breeze write bootloader with jtag - HTC Breeze

Hello to all.I messed up my bootloader in a customer breeze and found a solution to write it back with jtag.All is needed is a jtag interface and an utility here link http://210.118.57.197/Products/Semi...or/ARM9Series/SC32442/JtagFlash_Prog_Code.zip
First some usefull info about breeze mainboard:
jtag pins and Htc debug connector
Pin Signal | Signal Pin
------------+------------
1 TDO | TDI 2
3 TMS | TCK 4
5 n_TRST | ??? 6 (probably connected to ASIC3)
7 GND | A9 8
9 A8 | A7 10
11 A6 | A5 12
13 A4 | A3 14
15 A2 | A1 16
17 ??? | n_OE 18
19 ??? | GND 20
21 GND | n_SRST 22
23 D15 | D14 24
25 D13 | D12 26
27 D11 | D10 28
29 D9 | D8 30
31 D7 | D6 32
33 D5 | D4 34
35 D3 | D2 36
37 D1 | D0 38
39 VCC1.8 | GND 40
For better orientation pin 1 of the Htc debug connector is in the upper right corner with a white mark on it.
Ok, now lets write back the bootloader and the procedure is the following:
1. locate the JTAG pins
2. use a very small soldering iron and attach some wires to the testpoints
3. use one of the wiggler clones to built up a connection to the JTAG pins using LPT port of your host pc
4. insert fully charged battery and press power on button on breeze
5. use the samsung software (msp_2442.exe) and check if processor is recognized
6. grab iplsplbreeze.zip attached here
7. use samsungs software and try to reflash your NAND
type: msp_2442.exe /f:iplsplbreeze.bin
type: 1 to choose the flash type
NAND flash type on hermes is k9f1g08 and should be recognized
type: 0 K9f1g08 Program
Start page and block must be set to 0
8. be patient

it sound so cool! but what is jtag ? could you tell us the step amply? we all want to know the detail ! thank you

jtag is a cable or a machine ?

can you show step by step (preferably with pictures), and explain in more details please? a lot of people bricked their meteor and your help is greatly appreciated. thank you.
p/s: what if i have no LPT port? can i use those USB to LPT converters?

Please use search button and find an excellent thread about hermes jtag an read all the pages.After that I am sure U will understand what it is.

joegsmro said:
Please use search button and find an excellent thread about hermes jtag an read all the pages.After that I am sure U will understand what it is.
Click to expand...
Click to collapse
but the pictures about jtag pins are too small ! could you upload a biger one ?

it works for mee
it works for me dude...
thank you very very much, now i can use my phone again..............

yusndi said:
it works for me dude...
thank you very very much, now i can use my phone again..............
Click to expand...
Click to collapse
did u build your own JTAG interfacing connector? or did u buy one?

i bought JTAG connector (wiggler clones TO LPT), i pluged one of the wiggler clones to the attached cable in JTAG pins and suddenly my phone connected to my pc via LPT (i use windows xp prof). i followed the procedures of write bootloader from JTAG, and it worked.

workers
which factory do you work for? in china

yusndi said:
i bought JTAG connector (USB TO LPT), i pluged one of the wiggler clones to the attached cable in JTAG pins and suddenly my phone connected to my pc via LPT (i use windows xp prof). i followed the procedures of write bootloader from JTAG, and it worked.
Click to expand...
Click to collapse
and where did u buy the wiggler clone?

i bought it in computer hardwares shop.

or try to find that cable in e-buy

or u may browse here
http://wiki.openwrt.org/OpenWrtDocs/Customizing/Hardware/JTAG_Cable
http://www.sparkfun.com/commerce/product_info.php?products_id=15 (MSP-JTAG Parallel Port Programmer),
it has also 2 kinds of the wiggler, there are separated wiggler clones and integrated wiggler clones. so, choose one u want to buy and use.

