Everything on the HTC 8XT Obtained in 3 days... - Windows Phone 8 Development and Hacking

Okay, I picked one of these meh HTC 8XT units up from Sprint. I've done some coverage for this at the general Diagnostic dial codes page, but I've handed them money, to try some stuff once I get it developer unlocked... have to return it before Wednesday at 6PM EST (18:00 -500Z) to waive the $35 restocking fee. After that I still have 14 days from Monday when this post originally was made, but I'll probably need donations to keep it a bit longer. I'm hoping some of this will apply to the HTC 8X and 8S, but there aren't any guarantees.
I first tested these dial codes without any updates, so this may change very soon.
It seems there are THREE apps that have been mapped to the dialer menu: CSDiag, DiagnosticTool_Sprint, and HFA
##DIAG# launches HTC Function Test (CSDiag 1.01.01g)
##PST# launches Service Tools (DiagnosticTool_Sprint)
##DATA# launches Service Tools as well...
##786# does too....
##522# launches then crashes....
##72786# launches Service tools.
##6343# launches DiagnosticTool (the same page that gets launched from the DiagnosticTool tile)
##33284# launches EmbeddedTool (Diag and FieldTrial)
##611 launches, but prompts a search for an app in the store, but no results. When no is pressed, it just shows a sample page.
##737425# launches the DiagnosticTool again...
##43424# the same happens as above...
##873283# launches the prl (what Sprint calls Network Profile) update procedure. (app is called HFA)
##MFG# launches EmbeddedTool (DiagnosticTool_Sprint)
Both apps are installed to the app list.
I'll just start with some pictures to start....
EDIT: All of the accessible diagnostic pages were saved in a zip, due to the vast number of screenshots.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Any hints on what to do next?
I've got some drivers to list too.
Normal (MTP Mode)
USB\VID_0BB4&PID_F0CA&REV_0100&MI_00 - Windows Phone
USB\VID_0BB4&PID_F0CA&REV_0100&MI_01 - HTCPO881
##MFG# -> Diag -> DM Mode
USB\VID_0BB4&PID_0BFF&REV_0100&MI_00
USB\VID_0BB4&PID_0BFF&REV_0100&MI_01
USB\VID_0BB4&PID_0BFF&REV_0100&MI_02
USB\VID_0BB4&PID_0BFF&REV_0100&MI_03
(All DM Mode Drivers are unrecognized, but they will take the generic WinUSB driver when manually "updating" the drivers)
Disassembly video!
CODENAME:
HTC Tiara

Power+VolDown+CameraFull=flashing mode
USB\VID_0BB4&PID_00CE&REV_0000
Windows 8 just installed Windows Mobile Device Manager and the HTC USB SYNC mode driver!
Power+VolUP apparently is Qualcomm MSM mode.
USB\VID_045E&PID_062A&REV_0000
No driver is getting installed.
Photos are on the way...once I can strip the EXIF data off if it.

List of apps that shipped with this phone.
HTC Converter
HTC Flashlight
HTC
HTC Burst
HTC Camera
Make More Space
Photo Enhancer
Check out "DiagnosticTool_Sprint" for Windows Phone http://www.windowsphone.com/s?appid=e69a2877-59b8-43ed-898d-554fbc4b8b2b
Check out "activate your device" for Windows Phone http://www.windowsphone.com/s?appid=c7095f7f-263f-408c-afab-eccdb03ef4c6
Check out "attentive phone" for Windows Phone http://www.windowsphone.com/s?appid=59fba4ce-c8d6-df11-a844-00237de2db9e
Check out "Beats Audio" for Windows Phone http://www.windowsphone.com/s?appid=54b4b23e-c2cd-4433-9c34-17a4105d1679
Check out "hearing aids" for Windows Phone http://www.windowsphone.com/s?appid=39a21410-f59b-43b0-826e-356c211d4fa8
Check out "HTC Fetch" for Windows Phone http://www.windowsphone.com/s?appid=d762309e-ef1e-4967-9025-86bed588fa16
Check out "privacy alert" for Windows Phone http://www.windowsphone.com/s?appid=276bcc31-4365-45cf-ba0d-6199d288a688
Check out "Sprint Music Plus" for Windows Phone http://www.windowsphone.com/s?appid=8b30dccf-6fd1-482f-ae0a-b76b98978095
Check out "Sprint TV and Movies" for Windows Phone http://www.windowsphone.com/s?appid=ce3b4564-8555-e011-854c-00237de2db9e
Check out "Visual Voicemail" for Windows Phone http://www.windowsphone.com/s?appid=ee89621f-ffc6-4701-9bce-c0ffa0661861
Check out "Scout" for Windows Phone http://www.windowsphone.com/s?appid=d9deb87b-7c01-469c-abeb-416614fb6742
List of apps that have updates, but need to be manually triggered:
Sprint TV+Movies
DiagnosticTool_Sprint
HTC Fetch
Sprint Music Plus
Visual Voicemail
activate your device

We will probably need the XAPs. Can you install the standard-capabilities version of the webserver and go check the Windows folder and its subfolders for .XAP files? If you can't find any, we will probably need a ROM dump (do we have one already?)

GoodDayToDie said:
We will probably need the XAPs. Can you install the standard-capabilities version of the webserver and go check the Windows folder and its subfolders for .XAP files? If you can't find any, we will probably need a ROM dump (do we have one already?)
Click to expand...
Click to collapse
That's probably going to be the first thing I'll try. It'd be convenient if someone could reversion your webserver to generate a txt file that is similar to 'more' output or something similar to that; show all the files that are available from the directory that also shows the sub directories simultaneously, e.g. File tree. My command/dos skills are a tad rusty, so I'm not sure if I'm thinking if its either more or dir.

