please some suggestion for my bricked device - JASJAR, XDA Exec, MDA Pro General

Hello,
I have a type1brick.
I corrupt the radio after failed rom flash, now If i do a classic rom update, the process stuck at 0,1%.
I modify the hpruu.ini to reinstall the ceos and can reboot.
My device is a Ipaq 6515, but all i read here look very close and bootloader command are the same and a lot work for my device...and my questions general & not specific to this device.
Now I have a working os but no Gsm and the asset info blank (stack, imei ,etc..) just Radio present = Yes (The Gps & Bluetooth is ok.
With all i read on this forum i think or i have or :
1/ a CID problem
The command i try in bootloader :
Info 0 = Beetles
Info 1 = Bootloader
info 2 = NOTHING !!!
Just USB>
2/ A Corrupted OS of the radio that i have to manually erase (cf pof solution) and rewrite.
We have the password 0000000000000000 and erase and wdata work.
Rtask test :
Rtask 1 & 2 = radio on/off = ok
Rtask 3 = Radio image loaded
Rtask 4 = radio bootloader loaded
ernal bootloader & Stuck
Rtask 0 = Reset radio ok
Rtask a = stuck
rtask b : go to external bootloader & stuck
I successfully launch the radio booloader and the Radio Rom ??
So it's the Radio OS ??
We have do a dump rom of a working device on SD card,
of this adress : 60000000 with a length of 800000.
But the sd dump to our device fail to flash (via sd card)
If in the bricked device we do :
USB>Checksum
number is ok
but with the specified adress range d2s & checksum fail.
The device show "Cal.Checksum" and nothing happen.
I was very happy to have conclusions,
and if i can believe and spend time to investigate to solve my problem,
or if it's dead. My warranty is over and HP ask for 350$ motherboard replement.
So i really ready to try everything.
Thanks in advance for your analyse and suggestions.
Dimitri
Info log when trying to update the radio rom :
LOG of a Beetle P10504_BT_HP_Radio_Patch.EXE.
It hangs at 0% when trying to upgrade and the log looks like that:
09:20:18:137 [msg] : Client_Logging() !
09:20:18:137 [msg] : =============================================
09:20:18:137 [msg] : START Client_Initialize() !
09:20:18:137 [msg] : Call CheckActiveSyncVersion() !
09:20:18:137 [msg] : Call CheckCEMode() !
09:20:21:923 [msg] : Currecnt Not in CE Mode or in CE Mode but ActiveSync Not Connected.
09:20:21:923 [msg] : Call DisconnectActiveSync() !
09:20:26:149 [msg] : Start Get Connect Port !
09:20:26:379 [msg] : Currecnt in BL Mode. Open Port : [\\.\WCEUSBSH001] OK.
09:20:26:409 [msg] : Device CE Start Address : [80000000].
09:20:26:419 [msg] : Device Radio Start Address : [0].
09:20:26:419 [msg] : END Client_Initialize() !
09:20:26:419 [msg] : =============================================
09:20:26:419 [msg] : START Client_FlashRadioOS() ! FileName : [RADIOOS.nbf] ; HeaderLen : [1260].
09:20:26:439 [msg] : END Client_FlashRadioOS() !
09:20:26:439 [msg] : =============================================
09:20:46:508 [err] : Check Radio Status Error.
Attached you find a usbmonitor of a classic Hp rom update failed :
Thank for your help ! and sorry for the long post

dim920 said:
Hello,
I have a type1brick.
I corrupt the radio after failed rom flash, now If i do a classic rom update, the process stuck at 0,1%.
I modify the hpruu.ini to reinstall the ceos and can reboot.
My device is a Ipaq 6515, but all i read here look very close and bootloader command are the same and a lot work for my device...and my questions general & not specific to this device.
Now I have a working os but no Gsm and the asset info blank (stack, imei ,etc..) just Radio present = Yes (The Gps & Bluetooth is ok.
With all i read on this forum i think or i have or :
1/ a CID problem
The command i try in bootloader :
Info 0 = Beetles
Info 1 = Bootloader
info 2 = NOTHING !!!
Just USB>
2/ A Corrupted OS of the radio that i have to manually erase (cf pof solution) and rewrite.
We have the password 0000000000000000 and erase and wdata work.
Rtask test :
Rtask 1 & 2 = radio on/off = ok
Rtask 3 = Radio image loaded
Rtask 4 = radio bootloader loaded
ernal bootloader & Stuck
Rtask 0 = Reset radio ok
Rtask a = stuck
rtask b : go to external bootloader & stuck
I successfully launch the radio booloader and the Radio Rom ??
So it's the Radio OS ??
We have do a dump rom of a working device on SD card,
of this adress : 60000000 with a length of 800000.
But the sd dump to our device fail to flash (via sd card)
If in the bricked device we do :
USB>Checksum
number is ok
but with the specified adress range d2s & checksum fail.
The device show "Cal.Checksum" and nothing happen.
I was very happy to have conclusions,
and if i can believe and spend time to investigate to solve my problem,
or if it's dead. My warranty is over and HP ask for 350$ motherboard replement.
So i really ready to try everything.
Thanks in advance for your analyse and suggestions.
Dimitri
Info log when trying to update the radio rom :
LOG of a Beetle P10504_BT_HP_Radio_Patch.EXE.
It hangs at 0% when trying to upgrade and the log looks like that:
09:20:18:137 [msg] : Client_Logging() !
09:20:18:137 [msg] : =============================================
09:20:18:137 [msg] : START Client_Initialize() !
09:20:18:137 [msg] : Call CheckActiveSyncVersion() !
09:20:18:137 [msg] : Call CheckCEMode() !
09:20:21:923 [msg] : Currecnt Not in CE Mode or in CE Mode but ActiveSync Not Connected.
09:20:21:923 [msg] : Call DisconnectActiveSync() !
09:20:26:149 [msg] : Start Get Connect Port !
09:20:26:379 [msg] : Currecnt in BL Mode. Open Port : [\\.\WCEUSBSH001] OK.
09:20:26:409 [msg] : Device CE Start Address : [80000000].
09:20:26:419 [msg] : Device Radio Start Address : [0].
09:20:26:419 [msg] : END Client_Initialize() !
09:20:26:419 [msg] : =============================================
09:20:26:419 [msg] : START Client_FlashRadioOS() ! FileName : [RADIOOS.nbf] ; HeaderLen : [1260].
09:20:26:439 [msg] : END Client_FlashRadioOS() !
09:20:26:439 [msg] : =============================================
09:20:46:508 [err] : Check Radio Status Error.
Attached you find a usbmonitor of a classic Hp rom update failed :
Thank for your help ! and sorry for the long post
Click to expand...
Click to collapse
Humm... that is quite a mouthful. Have you got the correct version of Radio_.nbf ? Not really sure how things work in ipaq. If you have not tried this already, please remove all the .nbf files (in a full rom upgrade package there are 3) except the radio_.nbf and execute the upgrade with the original cable while in the bootloader mode. The original cable is particularly recomended for radio roms. Out of the three .nbf files radio_.nbf takes the maximum time so be patient. Hope this works....and yes please do search an ipaq fora as you will get more specific help.