joegsmro said:
Hello to all.I messed up my bootloader in a customer breeze and found a solution to write it back with jtag.All is needed is a jtag interface and an utility here link http://210.118.57.197/Products/Semi...or/ARM9Series/SC32442/JtagFlash_Prog_Code.zip
First some usefull info about breeze mainboard:
jtag pins and Htc debug connector
Pin Signal | Signal Pin
------------+------------
1 TDO | TDI 2
3 TMS | TCK 4
5 n_TRST | ??? 6 (probably connected to ASIC3)
7 GND | A9 8
9 A8 | A7 10
11 A6 | A5 12
13 A4 | A3 14
15 A2 | A1 16
17 ??? | n_OE 18
19 ??? | GND 20
21 GND | n_SRST 22
23 D15 | D14 24
25 D13 | D12 26
27 D11 | D10 28
29 D9 | D8 30
31 D7 | D6 32
33 D5 | D4 34
35 D3 | D2 36
37 D1 | D0 38
39 VCC1.8 | GND 40
For better orientation pin 1 of the Htc debug connector is in the upper right corner with a white mark on it.
Ok, now lets write back the bootloader and the procedure is the following:
1. locate the JTAG pins
2. use a very small soldering iron and attach some wires to the testpoints
3. use one of the wiggler clones to built up a connection to the JTAG pins using LPT port of your host pc
4. insert fully charged battery and press power on button on breeze
5. use the samsung software (msp_2442.exe) and check if processor is recognized
6. grab iplsplbreeze.zip attached here
7. use samsungs software and try to reflash your NAND
type: msp_2442.exe /f:iplsplbreeze.bin
type: 1 to choose the flash type
NAND flash type on hermes is k9f1g08 and should be recognized
type: 0 K9f1g08 Program
Start page and block must be set to 0
8. be patient
Click to expand...
Click to collapse
I want to use this way to guide my gentle breeze, but JTAG cable has 14 stitch/ 10 stitch/ 20 stitch/ usage which? The gentle breeze has 40 stitch , joegsmro to have given out two set: How do A and D , JTAG cable and their link up? Whether be or not, is a group OK arbitrarily?
Excuse my English , its for coming from Godict translation helping me, please , thank very.

A very nice thread.
One question: since I can't find a wiggler jtag cable here in Chios, can I use an unbuffered one (made by me)?

It ain't working for me
Hi!
I had successfully written the bootloader with this method, but my phone still won't turn on. The reason it got bricked is because i tried to flash Hardspl into it and during that process it just turned off, and never to turn on again (not even tricolour screen).
Is there something I can do to unbrik this phone?
It was an SPV C700 (Orange network).
Thanks in advance
B.R.:
d3m0n

Use this app to write bootloader and post results. Regards JOE.

it works thank you,
But the problem is the screen goes white even after rom update
any idea?
thanks

Related

Rooting CRC37 (DREA110)