Hello there sneaky little files...
Code:
<Setting Name="841.05.06_0_PartnerImmediateDialStrings" Value="##634#;##778#;##786#;##3424#;##3282#;##522#;##72786#;##6343#;##33284#;##611#;##737425#;##43424#;##873283#" />
<Setting Name="841.05.07_0_PartnerNonImmediateDialStrings" Value="##634;##778;##786;##3424;##3282;##522;##72786;##6343;##33284;##611;##737425;##43424;##873283" />
<Setting Name="841.05.08_0_PartnerAppProvisioningFilePath" Value="C:\Programs\CommonFiles\Provisioning\OEM\DiagnosticTool_Sprint_01.provxml" />

GoodDayToDie said:
We will probably need the XAPs. Can you install the standard-capabilities version of the webserver and go check the Windows folder and its subfolders for .XAP files? If you can't find any, we will probably need a ROM dump (do we have one already?)
Click to expand...
Click to collapse
That's a no for both. I couldn't find any xaps anywhere, and couldn't find anything worth looking at in the 2 hours I had spent looking.

moved to post 3

thals1992 said:
That's a no for both. I couldn't find any xaps anywhere, and couldn't find anything worth looking at in the 2 hours I had spent looking.
Click to expand...
Click to collapse
thals1992 said:
Hello there sneaky little files...
Code:
<Setting Name="841.05.06_0_PartnerImmediateDialStrings" Value="##634#;##778#;##786#;##3424#;##3282#;##522#;##72786#;##6343#;##33284#;##611#;##737425#;##43424#;##873283#" />
<Setting Name="841.05.07_0_PartnerNonImmediateDialStrings" Value="##634;##778;##786;##3424;##3282;##522;##72786;##6343;##33284;##611;##737425;##43424;##873283" />
<Setting Name="841.05.08_0_PartnerAppProvisioningFilePath" Value="C:\Programs\CommonFiles\Provisioning\OEM\DiagnosticTool_Sprint_01.provxml" />
Click to expand...
Click to collapse
if you want I can upload HTC 8x xaps.
I download them from a thread in xda but I don't remember where was it !
if You want please reply to this post to upload them for you

Sure, go ahead and attach them to your post. I just sat back down to work on it again.

thals1992 said:
Hello there sneaky little files...
Code:
<Setting Name="841.05.06_0_PartnerImmediateDialStrings" Value="##634#;##778#;##786#;##3424#;##3282#;##522#;##72786#;##6343#;##33284#;##611#;##737425#;##43424#;##873283#" />
<Setting Name="841.05.07_0_PartnerNonImmediateDialStrings" Value="##634;##778;##786;##3424;##3282;##522;##72786;##6343;##33284;##611;##737425;##43424;##873283" />
<Setting Name="841.05.08_0_PartnerAppProvisioningFilePath" Value="C:\Programs\CommonFiles\Provisioning\OEM\DiagnosticTool_Sprint_01.provxml" />
Click to expand...
Click to collapse
Code:
C:\Programs\CommonFiles\Provisioning\OEM\DiagnosticTool_Sprint_01.provxml
Download this file. It contains path to XAP.

OK I'm going to go to upload xap files in 7 parts !!!
maybe you know i'm from iran and iran internet is most likely a ****
Part 1:
http://d-h.st/TzA
Part 2:
http://d-h.st/KnR
Part 3:
http://d-h.st/EdQ
Part 4:
http://d-h.st/SQO
Part 5:
http://d-h.st/Zvz
-------------------------------------
Final Edit :
Part 6:
http://d-h.st/N3t
Part 7:
http://d-h.st/Fbg

-W_O_L_F- said:
Code:
C:\Programs\CommonFiles\Provisioning\OEM\DiagnosticTool_Sprint_01.provxml
Download this file. It contains path to XAP.
Click to expand...
Click to collapse
Unfortunately, I don't think I can access that with the Webserver. The second biggest challenge with this is that it doesn't have a rom for it yet..... But I have some app-ids that make it a little more helpful. I've got a complete list to post soon, which will be forwarded to whomever made the SysApp Updater.

thals1992 said:
Unfortunately, I don't think I can access that with the Webserver. The second biggest challenge with this is that it doesn't have a rom for it yet..... But I have some app-ids that make it a little more helpful. I've got a complete list to post soon, which will be forwarded to whomever made the SysApp Updater.
Click to expand...
Click to collapse
I updated my post and put Part 6 and 7 .
excuse me for my low speed net.
for Bold part of quote. do you mean you can't find official htc rom ?
check this two links :
http://www.fshare.vn/file/JBGVWXGXU4/
http://www.fshare.vn/file/TEWJCLCVT8/
I think these links are for HTC 8x but I think there's no difference between wp8 nbh files.
I will search for 8XT and 8S Roms for you and I will provide links even I find any link .

Pretty much... There hasn't been a HTC WP8 rom that's been leaked for US models. I know in the HTC 8X forum there are two roms available, but they both were European roms that were leaked. I have no clue about the HTC 8S, but bing doesn't come up with any results on the 8XT.
EDIT: looks like the ones that @ngame had linked to are asian and european roms
I'm sure HTC still uses the same format nbh that they have been using with their other WP8 devices.

thals1992 said:
Pretty much... There hasn't been a HTC WP8 rom that's been leaked for US models. I know in the HTC 8X forum there are two roms available, but they both were European roms that were leaked. I have no clue about the HTC 8S, but bing doesn't come up with any results on the 8XT.
EDIT: looks like the ones that @ngame had linked to are asian and european roms
I'm sure HTC still uses the same format nbh that they have been using with their other WP8 devices.
Click to expand...
Click to collapse
@thals1992
I think the best work is download this leaked nbh and try to extract it.
maybe we can get more files . I'm not sure these xaps are full package of them or not .
These files are provided from a topic who said can unlock the htc 8x bootloader and get a Super CID and he take some screenshots that shows he can directly access to system files ! maybe he didn't find all xaps but if we can extract one rom we can access to all files and maybe can find a solution to cook unofficial roms at least like Samsung Ativ S (that it only Interop Unlock your phone)
Regards .

Updating OP with disassembly video!
EDIT: added the alternative name to the OP as well.
Insert any four letter curse word here.....
I have to go to work tonght, so I'll only have ~ 6 hours to work on it tommorrow, and that's if I don't have any time to mess with it tonight after work.
I'm hoping someone will see this and possibly donate a bit of money for this.

I have already decompiled the dlls from the 8x XAPs...most of them have the capabilities we need...and there are some interesting XAML pages in there...but I couldn't test it because I don't have a HTC
Sent from my RM-821_eu_euro2_248 using Tapatalk

I have a TMO branded 8x. (currently in for service). The only files I ever could get to load via dial codes is CSDDiag. I do have a dump of the xaps from an engineering 8x I found on the DFT forums. It is most definitely the old version of it. I tried every single AppID I could find in there, but nothing exciting launched...only CSDDiag and the standard pre-installed xaps worked.
I have been waiting patiently for someone to see if they can download a copy of CSDDiag onto their ativ S via the Microsoft store Proxy trick (Unlike the Samsung xap, the HTC one is listed as published, and you can click the "install" link if you go directly to it in the Windows store).
I will try and install the sprint tool into my 8x and see if it lets me do anything special. (when I get it back).