Thank you very much to try to help me !
The Beetles device work very close to yours.
Excuse me to come in this forum, but i look around the world forums,
but i think helpfull persons are on device like yours.
The Rom upgrade beetles from Hp come with Hpruu.exe and 4 files :
RadioOS.nbf
RadioFS.nbf
CEOS.nbf
Extrom.nbf
If i do only a selected upgrade as you say, i can reinstall the Os,
but never the Radio, always stuck at 1%.
(after os reinstall, gps & bluetooth ok, but gsm asset blank)
It's very similar problem to a lot of bricked Universal device who was
successfully unbricked here.
I spend a lot of time in the Bootloader,
I Know now that my CID is ok, but my Radio Os dead.
All success story i see here manually erase some adress range,
and manually rewrite the radio part.
I can do that in the bootloader with commande "erase" and "wdata".
But i don't know how in the other device you have successfully
find the good adress range to erase and rewrite.
How i can investigate this ?
I have all install of rom from Hp, unofficial, dump rom of a working device of a selected adress range who normally include the radio part, etc..
Thank you
Dim

Related

AKU2.x CID and SIM unlock guide

I wrote this guide because i got frustrated at the seeming impossibility of downgrading a 2.21+ SPL ROM on my Wizard to CID unlock it, and the fact that lokiwiz did not work either.
After a day of research it became apparent that this was far from the truth, and that it was easily unlockable. All the tools were out there, just there wasn't a guide to help direct someone through all the steps.
Well this is that guide.
I've tried to make it newbie friendly, and although this has only been tested on my wizard, i see no reason why this wouldn't work on the Typhoon(infact most of the tools used are originally for the Typhoon) and Tornado seeing as they have almost identical boot loaders.
The guide comes with the usual warning:
“If you manage to brick your phone, it wasn't my fault ”
I cant stress this point enough though, get a few numbers wrong in some of the commands in the guide, and you could break your phone, tripple check everything you type in!!
Attached is the guide in a zipped version in html and .doc format (html for those of you that cant be arsed with MS Word files)
Enjoy
This guide works on G3 phones only, regardless of ROM version, but i see little point in going through all these steps when for 90% of you, lokiwiz should work fine. So i suggest you only use this guide if you are having trouble with lokiwiz, and/or you a 2.21+ SPL G3 Wizard.
**EDIT**Guide back up and updated
Looks good Craptree,
Unfortunately I don't own a G4 device to try it on.
Would love to hear some feedback from users that have a G4 CID Locked Wizard and used this how-to to succesfully CID unlock their G4 Wizard.
Regards,
Molski
Thankyou
keep up the good work Molski
Firstly good work, that was some reading and collating you did , I ive worked my way through but when i come to write the unlocked.nb file back using " pdocwrite -n 1 unlocked.nb" i get this error
CopyFileToTFFS(unlocked.nb:0, 0, 00010000)
ERROR: ITWriteDisk - A device attached to the system is not functioning.
can you shed some light.
Ok ive done some snooping around should the last command be something like
pdocwrite -n 1 0 0x10000 unlocked.nb ??
I have tried this method. And got cid.bin file from the device. How can I convert the cid.bin to cid.nf file? Will this command "perl typhooncidedit.pl cid.bin" will generate the cid.nf file? I don't get it. Please help me. Thanks!
Hi im by no means anywahere near an expert (as you can see from my posting above) but from my limited experience i can say no, perl typhooncidedit.pl cid.bin will read the current file , though note you need to reboot after installing Active Perl and there seems to be a spelling mistake in the commands in the howto its typhooncidedit_pl note the underscore not a full stop.
Its the command "perl typhooncidedit_pl cid.bin -c 11111111 -w unlocked.bin" that creates the file to be written back to the phone. However this is where it ends for me as i cant get the next stage to work just yet and am a little weary of playing around without mor einformed guidence in case i brick the device.
problem with soulcage
when I try to download the package with the crypt-des i got this message:
soulcage.net
This domain name expired on 10/09/2006 and is pending renewal or deletion.
is there any other place to get this package?!?
weird i did it last night and it worked, i even just reopened activeperl and it rececked with no errors, you are downloading the package through activeperl arent you ?
I'm also getting the ITWriteDisk errror and the problem with the Crypt-DES repository. Found Crypt-DES at http://theory.uwinnipeg.ca/ppms/ in the end.
wblqx - oops, looks like i got muddled up with my file name extensions. it doesnt matter if the files a .nb or .bin, theyre both identical. just reference the file you have. so if you have a cid.bin, the command would be