Hi guys,
I'm feeling stupid asking this but i have a new G1 now, the old one went to pieces, after i've dropped it from the 10th floor.
It is saying that is CRC37
Firmware version = 1.5
Baseband version = 62.505.20.17U_2.22.19.26I
kernel version = 2.6.27-00393-g6607056 [email protected] #1
DREA110 - PVT32B - CPLD-4
What i have tried:
1. Downloaded to the formated |FAT32| SD:
flashrec-20090815.apk
recovery-RA-magic-v1.2.3H.img
update.zip (EU)
2. Used ASTRO to install the APK file.
-> Run the program.
3. BackUp current recovery.
4. Type "/sdcard/recovery-RA-magic-v1.2.3H.img" into the text box.
-> Click "Flash Custom Recovery Image"
When Booting pressed HOME+POWER - Stuck at G1 screen for 30 minutes.
Removed battery .... restarted phone
Same CRC37 - nothing happened
followed these steps:
Now open up terminal and type
cd /sys/class/mmc_host/mmc1/
ls
You will find a directory mmc1:XXXX which are random numbers of some sort
cd /sys/class/mmc_host/mmc1/mmc1:XXXX
cat cid > /sdcard/cid.txt
The last line i do becuse USB is easy. Other people have found that just type; cat cid and then press the menu button and just email the terminal data to yourself :O.
Now that should have created a text file that you can now read of your SD card via the usb link.
Reverse the hex code like this and then zero the frist byte? (myne is below, it should be different for you.)
This is the string i got off the cid.txt file
03 53 44 53 55 30 31 47 80 30 ac a5 2b 00 91 ee
second row is all the bytes in reverse order. See the ee at the end is now the ee at the start and the 91 second from the end is now the second at the start.
ee 91 00 2b a5 ac 30 80 47 31 30 55 53 44 53 03
Finally zero the first byte which myne was ee now is 00
00 91 00 2b a5 ac 30 80 47 31 30 55 53 44 53 03
Go here to generate your goldcard
http://revskills.de/pages/goldcard.html
Just enter your cid and emailaddress, press the button "Continue" and
WAIT, only press Continue one time. It will then generate the goldcard and send it via Email.
Go grab HxD from http://mh-nexus.de/en/programs.php
Follow the details in this post. http://forum.xda-developers.com/showpost.php?p=3584419&postcount=246
Which are
- format sd card to fat32
- download HxD Hex Editor and install
- open program and go to "extra" and then "open disk"
- choose physical disk and then the removable disk. that is the same as your memory card. I've you don`t know with one it is. just remove the card and restart the program and you will see witch one is disappeared.
- uncheck open as readonly !!!!!!!
- go to "extra" again and the open disk image.
- open the goldcard.img witch you have created from Viper BJK website.
- press ok (512 is fine) en then "select all" and "copy"
- go to the removable disk tab and select offset 00000000 till offset 00000170 go to "edit" and then past write.
- save it
- now copy dreaming.nbh to the root off your memorycard.
- turn of your phone and restart by holding the camera and the power button.
Click to expand...
Click to collapse
Still same result - Not Allow ...
Tried with a few cards - 2 x 1GB Adata, 1x512MB Nokia, 2x2GB Sandisk, and 1x1GB Lexar.
What can i do ... what i'm doing wrong - ?
(ofcourse i press the right buttons). )
Help please ...
Erm, I have no idea what your talking about, lol, but if your just trying to root your G1, just start over and follow this;
http://forum.xda-developers.com/showthread.php?t=563679
Idk if your trying to do something special? If not, that guide should work perfectly for you.
The thing is that i receive a "Not Allow" at line 3 step 1 from the above guide.
Powering up G1 - holding camera button - Loading - Not Allow
Then Tricolor screen - Serial0
-------------------------------------------------------------
I think that the SPL is the problem. But i can't flash it - at least i don't know how ... or if that is possible ... Or maybe the BootLoader or FPL if something like this exists
-------------------------------------------------------------
Anyway ... thank you but i don't know what can i do ... for now i will use the soft i have without root ... maybe in time there will be an answer ...
-------------------------------------------------------------
Respect,
Soreen

How to change MAC address in Diamond ?

Hi, if this subject was here before ...... sorry , but i had a problem to find something like this here in this forum.
Is there any way to change MAC address of my wifi card ?
It can be temporary, maybe some registry changes ,or a program ?
Thanks in advance.
http://forum.xda-developers.com/showthread.php?t=292146&highlight=mac+change
Thanks, but this link was not clear enough (maybe i'm stupid ?) .
Is there any chance to do a program to change this MAC (temporary of course)?
Many people here could use it.
Could donate for fully working program.
Thanks.
used MTTY 1.4 maybe you can change your MAC address
make sure your useing a Cracked SPL
1. enter Tri-color screen connect your PPC with USB
2. in the port list of MTTY Choose USB and click OK
3. then you will to the Cmdline press Enter there will be CMD>
4. type : emapiwlanmac 01 02 03 04 05 06 (DO NOT COPY AND PASTE YOU MUST TYPE IT,PASTE IT WILL NOT WORK)
Hope this can help you ,my english not very well
This is word on C730