Habib.Mouissat said:
I have already decompiled the dlls from the 8x XAPs...most of them have the capabilities we need...and there are some interesting XAML pages in there...but I couldn't test it because I don't have a HTC
Sent from my RM-821_eu_euro2_248 using Tapatalk
Click to expand...
Click to collapse
I can test on my 8S everything just say.
compu829 said:
I have a TMO branded 8x. (currently in for service). The only files I ever could get to load via dial codes is CSDDiag. I do have a dump of the xaps from an engineering 8x I found on the DFT forums. It is most definitely the old version of it. I tried every single AppID I could find in there, but nothing exciting launched...only CSDDiag and the standard pre-installed xaps worked.
I have been waiting patiently for someone to see if they can download a copy of CSDDiag onto their ativ S via the Microsoft store Proxy trick (Unlike the Samsung xap, the HTC one is listed as published, and you can click the "install" link if you go directly to it in the Windows store).
I will try and install the sprint tool into my 8x and see if it lets me do anything special. (when I get it back).
Click to expand...
Click to collapse
I tried all codes on my 8S and only show CSDDiag like you said. I already installed sprint tool on my 8S by windows phone store and only got window with MEID(hex), MEID(dex), imei, sim id and version. Nothing special.

Related

Mango update news for DVP

Couple of months ago, we started the discussion with firmware fix on DVP. With help from active forum members, we opened discussion with Microsoft and Dell and finally got the fix, making DVP best WP7 ever.
Now it is time for Mango update! Yesterday, Toshiba released first Mango ever!
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
So when can Mango hit DVP? Any ideas?
Mango is still in beta testing, dude. All the phones should get it at once, save for the carriers who delay updates for whatever reason.
Also, Microsoft is the only one that can release the update, Toshiba probably just released a phone...atleast thats what the picture looks like.
roytellect said:
Couple of months ago, we started the discussion with firmware fix on DVP. With help from active forum members, we opened discussion with Microsoft and Dell and finally got the fix, making DVP best WP7 ever.
Now it is time for Mango update! Yesterday, Toshiba released first Mango ever!
So when can Mango hit DVP? Any ideas?
Click to expand...
Click to collapse
Thunder_47 said:
Mango is still in beta testing, dude. All the phones should get it at once, save for the carriers who delay updates for whatever reason.
Also, Microsoft is the only one that can release the update, Toshiba probably just released a phone...atleast thats what the picture looks like.
Click to expand...
Click to collapse
To be fair, news outlets did say this phone would be the first Mango phone to market. Considering Mango has been RTM'ed, I would guess we should see it pretty soon.
Thunder_47 said:
Mango is still in beta testing, dude. All the phones should get it at once, save for the carriers who delay updates for whatever reason.
Also, Microsoft is the only one that can release the update, Toshiba probably just released a phone...atleast thats what the picture looks like.
Click to expand...
Click to collapse
As Mango goes to carrier and manufactures already. I guess the rest of works should only be bunch of tests. And rumors said lots of people from dell are using Mango DVP already. So I guess not too much problem to see it coming out soon.
Its probably safe to say that everyone who owns a Windows Phone and has access to XDA has Mango now. We have the most-locked phone and even we got it.
Even so, Mango still has a "Release Date", and anything after that within a reasonable period of time should be blamed on the carriers for not releasing it. Possibly now since the release has been opened up to more professionals, more criticism can be achieved.
Thunder_47 said:
Its probably safe to say that everyone who owns a Windows Phone and has access to XDA has Mango now. We have the most-locked phone and even we got it.
Even so, Mango still has a "Release Date", and anything after that within a reasonable period of time should be blamed on the carriers for not releasing it. Possibly now since the release has been opened up to more professionals, more criticism can be achieved.
Click to expand...
Click to collapse
Two days ago, MSFT post something about "New Major Update". Will that be Mango?
Preparing for our next major update
Build 7720 is here http://forum.xda-developers.com/showthread.php?t=1215501. Anyone tried it on their DVP's?
BISDAKinLA said:
Build 7720 is here http://forum.xda-developers.com/showthread.php?t=1215501. Anyone tried it on their DVP's?
Click to expand...
Click to collapse
<----- this guy
I did it on my dvp works like a charm. No problems
Sent from my Venue Pro using XDA Windows Phone 7 App
Got it on my DVP now too..
Had to delete and Update UpdateWP.exe and wm7update.dll
go to the x64 folder of the new Zune folder you get when you downlaod the mango update and manually install Setup-Update-Wp-x64.exe (it will be in folder c:/zune/04.08.2134.00/updatetool/x64/)
The rerun the c:/RCToRTM/ISVto7720.bat file
That seemed to finally get it..
Now that all said, this is my backup phone (my old DVP with a small crack in teh screen that was to be sent back to Dell) it was updated to 7712, but while loading music the new DVP it bricked on me.. and I can not get it to get out of the SD card error. I try to boot into the "connect to PC" icon, but it wont do it.. stuck at Dell logo. Any ideas on that one..?
So, I have a Samsung Infuse, but I just upgraded my brothers DVP to Mango, and I thought I'd give you the play by play.
WARNING: THIS IS JUST HOW I MADE IT WORK, YOUR SITUATION MAY BE DIFFERENT!!! DO AT YOUR OWN RISK!!!
Tools needed:
Windows Phone 7 Backup
Mango Files
THESE THREADS SHOULD BE USED AS REFERENCE!!!
A. Back-up number 1 (optional)
1. Download the files listed in Windows Phone 7 Backup.
2. Make sure that you get all the prerequisites from that post, and for the most part follow those instructions to the T.
3. After completion you will restart the phone, and then its of to start installing Mango.
B. Pre-Update Setup. (!!!IMPORTANT!!!)
1. Uninstall Zune, and any other Windows Phone Support Tools you may have.
2. Navigate to the install location contained in Mango, and find the Zune Setup in the folder.
3. Install.
4. Change to the UpdateTool folder, and install the version that is required for your computer architecture.
5. Install.
6. Navigate to the "NoDoToRC" folder, and run the file "ISV_Provisioning_Live.exe" as an admin.
7. This will make a back up that is mentioned in the Mango Thread, and it should be quoted.
itje said:
In the directory "C: \ Users \ <user> \ AppData \ Local \ Microsoft \ Windows Mobile Update,"there should be the newly created backup folder with a cryptic name. Please feel free to copy the folder to a secure location (external hard disk, etc.) and keep safe!
Repeat to yourself many times: "Yes, I have copied my backup to a secure location"
Click to expand...
Click to collapse
C. MANGO INSTALL PT1 (BETA)
itje said:
11. Now start the Zune client (with your phone connected) and it will begin looking for updates.
12. Build 7403 will now be found found and installed.
13. After 7403 has finished updating, the update is moving seamless to 7712 - the public developer beta.
14. If everything is done properly: Congratulations, the phone is in now running build 7712
15. Close/exit Zune.
Click to expand...
Click to collapse
AFTER INSTALL OF BETA MAKE SURE THAT YOU HAVE A BIT OF SPACE ON YOUR PHONE I WOULD RECOMMEND REMOVING ALL MUSIC.
D. RTM Install
itje said:
16. Copy the "RCToRTM" folder to "c:\" and only there.
17. In the RCToRTM folder, locate the "ISVTo7720.bat" and run as admin /still right click on file...)
Click to expand...
Click to collapse
IF YOU GET STUCK AT THE GOODBYE SCREEN ON UPDATE, RESTART YOUR PHONE AND REMOVE MORE THINGS ON YOUR DEVICE.
IF YOU GET STUCK AT ANYTIME, USE WINDOWS PHONE 7 BACKUP TO RESTORE YOUR DEVICE.
DVP Updated to RTM Mango Yesterday.... Absolutely Great. Well worth it.
Mango installed one week ago and it runs perfectly on our DVP!
Just a few reboots when I write or send a messages (Official MANGO)
Didn't work for me.
getting an error "cant find clear type fonts for Vista" while trying to install zune.
I am Using Win XP
Have you tried to do the update on Windows 7?

