Hardware Nintendo Switch Won't Turn

  • Thread starter Thread starter K1ck09
  • Start date Start date
  • Views Views 5,999
  • Replies Replies 24

K1ck09

Active Member
Newcomer
Joined
Jan 29, 2019
Messages
25
Reaction score
1
Trophies
0
Age
27
XP
239
Country
Portugal
Hello Guys,

I have been following this forum for a couple of weeks and now I need your help.

I bought a Nintendo switch that doesn't turn on. I saw in a couple of threads, to check pin 5 of M92T36 and on that pin I get 3.3v. The battery charges because when I got this console I checked the voltage of the battery at the red cable and it was 2.6v, I connected my charger and let it charger for 30 min, and after that I checked again and it was 3.7v. I checked for shorts to ground on the board and found nothing. I asked on reddit and people there said to change the M92T36. I don't know my console version, if it's jailbreak or not, I don't know anything. For purpose tests only I made a paperclip jumper to get it to RCM mode and after a few seconds the switch got to RCM Mode(in device manager appeared APX device). What can be??? Is there a way to check if the lcd is good???

P.S.: My charger is a Samsung 5v/2A usb C.

EDIT: On pin 6 of m92t36 I get 3.3v

EDIT 2: Leaving the console with the battery plugged in, it doesnt drain the battery, only if I press the power button

Best Regards.
 
Last edited by K1ck09,
If the chip is damaged no point of pushing a payload, perhaps good idea to asks @mattytrog
I bought a new m92t36 so if it ends up to be that chip, I can replace it quickly. Anyways I want to know for sure that the m92t36 is bad before changing it, because if its working I will return the new one.
 
Last edited by K1ck09,
Hello Guys,

I have been following this forum for a couple of weeks and now I need your help.

I bought a Nintendo switch that doesn't turn on. I saw in a couple of threads, to check pin 5 of M92T36 and on that pin I get 3.3v. The battery charges because when I got this console I checked the voltage of the battery at the red cable and it was 2.6v, I connected my charger and let it charger for 30 min, and after that I checked again and it was 3.7v. I checked for shorts to ground on the board and found nothing. I asked on reddit and people there said to change the M92T36. I don't know my console version, if it's jailbreak or not, I don't know anything. For purpose tests only I made a paperclip jumper to get it to RCM mode and after a few seconds the switch got to RCM Mode(in device manager appeared APX device). What can be??? Is there a way to check if the lcd is good???

P.S.: My charger is a Samsung 5v/2A usb C.

EDIT: On pin 6 of m92t36 I get 3.3v

EDIT 2: Leaving the console with the battery plugged in, it doesnt drain the battery, only if I press the power button

Best Regards.
OK... You are getting 3v on pin 5 & pin 6 of M92T36? Good.

You are getting into APX mode... Good.

What happened when you tried to send the payload?

Is the backlight connected?
Please check the pins in the LCD connector.

If all is good, the LCD connector being the main one to check, then your problem should lie in BQ24193.
 
OK... You are getting 3v on pin 5 & pin 6 of M92T36? Good.

You are getting into APX mode... Good.

What happened when you tried to send the payload?

Is the backlight connected?
Please check the pins in the LCD connector.

If all is good, the LCD connector being the main one to check, then your problem should lie in BQ24193.

I didn't tried to sent a payload. What payload should I try? Should I connect the sd card reader to the board?

I don't know what is the backlight ribbon cable but I have all cables connected.

The pins on the LCD Connector look good.

BQ24193 is responsible for?
 
I didn't tried to sent a payload. What payload should I try? Should I connect the sd card reader to the board?

I don't know what is the backlight ribbon cable but I have all cables connected.

The pins on the LCD Connector look good.

BQ24193 is responsible for?
Battery charging. If APX is there, try Hekate. SD not important at this stage.
 
Anything happening with the console at all?
Any backlight?

Nope. All black

--------------------- MERGED ---------------------------

Anything happening with the console at all?
Any backlight?

Ok I changed the USB Port and tried again and know the payload was injected successfully. On switch shows a menu, what should I select there?
 
Nope. All black

--------------------- MERGED ---------------------------



Ok I changed the USB Port and tried again and know the payload was injected successfully. On switch shows a menu, what should I select there?
launch
 
"Initializing..."

"Identified pkg1 ('20181107105733')"
"Keyblob version 6"

"Loaded pkg1 and keyblob"

and nothing more happened.
Hmmm...

OK the next step is to get your BIS keys,make sure your PRODINFO is intact (to check you haven`t purchased a pikabricked unit) and rebuild NAND. 20181107105733 is FW 6.2. Go into hekate, look under console info and see what fuses you have that are burnt
 
Can't turn your Switch on, huh? Looks like you've lost your Mo Jo!
Guess it's time to go out and find you a new one.
 
  • Like
Reactions: K1ck09
Hmmm...

OK the next step is to get your BIS keys,make sure your PRODINFO is intact (to check you haven`t purchased a pikabricked unit) and rebuild NAND. 20181107105733 is FW 6.2. Go into hekate, look under console info and see what fuses you have that are burnt

8 burnt fuses. The rest that you said I'm not sure how to do it.

EDIT: I went to eMMC info and PRODINFO is green and has a size oh 3MiB
 
Last edited by K1ck09,
Hmmm...

OK the next step is to get your BIS keys,make sure your PRODINFO is intact (to check you haven`t purchased a pikabricked unit) and rebuild NAND. 20181107105733 is FW 6.2. Go into hekate, look under console info and see what fuses you have that are burnt

What should I do next?
 
8 burnt fuses. The rest that you said I'm not sure how to do it.

