0x809ED8 - Check for ELF. 0x0 APPSBL ~0x800000 - QCSBL ~0x900000 - OEMSBL FRONT EL PANEL - GPIO_OUT_0 0xA9200800 (Bit 15, Active LOW) SD CARD DETECT - GPIO_IN_2 (0xA9200800 + 0x38) - Bit 8 Write command 0x32 to 0xA0A00000 Write address to 0xA0A00004 Send execute 0x1 to 0xA0A00010 Read data from buffer 0xA0A00100 0x9104ac - already filled memory? (SMI first) 0x008038a8 - after filling (arm11 still frozen) > mww phys 0x11428800 0x1008000 > mdw phys 0x11428800 0x11428800: First APP ID - (0: DEFAULT) 0x1008000 - (1: EM) 0x1007001 - (2: CONFTEST) 0x1A2345F - (3: TECTOY) 0x1070798 - 0x1072195 ?0x101A0FE 0x114287F4: isLockKeyEvent 0x114287F5: SystemMode (00 - Normal, 01 - ?, 02 - ?) MCP: HYH0SQJ0MF3P NAND MCP Flash ID: ad b1 80 55 Olhar TLMM_INT_JTAG_CTL, APPS_ARM_DEBUG_CTL Media Player ClsID - 0x01010EF6 Patch sig! Z-200 @ 0x10d4ea1c MOV r5, #0 B 0x10d4eb1c Patch sig! Z-100 @ 0x10D43C0C MOV r5, #0 B 0x10D43D0C