KFHD7 bricked with Uboot authentication failed

Hi,
I have a bricked x43z60. It does not turn on at all.it was bricked using this method:
http://rootkindlefire.com/kindle-fi...t-kindle-fire-hd-8-9-into-pure-android-tablet
I've shorted the usb boot pads and now when I connect the usb cable the device get recognized as OMAP4440 for a few seconds and disconnects.
I've soldered an USB-FTDI cable to the Rx Tx pad. In minicon I get the following output:
PPA supports 4460 1.x only
Detected device: 04460e11 HS
PPA 1.8.2 hash 27d8da40
Build Date: Aug 3 2012 Time: 17:39:44, ONLY PUBLIC DEBUG ON
!OBFUSCATOR ON!
SEC_STATUS = 000379a2
Production Build
Free space for PPA: 3396 bytes
The PPA is about to free 2356 bytes
Memory initialization...start
**## ddr_density 0x18 ...
ddr 1cs detected ...
Texas Instruments Inc X-Loader 1.41.0-g6178feb2 (Jun 24 2013 - 17:38:46)
OMAP4460: 1.2 GHz capable SOM
U-boot Signature Authentication...
>>>> Signature verification failed!(lv_Return=0x00000001)
Error, Uboot authentication failed.
X-Loader hangs
---------------------------------------------------
I tried to flash signed uboot like otter2-u-boot-prod-10.2.4.bin with usbboot tool but it hangs at "waiting for 2ndstage response..." at this point in the UART console I see the that the device tries to boot and hangs at the xloader again.
I do get some data back from the device before it tries to boot like:
CHIP: 4440
IDEN: abe2e556b3bebcc53db3c19df3e7cab9b84d9eab
MPKH: 1efc5375b48ba984056286d5fb6d85fd38e63a29a9ff21ee31afffd35c0c8c5e
CRC0: 229e85ba
CRC1: dc5874bc
It means that the device DO receives the id signal and responds to it but I can't tell if it processes the boot signal or loads the file to memory.
I've searched all over the place...Where can I get a properly signed u-boot file?
Thanks,
Vadim
Sounds like you know a lot about hardware modification. It's all alien to me
I hate to tell you this, but I don't think there are no signed u-boot files. The only ones that exist are Amazon's, and they are definitely not going to leak those out to the likes of us. Until they do, there's no way of fixing a brick like that
This thread here might explain more.
Ph0enix_216 said:
Sounds like you know a lot about hardware modification. It's all alien to me
I hate to tell you this, but I don't think there are no signed u-boot files. The only ones that exist are Amazon's, and they are definitely not going to leak those out to the likes of us. Until they do, there's no way of fixing a brick like that
This thread here might explain more.
Click to expand...
Click to collapse
There are no hardware modification. Just some debugging.
I don't really want to install custom roms or something, I just want that thing to work. The boot loaders on the device are already signed, so the ones that come with an update file. Can I (or someone with a working device) dump the bootloader from the device? Can I extract it from the update file?
vadimbrk said:
There are no hardware modification. Just some debugging.
I don't really want to install custom roms or something, I just want that thing to work. The boot loaders on the device are already signed, so the ones that come with an update file. Can I (or someone with a working device) dump the bootloader from the device? Can I extract it from the update file?
Click to expand...
Click to collapse
It's still more than I could understand:cyclops:
If you want to try extracting it from the update, you can download it straight from Amazon's website. Just rename it from whatevertheynameit.bin to whatevertheynameit.zip and use 7zip to extract.
The boot loader is already dumped and available in the updates mentioned above, the problem with trying to do what you are trying to do if I remember right is that you also need a signed xloader or something that is pushed and launched before the boot loader can be, and I think that isn't something you can dump because it doesn't exist on the kindles emmc, otherwise we would have had this method working a long time ago, though it does work on kf1's. Though I thought from what you have in the logs it sounds like it might not be xloader I'm thinking of, but I thought the boot loader was referred to as u-boot. Anyways sorry I don't know much more about what I'm talking about. I noticed you mentioned otter2, if you want to give it a shot otter2 is kf2, if you look in the android development section for kf2's, there's a method for unhardbricking it, but it requires a USB sdcard reader and being very good at soldering. Look for the thread by kurohyou.
