Overview
Encountering a legacy Siemens S5-100U programmable logic controller (PLC) with a lost program and only a USB stick full of files using unknown extensions (such as .BCF, .BK5, .PLC, .UX1, .UXO, .URF, and .XRF) is a common field-engineering scenario. These extensions are not part of the standard STEP5 file-type grammar, and they are not generated by the standard STEP5 programming software, the standard S5-DOS floppy format, or by the standard S5 EPROM programming tools. The most likely explanation is that the original backup was made with a third-party EPROM programmer, a third-party memory-card tool, a CNC or machine-builder proprietary utility, or a different vendor's PLC tool that happens to have used overlapping or coincidental extensions.
This reference documents the standard STEP5 file extension set, the typical backup workflows for the S5-100U, the most plausible sources of the unknown file types, and a layered recovery procedure that starts with the most non-destructive options (extension translation, binary inspection) and ends with manual reconstruction of the program from observation of the running machine.
dd (Linux) or win32diskimager (Windows). Never operate on the original media. Label the copy with the date, the controller, and the machine's serial number.
Siemens S5-100U Hardware Identification
Before any recovery is attempted, confirm the exact controller model. The S5-100U family includes the CPU 100, CPU 102, CPU 103, and the later CPU variants released as 6ES5 1xx-xxxxx series modules. Each CPU has a specific instruction set, memory size, and program-block addressing range:
| CPU Module | Order Number (MLFB) | Program Memory | Data Memory | Scan Time (1 KB bit ops) |
|---|---|---|---|---|
| CPU 100 | 6ES5 100-8MA02 | 2 KB RAM (1 KB statements) | 1 KB | ~10 ms |
| CPU 102 | 6ES5 102-8MA02 | 4 KB RAM | 2 KB | ~6 ms |
| CPU 103 | 6ES5 103-8MA03 | 20 KB RAM | 10 KB | ~1.5 ms |
The label on the CPU module will show the order number. Read it; the recovery path (RAM loadable vs. EPROM-only) depends on the variant. The S5-100U uses a 16-bit internal data bus, supports up to 256 digital inputs and 256 digital outputs through the standard I/O bus, and has a program scan time dominated by bit operations.
Confirm the program is actually missing versus inaccessible:
- Power down, then power up. If the CPU enters RUN, the program is in the working memory and is not lost; only the offline documentation is missing.
- If the CPU enters STOP with the red LED, the working memory is empty. Check for a memory submodule (EPROM, EEPROM, or flash card) in the CPU socket.
- Read the LEDs: BASP (Output disable), STUEB (Stack overflow), ZYK (Cycle), RUN, STOP. Document the pattern. The pattern tells you whether the PLC crashed versus had no program loaded.
Standard STEP5 File Extension Reference
Standard STEP5 (as shipped by Siemens for the PG 605, PG 615, PG 635, PG 685, PG 710, PG 720, PG 730, PG 750, and field PCs running S5-DOS or STEP5 V6.x / V7.x) uses a defined set of file extensions. The following table lists the file types and their meaning. None of the unknown extensions in the source backup set match this canonical set.
| Extension | STEP5 Meaning | Notes |
|---|---|---|
.S5D |
S5 project (cross-block) container | Standard complete-project export; importable into STEP5 via "File → Open" |
.STL |
Statement List (Anweisungsliste) source | Textual representation; importable |
.LAD |
Ladder Diagram (Kontaktplan) source | Graphical ladder representation |
.CSF |
Control System Flowchart (Funktionsplan) | FBD-style representation |
.SEQ |
Sequential function chart (Graph5) | Step/transition representation |
.DB1....DB255
|
Data block source | Number is the DB number |
.OB1....OB255
|
Organization block source | OB1 is the cyclic main block |
.PB1....PB255
|
Program block source | Logical program segmentation |
.FB1....FB255
|
Function block source | Reusable code with parameter interface |
.SB1....SB255
|
Sequence block source | Step blocks for sequential logic |
.FX |
Function block extension header | Combined with .FB for FB documentation |
.DX |
Data block extension header | Combined with .DB for DB documentation |
.IN0/.IN1
|
Symbol table incremental save | STEP5 symbol files |
.BA0/.BA1
|
Assignment list (signal list) | I/Q/M assignment text |
.SCL |
STEP5 → STEP7 conversion helper | Generated by migration tools, not original STEP5 |
Reference: Siemens Industry Online Support — search index "STEP5 manual" or "S5-100U programming manual" (PDF catalog order: 6ES5 998-0PR05).
Analysis of the Unknown File Extensions
The file set on the USB stick contains extensions that do not match the canonical STEP5 set. The most likely origins are listed below in order of probability. The procedure in each case is different; the engineer should work through them in this order to avoid destroying information.
