I know that mate - already done it.
I mean how do we get the au fixed. Is it in the nagraromXX.bin files files (I ask because these were re-released last time to get it working I think?).
If it is then how do we edit these to try and get the au fixed? Is it nagra edit?
To fix the AU, you have to patch the nagraromXX.bin. This 'hit' is just like the one last March - I just figured out what its doing myself, and then found someone else had posted it in the main cable section.
You can get the evocamd to dump the emu's pretty easily, and from there you can disassemble the code in EMU Studio. Using that you can figure how how to mod the .bin file - thats where I am stuck - would love to patch the BIN, but I don't know how to.
I tried to do it last March following Coolguy121's posts, but someone else beat me to it! I think this hit is doing the same as last time and using some interrupt setting and jumps to fool the emulator - to fix it, I believe you need to recognise the emu, jump to some free space, run the code to fix the key and then jump back to the address the emu would have jumped to when it completed.
If someone who knows the tools and their way around this stuff wants to start a thread and go through this stuff a step at a time, I am more than willing to learn!
edit: I did search for coolguys posts to try and go through the stuff again, but I couldn't find them - I think they have been deleted!