This tutorial is only for those of you who; lost all of their original and hack nand dumps + erased/corrupted the nand/flash the wrong image to the nand.
If you find yourself in this situation then this tutorial will walk you step by step to make your console boot hack dash again.
Take note that you won't be able to restore your console to retail ever again and you will be unable to use your dvd drive until you extract the key off of it.
Things you will need;
usb spi nand programmer(nand-x, jr-programmer, any will do(eMMC R/W kit for corona 4gb)
J-Runner the ultimate JTAG/RGH app DOWNLOAD
Extracted nand files that match you motherboard model (download below)
Step 1; Recovery of cpu key and LDV's
Download one of the clean extracted donor nand files according to your motherboard model and extract the containing folder to the location of your choice;
Don't use these files to unban your console, first you don't have the original cpu key and second they are all from ban consoles. You have been warned!
Next you need to solder/plug in your nand programmer wires onto the motherboard
Open J-Runner app an click on "show working folder" button located at the bottom right
Open the folder name "data" located inside /J-Runner/xeBuild/ folders
Open your extracted nand files folder and copy and paste KV.bin, SMC.bin, smc_config.bin and fcrt.bin(if required) to data folder. It should look like this.
In J-Runner, copy and paste this cpu key F37C0CD50B928F4E67614ACD548A4E49 in the cpu key section.
Choose dashboard version according your hack type (for JTAG choose 7371 - for phat rgh1 choose 14699 - for R-JTAG choose 15574 - for phat RGH2 choose 14719 - for slim choose anything above 14719)
Select your motherboard nand type.
Select retail as your image type.
It should look like this.
In J-Runner under the Advanced tab click on Create an image without nanddump.bin
Then you will be ask to enter LDV just enter any number between 1 and 80 and click ok.
At this point the dummy image should be successfully created and automatically loaded in the "Load Source" section.
Now with your nand programmer properly connected to both you pc and motherboard click on "Write Nand".
Wait until J-Runner is finish writing the nand and select your "hack type" then click on "Create ECC" for rgh machine or "Create Xell-Reloaded" for JTAG/R-JTAG machine.
Now click on "Write ECC" or "Write Xell-Reloaded" depending on your hack type.
You are now ready to boot xell and recover your cpu key.
Power on your console and wait for xell to boot.
Once xell as booted write down your cpu key, fuseset 02 and fuseset 07
Understanding and calculating LDV's
Calculating CF/CG ldv is fairly simple. Just count the number of "F" in fuseset 07 to fuseset 11. So in the example above we have a cf/cg lock down value of 2.
Calculating CB LDV can be a little bit more trickier. You have to take the right-most "F" and calculate how many character it is from the left. In the example above the right-most "F" is 5 characters from the left so we have a cb lock down value of 5.
Understanding CB LDV; Quote from Martin C @ TX
This value is NOT updated every dashboard version and is not directly reflected in any apps. However, the value can be translated to a CB/dashboard version. You cannot 'edit' your image to use a different CB for a retail NAND. It MUST match the entry as found in XeLL, otherwise it'll fail to boot.
The example above is from a Jasper with a cb ldv cseq of 5 and by looking at the chart below we can determine that dashboard 7371 would be the highest version acceptable for this particular console.
Step 2; Building the fake OG nand image
Now back in J-Runner, enter your cpu key in the cpu key section.
Select your dashboard according to your CB LDV cseq
Select Retail as Image type.
Select Motherboard nand type.
Click on the "Advanced" tab and on "create an image without nanddump.bin"
You will be ask for LDV, this is the cf/cg LDV so you enter what you have in fuseset 07 and click "ok"
You have now created a fake original nand image. Even though you won't be able to boot your console with this image it would still be a good idea to keep it somewhere safe.
With your new image loaded in the "Load Source" section and your cpu key in the "Cpu Key" section click on the "kv info" tab. You will noticed that the info in there are obviously not from your console. So now would be a good time, for those who can, to extract your dvd drive key and patch the key vault with the appropriate dvd key.
Click on the "XB Settings" tab, click on "Advanced XeBuild Options", paste your dvd key in the "dvdkey" section, click "OK" then click the "Use Edited Options" check box.
For DG16D5S and DLN10N owners; the easiest and cheapest way to make your dvd drive functional would be to install a TX LTU 2 pcb.
Final Part; Building/writing your hack image
Back in J-Runner, with your new fake original nand image loaded in the "Load Source" section and cpu key in the "Cpu Key" section select hack image type(Jtag - rgh - rgh2 - r-jtag), select your desired dashboard(should be the latest which is 16537 at the moment of write), select motherboard nand type. You can also edit dashlaunch and xeBuild options at this point.
Click on create xeBuild image. You will see 3 or 4 warning messages poping up which will ask you if you want to delete kv.bin, smc.bin, fcrt.bin and smc_config.bin. Click yes on all of them.
With your nand programmer properly connected to both your console and pc click on "Write Nand"
Boot your console and have fun.