[REQUEST] latest extras+info

I need for someone to possibly dump the latest version of the app from their development/pre-production edition of their Nokia Lumia. I don't think it matters if its a BUILD 920 or if its a developer 822, or whatever. I have a few ideas of some things that can be done via this app, as almost all of the dial codes on the 928 launch extras+info. One of them involves launching the service tools (including EPST) menu and stuff of that nature. I could probably just experiment with the one that launched with the 928 GDR2 rom, but its probably missing some "features" that have been worked on, but still incomplete.
Its also possible that these are baked inside the rom and completely inaccessible to the app and will only be updated when Nokia Black update releases.
ANY HELP WOULD GREATLY APPRECIATED!!!
Sent from my RM-860 using Tapatalk
dumped from ROM .
but I don't know whether it is the latest one or not.
Also, I think you won't be able to deploy it to any NOKIA devices cause it requires INTEROP UNLOCK which is impossible on NOKIA now.
hjc4869 said:
dumped from ROM .
but I don't know whether it is the latest one or not.
Also, I think you won't be able to deploy it to any NOKIA devices cause it requires INTEROP UNLOCK which is impossible on NOKIA now.
Click to expand...
Click to collapse
did you extract it from GDR2 (Amber Rom) ?
It's not the last version .
maybe we have to wait for GDR3 then we can extract last version of Extras + Info.
or maybe someone who have Samsung Ativ S can try proxy and try to download Extras + Info from market place using Sysapp Pusher (to find market link)
Then Using Full File Access to copy app files.
ngame said:
did you extract it from GDR2 (Amber Rom) ?
It's not the last version .
maybe we have to wait for GDR3 then we can extract last version of Extras + Info.
or maybe someone who have Samsung Ativ S can try proxy and try to download Extras + Info from market place using Sysapp Pusher (to find market link)
Then Using Full File Access to copy app files.
Click to expand...
Click to collapse
That's essentially why I said I needed it from a developer lumia, I don't even think it will install on ATIVs, due to OEM drivers required. Those devices have the option to have their full filesystem exposed when changed via the "Diagnostics" app that only available on developer/pre-production handsets.
Besides that what ROM did you dump this from hjc?
thals1992 said:
That's essentially why I said I needed it from a developer lumia, I don't even think it will install on ATIVs, due to OEM drivers required. Those devices have the option to have their full filesystem exposed when changed via the "Diagnostics" app that only available on developer/pre-production handsets.
Click to expand...
Click to collapse
I haven't read your posts here, so not sure if my post is still relevant, but one great chinese guy asked me to send this to you:
from R&D Lumia
https://www.dropbox.com/s/pf31egysniuschp/extras-hongkong.zip
Is your dump from the first GDR2 that appeared on NCS for the 928 or the actual release? I have the 2nd update but not sure if extras&info updated since then??? Found this in a wim which gives me new hope that the tool is buried somewhere in this mess...
RegKeyName="$(hklm.microsoft)\Shell\OEM\Start"
RegName="AltLayoutID"
RegType="REG_DWORD" />
<!-- -->
<SettingMapping Name="FeatureTileID"
RegKeyName="$(hklm.microsoft)\Shell\OEM\Start"
RegName="FeatureTileID"
RegType="REG_DWORD" />
<!-- -->
<SettingMapping Name="DiagnosticEnabled"
RegKeyName="$(hklm.microsoft)\Shell\OEM\Start"
RegName="DiagnosticEnabled"
RegType="REG_DWORD" />
</SettingsGroupMapping>
</ComponentMapping>
Click to expand...
Click to collapse
Guys a little question
Why don't we use the first lumia 920 rom ?
maybe we can find something that can help us to Interop Unlock but Microsoft and Nokia delete that in next rom releases .
Then we can Prevent Re-lock and update phone again !
I'm not sure but it seams to be some different between GDR2 rom of Nokia Lumia 920 (Apac Malaysia White is mine) and it's first Rom .
I have some problems in these days and I don't see all the differents but In first view you can find that there is no test folder in first rom but GDR2 have a folder named test and includes "QCFMFTMApp.exe"
or another thing is all of the programs are listed in :
PROGRAMS\CommonFiles\Xaps
but in GDR2 there's some xap files in this address too :
PROGRAMS\CommonFiles\OEM\Public\PreloadedApps\tier3Apps
did anyone checked the older Roms?
Thats it! I needed ver. 3.0.6.1 (because I can't deploy this to it and I'm not reflashing to just have an older version) to first see if there were any changes to Nokia.FUE.WinPRTRegistry, and possibly launch that registry script that's been embedded in it. Now all I need to do is see if there is a URI that links to the page, but I believe all bets are off. Nokia has been good about cleaning up their tracks.
THe version from the other extras was 2.6.1.18.
ngame said:
Guys a little question
Why don't we use the first lumia 920 rom ?
I have some problems in these days and I don't see all the differences but in first view you can find that there is no test folder in first rom but GDR2 have a folder named test and includes "QCFMFTMApp.exe"
or another thing is all of the programs are listed in :
PROGRAMS\CommonFiles\Xaps
but in GDR2 there's some xap files in this address too :
PROGRAMS\CommonFiles\OEM\Public\PreloadedApps\tier3Apps
did anyone checked the older Roms?
Click to expand...
Click to collapse
QCFMTMApp.exe seems to be a driver level executable that physically tunes the FM Radio in Nokia's various phones.
tier3apps, seem to be xaps that need additional permissions that essentially use provxml like in WP7 days. The NFL app that @tonbonz had done some looking into had a settings page that changes the WAP address for Verizon devices.It was interesting at the very least to see the differences between HTC and Nokia. The difference? @wap vs no @wap
Dump files from 2nd 928 GDR2 .... http://sdrv.ms/1hnqgNA
This package(extra+info) contains a silent installer and it is worth doing some research around it.