perl typhooncidedit.pl cid.bin -c 11111111 -w unlocked.nb
flipside101 - hmmm im not quiet sure why it wont let you write the file back...all i can sugest is to make sure that cert_spcs.cab and enablerapi.cab have been loaded onto your phone. have you tried copying the files onto your phone and running them manualy?
PS - ive chaged the orignal guides to avoid this confusion in the future wblqx
Ok, I got the crypt-des from here: http://theoryx5.uwinnipeg.ca/ppms/package.xml
and it's version 2.05 from Dave Parishere and this is what I have here:
I got the cid.bin file and this is what I read "inside" it:
D:\qtek\cid>perl typhooncidedit.pl cid.bin
0x0000 - version : 00000001
0xfff8 - checksum: keyix=48: f75b0704 - f2c82199ed8f7449
0x01a0 - keyindex: 000000e600000000 -> 230
0x1930 - cid key : 'MODULESN'
0x0160 - cid : 0008:'WIZQTK01' 0e0f101112131415161718191a1b1c1d1e1f20212223
0x1c80 - lockflag: 0000000000000000
0x0140 - imei : 3563840009225810
0x1d00 - lock 0 : 7bea42ec25ae4b6eac30b47d9691fdac
0x1d10 - lock 1 : 4a02f79b693fe782ad1cf1a9133fc981
0x1d20 - lock 2 : 5afd85493fd413c46b2a28d3ead12c0e
0x1d30 - lock 3 : c82b3203be8574b85f141684499d1d85
0x1d40 - lock 4 : ea60e2bc84f2f60fc730cea22b3147ab
0x4000 - mncmcc : f5a235190000000000000000875f796f5cd3ce3ed6b1a16fc7cef324eed501e8
(the locks codes appears to be crypted, is that correct?)
then I did the perl typhooncidedit.pl cid.bin -c 11111111 -w unlocked.nb and got it:
D:\qtek\cid>perl typhooncidedit.pl cid.bin -c 11111111 -w unlocked.nb
0x0000 - version : 00000001
0xfff8 - checksum: keyix=48: f75b0704 - f2c82199ed8f7449
0x01a0 - keyindex: 000000e600000000 -> 230
0x1930 - cid key : 'MODULESN'
0x0160 - cid : 0008:'WIZQTK01' 0e0f101112131415161718191a1b1c1d1e1f20212223
0x1c80 - lockflag: 0000000000000000
0x0140 - imei : 3563840009225810
0x1d00 - lock 0 : 7bea42ec25ae4b6eac30b47d9691fdac
0x1d10 - lock 1 : 4a02f79b693fe782ad1cf1a9133fc981
0x1d20 - lock 2 : 5afd85493fd413c46b2a28d3ead12c0e
0x1d30 - lock 3 : c82b3203be8574b85f141684499d1d85
0x1d40 - lock 4 : ea60e2bc84f2f60fc730cea22b3147ab
0x4000 - mncmcc : f5a235190000000000000000875f796f5cd3ce3ed6b1a16fc7cef324eed501e8
olddata: 6d18c04e8ed463a6460f100469464259621e8365aeb43277cf2858b925828379
newdata: 95ea23df0bf16432cf7be60912a5cbdedee342037c9d3bd3dee342037c9d3bd3
newsum=3c8b458b encsum=4e3630065084dd42
and at least the: pdocwrite -n 1 unlocked.nb gave me this:
D:\qtek\cid>pdocwrite -n 1 unlocked.nb
3 partitions, 2 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 96 10 01 04 13 1d 11 2c 15 03 06 c5
CopyFileToTFFS(unlocked.nb:0, 0, 00010000)
ERROR: ITWriteDisk - An internal error occurred.
captree, do you have any clue about what is wrong?
here is the unlocked.nb:
D:\qtek\cid>perl typhooncidedit.pl unlocked.nb
0x0000 - version : 00000001
0xfff8 - checksum: keyix=48: 3c8b458b - 4e3630065084dd42
0x01a0 - keyindex: 000000e600000000 -> 230
0x1930 - cid key : 'MODULESN'
0x0160 - cid : 0008:'11111111' 00000000000000000000000000000000000000000000
0x1c80 - lockflag: 0000000000000000
0x0140 - imei : 3563840009225810
0x1d00 - lock 0 : 7bea42ec25ae4b6eac30b47d9691fdac
0x1d10 - lock 1 : 4a02f79b693fe782ad1cf1a9133fc981
0x1d20 - lock 2 : 5afd85493fd413c46b2a28d3ead12c0e
0x1d30 - lock 3 : c82b3203be8574b85f141684499d1d85
0x1d40 - lock 4 : ea60e2bc84f2f60fc730cea22b3147ab
0x4000 - mncmcc : f5a235190000000000000000875f796f5cd3ce3ed6b1a16fc7cef324eed501e8
Hi Craptree, no i tried the manual running of rapi but i still get the same error
D:\XDA\CID>pdocwrite -n 1 unlocked.bin
CopyFileToTFFS(unlocked.bin:0, 0, 00010000)
ERROR: ITWriteDisk - A device attached to the system is not functioning.
In case its any help heres some info on the locked and unlocked files
LOCKED
D:\XDA\CID>perl typhooncidedit_pl cid.bin
0x0000 - version : 00000001
0xfff8 - checksum: keyix=55: 431ca7b6 - fa9d45e5b52e53c3
0x01a0 - keyindex: 0000004a00000000 -> 74
0x1450 - cid key : 32421a0edf4fa9d6
0x0160 - cid : 0008:'WIZO2B01' 0e0f101112131415161718191a1b1c1d1e1f20212223
0x1c80 - lockflag: 0000000000000000
0x0140 - imei : 3563830004598750
0x1d00 - lock 0 : a2a9faccbbfbc0d94497e96264896558
0x1d10 - lock 1 : 58ff98fb2af1350f7fca4f890f358808
0x1d20 - lock 2 : 7b53c3aa8c9d522e46e73b558d75f287
0x1d30 - lock 3 : 0e92d1ddbc64b8e5f8c9950a0bf33284
0x1d40 - lock 4 : 92895c989f8ac37c77b97eadef53e5dc
0x4000 - mncmcc : 095ce2420000000000000000c7c8aba45e2c4b0f8d5e300ab86152430094117c
UNLOCKED
D:\XDA\CID>perl typhooncidedit_pl unlocked.bin
0x0000 - version : 00000001
0xfff8 - checksum: keyix=55: 7d3a21f5 - fdee2cb45bfc5c18
0x01a0 - keyindex: 0000004a00000000 -> 74
0x1450 - cid key : 32421a0edf4fa9d6
0x0160 - cid : 0008:'11111111' 00000000000000000000000000000000000000000000
0x1c80 - lockflag: 0000000000000000
0x0140 - imei : 3563830004598750
0x1d00 - lock 0 : a2a9faccbbfbc0d94497e96264896558
0x1d10 - lock 1 : 58ff98fb2af1350f7fca4f890f358808
0x1d20 - lock 2 : 7b53c3aa8c9d522e46e73b558d75f287
0x1d30 - lock 3 : 0e92d1ddbc64b8e5f8c9950a0bf33284
0x1d40 - lock 4 : 92895c989f8ac37c77b97eadef53e5dc
