[HELP PROJECT] "Data Crashes" Project [HELP PROJECT] - 8125, K-JAM, P4300, MDA Vario Software Upgrading

DATA CRASHES PROJECT:
If you have a G3 device in "Data Crashes" state check the CID collection to find the matching file to flash. Read bellow for the complete explanation about the theory and the procedure.
Theory:
Basis:
It's a known fact that the Wizard (and maybe Prophet) uses a DES encryption key from a list of 100 possible keys to decrypt the info of a CID block which is then verified by the cprog.exe utility. The 'key index' (list position) is calculated using the values from the DOC chip uniqueid which is a permanent value and the CID block must have been encrypted with same key otherwise the phone will never get to understand it and go in "Data Crashes" mode.
Theory:
There are two possibilities to get the "Data Crashes":
1- Corrupted CID block with invalid checksum;
2- Good CID block encrypted with different key index other than the one generated by the DOC chip uniqueid.
In scenario 2 if one is able to flash a good CID block encrypted with the correct key index then the problem will go away.
Purpose:
Since i've tested myself that it's possible to flash another phone's CID block with same key index and have phone work normally i purpose to make a collection of 100 good SuperCID blocks to cover all the 100 DES keys.
Even though only G3 devices downgraded to SPL 1.x allow to flash the CID block i won't discourage G4 members to contribute their CID blocks as they can be used in G3 devices (tested myself)
So i ask you to please contribute with dumps (unlocked or not) from the CID block of your devices.
In case you don't know how to provide what i'm looking for this is how to:
HOW TO SHARE:
1- Make the dump:
Get Wizard Service Tool (LINK) and use the "Read ROM" button to read the CID block (see pic below)
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
or... get itsme's pdocread.exe and make the dump with: pdocread.exe -n 1 0 0x10000 [filename.bin] using windows 'DOS' console (command)
2- Read the key index: (optional)
Use Wizard Service Tool and read "Device Info" to check the key index of your phone and post it along with the dump.
3- Share it:
Removed the email address as i no longer have time to assist this project (sorry)
You can still leave the file here as i get mail notifications but...
NOTE: For all those that have used lokiwiz you might have the file already since lokiwiz makes a backup and also creates new (unlocked) file to flash to the phone. It's the one of the *.bin files.
For all those afraid of sharing the file i assure you that there's no danger since i can mask the CID IMEI present in the dump so that it shows all FF's and your anonymity is guaranteed
HOW TO FLASH:
1- Get the CID file corresponding to your wizard's key index:
Use Wizard Service Tool and read "Device Info" to check the key index of your phone and, if you're lucky, get it from the collection in post bellow
2- Upload CID file with Wizard Service Tool:
Select "Write ROM" button and then "CID block (bdk 1)" to flash the file already in your hard-drive (SPL must be 1.xx !!!!)
3- Soft-reset the phone:
final step either via WST button or wizards side hole
mestrini
The theory has been confirmed!
2007/07/04 - emiconi recovered his wizard for FREE by flashing the apropriate CID block (http://forum.xda-developers.com/showpost.php?p=1348533&postcount=41 )
2007/10/18 - Another one bytes the dust. Kheops_974 fixed his phone after 3!! months of waiting for key #1
(http://forum.xda-developers.com/showpost.php?p=1594845&postcount=186)
2007/11/01 - And one more for the fixing count (http://forum.xda-developers.com/showpost.php?p=1630368&postcount=203) hehe
2007/11/28 - Once again a phone comes back to life after a LONG time of inactivity (http://forum.xda-developers.com/showpost.php?p=1697325&postcount=226)
2008/09/25 - Another success story (http://forum.xda-developers.com/showpost.php?p=2689813&postcount=303)

The list shows the keys that STILL HAVEN'T BEEN PROVIDED!!
If you have them please share the keys listed bellow:
key #07
key #09
key #13
key #17
key #29
key #33
key #43
key #63
key #67
key #71
key #85
MISSING = 11
key #80 - not released yet (having problems to handle it)
TOTAL = 89
thanks
mestrini
EDIT (2008-03-31)
Attached is the 8th collection with the 88 files gathered so far and all with MASKED IMEIs . They are spanned in 5 parts for easier downloading and with a max of 20 files per archive (starting at 0). So if you want to get a specific key just make the math
Someone noticed me once that some files are still SIM locked. It isn't a big deal since with bootloader 1.xx you can easily unlock it with Wizard Service Tool
As always you use these files at your OWN RISK but feedback is always VERY welcome
cheers
I apologize to all those that sent and also others that keep sending keys for not responding to mails or acknowledge the offerings but i haven't had much time to do it (had mails from November...)

Key index #94 attached -but removed later. But badly need CID block for key index #66
Someone could please post and that will be great help.
Thanks - Nishad

Great and thanks for mestrini...
Thanks mestrini for sharing this knowledge

nishadks said:
Thanks mestrini for sharing this knowledge
Click to expand...
Click to collapse
i invite everyone to share his CID dump to cover the needed blocks so as to solve this noisy problem totally

dr.moh said:
i invite everyone to share his CID dump to cover the needed blocks so as to solve this noisy problem totally
Click to expand...
Click to collapse
thanks for helping this cause m8s
i really hope this proves to be a valid theory so that G3 devices can have a free solution for this problem.
cheers
mestrini

here is my cid-block (super CID) key index 94.
(key-index as showed by Mestrini's tool)
Thanks for trying to solve this problem mestrini!!
EDIT: removed the file since Mestrini downloaded it already.

Come On People!!
Come on you guys!! This is a community forum and it shouldn't be only the ones with broken phones to try to help each other.
Everyone with working phone is a potential helper and should consider contributing to this task by providing a good/unlocked CID dump of a key index not yet provided.
Who doesn't like to get solutions for free? So get your wizards and make some dumps to share.
Right now the most wanted key indexes are: 66 for nishadks and 81 for peran.
Thanks in advance fellow members

Hi,
please send ur key indexes.
I need key index 81 very urgent. Plz help me.

Key Index #93 CID block
Anything I can do to help the geniuses who give freely of their time (and brains) here sounds good to me.

Come on guys. Send ur key index !!! PLZ

need key index #28 urgently
regards.

raid232 said:
need key index #28 urgently
regards.
Click to expand...
Click to collapse
Which one do you have now? It may not work for you but may be good to fix another phone

G4 Key Index # 70 Available
Sent to your mailbox mestrini, hope it helps to someone.

luiggi said:
Sent to your mailbox mestrini, hope it helps to someone.
Click to expand...
Click to collapse
tx for sharing it m8
and i must tell you guys that G4 CID blocks can be used in G3 devices. I just flashed my G3 (index88) with luiggi's G4 (index70) file and i got the expected "Data Crashes" message, nothing more
So what i'd like now is for other members with G4 devices to share their CID blocks; and it does not matter if the phone is CID locked since i can remove SuperCID the file and it will be good for a G3 owner to use
tx

I expected some more user participation.
Especially because it's a safe procedure, and done in a minute.
So people, chip in and contribute to this project.