.BCF, .BK5, .PLC
These three extensions are typical of EPROM-programmer file containers and PLC editor output filters from third-party vendors. Common matches:
-
.PLC— generic PLC source-text file. A number of OEMs use.PLCfor their raw program export (sometimes referred to as a "P-Code dump"). -
.BK5— historically used by certain EuroSoft / TISOFT / GraFiCon utilities for a S5-style block container, or by EPROM programmers as a binary-block container. -
.BCF— appears in some Agilent/HP/Philips PROM programmer output variants and certain Adept / Bosch controller exports.
.UX1, .UXO, .URF, .XRF
These four extensions share a common root signature: they look like an obfuscated Uxx / XRxx family. The most plausible match is an EPROM dump captured by a generic device programmer (Data I/O, Hi-Lo, BP, Conitec, Batronix, Xeltek, or Wells-CTI) where the programmer was configured for an EPROM device that matches the size of the S5-100U memory submodule. Common matches:
-
.UX1,.UXO— generic Motorola 2700/2700X-series EPROM image variants. -
.URF— uploader result file (some bootloader/PROM programmer chains save the uploaded buffer under a.URFsuffix). -
.XRF— Motorola S-record variant; on some programmers this is the raw 8-bit binary form of a Motorola S19 record set.
Verify this by opening one of the smaller files in a hex editor (HxD, 010 Editor, or xxd). The first bytes of an EPROM dump should be 0xFF (erased state). The first bytes of a STEP5 block should contain the block header (0x70 for OB, 0x71 for PB, 0x72 for FB, 0x73 for DB) followed by the block number, library number, author, family, and name. A direct match of either pattern confirms the source of the file.
Quick Hex-Based File Identification
Use the following procedure on the read-only copy of the USB stick:
- List the file sizes. The S5-100U program total rarely exceeds 4–20 KB across all blocks. Files larger than 64 KB are almost certainly not the S5 program.
- Open each file in a hex editor. Note the first 16 bytes.
- Match the first bytes against the patterns below:
| File Type | First Bytes (hex) | ASCII |
|---|---|---|
| Erased EPROM | FF FF FF FF FF FF FF FF... |
empty |
| STEP5 OB block | 70 01 00 00 00 00 70 73... |
(non-printable) |
| STEP5 PB block | 71 01 ... |
(non-printable) |
| STEP5 DB block | 73 01 ... |
(non-printable) |
| Intel HEX | 3A xx xx xx xx ... |
: (colon) leading |
| Motorola S-record | 53 xx ... |
S leading |
| Binary (Tek HEX) | 2F ... |
/ leading |
STEP5 Import Attempt Procedure
Even if the extensions are non-standard, the file content may still be a valid STEP5 program in disguise. Proceed with a non-destructive import attempt.
Prerequisites
- A PG or PC with STEP5 V6.x / V7.x installed. The official Siemens STEP5 package is no longer sold, but licenses are still serviced through the Siemens Industry Online Support for customers with active support contracts.
- A programming cable: 6ES5 734-1BD20 (RS-232 TTY to PG serial) for the S5-100U CPU programming port (PG interface on the front of the CPU, pin assignment: 1 = +5V sense, 2, 3, 6, 7, 8 used; pin 4 = enable; pin 5 = ground).
- Alternatively, a modern USB-to-serial adapter (FTDI FT232-based) with a level shifter to 15 mA current loop (the S5-100U uses TTY / 20 mA current loop, not true RS-232).
Step-by-Step Import
- Copy the files from the USB stick onto a working directory on the PG/PC. Preserve the original directory and timestamp.
- Open STEP5 and select File → Open.
- In the file-type filter, set "All files (*.*)" so the non-standard extensions are visible.
- Attempt to open the smallest
.BK5or.BCFfile first. STEP5 will reject it with one of the error codes listed below. - If the import is rejected, repeat with each file in turn.
- For any file STEP5 accepts, immediately save the project as
.S5Din a separate working directory. This produces a standard backup that can be opened in any later STEP5 install.
STEP5 Error Codes Relevant to Non-Standard Files
| Error Code | Meaning | Action |
|---|---|---|
| E 1 | Drive/path not found | Verify the path; the file is not the issue. |
| E 19 | Block header check failed | Header bytes do not match STEP5 expected values — confirms non-standard format. |
| E 30 | File is read-only | Remove read-only attribute and retry. |
| E 75 | Block type not recognized | File is a block, but the type field is not in the S5 grammar. |
| E 142 | File is not a STEP5 file | Confirms non-STEP5 origin. Re-classify the file by content. |
Recovery via EPROM Dump Conversion
If the hex inspection shows an erased EPROM header pattern (0xFF fill) or a recognizable binary image, the file is likely a raw EPROM dump from a memory submodule. The S5-100U uses submodules of 2 KB, 4 KB, 8 KB, or 16 KB. The matching EPROM types are 2716, 2732, 2764, 27128, and 27256.