Sent from my Amazon Kindle Fire HD running CM10.1 Tablet UI using xda-developers app
stunts513 said:
The boot loader is already dumped and available in the updates mentioned above, the problem with trying to do what you are trying to do if I remember right is that you also need a signed xloader or something that is pushed and launched before the boot loader can be, and I think that isn't something you can dump because it doesn't exist on the kindles emmc, otherwise we would have had this method working a long time ago, though it does work on kf1's. Though I thought from what you have in the logs it sounds like it might not be xloader I'm thinking of, but I thought the boot loader was referred to as u-boot. Anyways sorry I don't know much more about what I'm talking about. I noticed you mentioned otter2, if you want to give it a shot otter2 is kf2, if you look in the android development section for kf2's, there's a method for unhardbricking it, but it requires a USB sdcard reader and being very good at soldering. Look for the thread by kurohyou.
Sent from my Amazon Kindle Fire HD running CM10.1 Tablet UI using xda-developers app
Click to expand...
Click to collapse
The xloader is fine. Its the u-boot who's got corrupted. I've extracted the x loader and u-boot from the update bin. Still can't boot from it.
This is an OMAP 4460 HS(High Security) chip, I can't find any documentation to see if it supports booting from USB in this TrustZone secure state.
The usb booting option is almost offered by this device, they even made a marked pad for it....
Another option may be booting from serial using pserial and ukermit. It may offer more flexibility in the security checking crap....
In order to get into serial boot mode we need to locate the SYSBOOT pins. They located in the chip at:
GPIO 184 F26 0 SYS_BOOT0 SYSBOOT Input 0
GPIO 185 E27 0 SYS_BOOT1 SYSBOOT Input 1
GPIO 186 E26 0 SYS_BOOT2 SYSBOOT Input 2
GPIO 187 E25 0 SYS_BOOT3 SYSBOOT Input 3
GPIO 188 D28 0 SYS_BOOT4 SYSBOOT Input 4
GPIO 189 D27 0 SYS_BOOT5 SYSBOOT Input 5
They should have pullup resistors externally on the main board. If some one have a dead board with some free time and a heat gun that can pull the chip out and trace those pullup resistors....
I've managed to get the device in serial download mode by sending 0xF0034306 to the device right after the Get ASIC ID command(from modified usbboot) and then upload the u-boot file using pserial(via UART connection). The file get uploaded and then the device "freezes" for a minute or so until it restarts and spitting the " Signature verification failed!" error again.
vadimbrk said:
The xloader is fine. Its the u-boot who's got corrupted. I've extracted the x loader and u-boot from the update bin. Still can't boot from it.
This is an OMAP 4460 HS(High Security) chip, I can't find any documentation to see if it supports booting from USB in this TrustZone secure state.
The usb booting option is almost offered by this device, they even made a marked pad for it....
Another option may be booting from serial using pserial and ukermit. It may offer more flexibility in the security checking crap....
In order to get into serial boot mode we need to locate the SYSBOOT pins. They located in the chip at:
GPIO 184 F26 0 SYS_BOOT0 SYSBOOT Input 0
GPIO 185 E27 0 SYS_BOOT1 SYSBOOT Input 1
GPIO 186 E26 0 SYS_BOOT2 SYSBOOT Input 2
GPIO 187 E25 0 SYS_BOOT3 SYSBOOT Input 3
GPIO 188 D28 0 SYS_BOOT4 SYSBOOT Input 4
GPIO 189 D27 0 SYS_BOOT5 SYSBOOT Input 5
They should have pullup resistors externally on the main board. If some one have a dead board with some free time and a heat gun that can pull the chip out and trace those pullup resistors....
Click to expand...
Click to collapse
If I'm understanding right, the OMAP drivers are showing in device driver? I don't think anyone has got the KFHD to work after this. If I'm understanding the situation properly that is. That would be some history right there.
Sent from my Amazon Kindle Fire HD running CM 10.2 using xda app-developers