Here is CID Block with key index #82 Block index 227. My CID is Locked.
I hope i'm helping

key index#27
got a index from a friend.
here it is.

tx freeyayo50, your CID block is already in first collection
tx to Peran281 and Zzan who just shared another two (#27 and #00)
and tx AGAIN to Luiggi who has supplied two more (three on his own!) (keys #10 and #40)
cheers

Here's mine, Key Index: 96

Related

Help! Failed ROM-update 1.34.251.1

Hallo,
I’ve allready posted my problem at mobilejoe (http://www.mobilejoe.de/joeforums/showthread.php?t=16450&page=5). Unfortunately nobody there have had the same problem.
The current ROM RUU_BREE100_1.34.251.1_1.38.00.10_HTCEUR_SHIP.exe cannot be installed on my MteoR.
Registry-data of the MteoRs are the following:
HKEY_LOCAL_MACHINE\Security\Policies\Policies\0000 1001 = 1
HKEY_LOCAL_MACHINE\Security\Policies\Policies\0000 1005 = 40
HKEY_LOCAL_MACHINE\Security\Policies\Policies\0000 1017 = 16
Successfully unlocked with SDA_ApplicationUnlocker.
I also installed SP_AllowCertificateInstall.cab with microSD.
So here are the detailed steps how I tried to updated my MteoR.
• I connected with ActiveSync 4.2.0 (also tested with 4.1)
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
• RUU_BREE100_1.34.251.1_1.38.00.10_HTCEUR_SHIP.exe started
• I followed all update-instructions
• The loading bar stopped at 0%
• The connecting to ActiveSync finished with an acoustically signal
• Seconds later:
• ERROR [260]: CONNECTION or ERROR [262] : UPDATE ERROR
The screen on MteoR stays red, green, blue, white
BREE100
IPL-0.90
BREE100
SPL-2.05
Who of you guys has got an idea and can help me with my big problem???
Thanks and bye
Christian
read http://forum.xda-developers.com/showthread.php?t=306165
You need to upgrade the SPL first, otherwise the rom flashing fails with error 262.
The easiest and most reliable method for flashing the Mteor is as follow :
Get the SPL upgrade + Rom update programs from the file :
http://rapidshare.com/files/27665839/852727-mteor_upgrade_2.zip.html
This installation contains two separate files.
You need to run these files in a specific order to make it work.
The installation order is:
1) First_file_MTeoR_EUR_1.09SPL.exe : Run it once with the Mteor attached to the USB cable. This will upgrade the SPL in your phone. You must run this even if your phone reports having a superior version of the SPL. Once finished, stop the phone by removing the battery (this is the only method I know for getting out of the bootloader), restart it and check everything is OK (your former windows mobile should load normally).
2) Second_file_MTeoR_Upgrade_1.34.251.1_1.38.00.10_EU R_SHIP.exe : This is the ROM Flash. This one is quite long to execute (about 10 minutes), so be patient. Once finished, pull off the battery and restart the phone, then enjoy!
albanc said:
You need to upgrade the SPL first, otherwise the rom flashing fails with error 262.
The easiest and most reliable method for flashing the Mteor is as follow :
Get the SPL upgrade + Rom update programs from the file :
http://rapidshare.com/files/27665839/852727-mteor_upgrade_2.zip.html
This installation contains two separate files.
Click to expand...
Click to collapse
When I downloaded that file, it doesnt containt two files. It has the ROM but no SPL file. Anyone know where I can download either the SPL or the full file containing both?
I just tried it and there are two files as already mentioned.....
dmaunder said:
When I downloaded that file, it doesnt containt two files. It has the ROM but no SPL file. Anyone know where I can download either the SPL or the full file containing both?
Click to expand...
Click to collapse
Thank, I sorted that out, must have downloaded two similar files or something. Anyway, updated SPL to 1.09, but when I run the second file, it says [262] Invalid Vendor ID. What do I do about that.
This is on a imate SPJAS
albanc said:
You need to upgrade the SPL first, otherwise the rom flashing fails with error 262.
The easiest and most reliable method for flashing the Mteor is as follow :
Get the SPL upgrade + Rom update programs from the file :
http://rapidshare.com/files/27665839/852727-mteor_upgrade_2.zip.html
This installation contains two separate files.
You need to run these files in a specific order to make it work.
The installation order is:
1) First_file_MTeoR_EUR_1.09SPL.exe : Run it once with the Mteor attached to the USB cable. This will upgrade the SPL in your phone. You must run this even if your phone reports having a superior version of the SPL. Once finished, stop the phone by removing the battery (this is the only method I know for getting out of the bootloader), restart it and check everything is OK (your former windows mobile should load normally).
2) Second_file_MTeoR_Upgrade_1.34.251.1_1.38.00.10_EU R_SHIP.exe : This is the ROM Flash. This one is quite long to execute (about 10 minutes), so be patient. Once finished, pull off the battery and restart the phone, then enjoy!
Click to expand...
Click to collapse
Thank you!!! It works!!! I'm happy now...
MTeoR doesn't boot anymore
Hello,
I followed the instructions and applied the first file via active sync. Update was pretty short and phone restarted. However, it does not go past the HTC splash screen anymore.
I can enter the bootloader and it tells me:
BREE100
IPL-1.00
SPL-1.09.00
Trying to access the device with mtty shows the following information:
Cmd>info 2
HTCSVODAP110IqpÞHTCE
Cmd>info 7
HTC Integrated Re-Flash Utility, Common Base Version : 1.51d
Device Name: BREE100, Bootloader Version : 1.09.0000
Built at: Feb 27 2007 21:51:16
Copyright (c) 1998-2006 High Tech Computer Corporation
CPU ID=0x41129200
Main CPLD version=0x8
Main Board version=0x4
Cmd>info 8
Block 0x0(0) is Reversed block
Block 0x1(1) is Reversed block
Block 0x2(2) is Reversed block
Block 0x3(3) is Reversed block
Block 0x4(4) is Reversed block
Block 0x5(5) is Reversed block
Block 0x6(6) is Reversed block
Block 0x7(7) is Reversed block
Block 0x8(8) is Reversed block
Block 0x9(9) is Reversed block
Block 0xA(10) is Reversed block
Block 0xB(11) is Reversed block
Block 0xC(12) is Reversed block
Partition[0], type=0x20, start=0x2, total=0x18FE
Partition[1], type=0x23, start=0x1900, total=0x1500
Partition[2], type=0x25, start=0x2E00, total=0x18300
Partition[3], type=0x4, start=0x1B100, total=0x24F00
CE Total Length(with sector info) = 0x36F8800
CE CheckSum Length(without sector info) = 0x3620000
Can you please have a look, if these settings make sense or if there is anything wrong?
Further, I tried to download several images to flash them
ruu_bree100_1.15.709.3_dopodcht_ship.exe - no success
RUU_BREE100_1.34.251.1_1.38.00.10_HTCEUR_SHIP.exe - no success
Flashing via Windows stops after 1% and gives the error 294 - Invalid Vendor ID. Flashing via SD card shows "loading" & "checking" and ends with "00028002 - Not allow", then goes back to the bootloader screen.
I also tried to flash the HardSLP and SSLP roms, but as far as I understand can they not be flashed with the standard bootloader. I keep getting 00068.. something, which seems to happen on unsigned ROMs.
Is there any way, I can load a standard ROM with that bootloader or install SLP? Your help is much appreciated, since I am phone-less now
If you require any more information, let me know how to get it please. Will post it quickly then.
Regards, Marko
albanc said:
You need to upgrade the SPL first, otherwise the rom flashing fails with error 262.
The easiest and most reliable method for flashing the Mteor is as follow :
Get the SPL upgrade + Rom update programs from the file :
http://rapidshare.com/files/27665839/852727-mteor_upgrade_2.zip.html
This installation contains two separate files.
You need to run these files in a specific order to make it work.
The installation order is:
1) First_file_MTeoR_EUR_1.09SPL.exe : Run it once with the Mteor attached to the USB cable. This will upgrade the SPL in your phone. You must run this even if your phone reports having a superior version of the SPL. Once finished, stop the phone by removing the battery (this is the only method I know for getting out of the bootloader), restart it and check everything is OK (your former windows mobile should load normally).
Click to expand...
Click to collapse
In my phone don´t boot longer than
and then don´t working none of buttons and helps only removing battery, I did allready did hard reset to, but this to did´nt help.
I have the same problem as MAZDAGTI
yes mee too
look here
i had the same problem
http://forum.xda-developers.com/showthread.php?t=381364
just flash the RUU_BREE100_1.34.261.1_1.38.00.10_HTCRUS_SHIP update
it will work