EPROM Dump to STEP5 Block Conversion
- Identify the EPROM type by the dump size:
| Dump Size | Likely EPROM | Memory Submodule S5-100U |
|---|---|---|
| 2 KB (2048 bytes) | 2716 | 6ES5 375-0LC11 (early CPU 100/102) |
| 4 KB (4096 bytes) | 2732 | 6ES5 375-0LD11 |
| 8 KB (8192 bytes) | 2764 | 6ES5 375-0LA15 / 6ES5 375-1LA15 |
| 16 KB (16384 bytes) | 27128 | 6ES5 375-0LB15 |
| 32 KB (32768 bytes) | 27256 | CPU 103 series |
- Open the dump in the EPROM programmer software. Save it as Intel HEX (
.HEX) or Motorola S-record (.S19). - Run the Intel HEX file through the Siemens STEP5 EPROM upload tool (if available) or use a generic STEP5 import filter.
- The upload tool will populate the block list automatically. The block headers (0x70 / 0x71 / 0x72 / 0x73 prefixes) inside the EPROM image guide the parser.
- Verify each block by opening it in STEP5 and checking the STL/LAD view for sanity.
Serial Communication (PG ↔ S5-100U) Direct Recovery
If the program is in the CPU working memory and the CPU is in RUN, a "Read PLC" (PG function) will lift the program directly. If the CPU is in STOP, a "Read PLC" will still retrieve whatever is in working memory. This procedure does not require the USB stick at all — it gets the program from the controller.
Connection Setup
- CPU port: 15-pin D-sub on the front of the CPU. Use the Siemens PG cable (6ES5 734-1BD20) or build a 15-pin to DB9 cable per the Siemens pinout.
- Baud: 9600 baud (default for S5-100U AS511 protocol).
- Protocol: AS511 (Siemens proprietary PG protocol over the current loop).
- PG software: STEP5 → Online → Connect to PLC.
Procedure
- Power up the S5-100U. Note the LED status (RUN, STOP, BASP).
- Insert the PG cable into the CPU's programming port.
- On the PG, start STEP5. Online → Online Functions → Read PLC.
- STEP5 will handshake over AS511 and report the CPU type, memory size, and any active error.
- Read all blocks: OB, PB, FB, DB, SB, FX, DX. Use Online → Read Block with block range 0–255 for each type.
- Save the project as
.S5Dimmediately. This is your working backup.
Manual Reconstruction from Running Machine
If all other recovery paths fail, the only option is to reverse-engineer the program by observing the machine. This is the longest path and should be reserved for machines that are operational but undocumented.
Step 1 — I/O Inventory
- Identify every input and output module (6ES5 4xx-xA series digital and 6ES5 4xx-xC series analog). Note slot position and I/O address range.
- Force each output off, then on, using STEP5 Online → Force / Set. Document which physical terminal lights up or which actuator responds.
- Build an
.BA0assignment list with each address mapped to its physical function (e.g.,I 0.0 = "Conveyor start PB",Q 2.5 = "Vacuum valve K3").
Step 2 — Sequence Capture
- Run the machine through its operating cycle under Status / Single Step mode in STEP5.
- Use Online → Status Block on OB1. The PG will display live signal states and accumulator values.
- Capture each transition (start button, limit switch, timer done, count reached) and the resulting output action.
Step 3 — Block Authoring
- Author OB1 (cyclic main) to call PB1 (manual mode), PB2 (auto mode), and PB3 (fault handling) by default.
- Author each PB as a ladder or STL equivalent of the captured sequence.
- Author DBs for setpoints, timers, and counters. The S5-100U supports timers T 0–T 31 and counters C 0–C 31; flag bytes are FW 0–FW 254 (or as large as the CPU supports).
Step 4 — Verification
- Download the new project to a memory submodule (EPROM/EEPROM) and into the CPU.
- Cold-restart the CPU (power down, insert submodule, power up).
- Test under Single Step with a programmer monitoring each block.
- Run a complete production cycle and confirm identical behavior to the pre-failure state.
Preventing Future Program Loss
Once the program is recovered, lock in the backup so the situation never recurs.
- Save the STEP5 project as
.S5Don at least three media: the engineering laptop, a USB stick in a fireproof safe, and a network share with version control (Git, Subversion, or even a structured folder with date-stamped subfolders). - Export the program to an EPROM/EEPROM submodule and install it in the CPU socket. The submodule acts as a "gold master" that survives a CPU battery failure.
- Document the project's external I/O assignment (
.BA0), symbol table (.IN0/.IN1), and any HMI tag mapping in a PDF stored with the program. - For long-term supportability, consider migrating the S5 program to a SIMATIC S7-300 or S7-1500 using the Siemens S5 → S7 conversion tool. Note that the S5-100U's small instruction set and limited addressing make most S5-100U programs convertible to S7-1200 with only minor syntax edits.
