to restore the data that you messed with the trial record.
The second issue, on which there is also controversy, is the issue of placement of
bytes in a 16-bit word. There are two ways to display the 16-bit word in the editor:
1. The LSB of the word occupies the Low Memory Address (Little-endian) (the
number 0x1234 will be stored in the memory as 0x34 0x12),
2. The leftmost digit of the word occupies the left position in the dump (Big-endian)
(the number 0x1234 will be stored as 0x12 0x34). The format of number storage in
memory is not chosen by the programmer, but by the controller which used this chip
and stored the data in it.
By GenaAlfa
www.resetkits.lv
46 56
04/2015
CrumProg
That is, in whatever way I display the bytes in a word, this method would be correct
for one chip and incorrect for another. Moreover, chips themselves confuse this
issue. Some chips store in one way, the other chips in the other (e.g. a Microchip
will store the word in the format Little-endian, and an Atmel in the format Bigendian). As you can see there are quite many questions and we have to get used to
the confusion in these chips. Most (in my opinion) controllers use Little-endian
format, and I will display bytes in the word this way. Connecting chip also has a few
options. More often we see the Standard variant of connection, rarely - Rotated.
Connectivity option can be found in the documentation. Chip and programmer
protection against wrong connection is implemented in the programmer. As with
any electronic device protection, I would not advise testing for strength. Always
make sure the correct connection. If you cannot find the wiring diagram in the
documentation, you can check with the tester. In the regime of diode examination
you can find the pin of the chip GND, the protection diodes of all communication
pins and power output will be tested for continuity to this pin. The most powerful
diode with the lowest voltage of the opening (smaller numbers on the tester) will be
installed on the power output. Some chips have an additional pin PE (Program
Enable). If the chip has this pin, it should be connected to Vcc pin, then the storage
will be available. Unlike 24Cxx series chips, manufacturers do not allow to leave PE
pin on the series chips 93Cxx without connection. Bus scan to search for this chip is
not possible. When working with this chip it must be selected manually.
By GenaAlfa
www.resetkits.lv
47 56
04/2015
CrumProg
DAT
GND
GND
DAT
DAT
GND
By GenaAlfa
www.resetkits.lv
48 56
04/2015
CrumProg
DALLAS has developed a 1-wire communication bus. Chips utilizing 1-wire protocol
are connected by two (GND, DAT) or three (GND Vcc, DAT) wires. If the chip is
connected by two wires, the power is supplied into the chip on a communication wire.
Support for these chips is strongly dependent on the particular configuration of the
chip. Not all configuration options were added to the support list of the programmer.
At the moment, the programmer works only with chips DSQ8, DS2431 and DS2432.
Chip model and a storage method are determined automatically by the code of chip
series and configuration. 1-wire chips are divided into families. Family`s number is
stored in the chip area Lasered ROM. The code of the chip is also stored in this area.
This code is unique for each chip. Lasered ROM chip area is not in shared memory
of the chip, but it has a special cell for storage. For this reason, Lasered ROM is
displayed in a separate window as information for the user. At the moment, the
programmer does not have a function to change the password and configuration In
DS2432 chip to protect the chip from accidental lock up.
By GenaAlfa
www.resetkits.lv
49 56
04/2015
CrumProg
Please note that the connection of the chip has changed in this version and an
extra jumper to the pin of the Programmer is required.
Usually, the memory of the chip (0x00 0x7F) changes regardless of the state of
the protection bit (0x80 - 0x88). If Your chip is not resetted on the second try, Your
chip is one of the difficult resetted (it is about 10%) and requires special actions for
its resetting.
We offer not do it and just to throw them out, but if You do need to reset them, we
suggest to apply actions that will increase the chances of success. We do not
advise by e-mail any details on the use of these actions and limit our advice to this
instruction only.
So if the locked DSQ8 chip (address 0x80 = 55 AA 00 00 55 00 00 A5) is not
resetted immediately, the following measures will help to reset it:
- a short wire from the chip to the programmer (max 20cm).
- Do not connect any measuring instruments to the contact of the chip during the
operation. A frequency up to 8 MHz is applied to the chip and an interference from
the equipment is possible.
-freeze the chip (using spray) to -30c and write data during slow defrost. Repeat the
freezing if necessary (I have resetted all the chips after the first frost).
- Resetting data (0x00-0x7F address) and configuration (0x80 0x8F) use different
resetting algorithms. Try to reset both of them.
-for resetting the configuration, start with 0x84 address, it will speed up the process
of resetting the rest of the configuration.
- do not try to change the Manufacturer Code (0x8E - 0x8F), it is impossible to
restore it, but some printers checks it.
- programmer spends max 8 seconds on each reset byte, then the process is
considered as unsuccessful and requires a change in the paragraphs told above. If
you change just a lot of bytes at once in the dump, the process will be delayed. If
You wish to stop the process, You have to distort USB cable of the programmer.