[UPDATE April 3rd] WST v4.2.2 - Wizard Service Tool

Ok guys, here you have latest version of my tool
I decided to open a new thread because the original one was getting too big (my opinion at least) so if you want to know more about first versions then visit the old thread: http://forum.xda-developers.com/showthread.php?t=295038
EDIT: (2008-04-03)
I know it's been a while but things kinda busy lately... but here you have released the latest update which includes the changes present in the log below.
Change log:
v4.2.2 (2008-04-03)
-Added some "Device info" routine error checking;
-Replaced "Exit" button that was removed in last version (got too used to it);
-Fixed bugs with non-declared variables;
-Added possibility to try CID unlocking if IPL and SPL versions differ (IPL 1.xx & SPL >2.xx) due to failed downgrade (which has been proved to work HERE . Thanks Monktrump )
-Changed PagePool routine to allow editing value even if only one pattern is found (tested successfully in "Slim Edition v2.2" and "Snn Edition")
v4.2.1 (2007-10-10)
-Fixed User Area reading routine for G4 (size is different from G3);
-Fixed RADIO reading routine for G4 devices (thanks to itsme, once again);
-Fixed "Device Info" routine to display RADIO values for G4;
-Fixed "Device Info" HardSPL display info (wasn't showing values);
-Fixed "DOC has no value" bug;
-Fixed crash upon canceling 'device detection' routine;
-Removed "Exit" button because of above bug;
v4.2 (2007-10-05)
-Changed the version's numbering system. WST is no longer beta as someone pointed out so i remove the leading '0';
-Added HardSPL detection (checks for the string "Olip") for G4 devices;
-Fixed User Area reading (partition handle recognition wasn't working for G4 devices);
-Added size and signature check to OS.nb files to be flashed (safer to write OS now!);
-Improved Write ROM routine to display the progression of OS and Ext_ROM zones writing (no more freez&wait);
-Fixed a bug in key index (CID) routine that caused errors in key#22;
-Fixed a bug that was leaving WST process running even after closing program in some occasions;
-Added a 10MB option to the Poolpage routine;
v0.4.1.0 (2007-09-19)
-Fixed a bug in read/write ROM routines where a variable wasn't initialised properly and would crash program;
-Restored some commented code that prevented SPL check in CID unlocking routine (didn't check G4 nor G3 SPL 2.xx);
-Fixed IPL dump from memory to generate an exact copy of an original IPL;
-Added code to Extended_ROM option to COPY files to HDD (forgot to move code while porting functions);
-Improved 'PagePool' routine code (more time to read program messages);
-Added IPL version to "Device Info" routine;
-Added 'Check nk.nbf' routine (to know what chunks are in a nk.nbf)
v0.4.0.0 (2007-09-12)
-Cleaned up some code and fixed a lot of errors resulting from new REXX interpreter version;
-WST is now PORTABLE, i.e, no longer requires the install of Reginald interpreter and doesn't write to registry;
-Replaced the log window (list control) with a text entry to allow selecting and copying the information;
-Added more info to "Device Info" feature: cleary states if it's a G3 or G4, shows date of SPL, shows name and -visibility status of extended_rom;
-Removed 'Repair IMEI' section and placed the button in 'General options' (works the same way as previous);
NOTICE: Thanks to itsme that updated his itsutils it's now possible to change IMEI in G3 without the need to downgrade to 1.xx and also on G4 CID unlocked!!!
-Eliminated the Extended_ROM window and moved the functions to the main script;
-Added 'Format ROM' option to ext_rom;
-Added a patching for the PagePool that doesn't rely on a fixed address (looks for pattern);
-Added option to read IPL from memory;
-Fixed the read SPL routine to detect G3 or G4 device (now produces a replica of the SPL.nb);
-Added an option to read ALL ROM sections at-once and also automatic file naming;
-Fixed an issue with files being saved with spaces in their names (pdocread limitation, though);
mestrini
PS:
latest version ZIP already includes the windows DLL (msvcr71.dll) needed by Win2K and XP not up to date...
EDIT:
I had to remove version 4.2.2 from April 2nd to remove a debugging instruction i forgot and that was crashing WST.
I didn't change the version number so check if you have latest 4.2.2 from April 3rd!!!
EDIT2: (2008-04-12)
I removed v4.2.1 as the downloads kept increasing which i assume may be from external linking. This way people weren't getting the latest version
reserved for pics
Pictures of features:
1- PagePool
You can use the button to change the page pool that will take effect after a soft reset. if you just want to check the value you simply cancel the procedure and nothing will be written to ROM
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
2 - Check DOC chip version (G3 or G4??)
Select the "Device Info" button and wait for program to finish. Once finished check SPL version and the info about the Gx generation of your device.
3 - Check CID lock status
Use the "CID Actions" button and then the "Read CID block" from the drop down list (selected by default)
Once finished you'll be presented with the CID value (referring to the service provider code) and the corresponding status (unlocked in this case)
Enjoy...
Thanks mestrini!
It is fully working now without any problem.
Thanks Mestrini !
Great tool you got there man. Congrats !
Please read this post...can your tool read the build number wrong ?
anichillus said:
Great tool you got there man. Congrats !
Please read this post...can your tool read the build number wrong ?
Click to expand...
Click to collapse
Yes, it sure is possible because my tool grabs some some .dsm files from the \Windows folder and reads the build values present inside. I guess that not all the .dsm files have the build updated or are used from older builds. It's done this way because some kitchen builder (can't recall who) directed me that way.
Now if anyone knows a 'safer' way or a specific .dsm file that has the most recent build value i'll update my tool.
Anyway, thanks for the feedback m8s
Am I missing something?
I'm planning to load WM6 on my Wizard (T-Mobile MDA Vario II) but wary of bricking it, so when I came across references to WST I was very pleased. I'm hoping it will let me take a backup of the existing ROM that I can reload if my attempts at a WM6 install fail.
I downloaded WST and read the readme.txt file. I ran the installer, checked my Wizard is connected via USB and ActiveSync is happy. All is good so I fire up WST.
It looks great - very neat and no confusing stuff in the UI. Well done!
I note the bit about needing to enable RAPI stuff before anything else, so that's what I do. The tool seems to connect and run the cabs and then completes without reporting any problems, but then if I try any other option I get a message telling me a device was detected but one (or both) of RAPI
Communications and Applications Policy isn't enabled.
Do I need to do something else before I can use this tool?
Can I enable RAPI maually outside of the tool before I begin?
That is strange. Have you tried closing WST and then open it again? That's the problem of most cooked ROMs nowadays that are already RAPI enabled and it's possible to let something pass by when writing that procedure.
That is strange. Have you tried closing WST and then open it again? That's the problem of most cooked ROMs nowadays that are already RAPI enabled and it's possible to let something pass by when writing that procedure.
Click to expand...
Click to collapse
I tried that. My current ROM is not cooked. It's the one shipped by T-Mobile (I'm scared of breaking anything so I want to take a backup of this ROM before I try swapping it out for WM6).
Since then I've also done a soft reset on the Wizard and a reboot on my PC (Win XP Pro) but I get the same problem
There doesn't seem to be anything in the options or setup within the device to enable RAPI or unsigned apps. Do I need a registry editor too?
Just in case it's significant:
ROM version is 2.21.2.6 WWE
