Siemens S5-100U Program Recovery from Unknown Backup File

David Krause15 min read
PLC HardwareSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Encountering a legacy Siemens S5-100U programmable logic controller (PLC) with a lost program and only a USB stick full of files using unknown extensions (such as .BCF, .BK5, .PLC, .UX1, .UXO, .URF, and .XRF) is a common field-engineering scenario. These extensions are not part of the standard STEP5 file-type grammar, and they are not generated by the standard STEP5 programming software, the standard S5-DOS floppy format, or by the standard S5 EPROM programming tools. The most likely explanation is that the original backup was made with a third-party EPROM programmer, a third-party memory-card tool, a CNC or machine-builder proprietary utility, or a different vendor's PLC tool that happens to have used overlapping or coincidental extensions.

This reference documents the standard STEP5 file extension set, the typical backup workflows for the S5-100U, the most plausible sources of the unknown file types, and a layered recovery procedure that starts with the most non-destructive options (extension translation, binary inspection) and ends with manual reconstruction of the program from observation of the running machine.

Critical: Before performing any action, make a complete bit-for-bit copy of the USB stick using a tool such as dd (Linux) or win32diskimager (Windows). Never operate on the original media. Label the copy with the date, the controller, and the machine's serial number.

Siemens S5-100U Hardware Identification

Before any recovery is attempted, confirm the exact controller model. The S5-100U family includes the CPU 100, CPU 102, CPU 103, and the later CPU variants released as 6ES5 1xx-xxxxx series modules. Each CPU has a specific instruction set, memory size, and program-block addressing range:

CPU Module Order Number (MLFB) Program Memory Data Memory Scan Time (1 KB bit ops)
CPU 100 6ES5 100-8MA02 2 KB RAM (1 KB statements) 1 KB ~10 ms
CPU 102 6ES5 102-8MA02 4 KB RAM 2 KB ~6 ms
CPU 103 6ES5 103-8MA03 20 KB RAM 10 KB ~1.5 ms

The label on the CPU module will show the order number. Read it; the recovery path (RAM loadable vs. EPROM-only) depends on the variant. The S5-100U uses a 16-bit internal data bus, supports up to 256 digital inputs and 256 digital outputs through the standard I/O bus, and has a program scan time dominated by bit operations.

Confirm the program is actually missing versus inaccessible:

  1. Power down, then power up. If the CPU enters RUN, the program is in the working memory and is not lost; only the offline documentation is missing.
  2. If the CPU enters STOP with the red LED, the working memory is empty. Check for a memory submodule (EPROM, EEPROM, or flash card) in the CPU socket.
  3. Read the LEDs: BASP (Output disable), STUEB (Stack overflow), ZYK (Cycle), RUN, STOP. Document the pattern. The pattern tells you whether the PLC crashed versus had no program loaded.

Standard STEP5 File Extension Reference

Standard STEP5 (as shipped by Siemens for the PG 605, PG 615, PG 635, PG 685, PG 710, PG 720, PG 730, PG 750, and field PCs running S5-DOS or STEP5 V6.x / V7.x) uses a defined set of file extensions. The following table lists the file types and their meaning. None of the unknown extensions in the source backup set match this canonical set.

Extension STEP5 Meaning Notes
.S5D S5 project (cross-block) container Standard complete-project export; importable into STEP5 via "File → Open"
.STL Statement List (Anweisungsliste) source Textual representation; importable
.LAD Ladder Diagram (Kontaktplan) source Graphical ladder representation
.CSF Control System Flowchart (Funktionsplan) FBD-style representation
.SEQ Sequential function chart (Graph5) Step/transition representation
.DB1....DB255 Data block source Number is the DB number
.OB1....OB255 Organization block source OB1 is the cyclic main block
.PB1....PB255 Program block source Logical program segmentation
.FB1....FB255 Function block source Reusable code with parameter interface
.SB1....SB255 Sequence block source Step blocks for sequential logic
.FX Function block extension header Combined with .FB for FB documentation
.DX Data block extension header Combined with .DB for DB documentation
.IN0/.IN1 Symbol table incremental save STEP5 symbol files
.BA0/.BA1 Assignment list (signal list) I/Q/M assignment text
.SCL STEP5 → STEP7 conversion helper Generated by migration tools, not original STEP5

Reference: Siemens Industry Online Support — search index "STEP5 manual" or "S5-100U programming manual" (PDF catalog order: 6ES5 998-0PR05).

Analysis of the Unknown File Extensions

The file set on the USB stick contains extensions that do not match the canonical STEP5 set. The most likely origins are listed below in order of probability. The procedure in each case is different; the engineer should work through them in this order to avoid destroying information.