- After you have successfully resetted the configuration, do not rush to restore the
protection in the configuration. Maybe a printer does not check it and the next reset
will be faster.
By GenaAlfa
www.resetkits.lv
50 56
04/2015
CrumProg
Kyocera. Connection
Vcc
DAT
SCL
GND
By GenaAlfa
www.resetkits.lv
51 56
04/2015
CrumProg
2
1
pages counter (1) and the toner counter (2) are equal to zero in the reset status. In
attempt to reset the OEM chip, it will be damaged! Don't change the counters
in OEM chips!
Only some emulators are supported. OEM chips are not supported!
Communication with the chip on I2C bus with A0 AF address.
The chip has several numbered areas of memory. The most simple and useless
EEPROM memory can be read and written, but there is no useful data in it that can
be changed and it would help to achieve at least something.
Another memory area - OTP contains counters (8 pieces). Any entry in this field will
lead to an increase of the value of the counter. That is why when trying to write
zeros to the counter of the original chip, it will be increased to a maximum value
and will stop on it, as a result - chip will be damaged. However, the emulator does
not have a stop at the maximum value and "will go on the second circle", reaching
zero. It is not yet known what emulators are supported.
Writing to ROM area is not realized at all in the Resetter.
By GenaAlfa
www.resetkits.lv
52 56
04/2015
CrumProg
3x 1N4148
linc
Chip -
By GenaAlfa
www.resetkits.lv
Chip +
53 56
04/2015
CrumProg
Guarantees
There are no guarantees. Each programmer is tested before sale on all kinds of
chips. If something stops working, then we give technical advice via e-mail. If it is
not possible to solve the problem through the e-mail, then you send us the
programmer and we solve the problem on the spot. If it is ascertained our problem
and it cannot be solved by simple replacing of cheap parts, the repair will be free.
If for any reason the replace of the controller is required, the device is recognized
as fully unrecoverable, however, if we are able to read the serial number from the
old controller (for example, if the port of the controller is damaged, but the core still
works), we will replace the controller for the price of the controller. All shipment
both ways is at the expense of the user.
Independent production
For those who want to produce their own programmer, you need to buy a
programmed controller from us. We do not send kits "do it yourself", we just sell
the controller with firmware to everyone.
By GenaAlfa
www.resetkits.lv
54 56
04/2015
CrumProg
Dump transfer
Report on execution
Updatable block of
program memory
Hardware control
The cryptography
of update.
Read commands
Transferring parameters
and commands in the
reading chips block
Write commands
USB
By GenaAlfa
www.resetkits.lv
55 56
04/2015
CrumProg
R13 10k
3.3v
ICSP CLK
ICSP DAT
R11 10k
ICSP MCLR
Crum
Connector
Vpp Target
Vdd Target
SDA Target
SCL Target
5.0v
D1 BAS16
L1 680uH
R14 1k
R20 100
R12 330
R16 2.2k
R19 10k
Extension
connector
For chop with
more pins
www.resetkits.lv
C4 1uf
C9-C11 0.1x20
USB Mini
C2 16pf
Usb DUsb D+
Usb Vcc
Usb GND
5.0v
5.0v
R1 100
R10 2.2k
2-1
2-2
2-3
R21 1k
Q4 BC817-40
3.3v
3.3v
Q1 BC817-40
Q2 BC817-40
By GenaAlfa
GND
OSCO
OSCI
Vdd
Usb D+
Usb DVusb
Vbus
RF3
48
47
46
45
44
43
42
41
40
39
38
37
36
35
34
33
Vdd Target
R8-R9 2.2k
R18 10k
Vpp Target
R15 10k
R6-R7 68
C8 10x25
PIC24FJ256GB106
GND
Vdd
PGEC3
PGED3
AN3 Vpp Feedback
RP13 Vpp Pump
RB1 Vpp On
RB0 Vpp Gnd
Vout
Gnd
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
R17 100k
3 En
SDA Target
SCL Target
Q3 BC807-40
3.3v
ICSP CLK
ICSP DAT
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
3.3v
1-5
1-4
1-3
1-2
1-1
3.3v
Vin
C3 1uf
SPX5205M5-3.3
En
5.0v
C7 10uf
3.3v
LED
Vcc
DD+
NC
GND
Vdd Target
C6 1uf
GND
Vdd
RB12
RB13
RB14 RP14
RB15 AN15 Vdd Target Feedback
RF4 SDA2 RP10
RF5 SCL2 RP17
Gnd
ICSP MCLR
Vout
R2-R4 68
R5 2.2k
3-5
3-4
3-3
3-2
3-1
Vin
64
63
62
61
60
59
58
ENVREG 57
Vcap 56
55
54
53
52
51
50
49
In-circuit serial
programming
AVdd
AVss
C5 1uf
3.3v
R22 1
5.0v
SPX5205M5-3.3
Programmer circuit
top
top
56 56