How To Unbricked A Hard Bricked Phone [ Moto X ]

How To UnBrick A Hard Bricked Moto X​
Hii , First of all I wanna thanks to this awesome scrpit by @s5610 who brought my phone from dead to alive , I think i am the first guy to unbricked the hardbricked phone using this script lol , My phone was hardbricked because i was testing my kernel and entered wrong path in partition due to which i got hard bricked i was worried for my phone , Service Center was asking for 7k in Indian Rupees , i was hopeless then i gave a try to this method , followed all steps written here and then finally i entered to fastboot menu of 30.B7 Kitkat As i was using 30.B7 Bootloader earlier and then i flashed My gpt.bin and S-partition and flashed my stock rom voilla !! and my phone booted the aim was to share this post was this method was on page 42 and only less guys have seen this post , so i created a new thread regarding this
All Credits Goes to - @s5610​
s5610 said:
Unbricking Guide for any Moto X Gen 1 (wire trick)​
Download, and unpack supplied zip to any disk, C: or D:, in root folder. Install driver by launching Qusb.drv.inst.msi, then open Windows' Device Manager, and see if you got "Qualcomm HS-USB QDLoader 9008" device (it is "QHSUSB_DLOAD" without driver installed) located in "COM & LPT ports" section.
If yes, you see it, go to software part below. If it's not there, a full disassemble of the phone is needed to get close to back side of motherboard (google for "iFixit Teardown Moto X Guide" for step-by-step instruction).
So, when you are inside, disconnect the battery first. No need to pull it out, it's glued. Now get to back side of motherboard, and very very gently gain access to the lower left corner of ARM+DRAM shield (see picture). I've done it with Stanley knife. Also you can use miniature nippers - but very carefuly! Once you get access to inner space of shield, use tiny wire to short special pin to the ground (see picture), then connect USB cable, and in the moment when you see "QHSUSB_DLOAD" device (or "Qualcomm HS-USB QDLoader 9008" if driver is installed) pop out in Windows' Device Manager, quickly remove the wire. The goal is to have "Qualcomm HS-USB QDLoader 9008" in "COM & LPT ports" section of Device Manager. If it is achieved, we are done with hardware, and move on to soft part.
Now software part. Go to unzipped C:\Python27 folder, launch bat-file, and wait until finish:
RUN_blank_bootloader_flash.bat
(if you got error like "No data read from USB..." etc, just skip to next step)
Next launch either
- .Boot_KK_4.4.2_B4.exe,
or .Boot_KK_4.4.4_B7.exe,
or .Boot_LP_5.0.2_BC.exe,
or .Boot_LP_5.1.0_BD.exe,
or .Boot_LP_5.1.0_BE.exe
- depends on Android version your phone has last time. If you don't know what you need, begin with first one.
Wait 10 seconds, then launch next bat-file, and wait until finish:
RUN_moto_x_bootloader_flash.bat
Phone should go into fastboot mode! If it doesn't, repeat previous step trying higher version. But don't try to flash BC, BD, and BE, if you didn't install Lollipop on this phone!
OK. Disconnect the USB cable, connect the battery, connect again USB cable (fastboot don't work, if don't see battery). Launch next bat-file:
RUN_gpt.bin_flash.bat
The phone will get in fastboot, ready to be flashed by appropriate firmware. If it is official RSD (SBF), delete from xml strings consisting gpt.bin and motoboot.img for safe flashing.
...
Download link: http://www.mediafire.com/download/3e38rr3wy28s071/Moto.X.Unbrick.zip
This guide was brought to you by s5610
Links that this guide is based on (where I took files and general idea):
http://forum.xda-developers.com/droid-ultra/general/droid-ultra-maxx-brick-recovery-t2830806
http://forum.xda-developers.com/mot...-moto-x-t2629057[/url[/QUOTE][/QUOTE][/QUOTE]
Click to expand...
Click to collapse
Click to expand...
Click to collapse
Click to expand...
Click to collapse
Not sure if additional thread is necessary )
UPDATED
The best resurrection method for Moto X is here.
Can Someone re-upload that file? Thanx!
Please upload the mediafire link...
Plz plz.. I have bricked my phone. It seems that this procedure will work for me. Please upload and save my life.
even i have bricked my moto x...need a working download link..please.
https://drive.google.com/file/d/0B3EDzuzDCakzdWxHa2RWVDJhRXc/view?usp=sharing
Cannot install qsub.drv.inst.msi on my windows 10...says failed to attribute and failed to delete qcusbser.sys.
Thanks
Can we write the full firmware through Qload 9008 mode ???