0x4000 - mncmcc : 095ce2420000000000000000c7c8aba45e2c4b0f8d5e300ab86152430094117c
Hello,
First I have to say this initiative for a CID unlock guide is GREAT !
Unfortunately, I went to the same process and also got write error in the end.
Here's for me :
- Had to use Crypt-DES from http://theoryx5.uwinnipeg.ca/ppms/package.xml while Soulcage.net access is off (or so it seems)
- Installed Cert_SPCS.cab and EnableRapi.cab both using .bat and manual installation
- Was able to get the CID.bin & modify without problem
- Last operation results in following error:
"3 partitions, 2 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 3a 20 01 02 23 2a 12 8d 01 09 05 40
CopyFileToTFFS(cid_unlocked.nb:0, 0, 00010000)
ERROR: ITWriteDisk - Internal error" (translated from French).
My CID binaries :
## perl typhooncidedit.pl cid_original.bin
0x0000 - version : 00000001
0xfff8 - checksum: keyix=40: 1cab1674 - 37f31b4a27fe4616
0x01a0 - keyindex: 000000d900000000 -> 217
0x18c8 - cid key : 'MODULESN'
0x0160 - cid : 0008:'WIZQTK24' 0e0f101112131415161718191a1b1c1d1e1f20212223
0x1c80 - lockflag: 0000000000000000
0x0140 - imei : 3563840001521300
0x1d00 - lock 0 : 76a905824418f065eefd32cbfb611d28
0x1d10 - lock 1 : 91450180424a15f000bdd1851e5fbb51
0x1d20 - lock 2 : c14cc13d337415f59b71512adfb0319d
0x1d30 - lock 3 : 8b62365380a7f3436e43a4299ce97c0d
0x1d40 - lock 4 : 867bbb89c9d3593a72621810278c89db
0x4000 - mncmcc : 762173b9000000000000000091bcf2bbcf1921a206e6fd057e61d6c08f467a95
## perl typhooncidedit.pl cid_unlocked.nb
0x0000 - version : 00000001
0xfff8 - checksum: keyix=40: 500ec10b - c44c8893515dcabf
0x01a0 - keyindex: 000000d900000000 -> 217
0x18c8 - cid key : 'MODULESN'
0x0160 - cid : 0008:'11111111' 00000000000000000000000000000000000000000000
0x1c80 - lockflag: 0000000000000000
0x0140 - imei : 3563840001521300
0x1d00 - lock 0 : 76a905824418f065eefd32cbfb611d28
0x1d10 - lock 1 : 91450180424a15f000bdd1851e5fbb51
0x1d20 - lock 2 : c14cc13d337415f59b71512adfb0319d
0x1d30 - lock 3 : 8b62365380a7f3436e43a4299ce97c0d
0x1d40 - lock 4 : 867bbb89c9d3593a72621810278c89db
0x4000 - mncmcc : 762173b9000000000000000091bcf2bbcf1921a206e6fd057e61d6c08f467a95
Could this be because we had to use a different Crypt-DES package ? Or shall we look some other reason ?
Thanks and good luck
Sylvain
This is weird, it looks like its worked no one except me
sorry...
my wizard was a G3, but it was locked into 2.26 spl, and refused to be
unlocked with lokiwiz (as G3's with 2.21+ roms seem to have the same problem with cid unlocking that G4's do), or any thing else, and this manual way was the
only thing that did the job for me...
I have two reasons, and i fear its the first one...
1)G3 2.21+ CID locked phones don't have the same problem with CID unlocking that G4's do. So this solution may only work on G3 2.21+ phones
2)I semi downgraded the phone with ftp://xda:[email protected]__RUU_Wizard_1050412_WWE_101_11210_WWE.exe first (it downgraded everything except the spl), then did all the steps layed out in the guide.
riz
jubanet - yea, it appears the lock code is encrypted. if someone with the crypted lock code cid.bin files could send me one, i can see if it appears unencrypted on my version of crypt-des
craptree said:
jubanet - yea, it appears the lock code is encrypted. if someone with the crypted lock code cid.bin files could send me one, i can see if it appears unencrypted on my version of crypt-des
Click to expand...
Click to collapse
here it is!
craptree said:
This is weird, it looks like its worked no one except me
sorry...
my wizard was a G3, but it was locked into 2.26 spl, and refused to be
unlocked with lokiwiz (as G3's with 2.21+ roms seem to have the same problem with cid unlocking that G4's do), or any thing else, and this manual way was the
only thing that did the job for me...
I have two reasons, and i fear its the first one...
1)G3 2.21+ CID locked phones don't have the same problem with CID unlocking that G4's do. So this solution may only work on G3 2.21+ phones
2)I semi downgraded the phone with ftp://xda:[email protected]__RUU_Wizard_1050412_WWE_101_11210_WWE.exe first (it downgraded everything except the spl), then did all the steps layed out in the guide.
riz
Click to expand...
Click to collapse
hummm...
everyboody says that's impossible to CID unlock the G4...
I'll try downgrading to that rom (without touching the ipl/spl)
@ craptree
Im on a g3 2.21.4.1 o2 wizard, so similar to yours, ill try the partial downgrade
Might be a stupid question but the subject says that it's a CID and SIM unlock. The doc only meantions SIM unlock.
LordPhong said:
Might be a stupid question but the subject says that it's a CID and SIM unlock. The doc only meantions SIM unlock.
Click to expand...
Click to collapse
The only bit in the doc thats about SIM unlocking is
"**The number at 0x1d00 is your sim unlock code. Write it down somewhere and use it to sim unlock your phone (i.e. when you insert a different providers sim card, it will ask you for a code)"
The rest is purely about the cid

