killed my s10

Status
Please reply by conversation.

xtgold

SatelliteGuys Pro
Original poster
Nov 17, 2008
1,109
13
nutmeg state
I killed my s10 trying to take temp readings on the processor.The probe fell on the mainboard with power on and I killed the I2C bus to the tuner.
Tuner says signal and quality 90% even with no coax connected.The temp was 120 degrees before the mishap.
The firmware then detected the receiver as a clone and did the clone kill even though it was a genuine s10 id 07DE.
 
Why were u doing the reading for?

Sent from my SPH-D710 using Tapatalk
 
The newer the firmware the hotter it runs.
The heatsink on it is too puny for the latest firmwares IMO.
I've had a 12v fan on mine for months now.
If you burn your finger on the heatsink,time for a fan.
 
autopsy report

The clone kill FF's the first 64k of flash and overwrites the next 64k of maincode with 68's.I was able to dump the entire flash with the 2.0.0c loader and load clone safe firmware.A moot point,since the tuner is dead.
This proves you can't brick the s10,since the bootloader was all FF's,firmware was corrupt and I was still able to recover via rs232.
Code:
0000FF00 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF10 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF20 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF30 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF40 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF50 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF60 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF70 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF80 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FF90 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FFA0 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FFB0 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FFC0 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FFD0 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FFE0 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
0000FFF0 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF ................
00010000 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010010 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010020 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010030 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010040 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010050 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010060 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010070 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010080 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010090 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000100A0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000100B0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000100C0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000100D0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000100E0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000100F0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010100 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010110 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010120 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010130 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010140 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010150 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010160 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010170 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010180 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
00010190 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000101A0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000101B0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000101C0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000101D0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000101E0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
000101F0 6868 6868 6868 6868 6868 6868 6868 6868 hhhhhhhhhhhhhhhh
 
Well Ive also had a usb laptop fan on my s10 since i purchased it back in June. Caz these are always hot to begin with with or without newer fw.

Sent from my SPH-D710 using Tapatalk
 
I had a few new CPU fans that were for old 486 machines and I installed them on top of all my box as a preventive measure as other had talked about their boxes getting warm. As all my S10 are on 24/7 and never get turned off and this keeps them all runs real cool to the touch.
 
What on earth did they do to the S10s to make them run so hot? The S9 certainly doesn't do that, and I thought that they were supposed to be almost the same hardware!
 
What on earth did they do to the S10s to make them run so hot? The S9 certainly doesn't do that, and I thought that they were supposed to be almost the same hardware!

Yeap and the S9 seems to be the better model of the Openbox clan.

Sent from my SPH-D710 using Tapatalk
 
Funny,when the s10 was good the only firmware from march 2011 that would boot was the one from the 25th.
Now that the thing is half dead,I was able to boot the 3/14 and 3/21,but the tuner is still dead.
Firmware prior to that the tuner wouldn't work and still doesn't work(I was hoping it might)
Question about the mac address:the info screen shows all zeroes,since the id isn't stored in the lan chip itself(I read the pdf)it must be in an eeprom on the I2C bus with the tuner.I haven't found any eeprom yet,maybe in the tuner?
Maybe some kind soul can disconnect his s10 tuner and see how the receiver reacts via the receiver info screen-if you get all zeroes.Maybe the tuner itself is shot.
 
What on earth did they do to the S10s to make them run so hot? The S9 certainly doesn't do that, and I thought that they were supposed to be almost the same hardware!

if you load old firmware,the processor just runs warm.
 
The AnonymousX clone safe firmware also shows all zeros on the info screen.
What he calls the M3501id is 0000.
The M3501 is the chip on the tuner board.
 
Maybe it depends which factory made which S10 out of what bits and pieces... my s10 case gets warm to the touch but not hot at all, and certainly not as hot as my VS Ex or Ultra could get. No need for a fan. Running October 2011 firmware.
 
Just a wondering question since the firmware came up.
What IS the best firmware to prevent freezing an get good reaction?
I'm running the Euro firmware,and get very occasional freezing,but if there is FW out there that doesn't freeze and have other issues,I'd be happy to try it.
Any my thought of the subject while I was reading the thread is--there is a differance between warm and hot.All electronics can run warm,and some run hot.I work on pinball machines,and some electronics get too hot to touch.Even the processors get very hot.
 
back in the saddle again

I took the tuner out of the s10 but to get it back in I had to take all the screws out and slide the mainboard out.That action fixed the receiver some how so I got it working again knock wood.
Bizarre but educational.Details on info screen are correct and id is back to 07DE.
Fan is back in place over processor.
 
I removed the tuner from the working s10 and fired the receiver up.
The info screen shows all zeroes for info.
I rebooted 3x and got the dreaded "your box is clone version!!!!!!!" and it said copy on receiver front panel.
The next step I replaced the tuner and tried saving the firmware to pc before the kill,but I was too late.
The bootloader and 64k of the maincode already had the FF's and 68's
I reloaded a full good firmware and the receiver ran fine again.
So the tuner has something to do with the info screen,which makes no sense to me unless the tuner connector
is a serial path for the I2C bus back to the processor. 30 pins for a tuner seems to be overkill and the security chip
isn't even on the tuner board and has it's own bus.
 
µp queries tuner, tuner returns data, µp compares data to list. Data is on list- OK, not on list or no data- clone? Would think the clone builders would forge the data or list, but in haste to market, skipped(??)
Thinking again(scary) they must have forged the list, for to run their FW.
In the end- it appears that the clone kill doesn't brick it. As you've resurrected two "killed"(?) boxes.
 
You can buy the tuner from china for $15 so nothing exotic there.The m3501b uses the I2C bus and also has pins called xsda_through and xscl_through which may mean the tuner is just a link in the chain.The security chip has it's own bus,so why it wasn't detected is unknown since it isn't on the tuner..Still unknown is the storage location for mac id,machine and other whatnot on the info screen.Maybe the security chip also has an eeprom section to store that info.
 
µp queries tuner, tuner returns data, µp compares data to list. Data is on list- OK, not on list or no data- clone? Would think the clone builders would forge the data or list, but in haste to market, skipped(??)Thinking again(scary) they must have forged the list, for to run their FW. In the end- it appears that the clone kill doesn't brick it. As you've resurrected two "killed"(?) boxes.
It has been said on other sites you can't brick a m3602 based receiver,I am convinced.You must use the 2.0.0c loader to recover.Older versions and newer versions are useless for that function.
Looks like I bought blank flash chips for nothing.
 
Status
Please reply by conversation.