HI I have a question. I bricked my gf's phone while trying to unlock the bootloader and I am not able to turn the phone on. Only positive feedback is that when I plug it in to the computer, I can hear a notification on my computer. I followed your guide. I can see the "Qualcomm HS-USB QDLoader 9008" device (it is "QHSUSB_DLOAD" without driver installed) located in "COM & LPT ports" section.
Then I followed your software instructions. When I run the RUN_blank_bootloader_flash.bat, I get the following
Code:
Starting qflash!
Executing command qflash.exe -com3 -ramload MPRG8960.hex -mbn 33 MSM8960_bootloa
der_singleimage.bin -v -o
Motorola qflash Utility version 1.3
qflash - com3 is an invalid port
Invalid COM port enteredBlank flashing successful
Device will now enumerate in fastboot mode
Then, I followed the rest of the instructions by trying each .Boot .exe and waitng 10 seconds and finally with RUN_moto_x_bootloader_flash
but I am getting the following error.
Code:
C:\Users\cxx\Desktop\Python27>python qdload.py MPRG8960.bin -ptf _boot\partiti
ons.txt -pt
QDLoad utility version 1.2 (c) VBlack 2014
Found TTY port: com3
Traceback (most recent call last):
File "qdload.py", line 815, in <module>
main()
File "qdload.py", line 762, in main
tty = openTTY(args.ttyPort)
File "qdload.py", line 174, in openTTY
tty = serial.Serial(port=tty_path, baudrate=115200)
File "C:\Python27\lib\site-packages\serial\serialwin32.py", line 38, in __init
__
SerialBase.__init__(self, *args, **kwargs)
File "C:\Python27\lib\site-packages\serial\serialutil.py", line 282, in __init
__
self.open()
File "C:\Python27\lib\site-packages\serial\serialwin32.py", line 66, in open
raise SerialException("could not open port %r: %r" % (self.portstr, ctypes.W
inError()))
serial.serialutil.SerialException: could not open port 'com3': WindowsError(2, '
The system cannot find the file specified.')
C:\Users\cxx\Desktop\Python27>pause
Press any key to continue . . .
please help.
Thanks.
Device Shows As USB Input
Hey all,
I'm having trouble getting my Windows 7 machine to recognize my XT862 as a QHSUSB device. Windows does recognize it, just as a "USB Input Device" -- very generic, I know -- so I don't think I have to do any motherboard hacks (and I sure hope not!). However, as it won't let me update the driver either, so I can't do anything. Also, when I plug it into my Mac, it does pop up as a Qualcomm Composite Device. Since something's obviously still ticking, where did I go wrong?
Thanks
shengslogar said:
Hey all,
I'm having trouble getting my Windows 7 machine to recognize my XT862 as a QHSUSB device. Windows does recognize it, just as a "USB Input Device" -- very generic, I know -- so I don't think I have to do any motherboard hacks (and I sure hope not!). However, as it won't let me update the driver either, so I can't do anything. Also, when I plug it into my Mac, it does pop up as a Qualcomm Composite Device. Since something's obviously still ticking, where did I go wrong?
Thanks
Click to expand...
Click to collapse
Put it on a charger for 5-6 hrs and see if that will help.I had this same problem but on a Moto G and charging it up helped.
liveroy said:
Put it on a charger for 5-6 hrs and see if that will help.I had this same problem but on a Moto G and charging it up helped.
Click to expand...
Click to collapse
Will do! I think I did try charging it awhile ago, but I'll give it another shot.
can my phone be unbricked?? here is the error log:
RAMLOADER VERSION: PBL_DloadVER2.0
------------------------------------------------------
DEVICE INFORMATION:
------------------------------------------------------
Version : 0x8
Min Version : 0x1
Max Write Size: 0x600
Model : 0x90
Device Size : 0
Description : Intel 28F400BX-TL or Intel 28F400BV-TL
------------------------------------------------------
Using passed in packet size, changing from 0x600 -> 0x600
EXTENDED_LINEAR_ADDRESS_REC @ 0x2a000000
Write 65536 bytes @ 0x2a000000
100EXTENDED_LINEAR_ADDRESS_REC @ 0x2a010000
Write 11840 bytes @ 0x2a010000
100START_LINEAR_ADDRESS_REC @ 0x2a000000
EOF_REC
Sleeping for 3s
sdl_hello() - Invalid response: 7e030003331b7e
sdl_hello() - This is a NAK response from ROM code, which means the device has
een reset back to blank flash mode. Usually this is caused by power supply issu
s. Please try again with battery eliminator if it persists
Unexpected target reset, bailing out after 2 retries
I am trying to install the drivers and it will show up as qhsusb_dload for about 5 seconds then reverts back to Relink HS USB QDloader 9008. Should i try the wire trick? It will say that the Qhsusb drivers are installed but always changes.