I opened it using ilspy only to find it called AddPackageAsync(), which is available in Windows Runtime to deploy enterprise xap and nobody knows how it works. @GoodDayToDie @ultrashot how do you think about it? Nokia use this API to install and update xap in settings page. It seems to be a service agent,too ,which is very interesting. How did it call the API silently...when we call the API, user will notice a notification asking whether he/she wants to install the enterprise app but no matter how you call it, the deployment won't succeed
hjc4869 said:
This package(extra+info) contains a silent installer and it is worth doing some research around it.
I opened it using ilspy only to find it called AddPackageAsync(), which is available in Windows Runtime to deploy enterprise xap and nobody knows how it works. @GoodDayToDie @ultrashot how do you think about it? Nokia use this API to install and update xap in settings page. It seems to be a service agent,too ,which is very interesting. How did it call the API silently...when we call the API, user will notice a notification asking whether he/she wants to install the enterprise app but no matter how you call it, the deployment won't succeed
Click to expand...
Click to collapse
I am also wondering about details of Enterprise deployment - I haven't looked into it too much, but as i remember you have to install .cer provided by MS to device and then sign your xap with it, and such apps will get installed.
(I was wondering if such signing can "unlock" any of interesting capabilities)
Sadly, enterprise apps (CAPABILITY_CLASS_ENTERPRISE_APPLICATIONS) just uses the same capability list as CAPABILITY_CLASS_THIRD_PARTY_APPLICATIONS; nothing useful there. It's a shame.
GoodDayToDie said:
Sadly, enterprise apps (CAPABILITY_CLASS_ENTERPRISE_APPLICATIONS) just uses the same capability list as CAPABILITY_CLASS_THIRD_PARTY_APPLICATIONS; nothing useful there. It's a shame.
Click to expand...
Click to collapse
After diving into a Lumia 521 ROM, I am not 100% sure that's the case....
I was poking around in the tier3apps directory (\PROGRAMS\CommonFiles\OEM\Public\PreloadedApps\tier3Apps\), and I noticed that some of these apps ("Nokia Accessories" and "Network Settings" apps) have interesting capabilities such as <Capability Name="ID_CAP_CELL_API_OEM_PASSTHROUGH"/>, <Capability Name="ID_CAP_INTEROPSERVICES"/>, and <Capability Name="ID_CAP_OEM_DEPLOYMENT"/>. These apps can be installed/updated via Nokia's "SilentInstaller" app. Nokia's "SilentInstaller" app just calls into AddPackageAsync(), which is available to us "normal folk" for Enterprise app deployment.
I am wondering if we could create some sort of a "shell" xap with a giant "Install button" that contains a payload such as an unaltered copy of the Samsung Diagnostics xap and appropriate license file. Clicking on the Install button would then install the signed "elevated app" onto any device. We could then launch a toast that will launch the "Registry Editor" page in the Samsung app, allowing for us to interop unlock.
The only thing that I can think of that would make this fruitless is if somehow "AddPackageAsync()" is being called "elevated" by Extras + Info (maybe it inherits whatever capabilities the parent process launched as?), and that is why Nokia can deploy things like this.
What do you guys think? This is all speculation, but I think it could be worth exploring.
**EDIT**
My phone will be back from service Wednesday, so maybe I will whip something up next weekend, if no one tries before then.
compu829 said:
After diving into a Lumia 521 ROM, I am not 100% sure that's the case....
I was poking around in the tier3apps directory (\PROGRAMS\CommonFiles\OEM\Public\PreloadedApps\tier3Apps\), and I noticed that some of these apps ("Nokia Accessories" and "Network Settings" apps) have interesting capabilities such as <Capability Name="ID_CAP_CELL_API_OEM_PASSTHROUGH"/>, <Capability Name="ID_CAP_INTEROPSERVICES"/>, and <Capability Name="ID_CAP_OEM_DEPLOYMENT"/>. These apps can be installed/updated via Nokia's "SilentInstaller" app. Nokia's "SilentInstaller" app just calls into AddPackageAsync(), which is available to us "normal folk" for Enterprise app deployment.
I am wondering if we could create some sort of a "shell" xap with a giant "Install button" that contains a payload such as an unaltered copy of the Samsung Diagnostics xap and appropriate license file. Clicking on the Install button would then install the signed "elevated app" onto any device. We could then launch a toast that will launch the "Registry Editor" page in the Samsung app, allowing for us to interop unlock.
The only thing that I can think of that would make this fruitless is if somehow "AddPackageAsync()" is being called "elevated" by Extras + Info (maybe it inherits whatever capabilities the parent process launched as?), and that is why Nokia can deploy things like this.
What do you guys think? This is all speculation, but I think it could be worth exploring.
**EDIT**
My phone will be back from service Wednesday, so maybe I will whip something up next weekend, if no one tries before then.
Click to expand...
Click to collapse
Samsung Diagnosis uses RPC (Remote Procedure Call) to access high privileged functions. We are not sure if Server exists on other phones.
-W_O_L_F- said:
Samsung Diagnosis uses RPC (Remote Procedure Call) to access high privileged functions. We are not sure if Server exists on other phones.
Click to expand...
Click to collapse
I don't know is it that thing you want or no but check it :
http://d-h.st/Me3
ngame said:
I don't know is it that thing you want or no but check it :
http://d-h.st/Me3
Click to expand...
Click to collapse
Yep! That's it. But I'm not sure it'll work.
-W_O_L_F- said:
Yep! That's it. But I'm not sure it'll work.
Click to expand...
Click to collapse
No problem I can test for you . my device is a Lumia 920 with Malaysia GDR 3 (Developer test) rom. and surely it's dev unlock
please tell me what can I do and how can I help you ?
I could test too... I don't know if the fact this is a dual CDMA+GSM device will change any parts of the app, but I can always try!
Sent from my RM-860 using Tapatalk
I have uploaded Extras And Info v3.0.6.1.xap here:
https://hotfile.com/list/2278056/5476aae