Please help me with my radio rom dead

Hello,
I have a type1brick.
I corrupt the radio after failed rom flash, now If i do a classic rom update, the process stuck at 0,1%.
I modify the hpruu.ini to reinstall the ceos and can reboot.
My device is a Ipaq 6515, but all i read here look very close and bootloader command are the same and a lot work for my device...and my questions general & not specific to this device.
Now I have a working os but no Gsm and the asset info blank (stack, imei ,etc..) just Radio present = Yes (The Gps & Bluetooth is ok.
With all i read on this forum i think or i have or :
1/ a CID problem
The command i try in bootloader :
Info 0 = Beetles
Info 1 = Bootloader
info 2 = NOTHING !!!
Just USB>
2/ A Corrupted OS of the radio that i have to manually erase (cf pof solution) and rewrite.
We have the password 0000000000000000 and erase and wdata work.
Rtask test :
Rtask 1 & 2 = radio on/off = ok
Rtask 3 = Radio image loaded
Rtask 4 = radio bootloader loaded
ernal bootloader & Stuck
Rtask 0 = Reset radio ok
Rtask a = stuck
rtask b : go to external bootloader & stuck
I successfully launch the radio booloader and the Radio Rom ??
So it's the Radio OS ??
We have do a dump rom of a working device on SD card,
of this adress : 60000000 with a length of 800000.
But the sd dump to our device fail to flash (via sd card)
If in the bricked device we do :
USB>Checksum
number is ok
but with the specified adress range d2s & checksum fail.
The device show "Cal.Checksum" and nothing happen.
I was very happy to have conclusions,
and if i can believe and spend time to investigate to solve my problem,
or if it's dead. My warranty is over and HP ask for 350$ motherboard replement.
So i really ready to try everything.
Thanks in advance for your analyse and suggestions.
Dimitri
Info log when trying to update the radio rom :
LOG of a Beetle P10504_BT_HP_Radio_Patch.EXE.
It hangs at 0% when trying to upgrade and the log looks like that:
09:20:18:137 [msg] : Client_Logging() !
09:20:18:137 [msg] : =============================================
09:20:18:137 [msg] : START Client_Initialize() !
09:20:18:137 [msg] : Call CheckActiveSyncVersion() !
09:20:18:137 [msg] : Call CheckCEMode() !
09:20:21:923 [msg] : Currecnt Not in CE Mode or in CE Mode but ActiveSync Not Connected.
09:20:21:923 [msg] : Call DisconnectActiveSync() !
09:20:26:149 [msg] : Start Get Connect Port !
09:20:26:379 [msg] : Currecnt in BL Mode. Open Port : [\\.\WCEUSBSH001] OK.
09:20:26:409 [msg] : Device CE Start Address : [80000000].
09:20:26:419 [msg] : Device Radio Start Address : [0].
09:20:26:419 [msg] : END Client_Initialize() !
09:20:26:419 [msg] : =============================================
09:20:26:419 [msg] : START Client_FlashRadioOS() ! FileName : [RADIOOS.nbf] ; HeaderLen : [1260].
09:20:26:439 [msg] : END Client_FlashRadioOS() !
09:20:26:439 [msg] : =============================================
09:20:46:508 [err] : Check Radio Status Error.
Attached you find a usbmonitor of a classic Hp rom update failed :
Thank for your help ! and sorry for the long post