ROM date is 3/9/06
Radio version is 02.19.11
Protocol version is 4.1.13.09
ExtROM version is 2.21.2.109
Thanks for supporting WST - this is great!
Sorted!
I copied the .cab files from the WST folder (created when I installed WST) on to my Wizard and ran them from the Wizard UI.
Now WST can talk to my device! Yayy!
Yes I am missing something.
When I read the original messages I misunderstood the purpose of WST. I got the idea that I'd be able to copy my current ROM as a backup before I started fiddling (loading WM6).
Having got WST to talk to my device I now find I was mistaken. There doesn't seem to be the option of capturing the whole ROM for use as a backup, so I'm no nearer (except I do have a neat way to interrogate my device now - that's cool!)
So, what do other people do about safeguarding their original setup - or at least making sure they will be able to reload an official ROM if necessary - before trying new ROMs?
Am I just being over-cautious? Does everyone just jump in without thinking about a safety net?
Tulaine said:
When I read the original messages I misunderstood the purpose of WST. I got the idea that I'd be able to copy my current ROM as a backup before I started fiddling (loading WM6).
Having got WST to talk to my device I now find I was mistaken. There doesn't seem to be the option of capturing the whole ROM for use as a backup, so I'm no nearer (except I do have a neat way to interrogate my device now - that's cool!)
So, what do other people do about safeguarding their original setup - or at least making sure they will be able to reload an official ROM if necessary - before trying new ROMs?
Am I just being over-cautious? Does everyone just jump in without thinking about a safety net?
Click to expand...
Click to collapse
You can backup your ROM but you must do it in several steps (or one step but will several files)
Later you can pack the files inside an RUU and flash back to phone or use WST to flash them back (OS & Ext_Rom at least)
Installed and running. Using the Start|Programs|Wizard Service Tool!Wizard Service Tool shortcut, found that I needed to modify the working folder, that is, remove "files" from the path. Running XP Home SP2. Installed to defaults.
Like the ability to save the Device Info to the clipboard. Useful as is providing a filename template including the date when saving ROM Zones
mestrini said:
You can backup your ROM but you must do it in several steps (or one step but will several files)
Later you can pack the files inside an RUU and flash back to phone or use WST to flash them back (OS & Ext_Rom at least)
Click to expand...
Click to collapse
A few questions about using WST to upgrade a Wizard, getting close to doing so on a G3 with the current ROM versions 1.-- that is now CID unlocked.
From what I am reading here WST will write ROM Zones as and when but should care be taken such as upgrading the IPL/SPL zones at the same time between soft resets?
I also note previous comments that the version relationship between the IPL/SPL and the OS should be maintained but looking at some of the cooked ROMs these sometimes look to mix the version 2 and 3 IPL/SPL zones with the different OS versions including whether it has WM5 or WM6. Indeed, have read that some feel that there is limited value in going above the version 2.-- IPL/SPL zones. Is there a rule of thumb here that can be checked, versions of particular files in the OS against the version of IPL/SPL or is it only version 1.-- IPL/SPL that can cause dependency problems with later OS ROMs?
Thanks for every ones contributions here.
mick.j said:
Installed and running. Using the Start|Programs|Wizard Service Tool!Wizard Service Tool shortcut, found that I needed to modify the working folder, that is, remove "files" from the path. Running XP Home SP2. Installed to defaults.
Click to expand...
Click to collapse
There was a similar complaint in version 0.2 but i don't see how that "files" ended up there. It installs perfectly on my system. Please paste here the full path you got.
mick.j said:
A few questions about using WST to upgrade a Wizard, getting close to doing so on a G3 with the current ROM versions 1.-- that is now CID unlocked.
From what I am reading here WST will write ROM Zones as and when but should care be taken such as upgrading the IPL/SPL zones at the same time between soft resets?
I also note previous comments that the version relationship between the IPL/SPL and the OS should be maintained but looking at some of the cooked ROMs these sometimes look to mix the version 2 and 3 IPL/SPL zones with the different OS versions including whether it has WM5 or WM6. Indeed, have read that some feel that there is limited value in going above the version 2.-- IPL/SPL zones. Is there a rule of thumb here that can be checked, versions of particular files in the OS against the version of IPL/SPL or is it only version 1.-- IPL/SPL that can cause dependency problems with later OS ROMs?
Thanks for every ones contributions here.
Click to expand...
Click to collapse
The big difference lies between 1.xx and 2.xx. Everything else should be safe. WM5 or WM6 can be run with IPL/SPL 2.xx or 3.xx and also with any 2.xx radio
But since your device is CID unlocked you should consider upgrading your Wizard via RUU
WST
This program is Awesome many many thanks!
The last version before this one worked perfectly.
mestrini said:
There was a similar complaint in version 0.2 but i don't see how that "files" ended up there. It installs perfectly on my system. Please paste here the full path you got.
Click to expand...
Click to collapse
Checked the WST folder in Program Files and it had the following folder tree.
Wizard Service Tool\
Wizard Service Tool\Files\
Wizard Service Tool\Files\Temp\
Wizard Service Tool\Files\ Files\
Wizard Service Tool\Files\ Files\Temp\
Un-installed and deleted the respective folders in Program Files. Reinstalled and the "start in" path is "C:\Program Files\Wizard Service Tool" and opened OK whereas in the previous install it had been "C:\Program Files\Wizard Service Tool\files"
Looks like some residue from the previous version may have affected the path.
The big difference lies between 1.xx and 2.xx. Everything else should be safe. WM5 or WM6 can be run with IPL/SPL 2.xx or 3.xx and also with any 2.xx radio
But since your device is CID unlocked you should consider upgrading your Wizard via RUU
Click to expand...
Click to collapse
I was looking to bypass installing a full ROM to update Radio, IPL and SPL and then installing an OS of choice but your advice is well taken and thanks for clarifying the version issues that I had.
Regards.
GateArray said:
The last version before this one worked perfectly.
Click to expand...
Click to collapse
That is not very helpful. Now i know there's a bug in it but not what it is or how to try and fix...
Pls give more details as how you got there and what did you do
mick.j said:
Un-installed and deleted the respective folders in Program Files. Reinstalled and the "start in" path is "C:\Program Files\Wizard Service Tool" and opened OK whereas in the previous install it had been "C:\Program Files\Wizard Service Tool\files"
Looks like some residue from the previous version may have affected the path.
Click to expand...
Click to collapse
What OS are you running? XP Pro English? It may also be related to a specific OS version? Anyway, I'm glad you sorted it.
mestrini said:
That is not very helpful. Now i know there's a bug in it but not what it is or how to try and fix...
Pls give more details as how you got there and what did you do
What OS are you running? XP Pro English? It may also be related to a specific OS version? Anyway, I'm glad you sorted it.
Click to expand...
Click to collapse
Here I am
SO: W2000 server english
I have tried to re-install ver 0.3.0.3 and it works fine
I also have tried to "clean" old version before install 0.4.0.0.... same problem
I tried to uninstall the compiler REXX from CP
same result still....
Tomorrow next tests.
Hold. You're getting it as soon as WST starts?