[XAP] Xbox Games Hub extracted from Windows Phone 8.1 Emulator

I've extracted the XAP for the Games Hub and edited the manifest so that it would run on Windows Phone 8. Screenshot below and XAP attached
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
To download the APPX and XAP files I found in the ROM, click here. It is a mediafire link.
AlvinPhilemon said:
I've extracted the XAP for the Games Hub and edited the manifest so that it would run on Windows Phone 8. Screenshot below and XAP attached
To download the APPX and XAP files I found in the ROM, click here. It is a mediafire link.
Click to expand...
Click to collapse
I am working on Porting file manager to wp 8 xap file .
It's now only shows a loading... page nothing work .
maybe I need a Interop Unlocked Ativ S because of it's capabilities
Working well
AppPlat.Apps.FileManager.appx can be deployed to Win8.1 computer without any modify.
Actually it's not a File Manager app, it's just a file picker user interface.
reker said:
AppPlat.Apps.FileManager.appx can be deployed to Win8.1 computer without any modify.
Actually it's not a File Manager app, it's just a file picker user interface.
Click to expand...
Click to collapse
I tried to install this appx via power shell but it couldn't deployed .
could you please tell how to install it ?
I checked it yes it's only able to browse and open files .
really not a file *MANAGER*
well I am on Samsung Ativ S and all this app does is that it lists all my apps under the "other" section, while telling me I don't own any xbox enabled games... what is not true.
also, when I try to rate an app via this view, it brings up a message saying I have to install an app for that and sending me to the marketplace, showing me apps that support viewing apps on the Windows Store (e. g. Store Companion)
cheers, fadenfisch
AlvinPhilemon said:
I've extracted the XAP for the Games Hub and edited the manifest so that it would run on Windows Phone 8. Screenshot below and XAP attached
To download the APPX and XAP files I found in the ROM, click here. It is a mediafire link.
Click to expand...
Click to collapse
What exactly did you edit in the manifest?, because I could run this app on my L925 but only after removing the OEM capability.
I would like to edit the same on the other apps and try running them.
When I try doing the same as on the file you attached on other files I only get an deployment error with something about invalid WMAppManifest file.
ngame said:
I tried to install this appx via power shell but it couldn't deployed .
could you please tell how to install it ?
I checked it yes it's only able to browse and open files .
really not a file *MANAGER*
Click to expand...
Click to collapse
I used a simple gui tool written in Chinese to deploy it, I think it just executed powershell commands because the shell window opened up while the tool is deploying.
I just have a dev-unlocked win8.1, no further operation.
reker said:
I used a simple gui tool written in Chinese to deploy it, I think it just executed powershell commands because the shell window opened up while the tool is deploying.
I just have a dev-unlocked win8.1, no further operation.
Click to expand...
Click to collapse
mine is dev unlocked too but add-appxpackage didn't work on power shell !
It needs a certificate that trusted as Root for any app I think .
If you can send me that tool in PM or share it here to try it
Any way to extract the Music Hub too? ANd the Social/Me Hub? I am sick of both of these on 8.1
X0LARIUM said:
Any way to extract the Music Hub too? ANd the Social/Me Hub? I am sick of both of these on 8.1
Click to expand...
Click to collapse
Social/Me Hub is not an XAP/APPX iirc.
The Xbox Music Hub attached is from the Emulator modified to run on 8.0 too
AlvinPhilemon said:
Social/Me Hub is not an XAP/APPX iirc.
The Xbox Music Hub attached is from the Emulator modified to run on 8.0 too
Click to expand...
Click to collapse
Thanks so much buddy!! I am on 8.1..and sick of the XBMusic ..
Coded from my Clover Trail+ Machine.
AlvinPhilemon said:
Social/Me Hub is not an XAP/APPX iirc.
The Xbox Music Hub attached is from the Emulator modified to run on 8.0 too
Click to expand...
Click to collapse
hey man...i am getting this error..i believe it has somethng to do with the XBM app..
any way to get around this?
Thanks!
X0LARIUM said:
hey man...i am getting this error..i believe it has somethng to do with the XBM app..
any way to get around this?
Thanks!
Click to expand...
Click to collapse
The problem is, by default, you shouldn't be able to uninstall the app, as it is set by default, as assigned to the app's unique id.
I have reattached the app, with a new app ID, the only problem now is that you cannot uninstall the old one.
AlvinPhilemon said:
The problem is, by default, you shouldn't be able to uninstall the app, as it is set by default, as assigned to the app's unique id.
I have reattached the app, with a new app ID, the only problem now is that you cannot uninstall the old one.
Click to expand...
Click to collapse
Oh man...so there is no way I can revert to the old app? I've heard that the XBM can't even be removed with the date trick. Sad
Sent from iCeborg's iPad.
I don't mean to resurrect this thread, but I wanted to verify something...
The original post reads like you took the new apps, from Windows Phone 8.1, and made them to be installed on Windows Phone 8.0.
Is that correct?
If it is, why?
Doesn't everyone think the Games and Music + Videos apps, from Windows Phone 8.0, are better than their 8.1 variants?
Maybe I'm reading it backwards and you actually got the old apps working on the new OS.
If that's the case, thank you...
JJ
reker said:
I used a simple gui tool written in Chinese to deploy it, I think it just executed powershell commands because the shell window opened up while the tool is deploying.
I just have a dev-unlocked win8.1, no further operation.
Click to expand...
Click to collapse
Could you please share the tool?
Fa310tx said:
I don't mean to resurrect this thread, but I wanted to verify something...
The original post reads like you took the new apps, from Windows Phone 8.1, and made them to be installed on Windows Phone 8.0.
Is that correct?
If it is, why?
Doesn't everyone think the Games and Music + Videos apps, from Windows Phone 8.0, are better than their 8.1 variants?
Maybe I'm reading it backwards and you actually got the old apps working on the new OS.
If that's the case, thank you...
JJ
Click to expand...
Click to collapse
sorry for the noob question, is there a way to install de new xbox app from w10 to wp 8.1 ?
rickastillo said:
sorry for the noob question, is there a way to install de new xbox app from w10 to wp 8.1 ?
Click to expand...
Click to collapse
surely no.
AlvinPhilemon said:
The problem is, by default, you shouldn't be able to uninstall the app, as it is set by default, as assigned to the app's unique id.
I have reattached the app, with a new app ID, the only problem now is that you cannot uninstall the old one.
Click to expand...
Click to collapse
how did you manage to get the xap??
i desperately need that method.
i tried to copy xap found in phone internals but could not deploy it.