Help with bricked HTC Magician

I need help with reviving my bricked HTC Magician. It got bricked when I tried to update with Cotulla WWE 04 ROM. I tried to find an original HTC Magician rom and could only find MA_O2AW_11200_920_11200_Ship.exe. Well trying this too does not work as the following errors appear on the RUU log. Can someone HELP me please?
11:05:15:205 [msg] : Version : [1.5.0].
11:05:15:236 [msg] : Config Info : [776571],[1],[1],[0].
11:05:20:001 [msg] : Current Not in CE Mode or in CE Mode but ActiveSync Not Connected.
11:05:24:611 [msg] : Disconnect ActiveSync .... [2]
11:05:24:783 [msg] : Current in BL Mode. Open Port : [\\.\WCEUSBSH001] OK.
11:05:26:861 [err] : BL Get Device Data Error.
11:05:26:908 [msg] : IsBL. BL : [1]
11:05:26:939 [msg] : START UnInitialization !
11:05:26:970 [msg] : END UnInitialization !

Phone bricked?

Hi All,
I was updating my LG 540GT toswift droid 2.3 from 2.1.While using kdz_fw_upd.exe ,some error occured in between and the process was some what like stuck and not responding.So i exit the program,(meanwhile phone was showing downloading mode).So i unplugged the usb cable and removed the battery to restart it.But after that it is not even switching ON.i tried to go to recovery mode by pressing volume down+camera+power keys,button nothing happened.i tried home+volume up key,the same result.
i tried using Kdz_fw_upd.exe again,its showing "PHONE WAS NOT FOUND" error.I tried all the ways i could.Please help me if i can do anything with it?
Its bricked.
Sent from my GT540 using xda premium
So i cant do anything???
anoopmohamed said:
So i cant do anything???
Click to expand...
Click to collapse
if the phone doesnt turn on at all then u can't
do anything about it..
can the service center rectify it??my warranty expired lst month.i am ready to pay charge. they wiil not replace as the warranty expired.or the phone is unusable permenantly?
anoopmohamed said:
can the service center rectify it??my warranty expired lst month.i am ready to pay charge. they wiil not replace as the warranty expired.or the phone is unusable permenantly?
Click to expand...
Click to collapse
actually u do have little hope!
Follow this, this might unbrick ur phone if u
are lucky!
[HOW-TO] Repair your device if it feels like dead | When you click power button nothing happens (Note that this may or may not work)
Make sure you use USB ports that are in back of youre PC, dont use front ones.
Disable LGE Virtual Modem. In your Windows operating system, go to Control Panel > System > Hardware > Device Manager > Modems > Right click on LGE Virtual Modem and click Disable.
Try to boot your phone into Emergency/Download mode (VOL DOWN + POWER).
If the phone booted into Emergency/Download mode, launch KDZ Updater.
In TYPE dropdown menu, choose EMERGENCY.
Load KDZ(ROM) and flash your phone.
If the phone failed to boot into Emergency/Download mode (VOL DOWN + POWER), launch KDZ Updater.
In TYPE dropdown menu, choose CS_EMERGENCY.
Load KDZ(ROM) and flash your phone.
Thanks to fishears!
Thanks,
i had tried it all earlier :'( bt in vain...
cursing the moment where i thought of upgrading
anoopmohamed said:
Thanks,
i had tried it all earlier :'( bt in vain...
cursing the moment where i thought of upgrading
Click to expand...
Click to collapse
trust me i know how it feels...
the first week i got my phone i stuffed it up by trying
fastboot... then i managed to fix it myself. from then on
i stuffed my phone nearly every single time i tried something...
But i always managed to fix it!
But i guess bad luck 4 u..
Thanks dude..
i think my bootloader is gone if it is switching ON i had hope.bt
I heared something about Riff box jtag which can repair from brick..but i am not sure.
Can the service center fix this issue???
anoopmohamed said:
Thanks dude..
i think my bootloader is gone if it is switching ON i had hope.bt
I heared something about Riff box jtag which can repair from brick..but i am not sure.
Can the service center fix this issue???
Click to expand...
Click to collapse
yeah they can be changing the motherboard!
But i think that will cost more than the phone itself..
If u have warranty just say ur phone doesn't turn on and
they will give u a new one!
Actually the 1 warranty expired by last month(oct). When i purchased it,it came with 1.6,later i upgraded to 2.1 successfully.With this confidence only i planned to upgraded to swift droid 2.3.Do u know what had went wrong??
anoopmohamed said:
Actually the 1 warranty expired by last month(oct). When i purchased it,it came with 1.6,later i upgraded to 2.1 successfully.With this confidence only i planned to upgraded to swift droid 2.3.Do u know what had went wrong??
Click to expand...
Click to collapse
Yeah u took out the USB cable while flashing!
Sent from my GT540 using xda premium
but the program was non responsive and return with some error
[00:15:55:880] : TYPE_WPARAM_UPGRADE_ERROR
[00:15:55:880] : ¸Þ½ÃÁö º¸³¿ - TYPE_WPARAM_UPGRADE_ERROR Error Code = 1002...
so i had exit the program,then only i removed the cable unfortunate..
anoopmohamed said:
but the program was non responsive and return with some error
[00:15:55:880] : TYPE_WPARAM_UPGRADE_ERROR
[00:15:55:880] : ¸Þ½ÃÁö º¸³¿ - TYPE_WPARAM_UPGRADE_ERROR Error Code = 1002...
so i had exit the program,then only i removed the cable unfortunate..
Click to expand...
Click to collapse
I dont know about that ....
Sent from my GT540 using xda premium
the program showed up a windows-message that it does not work anymore ?
or was it just doing nothing ?
1st the program showed windows error(im using vista) asking the close down the program.So i closed and restarted the program and loaded the kdz file and it again started to do the work.but after few seconds it displayed some upgrade error like "WPARAM_UPGRADE_ERROR Error Code = 1002"