.BCF, .BK5, .PLC

These three extensions are typical of EPROM-programmer file containers and PLC editor output filters from third-party vendors. Common matches:

  • .PLC — generic PLC source-text file. A number of OEMs use .PLC for their raw program export (sometimes referred to as a "P-Code dump").
  • .BK5 — historically used by certain EuroSoft / TISOFT / GraFiCon utilities for a S5-style block container, or by EPROM programmers as a binary-block container.
  • .BCF — appears in some Agilent/HP/Philips PROM programmer output variants and certain Adept / Bosch controller exports.

.UX1, .UXO, .URF, .XRF

These four extensions share a common root signature: they look like an obfuscated Uxx / XRxx family. The most plausible match is an EPROM dump captured by a generic device programmer (Data I/O, Hi-Lo, BP, Conitec, Batronix, Xeltek, or Wells-CTI) where the programmer was configured for an EPROM device that matches the size of the S5-100U memory submodule. Common matches:

  • .UX1, .UXO — generic Motorola 2700/2700X-series EPROM image variants.
  • .URF — uploader result file (some bootloader/PROM programmer chains save the uploaded buffer under a .URF suffix).
  • .XRF — Motorola S-record variant; on some programmers this is the raw 8-bit binary form of a Motorola S19 record set.

Verify this by opening one of the smaller files in a hex editor (HxD, 010 Editor, or xxd). The first bytes of an EPROM dump should be 0xFF (erased state). The first bytes of a STEP5 block should contain the block header (0x70 for OB, 0x71 for PB, 0x72 for FB, 0x73 for DB) followed by the block number, library number, author, family, and name. A direct match of either pattern confirms the source of the file.

Quick Hex-Based File Identification

Use the following procedure on the read-only copy of the USB stick:

  1. List the file sizes. The S5-100U program total rarely exceeds 4–20 KB across all blocks. Files larger than 64 KB are almost certainly not the S5 program.
  2. Open each file in a hex editor. Note the first 16 bytes.
  3. Match the first bytes against the patterns below:
File Type First Bytes (hex) ASCII
Erased EPROM FF FF FF FF FF FF FF FF... empty
STEP5 OB block 70 01 00 00 00 00 70 73... (non-printable)
STEP5 PB block 71 01 ... (non-printable)
STEP5 DB block 73 01 ... (non-printable)
Intel HEX 3A xx xx xx xx ... : (colon) leading
Motorola S-record 53 xx ... S leading
Binary (Tek HEX) 2F ... / leading

STEP5 Import Attempt Procedure

Even if the extensions are non-standard, the file content may still be a valid STEP5 program in disguise. Proceed with a non-destructive import attempt.

Prerequisites

  • A PG or PC with STEP5 V6.x / V7.x installed. The official Siemens STEP5 package is no longer sold, but licenses are still serviced through the Siemens Industry Online Support for customers with active support contracts.
  • A programming cable: 6ES5 734-1BD20 (RS-232 TTY to PG serial) for the S5-100U CPU programming port (PG interface on the front of the CPU, pin assignment: 1 = +5V sense, 2, 3, 6, 7, 8 used; pin 4 = enable; pin 5 = ground).
  • Alternatively, a modern USB-to-serial adapter (FTDI FT232-based) with a level shifter to 15 mA current loop (the S5-100U uses TTY / 20 mA current loop, not true RS-232).

Step-by-Step Import

  1. Copy the files from the USB stick onto a working directory on the PG/PC. Preserve the original directory and timestamp.
  2. Open STEP5 and select File → Open.
  3. In the file-type filter, set "All files (*.*)" so the non-standard extensions are visible.
  4. Attempt to open the smallest .BK5 or .BCF file first. STEP5 will reject it with one of the error codes listed below.
  5. If the import is rejected, repeat with each file in turn.
  6. For any file STEP5 accepts, immediately save the project as .S5D in a separate working directory. This produces a standard backup that can be opened in any later STEP5 install.

STEP5 Error Codes Relevant to Non-Standard Files

Error Code Meaning Action
E 1 Drive/path not found Verify the path; the file is not the issue.
E 19 Block header check failed Header bytes do not match STEP5 expected values — confirms non-standard format.
E 30 File is read-only Remove read-only attribute and retry.
E 75 Block type not recognized File is a block, but the type field is not in the S5 grammar.
E 142 File is not a STEP5 file Confirms non-STEP5 origin. Re-classify the file by content.

Recovery via EPROM Dump Conversion

If the hex inspection shows an erased EPROM header pattern (0xFF fill) or a recognizable binary image, the file is likely a raw EPROM dump from a memory submodule. The S5-100U uses submodules of 2 KB, 4 KB, 8 KB, or 16 KB. The matching EPROM types are 2716, 2732, 2764, 27128, and 27256.