Softbank X03HT (S730) won't unlock

This is a copy of a post I made on the general/unlocking board. Posting here in case people are looking only at this forum:
I have just bought a Sofbank X03HT. It is locked up tight. I travel a lot and have SIMs for the places I go most so I want to unlock the SIM. I'd also like to unlock the applications so I can make reg edits as the mood strikes me.
But, none of the tools and/or tricks I have found on here or other sites works. I suspect the issue is with the certification. Have tried the AllowCertificateInstall but it doesn't seem to help. Also tried SurrealNetworksAppUnlock.cab. Again, no joy. Tried SDA Unlocker and the XDA (PDA) tools and tricks. Nada.
Here is what I've got:
Softbank Mobile (Japan)
X03HT (an HTC S730)
Windows Mobile 6 Standard
CE OS 5.2.1947
ROM version 1.71.761.1
Have you tried the deive security manager(maybe not this name)?
A tool in Microsoft Visual Studio 2008 (pro version)
Sorry, I only have chinease version
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
You can download it at
http://www.microsoft.com/downloads/...EC-ED72-4A79-8961-25635DB0192B&displaylang=en
for free 90days trial.
and it allowed you to adjust your handset security settings freely.
I have tried to my Vox, if i set to high level security, i can not run any apps without cert.
Still can not
We need a softbank cert.
Any ideas, anyone? I'm having the exact problem.
i have the same problem too....please help me...
pahpoh said:
i have the same problem too....please help me...
Click to expand...
Click to collapse
I think you must tried to confirm it to Jockyw2001, since only he who knows..
Don't confuse the various "unlock" for the Windows Mobile devices! There are 3 of them and to get rid of some you may need the others removed in advance, depending on the method.
Application Lock: Execution of applications or many other activities is secured on the windows mobile platform. There is a dedicated security model that distinguishes activities (what is done) and roles (who can do it). The assignment of roles to such activities is called policy. These policies are stored in the registry of the operating system and are only in place when the OS is up and running. Look up MSDN for mobile security policy to learn more.
It is common that many users who want to execute special applications want to have their devices "application unlocked".
CID Lock: This ties the ROM of an operator to the device it is loaded. This way the operators make sure that users are not buying a subsidized phone and replace the ROM on them with non customized ones. This lock is treated in the SPL (Secondary Program Loader) and checks on data that are stored encrypted in the ROM outside the normal flash areas. Other ROMs (the OS in them) may not be as restrictive set up on the application lock if you really were after this (I doubt is). Loading any ROM can be achieved by either
Super-CID the phone: This allows the onboard SPL to pass the CID check and continue with the ROM flashing process.
You either replace the operator CID with the Super CID in the encrpyted block by special tools that can calculate the CID and write to the encrypted block (itsutils). To run these tools, the device must be properly application unlocked. Several frameworks have been created to guide this activity, but more recent devices cannot be cracked this way any more to my understanding.
Or you can have a device be temporarily have the "Super CID rights by inserting a "GoldCard" into the device. This is a normal memory card which has a device specific key written to the bootsector of the card. The bootsector written to the card is specific to the HW serial number of the memory card. The only tool I know that can write this is "PSAS" from http://psas.revskills.de. You need to have a working application unlocked Windows Mobile device for that as also here itsutils are used for some parts of the job.
Replace the SPL
either temporarily (jumpSPL, HARET) by loading the code for upgrade in the RAM
or permanently by flashing the SPL to the device. This requires one temporary use to have it done permanently, of course.
SIM lock. This is most commonly know "lock" as it links the device usage to the SIM card of an operator. I am not aware of the reference that this linkage is done (but I suspect IMSI + parts of the MSISDN), but the final place to store that is done again in an encrypted area of the ROM that is outside any normal flash region, so it cannot be removed with any ROM update. Also here several services exist from people that know how to deal with encrypted data. A well known user is jockyw2001 for that, but there also exist commercial services that do that for reasonable prices on older devices. I made good experience with http://www.imei-check.co.uk/ who are very responsive and as I understood their service will both SIM unlock and Super-CID your device (at least for Tornado).
Be warned: messing with the encrypted block in an unqualified way (for CID or SIM unlock) may leave your device useless for telephony use. Inserting a SIM in the device will return the message "data crashes, please contact your service center" when you try to get radio access.
tobbbie said:
Don't confuse the various "unlock" for the Windows Mobile devices! There are 3 of them and to get rid of some you may need the others removed in advance, depending on the method.
Application Lock: Execution of applications or many other activities is secured on the windows mobile platform. There is a dedicated security model that distinguishes activities (what is done) and roles (who can do it). The assignment of roles to such activities is called policy. These policies are stored in the registry of the operating system and are only in place when the OS is up and running. Look up MSDN for mobile security policy to learn more.
It is common that many users who want to execute special applications want to have their devices "application unlocked".
CID Lock: This ties the ROM of an operator to the device it is loaded. This way the operators make sure that users are not buying a subsidized phone and replace the ROM on them with non customized ones. This lock is treated in the SPL (Secondary Program Loader) and checks on data that are stored encrypted in the ROM outside the normal flash areas. Other ROMs (the OS in them) may not be as restrictive set up on the application lock if you really were after this (I doubt is). Loading any ROM can be achieved by either
Super-CID the phone: This allows the onboard SPL to pass the CID check and continue with the ROM flashing process.
You either replace the operator CID with the Super CID in the encrpyted block by special tools that can calculate the CID and write to the encrypted block (itsutils). To run these tools, the device must be properly application unlocked. Several frameworks have been created to guide this activity, but more recent devices cannot be cracked this way any more to my understanding.
Or you can have a device be temporarily have the "Super CID rights by inserting a "GoldCard" into the device. This is a normal memory card which has a device specific key written to the bootsector of the card. The bootsector written to the card is specific to the HW serial number of the memory card. The only tool I know that can write this is "PSAS" from http://psas.revskills.de. You need to have a working application unlocked Windows Mobile device for that as also here itsutils are used for some parts of the job.
Replace the SPL
either temporarily (jumpSPL, HARET) by loading the code for upgrade in the RAM
or permanently by flashing the SPL to the device. This requires one temporary use to have it done permanently, of course.
SIM lock. This is most commonly know "lock" as it links the device usage to the SIM card of an operator. I am not aware of the reference that this linkage is done (but I suspect IMSI + parts of the MSISDN), but the final place to store that is done again in an encrypted area of the ROM that is outside any normal flash region, so it cannot be removed with any ROM update. Also here several services exist from people that know how to deal with encrypted data. A well known user is jockyw2001 for that, but there also exist commercial services that do that for reasonable prices on older devices. I made good experience with http://www.imei-check.co.uk/ who are very responsive and as I understood their service will both SIM unlock and Super-CID your device (at least for Tornado).
Be warned: messing with the encrypted block in an unqualified way (for CID or SIM unlock) may leave your device useless for telephony use. Inserting a SIM in the device will return the message "data crashes, please contact your service center" when you try to get radio access.
Click to expand...
Click to collapse
ok...
Tell me.. if i don't have a SHIP ROM, then what i must do??
How to unbrick my device -> Monet??