Verification Checklist
| Step | Verification | Pass Criterion |
|---|---|---|
| Identify CPU | Read MLFB label on module | Matches CPU 100/102/103 documentation |
| Hex inspection | Open all unknown files in hex editor | Pattern identified (STEP5, EPROM, S-record, or vendor-specific) |
| STEP5 import attempt | File → Open with *.* filter | One or more blocks successfully imported, or all rejected with documented error codes |
| PG online read | Online → Read PLC, save as .S5D | OB1, PB1..n, DB1..n, FB1..n present and non-empty |
| Block integrity | Open each block in STL view; check for valid opcodes | Each block contains valid STEP5 statements; no ??? or empty bodies |
| Live test | Run machine in single-step and auto mode | Cycle behavior matches pre-failure observations |
| Gold-master EPROM | Burn EPROM submodule, install in CPU, cold-restart | CPU enters RUN with program loaded |
| Backup redundancy | Verify .S5D on three separate media | Three independent media each contain identical project |
Troubleshooting Matrix
| Symptom | Likely Cause | Resolution |
|---|---|---|
| STEP5 rejects all .BCF/.BK5/.PLC files with E 142 | Files are not in STEP5 format | Run hex inspection; identify the underlying format; convert or extract blocks |
| PG cannot connect to CPU | Wrong cable (RS-232 vs. current loop), wrong baud, port disabled | Use Siemens PG cable 6ES5 734-1BD20; verify 9600 baud; check AS511 protocol selected |
| CPU enters STOP with red STUEB LED | Stack overflow or no program loaded | If a submodule is present, ensure EPROM is correctly oriented; clear and re-load |
| Hex dump shows all 0xFF | EPROM is erased; no program to recover | Confirm with PG online read; if CPU is empty, plan for manual reconstruction |
| Hex dump shows STEP5 block headers but file extension is non-standard | Third-party export of a valid STEP5 binary | Rename to .S5D and try STEP5 import; if it fails, manually slice the file at block-header boundaries (0x70/0x71/0x72/0x73) and re-import |
| Files open in another vendor's PLC tool | Misidentification of PLC; original PLC is not S5-100U | Verify the actual controller; re-evaluate the recovery plan against the correct vendor's documentation |
Frequently Asked Questions
What are the standard STEP5 file extensions?
The canonical STEP5 extensions are .S5D (full project), .STL (statement list), .LAD (ladder), .CSF (function chart), .SEQ (sequential), and block-numbered files like .OB1, .PB1, .FB1, .DB1, .SB1. Extensions like .BCF, .BK5, .UX1, .URF, and .XRF are not standard STEP5 formats and most likely come from a third-party EPROM programmer or a non-Siemens PLC tool.
Can STEP5 read a file with a non-standard extension?
Yes — set the file-type filter in STEP5's File → Open dialog to All files (*.*) and select the file. If the underlying content is valid STEP5 block data, STEP5 will import it regardless of extension. If the content is not STEP5, STEP5 returns error E 142 ("file is not a STEP5 file") and the file must be re-classified or re-converted.
How do I connect a modern PC to an S5-100U serial port?
The S5-100U uses a 20 mA current-loop interface, not RS-232. Use a Siemens PG with a native current-loop port, a USB-to-current-loop adapter (ACCON-S5-LAN or IBH-Link S5 plus), or build a current-loop adapter from a USB-FTDI module and a pair of 24 V optocouplers. The protocol is Siemens AS511 at 9600 baud by default; STEP5 handles the handshake automatically under Online → Connect to PLC.
What if the CPU still has the program in working memory?
Connect with STEP5 and use Online → Read PLC (or Online → Read Block for each block) to lift the program from the CPU and save it as a .S5D project on the PG. This is the fastest and most reliable recovery path and does not require the USB stick backup at all.
Is there a free tool to read an EPROM dump from a Siemens memory submodule?
Yes — a generic EPROM programmer software (such as the open-source minipro tool by Sylvain Munaut, or commercial packages from Data I/O, Conitec, Batronix, or Xeltek) can read the submodule. The trick is selecting the correct EPROM type (2716, 2732, 2764, 27128, or 27256) to match the physical submodule. After the read, the dump is usually a binary blob; it must be uploaded back into STEP5 via the EPROM-to-project utility to regenerate the individual OB, PB, FB, and DB block files.
Why is the program in .UX1 format when the CPU is Siemens?
Most likely the backup was made with a generic EPROM programmer rather than with STEP5 itself. The UX1/UXO/URF/.XRF extensions are typical of generic programmer output for a 27xxx-series EPROM, and the dump contains the raw bytes that were on the memory submodule. Convert the dump to Intel HEX or STEP5 block format using the EPROM programmer's export function, then re-import into STEP5.