EPROM Dump to STEP5 Block Conversion

  1. Identify the EPROM type by the dump size:
Dump Size Likely EPROM Memory Submodule S5-100U
2 KB (2048 bytes) 2716 6ES5 375-0LC11 (early CPU 100/102)
4 KB (4096 bytes) 2732 6ES5 375-0LD11
8 KB (8192 bytes) 2764 6ES5 375-0LA15 / 6ES5 375-1LA15
16 KB (16384 bytes) 27128 6ES5 375-0LB15
32 KB (32768 bytes) 27256 CPU 103 series
  1. Open the dump in the EPROM programmer software. Save it as Intel HEX (.HEX) or Motorola S-record (.S19).
  2. Run the Intel HEX file through the Siemens STEP5 EPROM upload tool (if available) or use a generic STEP5 import filter.
  3. The upload tool will populate the block list automatically. The block headers (0x70 / 0x71 / 0x72 / 0x73 prefixes) inside the EPROM image guide the parser.
  4. Verify each block by opening it in STEP5 and checking the STL/LAD view for sanity.

Serial Communication (PG ↔ S5-100U) Direct Recovery

If the program is in the CPU working memory and the CPU is in RUN, a "Read PLC" (PG function) will lift the program directly. If the CPU is in STOP, a "Read PLC" will still retrieve whatever is in working memory. This procedure does not require the USB stick at all — it gets the program from the controller.

Connection Setup

  • CPU port: 15-pin D-sub on the front of the CPU. Use the Siemens PG cable (6ES5 734-1BD20) or build a 15-pin to DB9 cable per the Siemens pinout.
  • Baud: 9600 baud (default for S5-100U AS511 protocol).
  • Protocol: AS511 (Siemens proprietary PG protocol over the current loop).
  • PG software: STEP5 → Online → Connect to PLC.

Procedure

  1. Power up the S5-100U. Note the LED status (RUN, STOP, BASP).
  2. Insert the PG cable into the CPU's programming port.
  3. On the PG, start STEP5. Online → Online Functions → Read PLC.
  4. STEP5 will handshake over AS511 and report the CPU type, memory size, and any active error.
  5. Read all blocks: OB, PB, FB, DB, SB, FX, DX. Use Online → Read Block with block range 0–255 for each type.
  6. Save the project as .S5D immediately. This is your working backup.
Caution: The S5-100U's serial interface is a 20 mA current loop, not RS-232. A direct DB-9 to DB-9 cable with a voltage-based serial port will not work. You must use either a Siemens PG with a native current-loop port, or a USB-to-current-loop adapter such as the ACCON-S5-LAN or the IBH-Link S5 plus, or build a current-loop adapter using a USB-FTDI module and a pair of optocouplers with 24 V loop supply.

Manual Reconstruction from Running Machine

If all other recovery paths fail, the only option is to reverse-engineer the program by observing the machine. This is the longest path and should be reserved for machines that are operational but undocumented.

Step 1 — I/O Inventory

  1. Identify every input and output module (6ES5 4xx-xA series digital and 6ES5 4xx-xC series analog). Note slot position and I/O address range.
  2. Force each output off, then on, using STEP5 Online → Force / Set. Document which physical terminal lights up or which actuator responds.
  3. Build an .BA0 assignment list with each address mapped to its physical function (e.g., I 0.0 = "Conveyor start PB", Q 2.5 = "Vacuum valve K3").

Step 2 — Sequence Capture

  1. Run the machine through its operating cycle under Status / Single Step mode in STEP5.
  2. Use Online → Status Block on OB1. The PG will display live signal states and accumulator values.
  3. Capture each transition (start button, limit switch, timer done, count reached) and the resulting output action.

Step 3 — Block Authoring

  1. Author OB1 (cyclic main) to call PB1 (manual mode), PB2 (auto mode), and PB3 (fault handling) by default.
  2. Author each PB as a ladder or STL equivalent of the captured sequence.
  3. Author DBs for setpoints, timers, and counters. The S5-100U supports timers T 0–T 31 and counters C 0–C 31; flag bytes are FW 0–FW 254 (or as large as the CPU supports).

Step 4 — Verification

  1. Download the new project to a memory submodule (EPROM/EEPROM) and into the CPU.
  2. Cold-restart the CPU (power down, insert submodule, power up).
  3. Test under Single Step with a programmer monitoring each block.
  4. Run a complete production cycle and confirm identical behavior to the pre-failure state.

Preventing Future Program Loss

Once the program is recovered, lock in the backup so the situation never recurs.

  • Save the STEP5 project as .S5D on at least three media: the engineering laptop, a USB stick in a fireproof safe, and a network share with version control (Git, Subversion, or even a structured folder with date-stamped subfolders).
  • Export the program to an EPROM/EEPROM submodule and install it in the CPU socket. The submodule acts as a "gold master" that survives a CPU battery failure.
  • Document the project's external I/O assignment (.BA0), symbol table (.IN0/.IN1), and any HMI tag mapping in a PDF stored with the program.
  • For long-term supportability, consider migrating the S5 program to a SIMATIC S7-300 or S7-1500 using the Siemens S5 → S7 conversion tool. Note that the S5-100U's small instruction set and limited addressing make most S5-100U programs convertible to S7-1200 with only minor syntax edits.