Help out OliNex / HARDSPL development by looking up your internal storage brandname

Hi There!
As requested in this topic, I promised to write an tutorial regarding on how to find your internal memory brand (to be clear, NOT your SD Storage Card brand).
This is important because there are ALOT of Rhodium Devices out there which use "Samsung" internal memory and OliNex needs to find a device which uses Hynix (or any different then samsung_kby00xxx) so they can test HardSPL for the Rhodium with it.
So...In short, read the tutorial below if you wan't to help out hardspl development AND if you're willing to, if you have internal memory that's from Hynix (or any different then samsung_kby00xxx), act as a tester for their HardSPL.
Cmonex also wrote a very short tutorial using a different program, you can scroll down a bit and read it or click here.
Originally Posted by cmonex
[SIZE=+3]PLEASE STOP POSTING YOUR FLASH INFO IF YOU ONLY HAVE THE samsung_kby00n00hm[/SIZE]
...because it gives no new information to anyone, or anything useful.
The Tutorial:
Requirements:
QMAT
Windows Mobile Device Center 6.1 for vista or ActiveSync 4.5 for Windows XP
USB Cable for connecting your phone with your pc
Warning:
I'm in no way reliable if you screw your phone up...altrough I seriously doubt that you can actually screw anything up using QMAT and just these instructions.
Step 1
Note:
As I'm personally using Vista x64 I can't explain in full length on how to disable USB Connections in ActiveSync for Windows XP.
Note2: Begin with your device NOT connected to your pc.
First we are going to disable USB connections so QMAT can succesfully communicate with your device.
To do this, open the Windows Mobile Device Center.
Click on "Mobile Device Settings" and then click on "Connection Settings".
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Untick "Allow USB Connections" in the new window that just popped up.
Click on "Ok" and then close Windows Mobile Device Center.
Step 2
Enter bootloader mode with your device, DO NOT CONNECT YOUR DEVICE JUST YET!. To do this:
* Remove the stylus from your phone then remove the back cover from the phone.
* Hold the Volume Down button.
* Use the stylus to press the reset hole.
* Or if the device was powered off, hold the volume down button and then press the power button to turn the device on.
You should see "Serial" at the bottom of the screen.
Step 3
Connect your phone to your pc using a USB cable, any USB to Mini-USB cable should be fine, just to be on the safe side you could use the USB cable from the original packaging.
The word "Serial" at the bottom of the screen should turn into "USB", also if this is your first time entering bootmode and connecting your device to the pc it should install some drivers and stuff...this is normal
Step 4
Now the real stuff begins....
Open up QMAT
Click "Hardware Forensics" at the top of the program.
Click on "Use Mobile Ports" at the sub-menu which just appeared.
Click on the tab "Modem Port (Async)"
Click on either Start USB (Vista) if you have vista, or Start Serial (XP) if you have XP.
If everything wen't ok the button you just clicked turned into "Stop USB". Just don't click it just yet
In the Textfield at the left of the buttons you type in:
"info 8" (without the quotes afcourse...) and then press return (enter).
All kinds of information should start popping up in the big textfield below.
Scroll up....and you should see something like this:
Code:
info 8
--- 2K bytes sector version ---
DEVICE NAME=*YOUR INFO HERE*
DEVICE ID=*YOUR INFO HERE*
DEVICE MAKER ID=*YOUR INFO HERE*
PAGE SIZE=*YOUR INFO HERE*
TOTAL PAGE SIZE=*YOUR INFO HERE*
BLOCK COUNT=*YOUR INFO HERE*
BLOCK PAGE=*YOUR INFO HERE*
This is what it displayed with me:
Your brand is stated after "Device Name". Now...please reply with this information if the one you're seeing is displaying ANYTHING else then samsung_kby00xxx (specially if it's stating Hynix)
You can select the text needed and copy it to a notepad file or any other text-file...or this forum afcourse
After you're finisht, hit "Stop USB" and close down QMAT.
Safely remove your device from your pc, reset it and it should start up again as normal.
Re-enable usb connection in the Windows Mobile Device Center.
Thanks to Olipro for personally giving instructions to me on how to do all of this in the first place.
Todo:
Make Video tutorial.
Works in windows 7 as well!
For those cutting edge folkies who use windows 7, it works as well.. just follow the Vista instructions. I can also confirm that it did NOTHING to any any information on my device..
BTW.. sorry guys.. mines samsung!
many thanks for the tut & here is a perhaps simpler way for some people.
1. simply download itsutils from http://nah6.com/~itsme/itsutilsbin-20090515.zip
2. extract to empty folder and make sure your device is synced.
2b. you may have to install http://hpcmonex.net/roms/enablerapinew.cab on the device.
3. goto to the above folder with cmd - if you dont know how to use cmd then i dont need you as a tester anyway (sorry no offense meant!)
4. command: pmemdump -p 0x01ffc0ac 0x4
5. if it shows ad bc 10 55 (flash deviceid) then it's hynix flash
edit: actually the first tutorial is still very useful, if "info 8" shows something other than samsung_kby00n00hm it may still be very interesting!
if you do my steps then if it shows anything other than ec bc 42 15 (which is samsung_kby00n00hm) then please let me know.
Cmonex thank you for your short tutorial.
I edited my tutorial stating explicitly that if someone finds anything other then samsung they should reply with the info
Hi,
I'm under Seven x64, and the first how to didn't word, Qmat can't find usb port.
Cmonex's solution works well, unfortunately, I have Samsung's memory
mtech said:
Same here, Samsung.
Out of curiousity, anyone get this:
BLOCK 32 (0x20) is reversed block
BLOCK 2585 (0xA19) is bad block
Partition[0], type=0x20, start=0x2, total=0x63E
Partition[1], type=0x23, start=0x640, total=0xA80
Partition[2], type=0x25, start=0x10C0, total=0x15980
Partition[3], type=0x4, start=0x16A40, total=0x24580
about BLOCK 2585 being bad?
Click to expand...
Click to collapse
Also had that. Think it's normal.
I have a TP2 WWE and the result is:
C:\0>pmemdump -p 0x01ffc0ac 0x4
Copying C:\0\itsutils.dll to WCE:\windows\itsutils.dll
01ffc0ac: ec bc 42 15 ..B.
Click to expand...
Click to collapse
Thread stuck.
Dave
monx® said:
it seems until now everybody hv samsung chipset (including me).
what about only post here if u hv other than samsung chip? so we wont get over excited when see new post here (except this post please )
Click to expand...
Click to collapse
Agreed.
I edited my start-post/tutorial and clearly stated that people only should reply if they have anything else then samsung_kby00xxx.
Can somebody explane me why need Hynix chip ? Samsung are more secured or what ?
ps: 3 pieces of TP2, all samsung chips. I remember that week or two ago, I disassembled one tp2 with damaged screen and i think it was Hynix chip on board, if it mean anything.
borce_razor said:
Can somebody explane me why need Hynix chip ? Samsung are more secured or what ?
ps: 3 pieces of TP2, all samsung chips. I remember that week or two ago, I disassembled one tp2 with damaged screen and i think it was Hynix chip on board, if it mean anything.
Click to expand...
Click to collapse
It's probably an inventory/stock issue. Vendors may not have the same flash chips in stock to use on all manufactured devices. Or there could be different factories with different components available, so one factory could be putting in Hynix flash. This is a very common practice...