the log file is shown below
[00:15:21:945] : =============================================
[00:15:21:945] : Log is started on 26.11.2011, at 00:15:21:945,
executable: C:\Users\anoopmohamed\Desktop\swift droid\KDZ_FW_UPD.exe (ProcID: 0x00001120),
compile time : Sep 8 2010 17:19:53
[00:15:21:945] : Version :
[00:15:21:947] : strFilename1 = eur
[00:15:21:948] : m_DlMode = 4, m_strBinaryPath = C:\ProgramData\LGMOBILEAX\Phone\europen+fastboot.dz, m_nSelectedImages= 70787108
[00:15:46:357] : Start Web Downloading
[00:15:46:357] : Get Usb Port
[00:15:46:436] : rsi.strFriendlyName=Standard Serial over Bluetooth link (COM6)
[00:15:46:436] : Remove Standard Serial over Bluetooth link (COM6)
[00:15:46:436] : rsi.strFriendlyName=Standard Serial over Bluetooth link (COM8)
[00:15:46:436] : Remove Standard Serial over Bluetooth link (COM8)
[00:15:46:436] : rsi.strFriendlyName=Standard Serial over Bluetooth link (COM5)
[00:15:46:436] : Remove Standard Serial over Bluetooth link (COM5)
[00:15:46:436] : rsi.strFriendlyName=Standard Serial over Bluetooth link (COM7)
[00:15:46:436] : Remove Standard Serial over Bluetooth link (COM7)
[00:15:46:436] : rsi.strFriendlyName=Standard Modem over Bluetooth link #2
[00:15:46:436] : Remove Standard Modem over Bluetooth link #2
[00:15:46:436] : rsi.strFriendlyName=Nokia 6300 Bluetooth Modem
[00:15:46:436] : Remove Nokia 6300 Bluetooth Modem
[00:15:46:436] : rsi.strFriendlyName=Agere Systems HDA Modem
[00:15:46:436] : Remove Agere Systems HDA Modem
[00:15:46:436] : rsi.strFriendlyName=RIM Virtual Serial Port v2 (COM29)
[00:15:46:436] : Remove RIM Virtual Serial Port v2 (COM29)
[00:15:46:436] : rsi.strFriendlyName=RIM Virtual Serial Port v2 (COM30)
[00:15:46:436] : Remove RIM Virtual Serial Port v2 (COM30)
[00:15:46:436] : rsi.strFriendlyName=LGE Android Platform USB Serial Port (COM13)
[00:15:46:436] : FriendlyNameList[iii].szFriendlyName=LGE Android Platform USB Serial Port
[00:15:46:436] : WM_COPYDATA ¸Þ½ÃÁö º¸³¿ 1 - COM13
[00:15:46:436] : Port = COM13
[00:15:46:436] : Clear
[00:15:46:437] : Clear
[00:15:46:438] : UNKNOWN : Req(12) -> Rsp(13)
[00:15:46:438] : Clear
[00:15:46:439] : UNKNOWN : Req(12) -> Rsp(13)
[00:15:46:439] : Clear
[00:15:46:440] : UNKNOWN : Req(12) -> Rsp(13)
[00:15:46:440] : >> DIAG_STATUS_F FAILED
[00:15:46:445] : >>Get Model Name [DIAG_VERNO_F]
[00:15:46:445] : Clear
[00:15:46:446] : BAD CONN MODE : Req(0) -> Rsp(3)
[00:15:46:446] : Clear
[00:15:46:447] : BAD CONN MODE : Req(0) -> Rsp(3)
[00:15:46:447] : Clear
[00:15:46:448] : BAD CONN MODE : Req(0) -> Rsp(3)
[00:15:46:448] : Clear
[00:15:46:449] : BAD CONN MODE : Req(0) -> Rsp(3)
[00:15:46:449] : Clear
[00:15:46:450] : BAD CONN MODE : Req(0) -> Rsp(3)
[00:15:46:450] : Clear
[00:15:46:451] : BAD CONN MODE : Req(0) -> Rsp(3)
[00:15:46:451] : FAIL (No Phone)
[00:15:46:451] : GetModelName() Operation Failed Check Diag CMD
[00:15:46:451] : EMERGENCY Booting Mode
[00:15:46:451] : >>Get Model Name in Emergency Mode [DLOAD_VERREQ_F]
[00:15:46:451] : Clear
[00:15:46:451] : Clear
[00:15:46:452] : BS/GT540/7D
[00:15:46:452] : WM_COPYDATA ¸Þ½ÃÁö º¸³¿ 0 - GT540
[00:15:46:452] : >>Get Mobile SW [DIAG_EXT_BUILD_ID_F]
[00:15:46:452] : Clear
[00:15:46:452] : Clear
[00:15:46:453] : DLOAD_NAK_F reason_msb = 6, reason_lsb = 6
[00:15:46:453] : [ DLOAD ERROR ] : NAK_INVALID_CMD
[00:15:46:453] : Clear
[00:15:46:454] : DLOAD_NAK_F reason_msb = 6, reason_lsb = 6
[00:15:46:454] : [ DLOAD ERROR ] : NAK_INVALID_CMD
[00:15:46:454] : Clear
[00:15:46:455] : DLOAD_NAK_F reason_msb = 6, reason_lsb = 6
[00:15:46:455] : [ DLOAD ERROR ] : NAK_INVALID_CMD
[00:15:46:455] : FAIL
[00:15:46:455] : Phone_Diag_Status = FALSE
[00:15:46:455] : Clear
[00:15:46:455] : Clear
[00:15:46:456] : DLOAD_NAK_F reason_msb = 3, reason_lsb = 3
[00:15:46:456] : [ DLOAD ERROR ] : NAK_INVALID_LEN
[00:15:46:456] : Clear
[00:15:46:457] : DLOAD_NAK_F reason_msb = 3, reason_lsb = 3
[00:15:46:457] : [ DLOAD ERROR ] : NAK_INVALID_LEN
[00:15:46:457] : Clear
[00:15:46:458] : DLOAD_NAK_F reason_msb = 3, reason_lsb = 3
[00:15:46:458] : [ DLOAD ERROR ] : NAK_INVALID_LEN
[00:15:46:458] : NV Write Fail : NV ITEM 9028(9028)
[00:15:46:558] : m_pPhoneCtrl->m_pDload->Dl_GetCommMode(&m_pPhoneCtrl->m_pDload->m_nCommMode)
[00:15:46:558] : >> GET DLOAD COMM MODE
[00:15:46:558] : Clear
[00:15:46:558] : Clear
[00:15:46:559] : [GetCommMode] Communication mode : 2
[00:15:46:559] : Pre Nand Download
[00:15:46:559] : >>Set Trusted Mode [DLOAD_NAND_SEC_MODE] sec_mode = 1 (1=trusted 0=NonTrusted)
[00:15:46:559] : WM_COPYDATA ¸Þ½ÃÁö º¸³¿ 3 - TRUSTED MODE
[00:15:46:559] : Clear
[00:15:46:559] : Clear
[00:15:46:560] : [COM13] >>NandFlashInitWithFile(PARTITION TBL), BinType =8
[00:15:46:560] : NandFlashInitWithFile :: LG3GBinaryList[BinType].szBinaryTypeName = PARTITION TBL, BinType = 8
[00:15:46:560] : NandFlashInitWithFile ::
[00:15:46:560] : WM_COPYDATA ¸Þ½ÃÁö º¸³¿ 3 - INIT PARTITION TBL
[00:15:46:560] : Clear
[00:15:46:560] : Clear
[00:15:49:672] : DLOAD_NAK_F reason_msb = 55, reason_lsb = 55
[00:15:49:672] : [ JNAND ERROR ] : ERR_RESERVED_x37
[00:15:49:672] : Clear
[00:15:52:777] : DLOAD_NAK_F reason_msb = 55, reason_lsb = 55
[00:15:52:777] : [ JNAND ERROR ] : ERR_RESERVED_x37
[00:15:52:777] : Clear
[00:15:55:880] : DLOAD_NAK_F reason_msb = 55, reason_lsb = 55
[00:15:55:880] : [ JNAND ERROR ] : ERR_RESERVED_x37
[00:15:55:880] : [COM13] FAIL
[00:15:55:880] : Clear
[00:15:55:880] : WM_COPYDATA ¸Þ½ÃÁö º¸³¿ 3 - Close Port
[00:15:55:880] : Close Port<<
[00:15:55:880] : TYPE_WPARAM_UPGRADE_ERROR
[00:15:55:880] : ¸Þ½ÃÁö º¸³¿ - TYPE_WPARAM_UPGRADE_ERROR Error Code = 1002
[00:15:55:904] : Log finished
So no process was showing later.I tried a couple of times,same.So i thought of doing it later.Exit the program.But the phone was still in DOWNLOAD MODE,then i pulled out the battery and the usb cable from it.