Cannot get TpDebrick to work on 16GB HP Touchpad

Hello,
So I'm trying to use the TPDebrick tool by jcsullins to get my old touchpad to work again. Now the thing still boots just it'll only go to the battery with a question mark symbol. Now whenever I put it into the mode where I hold Power+Home Button+Vol Down and use the tool the terminal will put out this.
sudo ./tpdebrick 16
Checking doc files ...
Requesting SoftwareVersion...
Version: PBL_DloadVER1.0
Requesting Params...
Invalid Response: 06 01 01 00 90 00 00
load of emmcbld.bin failed
Aborting.
Not sure why its doing this but if anyone has any idea let me know. If you need more info about something I didnt list here let me know and Ill provide it. Thanks!
Camry2731 said:
Hello,
So I'm trying to use the TPDebrick tool by jcsullins to get my old touchpad to work again. Now the thing still boots just it'll only go to the battery with a question mark symbol. Now whenever I put it into the mode where I hold Power+Home Button+Vol Down and use the tool the terminal will put out this.
sudo ./tpdebrick 16
Checking doc files ...
Requesting SoftwareVersion...
Version: PBL_DloadVER1.0
Requesting Params...
Invalid Response: 06 01 01 00 90 00 00
load of emmcbld.bin failed
Aborting.
Not sure why its doing this but if anyone has any idea let me know. If you need more info about something I didn't list here let me know and Ill provide it. Thanks!
Click to expand...
Click to collapse
First of all the HP TOUCHPAD can not be bricked, it is my opinion that was a falsely driven narrative of the past, that has been mostly debunked by modern techniques. Now those people in the past who thought the HP TOUCHPAD can be bricked, may have been honest in their opinion but it was probably out of ignorance.
I will point you to a modern technique to "de-brick" your tablet, but I am afraid the symbol you are getting is
a "battery with a question mark" so it sounds like your battery is not being detected or its damaged. But I will want you to flash the "A6 firmware" and that will probably fix your issue. So you have some reading to do pal. Start with this link: Good luck and Good Day. I have "cc'ed" some of the best mind on this thread ( well the only minds LOL )
to read your problem and offer help, or engage in debate. LOL
https://forum.xda-developers.com/hp-touchpad/general/hp-touchpad-novacom-repair-android-t3960435
@HP_TOUCHPAD
 @smithylovestouchpad
 @middle_road
Discharged Battery
If the Tablet displays any simbol on the screen, then is not brick and is working as it should.
The original HP Charger must be use and it could take a week to get some minimal charge.
So I know this post is super old, but wanted to update and say I got it working finally and its good to go, I appreciate all the help
HP TOUCHPAD DEBRICK Linux Live CD
I have created an Ubuntu Live CD with all the necessary files to Debrick the Tablet from TP Debrick v005 by jcsullins.
If there is any Tablet that did not finished the flash process, run this Live CD and perform the Debrick again.
If you do not know the Tablet model do the following:
Flash using the 16 GB, then connect to charger. If the home LED does not come on after some time then.
Flash using the 32 GB, then connect to charger. If no LED light then
Flash using the 64 GB.
All process must finish in " ALL DONE "
Click HERE for the HP TOUCHPAD DEBRICK LIVE CD
For information about charging a Tablet after been store for 9 years go here:
https://forums.webosnation.com/hp-touchpad/332615-hp-touchpad-won-t-turn-brand-new-never-opened.html

Categories

Resources