Hynix/Hyundai also produces RAM and other ICs, so this may have been what you've seen on your broken TP2.
cmonex,
is it geometry/block size or mfg partition location that is different on Hynix chips?
pen-pen said:
Hi,
I'm under Seven x64, and the first how to didn't word, Qmat can't find usb port.
Cmonex's solution works well, unfortunately, I have Samsung's memory
Click to expand...
Click to collapse
if you need help with that USB thing, feel free to PM me
mtech said:
Same here, Samsung.
Out of curiousity, anyone get this:
BLOCK 32 (0x20) is reversed block
BLOCK 2585 (0xA19) is bad block
Partition[0], type=0x20, start=0x2, total=0x63E
Partition[1], type=0x23, start=0x640, total=0xA80
Partition[2], type=0x25, start=0x10C0, total=0x15980
Partition[3], type=0x4, start=0x16A40, total=0x24580
about BLOCK 2585 being bad?
Click to expand...
Click to collapse
it's normal, most nand devices ship with at least one bad block though I have some that have no bad blocks just luck really, and it's not a problem if it has a couple of them, there is enough other blocks to replace them.
shure2 said:
samsung here too, are you sure that they have used hynix memory?
Click to expand...
Click to collapse
well, looks like for topaz there was no non-samsung chips, while hspl was in testing... I know that because no tester had any issues regarding flashing itself; but as soon as I released it they started getting hynix ones. that was nice timing.
CHfish said:
Sorry for spaming the thread (I've got samsung too) but
I've got a test device from HTC - and it says "Security Unlocked" on the top line of the bootloader - is this of any interest to you?
Does this mean I might flash any (unsigned) ROM?
Further information:
Code:
RHD100 32M SS-BC
SPL-0.78.0000
MicroP-Rhodium (LED) v9
MicroP-Rhodium (KEY) v4
TURBO HW/TURBO SW
TP MFG DATA
512,524 794,844
793,200 225,198
227,846 Calibrated
CHfish
Click to expand...
Click to collapse
neat that you have a prerelease. security unlock got nothing to do with OS flashing, sorry. but it is probably also supercid, so you can flash any HTC rom (but not cooked roms).
stepw said:
It's probably an inventory/stock issue. Vendors may not have the same flash chips in stock to use on all manufactured devices. Or there could be different factories with different components available, so one factory could be putting in Hynix flash. This is a very common practice...
Hynix/Hyundai also produces RAM and other ICs, so this may have been what you've seen on your broken TP2.
cmonex,
is it geometry/block size or mfg partition location that is different on Hynix chips?
Click to expand...
Click to collapse
a nand ctl config register is different. this configs for example where to find bad block bytes in the raw read of a nand page (btw, some of the config values are different on hynix than on samsung, but the bad block one happens to be the same on both). on topaz its contents can get "corrupt" (as I dont have such a problematic device I still don't know why), and it happens that the "corrupt" contents didn't affect much except that the SSPL could not read/write nand (it thought all blocks were bad but did not attempt to write the bad block data back); I put "corrupt" in quotes as it is always the same value, not random. anyway, I fixed that on topaz in the end but I would like to see one such device on rhodium, let's see if someone comes up with one soon. I'm pretty sure rhodium has devices with hynix too (even raphael has them, but it wasn't a problem on raphael).
PS: I think the problem with it getting "corrupt" is that topaz (and rhodium probably) handles this config register differently anyway (different from raphael etc). I mean the part is different when you send a request to nand via dm with some buffers with commands and configs in them. what I don't know is exactly how this affects the hynix devices.
cmonex said:
well, looks like for topaz there was no non-samsung chips, while hspl was in testing... I know that because no tester had any issues regarding flashing itself; but as soon as I released it they started getting hynix ones. that was nice timing.
Click to expand...
Click to collapse
Uhhh...that's bad.
Don't you think people would be clever enough to understand a warning message like "check your internal memory before flashing HardSPL!"
...uhm...no...
...forget my words...just a moronic touch of confidence in mankind
cmonex said:
a nand ctl config register is different. this configs for example where to find bad block bytes in the raw read of a nand page (btw, some of the config values are different on hynix than on samsung, but the bad block one happens to be the same on both). on topaz its contents can get "corrupt" (as I dont have such a problematic device I still don't know why), and it happens that the "corrupt" contents didn't affect much except that the SSPL could not read/write nand (it thought all blocks were bad but did not attempt to write the bad block data back); I put "corrupt" in quotes as it is always the same value, not random. anyway, I fixed that on topaz in the end but I would like to see one such device on rhodium, let's see if someone comes up with one soon. I'm pretty sure rhodium has devices with hynix too (even raphael has them, but it wasn't a problem on raphael).
PS: I think the problem with it getting "corrupt" is that topaz (and rhodium probably) handles this config register differently anyway (different from raphael etc). I mean the part is different when you send a request to nand via dm with some buffers with commands and configs in them. what I don't know is exactly how this affects the hynix devices.
Click to expand...
Click to collapse
This is odd, there's a flash driver - a geometry descriptor and a set of flash related procs in SPL for each supported NAND flash type. I don't see how SPL would work at all (e.g. flash OS and such) if Hynix driver is broken/missing. There should be no need to program NAND directly in SSPL AFAIK, the driver should be taking care of setting proper flags (block status, bad block, etc...) in out-of-band portion of NAND page.
Is there a chance SPL on devices with Hynix NAND includes a Hynix driver and SPL on devices with Samsung NAND does not? They might even be the same version, but the driver could be missing in one...
stepw said:
This is odd, there's a flash driver - a geometry descriptor and a set of flash related procs in SPL for each supported NAND flash type. I don't see how SPL would work at all (e.g. flash OS and such) if Hynix driver is broken/missing. There should be no need to program NAND directly in SSPL AFAIK, the driver should be taking care of setting proper flags (block status, bad block, etc...) in out-of-band portion of NAND page.
Is there a chance SPL on devices with Hynix NAND includes a Hynix driver and SPL on devices with Samsung NAND does not? They might even be the same version, but the driver could be missing in one...
Click to expand...
Click to collapse
OK I'll try to explain a bit better... when the topaz (and rhodium) SPL boots, its nand driver code can of course handle either chip, but it relies on this nand config register having the right value on booting SPL (normally radio bootloader sets it up for SPL). this value is what changes on hynix units when or before loading SSPL, and I don't know why. - but I intend to find out
PS: the SPL binary itself is same for both types.
Is there any chance you guys will release a Samsung-only HardSPL with a big fat warning label?

[Testing] Bigger ROM size.