[SUCCESS] Interop-Unlocking LUMIA - with JTAG

Hi there
Well, as we really need Interop Unlock for our Lumia phones, i decided to check this out myself.
As i already have ATF Box for a long time, i decided to buy JTAG activation and dolphin clip + lumia jigs, that i do not have to solder my phone.
Also i have ordered a Lumia 520 testing phone on ebay.
So, as the ATF Team made an awesome JTAG software update, i'm trying to interop unlock that Lumia 520 the hardware way, as just software seems to be too tough...
Well, what i did so far:
1. Freshly flashed Lumia 520 RM-914 with latest stock rom
2. Did the setup/beginning after turning it on for 1st time
3. developer unlocked it with SDK on PC
4. Made Full Dump with JTAG from dev-unlocked phone
5. Mounted MainOS partition of dump with program "OSFMount" (-->appears as Local harddisk example drive E: )
6.Loaded the SOFTWARE hive with regedit on PC from "E:\Windows\System32\config"
7. Edited the following values:
PortalUrlInt = http://127.0.0.1
PortalUrlProd = http://127.0.0.1
MaxUnsignedApp = 10003
8. unloaded SOFTWARE hive
9. unmounted dump-image
10. wrote image back via jtag
I thought it might be a good Idea to dev-unlock the phone before messing with the registry, to make sure "DeveloperUnlockState = 1" gets written the "legal" way, as the key is not available in registry before.
Maybe it's better to just modify an existing key, than adding a new one...
Well, long story short: The result is not totally satisfying.
After writing the modified image back to the EMMC, the phone is booting up, but i can NOT deploy homebrew apps that require interop unlock, like @GoodDayToDies "EnableAllSideloading.xap" for example.
But i can deploy "nomal" apps like @cpuguys "Toastlauncher" and @GoodDayToDies "Webserver"
The weird thing: If i check the reg-values via WebServer on the Phone, i can see my edited values.
So the changes ARE written to the phone. The phone just doesn't use them...
So, the good thing: phone is booting with modified rom :good:
But, the bad thing: Changes are not working.
EDIT:
SUCCESS!!!
After adding
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
i could successfully sideload "EnableAllSideloading.xap"
After executing enableallsideloading i could sideload latest WPHTweaks build.
Now i have 3rd tile row enabled!
awesome!
Also member @myst02 is working on interop-unlocking the lumia phones. So we decided to make this a together-project.
See his achievements here: http://forum.xda-developers.com/showthread.php?t=2713098&page=10 :good:
reserved
to be able to sideload EnableAllSideloading.xap you need to change following registry key:
Software\Microsoft\SecurityManager\CapabilityClasses
add: MultiSz String
name: ID_CAP_DEVELOPERUNLOCK_API
value: CAPABILITY_CLASS_THIRD_PARTY_APPLICATIONS
have fun.
I have found this during smurfing on the internet.
Dont know if this is something worth trying, but maybe it gives you some pointers or help.
http://windowsphonehub.in/tutorials...eloper-unlock-windows-phone-sideload-10-xaps/
lordmaxey said:
Well, as we really need Interop Unlock for our Lumia phones, i decided to check this out myself.
Click to expand...
Click to collapse
Good job!
lordmaxey said:
Let's get this rolling, guys! :good:
Click to expand...
Click to collapse
BTW, it's not a real "hack", and not acceptable/affordable for the 99.9% Lumia users and developers...
Wow you did a fantastic job
as @error0x0000034 mentioned you forget to open DeveloperUnlock_API
Software\Microsoft\SecurityManager\CapabilityClass es
add: MultiSz String
name: ID_CAP_DEVELOPERUNLOCK_API
value: CAPABILITY_CLASS_THIRD_PARTY_APPLICATIONS
sensboston said:
BTW, it's not a real "hack", and not acceptable/affordable for the 99.9% Lumia users and developers...
Click to expand...
Click to collapse
Yeah, but it's at least something worth trying
ngame said:
Wow you did a fantastic job
as @error0x0000034 mentioned you forget to open DeveloperUnlock_API
Software\Microsoft\SecurityManager\CapabilityClass es
add: MultiSz String
name: ID_CAP_DEVELOPERUNLOCK_API
value: CAPABILITY_CLASS_THIRD_PARTY_APPLICATIONS
Click to expand...
Click to collapse
Oh, i see...
I'm just wondering that this CAP was not secessary on Ativ S?
Or am i wrong?
I really thought it was just the 3 regkeys quoted in the first post...
lordmaxey said:
Yeah, but it's at least something worth trying
Oh, i see...
I'm just wondering that this CAP was not secessary on Ativ S?
Or am i wrong?
I really thought it was just the 3 regkeys quoted in the first post...
Click to expand...
Click to collapse
I don't remember Ativ S Interop but I know it had a BootStrap app
maybe that app unlock this api i'm not sure but I know you have to open this cap first to run EnableAllCapabilities
Nice work :good:
so now , you can make a small bussines with this
interop unlock for only *** $
and you are now the one and only interop unlocked retail Lumia owner
ceesheim said:
Nice work :good:
so now , you can make a small bussines with this
interop unlock for only *** $
Click to expand...
Click to collapse
Haha Yay, i'm going to be rich *lol*
ceesheim said:
and you are now the one and only interop unlocked retail Lumia owner
Click to expand...
Click to collapse
No, not yet.
I'm trying to deploy the bootstrap samsung app to the 520 this afternoon. If it works, i maybe can deploy the other apps.
If not, i'm trying to open that CAP by editing the Dump again and writing it back via JTAG.
We'll see, but i'm curious
btw: Why are these damn smileys always displayed in the next line?
btw: Why are these damn smileys always displayed in the next line?
don't know , i just seen that too
lordmaxey said:
Haha Yay, i'm going to be rich *lol*
No, not yet.
I'm trying to deploy the bootstrap samsung app to the 520 this afternoon. If it works, i maybe can deploy the other apps.
If not, i'm trying to open that CAP by editing the Dump again and writing it back via JTAG.
We'll see, but i'm curious
btw: Why are these damn smileys always displayed in the next line?
Click to expand...
Click to collapse
Samsung Bootstrap uses some Samsung-specific DLLs as far as I know. This won't help you, tried this already on my Huawei Ascend W1. This won't work on your Lumia either I think. But its worth a try of course.