Verification Checklist

Step Verification Pass Criterion
Identify CPU Read MLFB label on module Matches CPU 100/102/103 documentation
Hex inspection Open all unknown files in hex editor Pattern identified (STEP5, EPROM, S-record, or vendor-specific)
STEP5 import attempt File → Open with *.* filter One or more blocks successfully imported, or all rejected with documented error codes
PG online read Online → Read PLC, save as .S5D OB1, PB1..n, DB1..n, FB1..n present and non-empty
Block integrity Open each block in STL view; check for valid opcodes Each block contains valid STEP5 statements; no ??? or empty bodies
Live test Run machine in single-step and auto mode Cycle behavior matches pre-failure observations
Gold-master EPROM Burn EPROM submodule, install in CPU, cold-restart CPU enters RUN with program loaded
Backup redundancy Verify .S5D on three separate media Three independent media each contain identical project

Troubleshooting Matrix

Symptom Likely Cause Resolution
STEP5 rejects all .BCF/.BK5/.PLC files with E 142 Files are not in STEP5 format Run hex inspection; identify the underlying format; convert or extract blocks
PG cannot connect to CPU Wrong cable (RS-232 vs. current loop), wrong baud, port disabled Use Siemens PG cable 6ES5 734-1BD20; verify 9600 baud; check AS511 protocol selected
CPU enters STOP with red STUEB LED Stack overflow or no program loaded If a submodule is present, ensure EPROM is correctly oriented; clear and re-load
Hex dump shows all 0xFF EPROM is erased; no program to recover Confirm with PG online read; if CPU is empty, plan for manual reconstruction
Hex dump shows STEP5 block headers but file extension is non-standard Third-party export of a valid STEP5 binary Rename to .S5D and try STEP5 import; if it fails, manually slice the file at block-header boundaries (0x70/0x71/0x72/0x73) and re-import
Files open in another vendor's PLC tool Misidentification of PLC; original PLC is not S5-100U Verify the actual controller; re-evaluate the recovery plan against the correct vendor's documentation

Frequently Asked Questions

What are the standard STEP5 file extensions?

The canonical STEP5 extensions are .S5D (full project), .STL (statement list), .LAD (ladder), .CSF (function chart), .SEQ (sequential), and block-numbered files like .OB1, .PB1, .FB1, .DB1, .SB1. Extensions like .BCF, .BK5, .UX1, .URF, and .XRF are not standard STEP5 formats and most likely come from a third-party EPROM programmer or a non-Siemens PLC tool.

Can STEP5 read a file with a non-standard extension?

Yes — set the file-type filter in STEP5's File → Open dialog to All files (*.*) and select the file. If the underlying content is valid STEP5 block data, STEP5 will import it regardless of extension. If the content is not STEP5, STEP5 returns error E 142 ("file is not a STEP5 file") and the file must be re-classified or re-converted.

How do I connect a modern PC to an S5-100U serial port?

The S5-100U uses a 20 mA current-loop interface, not RS-232. Use a Siemens PG with a native current-loop port, a USB-to-current-loop adapter (ACCON-S5-LAN or IBH-Link S5 plus), or build a current-loop adapter from a USB-FTDI module and a pair of 24 V optocouplers. The protocol is Siemens AS511 at 9600 baud by default; STEP5 handles the handshake automatically under Online → Connect to PLC.

What if the CPU still has the program in working memory?

Connect with STEP5 and use Online → Read PLC (or Online → Read Block for each block) to lift the program from the CPU and save it as a .S5D project on the PG. This is the fastest and most reliable recovery path and does not require the USB stick backup at all.

Is there a free tool to read an EPROM dump from a Siemens memory submodule?

Yes — a generic EPROM programmer software (such as the open-source minipro tool by Sylvain Munaut, or commercial packages from Data I/O, Conitec, Batronix, or Xeltek) can read the submodule. The trick is selecting the correct EPROM type (2716, 2732, 2764, 27128, or 27256) to match the physical submodule. After the read, the dump is usually a binary blob; it must be uploaded back into STEP5 via the EPROM-to-project utility to regenerate the individual OB, PB, FB, and DB block files.

Why is the program in .UX1 format when the CPU is Siemens?

Most likely the backup was made with a generic EPROM programmer rather than with STEP5 itself. The UX1/UXO/URF/.XRF extensions are typical of generic programmer output for a 27xxx-series EPROM, and the dump contains the raw bytes that were on the memory submodule. Convert the dump to Intel HEX or STEP5 block format using the EPROM programmer's export function, then re-import into STEP5.

Back to blog