Hi
I managed to use extrom as a part of rom, just like 2k3 does it, but some better.
This rom is 6.5 23140 fully provided, with EzInput, MS Office 2010 and Esmertec Java
I also got 236% in tcpmp benchmark, comparing to 157% in 23668. All important drivers are moved to xip to speed anything up.
Sounds good enough ;>?
Also I activated media control in lockscreen and fixed Internet Explorer
After installation you will get 2 partitions, root \ and Storage.
Some screens:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
How to install? It's not that easy, read it carefully:
1. Download MTTY attachment, download Rom (link above).
2. Put your phone into bootloader and put into crandle
3. Run MTTY and click USB button. Then type in white field "task 28" without quotes and wait 5 seconds. Some confirmation informations should appear.
4. Close MTTY, Unpack Rom, run Upgrade.exe, having 3 files is important (nk, ms_ and upgrade)
5. Flash normally. Updating process will take more time than always!
6. After upgrade completed, take hima out of crandle, JUST RESET, Do not hard reset!!, and IMMEDIATELY put into crandle!!.
7. Wait until installation message will apear, after reading click Continue and then wait until device get rebooted. 5 minutes is okay to wait.
8. When device rebooted, don't do anything and wait until Debug message will appear, saying Extrom got unblocked, then click on OK.
9. Installation finished, click FINISH! and wait some seconds, after doing all stuff Welcome will appear.
10. Tap on screen, calibrate screen, set time, and enjoy
Link to this test:
http://www.4shared.com/file/ArKkI1Ls/Ext23140test.html
this looks like another hima historic hurdle has been passsed !!
will be trying soon..
sounds cool,real good about being able to use extrom as a part of rom...amazing !!
one small question in step 6. you mention JUST RESET is that just a matter of pressing the reset button and no other button ?
or is it a RESET where you have to press a few buttons at the same time like when you put the hima in bootloader mode ?
keep up the amazing work !!!
Nice aero, to see, that you go, where noone else ever had been before!
aero you are a legend!!
I of course WILL be trying this!
EDIT: There is no usb button there is only com1 and com2 in a drop down menu.
help!!
flyboyovyick said:
aero you are a legend!!
I of course WILL be trying this!
EDIT: There is no usb button there is only com1 and com2 in a drop down menu.
help!!
Click to expand...
Click to collapse
advanced15 said:
will be trying soon..
sounds cool,real good about being able to use extrom as a part of rom...amazing !!
one small question in step 6. you mention JUST RESET is that just a matter of pressing the reset button and no other button ?
or is it a RESET where you have to press a few buttons at the same time like when you put the hima in bootloader mode ?
keep up the amazing work !!!
Click to expand...
Click to collapse
If there is no USB do this:
Disable USB connection in Activesync
Remember to have himalaya in bootloader mode and on USB, lol obvious
If none of this helps, tell me what windows do you use
--
With JUST RESET i mean JUST RESET, just put anything in reset hole and don't press anything
aeroflyluby said:
If there is no USB do this:
Disable USB connection in Activesync
Remember to have himalaya in bootloader mode and on USB, lol obvious
If none of this helps, tell me what windows do you use
--
With JUST RESET i mean JUST RESET, just put anything in reset hole and don't press anything
Click to expand...
Click to collapse
I use windows 7, it shows com1-3
flyboyovyick said:
I use windows 7, it shows com1-3
Click to expand...
Click to collapse
Also did you installed this driver? (Vista = 7)
http://forum.xda-developers.com/showthread.php?t=428469
// This formatting mess is required because some people repartitioned theirs DoCs to remove EXTRom, so I don't really want to know what would happen without it.
When I upgrade,there are : error 112
why can it happens?
what will I do?
thanks
testing it now... will post report after... finger crossed..
done it..working now..
one question.. since memory in main is almost full thus this means i cant no longer install some programs?
main storage memory only now 1.58mb and programs 65.62mb,while storage is 15.96mb....
jonrols said:
done it..working now..
one question.. since memory in main is almost full thus this means i cant no longer install some programs?
main storage memory only now 1.58mb and programs 65.62mb,while storage is 15.96mb....
Click to expand...
Click to collapse
Why not to install on \Storage ?
It's not removeable
When I upgrade,
error 112
can you help me
arifurrokhman said:
When I upgrade,
error 112
can you help me
Click to expand...
Click to collapse
Hi arifurrokham,
If i'm not mistaken you've disabled the allow usb connections in the activesync connection settings before running mtty to show usb. After finished running mtty just enable the allow usb connections before running the upgrade to address error 112. Hope this helps
japo_g said:
Hi arifurrokham,
If i'm not mistaken you've disabled the allow usb connections in the activesync connection settings before running mtty to show usb. After finished running mtty just enable the allow usb connections before running the upgrade to address error 112. Hope this helps
Click to expand...
Click to collapse
This shouldn't because Upgrade tool disables AS automatically.
RUU LOG
08:04:09 Connection with USB
08:05:57 Begin stage 1
08:06:27 CE Erase retry 1
08:07:08 CE Erase retry 2
08:07:48 CE Erase retry 3
himalaya screen : serial
v 1.03
when I update : error 112
AERO...Can you help me...
excellent aeroflyluby !!!
i have run this excellent stuff..
all working good so far....
question ? after looking at the "ms_.nbf" with "er2003edit" i see that most of the actions to make extrom as part of rom is done with this.
with you permission? would it be possible to use this "ms_.nbf" with any "nk.nbf/ROM" so i could have the AMAZING extrom as part of rom on any ROM i like...
is this possible? if i follow the exact same guide but just change the "nk.nbf" ?
aeroflyluby keep up the great work !
advanced15 said:
i have run this excellent stuff..
all working good so far....
question ? after looking at the "ms_.nbf" with "er2003edit" i see that most of the actions to make extrom as part of rom is done with this.
with you permission? would it be possible to use this "ms_.nbf" with any "nk.nbf/ROM" so i could have the AMAZING extrom as part of rom on any ROM i like...
is this possible? if i follow the exact same guide but just change the "nk.nbf" ?
aeroflyluby keep up the great work !
Click to expand...
Click to collapse
Look, extrom have cabs, autorun, some exe's and config. ROM part is to unhide extrom, then run autorun and after installing all, device will reset, clear.exe will unblock extrom to write on it and clear it, after that extrom is mounted as Storage. clear.ink from startup is removed and last operation is to run Welcome screen.
To use it on any rom you need to unhide your extrom and run autorun.
RUU LOG
08:04:09 Connection with USB
08:05:57 Begin stage 1
08:06:27 CE Erase retry 1
08:07:08 CE Erase retry 2
08:07:48 CE Erase retry 3
himalaya screen : serial
v 1.03
when I update : error 112
AERO...Can you help me...please
or somebody....
I hope can use AERO ROM
aeroflyluby said:
Why not to install on \Storage ?
It's not removeable
Click to expand...
Click to collapse
sir aero, yes i can install apps on storage but those apps that needs to be installed on ram cannot be for instance spb mob shell... is there a way o increase ram size like in xda 2s?
thanks again..
jonrols said:
sir aero, yes i can install apps on storage but those apps that needs to be installed on ram cannot be for instance spb mob shell... is there a way o increase ram size like in xda 2s?
thanks again..
Click to expand...
Click to collapse
I can't really understand you. You got 108 free ram and I think you won't get any better

Categories

Resources