Droid RAZR M: Qflash Utility Help

QFLASH Problem
What the hell .. squint emoticon
"No data read from USB. This may not be an error. Trying again..."
if anyone knw about it so Guide me .i am very close :|
D:\Downloads\Compressed\Moto.X.Unbrick\Python27>python 8960_blankflash.py
Emergency download enumeration detected on port - com3
Starting qflash!
Executing command qflash.exe -com3 -ramload MPRG8960.hex -mbn 33 MSM8960_bootloa
der_singleimage.bin -v -o
Motorola qflash Utility version 1.3
COMPORT :COM3
RAMLOADER :MPRG8960.hex
type is 0x21
7 mbn file name MSM8960_bootloader_singleimage.bin type 33
verbose mode on
Motorola qflash dll version 1.6
RAMLOADER VERSION: PBL_DloadVER2.0
------------------------------------------------------
DEVICE INFORMATION:
------------------------------------------------------
Version : 0x8
Min Version : 0x1
Max Write Size: 0x600
Model : 0x90
Device Size : 0
Description : Intel 28F400BX-TL or Intel 28F400BV-TL
------------------------------------------------------
Using passed in packet size, changing from 0x600 -> 0x600
EXTENDED_LINEAR_ADDRESS_REC @ 0x2a000000
Write 65536 bytes @ 0x2a000000
100EXTENDED_LINEAR_ADDRESS_REC @ 0x2a010000
Write 11840 bytes @ 0x2a010000
100START_LINEAR_ADDRESS_REC @ 0x2a000000
No data read from USB. This may not be an error. Trying again...
No data read from USB. This may not be an error. Trying again...
No data read from USB. This may not be an error. Trying again...
No data read from USB. This may not be an error. Trying again...
No data read from USB. This may not be an error. Trying again...
Still no data, giving up!
dmss_go : failed to receive ACK
Error loading MPRG8960.hex into device
Blank flashing successful
Device will now enumerate in fastboot mode
D:\Downloads\Compressed\Moto.X.Unbrick\Python27>pause
Press any key to continue . .

Categories

Resources