EDIT: I went to eMMC info and PRODINFO is green and has a size oh 3MiB
OK. It is quite involved. There is a thread how to do it... However, you need to downgrade to 6.1.

Take a look here.

https://gbatemp.net/threads/how-to-...nofficially-without-burning-any-fuses.507461/

But first, you need to get your BIS keys
What should I do next?

OK...

Now you need to do the following... I`m going to be brief as there are tuts on this site...

1) You need to get your BIS keys... Use BISKeydump... Use a QR code reader and email the keys to yourself.

2) You need memloader and the sample files. Run memloader and you need the emmc.ini (this allows access from USB to your emmc)

3) You need Hacdiskmount... You then need to mount your switch (UMS LINUX disk) in hacdiskmount and check your key entropy is good (this means the keys are correct that you emailed to yourself)

4) There will be a partition called PRODINFO. You need to dump this using hacdiskmount and you keys that you emailed to yourself.

5) Have a look at prodinfo in a hex editor... If you see CAL0 at the start, you can assume it is good.

5a) If you see 8008580085 or whatever repeated, you have a pikabricked unit and is only usable for parts sadly. Unless a PRODINFO bypass gets developed.

I know it is information overload. Don`t try to take it all in in one night. Take your time.
 
OK. It is quite involved. There is a thread how to do it... However, you need to downgrade to 6.1.

Take a look here.

https://gbatemp.net/threads/how-to-...nofficially-without-burning-any-fuses.507461/

But first, you need to get your BIS keys


OK...

Now you need to do the following... I`m going to be brief as there are tuts on this site...

1) You need to get your BIS keys... Use BISKeydump... Use a QR code reader and email the keys to yourself.

2) You need memloader and the sample files. Run memloader and you need the emmc.ini (this allows access from USB to your emmc)

3) You need Hacdiskmount... You then need to mount your switch (UMS LINUX disk) in hacdiskmount and check your key entropy is good (this means the keys are correct that you emailed to yourself)

4) There will be a partition called PRODINFO. You need to dump this using hacdiskmount and you keys that you emailed to yourself.

5) Have a look at prodinfo in a hex editor... If you see CAL0 at the start, you can assume it is good.

5a) If you see 8008580085 or whatever repeated, you have a pikabricked unit and is only usable for parts sadly. Unless a PRODINFO bypass gets developed.

I know it is information overload. Don`t try to take it all in in one night. Take your time.

Payload memloader using tegraRCMSmash "TegraRcmSmash.exe memloader.bin --dataini=sample\ums_emmc.ini" and if I'm correct its suppose to appear a new disk drive on windows, nothing, but on nintendo screen says:

Failed to mount SD Card, switching to USB command mode...
Attempting to communicate with USB host... try 1 (last retVal 0 xfer'd 0 bytes)
RECV 0x00000056 bytes -> 0xB0110000
RECV 0x0006e13f bytes -> 0xB0110000
BOOT section 'RCM'
pc=0xB0110000
[MTC] Switching 20400 kHz -> 408000 kHz
[MTC] Switching 408000kHz -> 665600kHz
[MTC] Switching 665600kHz -> 800000kHz

And just stops here.
 
Payload memloader using tegraRCMSmash "TegraRcmSmash.exe memloader.bin --dataini=sample\ums_emmc.ini" and if I'm correct its suppose to appear a new disk drive on windows, nothing, but on nintendo screen says:

Failed to mount SD Card, switching to USB command mode...
Attempting to communicate with USB host... try 1 (last retVal 0 xfer'd 0 bytes)
RECV 0x00000056 bytes -> 0xB0110000
RECV 0x0006e13f bytes -> 0xB0110000
BOOT section 'RCM'
pc=0xB0110000
[MTC] Switching 20400 kHz -> 408000 kHz
[MTC] Switching 408000kHz -> 665600kHz
[MTC] Switching 665600kHz -> 800000kHz

And just stops here.
Yes you need the ini files in your SD card.

Look in memloader download in "sample" folder. Copy all these ini files to root of SD card, place in sdwitch and try again. Screen will go black when succeeded.
 
Yes you need the ini files in your SD card.

Look in memloader download in "sample" folder. Copy all these ini files to root of SD card, place in sdwitch and try again. Screen will go black when succeeded.

I forgot the sd card reader board that attaches to the console at my office... No other solution?

--------------------- MERGED ---------------------------

Yes you need the ini files in your SD card.

Look in memloader download in "sample" folder. Copy all these ini files to root of SD card, place in sdwitch and try again. Screen will go black when succeeded.
I get this text on console:

TegraRcmSmash (64bit) 1.2.1-3 by rajkosto
Unknown key 'pwroffHoldTime' for BOOT section on line 12, skipping
Opened USB device path \\?\usb#vid_0955&pid_7321#5&11eef136&0&8#{3342fc77-77e2-4b16-b8d4-a05f5e186236}
RCM Device with id 400107190000001400532C6401101062 initialized successfully!
Uploading payload (mezzo size: 92, user size: 124720, total size: 190936, total padded size: 192512)...
Smashing the stack!
Smashed the stack with a 0x7000 byte SETUP request!
Switching to command mode due to READY.
Sending C:\Users\Bruno\Downloads\TegraRcmSmash1213\x64\sample\uboot/ums_emmc.scr.img (86 bytes) to address 0x80100000
Sending C:\Users\Bruno\Downloads\TegraRcmSmash1213\x64\sample\uboot/u-boot.elf (450879 bytes) to address 0x80110000
Booting AArch64 with PC 0x80110000...
BOOT command sent successfully! Exiting.

On the readme files says that I can copy the files to the microsd card or send them by USB usign TegraRCMSmash
 

Site & Scene News

Popular threads in this forum