You'll have to edit the registry key I mentioned before to be able to sideload EnableAllSideloading.xap. You need to load the SOFTWARE file from Windows/System32/config again into your registry and edit following key. Maybe try using a registry editor on your phone before using the method you described above, but I don't think that this will work. So, you probably have no other choice than opening up your device again and edit the SOFTWARE reg-file. Then sideload EnableAllSideloading.xap and you'll be able to sideload pretty much everything you want.
Question for more experienced devs and hackers:
Is there a registry tweak or some settings anywhere else on the phone that we can access though JTAG and that allows us to boot the phone (Lumia in this case) as a mass storage device with full filesystem access? Like on the Huawei Ascend W1. This would simplify the process of changing registry keys a lot.
Best regards and good luck.
lordmaxey said:
Haha Yay, i'm going to be rich *lol*
No, not yet.
I'm trying to deploy the bootstrap samsung app to the 520 this afternoon. If it works, i maybe can deploy the other apps.
If not, i'm trying to open that CAP by editing the Dump again and writing it back via JTAG.
We'll see, but i'm curious
btw: Why are these damn smileys always displayed in the next line?
Click to expand...
Click to collapse
Bootstrap Samsung will not work on Lumia.
error0x0000034 said:
Samsung Bootstrap uses some Samsung-specific DLLs as far as I know. This won't help you, tried this already on my Huawei Ascend W1. This won't work on your Lumia either I think. But its worth a try of course.
You'll have to edit the registry key I mentioned before to be able to sideload EnableAllSideloading.xap. You need to load the SOFTWARE file from Windows/System32/config again into your registry and edit following key. Maybe try using a registry editor on your phone before using the method you described above, but I don't think that this will work. So, you probably have no other choice than opening up your device again and edit the SOFTWARE reg-file. Then sideload EnableAllSideloading.xap and you'll be able to sideload pretty much everything you want.
Click to expand...
Click to collapse
Like this then, right?
Ok, I'll try this next week, i sadly won't have time this weekend.
error0x0000034 said:
Question for more experienced devs and hackers:
Is there a registry tweak or some settings anywhere else on the phone that we can access though JTAG and that allows us to boot the phone (Lumia in this case) as a mass storage device with full filesystem access? Like on the Huawei Ascend W1. This would simplify the process of changing registry keys a lot.
Best regards and good luck.
Click to expand...
Click to collapse
No. once JTAG halts the phone, it's halted. You can't just "pause" the phone, make changes and continue booting. Sadly.
So, only chance is by writing the modified dump back.
It's not for Lumia only, it's a universal method for every WP8 devices (including emulator) that could enter MassStorage mode
And the Bootstrap app is not a magic, it use the system service by Samsung to modify the CapabilityClasses registry key mentioned by above and this could be done by modify reg hive directly
lordmaxey said:
Like this then, right?
Ok, I'll try this next week, i sadly won't have time this weekend.
Click to expand...
Click to collapse
exactly. I have done this on my Ascend W1 several times, but its easier, because I can enter Mass Storage Mode through bootloader.
No. once JTAG halts the phone, it's halted. You can't just "pause" the phone, make changes and continue booting. Sadly.
So, only chance is by writing the modified dump back.
Click to expand...
Click to collapse
I don't know how JTAG method works exactly, I only know that the device needed isn't cheap and can restore bricked phones. How it works? I have no idea, but I'm sure I'll learn quickly.
I will do some research on that soon. I'm a learning noob. :cyclops:
best regards,
error0x0000034
error0x0000034 said:
I don't know how JTAG method works exactly, I only know that the device needed isn't cheap and can restore bricked phones. How it works? I have no idea, but I'm sure I'll learn quickly.
I will do some research on that soon. I'm a learning noob. :cyclops:
Click to expand...
Click to collapse
Me neither
Most credits go to X-Shadow from advance-box team.
Because i had the Idea of modifying the phone dump and read/write via JTAG.
But usually, ATF only supported bootloader repair via JTAG. So i contacted X-Shadow and within only two weeks he updated the jtag-application, and added Custom Read/Write to every part of the EMMC.
That's how i could dump the rom, modify it and write it back.
Absolutely awesome work from that team, just releasing a software because of ONE single inquiry. :good::good::good:
Aw crap, I totally forgot to tell you to test a pure-interop app (like the bootstrap one). You interop-unlocked but failed to capability-unlock, and most WP8 homebrew requires both so of course you couldn't sideload it. DERP
But hey, if you successfully edited the capability class of ID_CAP_DEVELOPERUNLOCK_API - and it looks like you did, or could - then you can use EnableAllSideloading to capability-unlock the phone (it just edits all the other capabilities' classes). I could probably also write a "BootstrapNokia" app if you'd like; I think we have interop-based registry functions for WP8 Lumias, which would allow (for example) making SamWP8 Tools work on your Nokia as well.
SamWP8 tools on Nokia would be great.
I'll check that monday evening, when i'm back at my computer.
I'll keep you informed
GoodDayToDie said:
Aw crap, I totally forgot to tell you to test a pure-interop app (like the bootstrap one). You interop-unlocked but failed to capability-unlock, and most WP8 homebrew requires both so of course you couldn't sideload it. DERP
But hey, if you successfully edited the capability class of ID_CAP_DEVELOPERUNLOCK_API - and it looks like you did, or could - then you can use EnableAllSideloading to capability-unlock the phone (it just edits all the other capabilities' classes). I could probably also write a "BootstrapNokia" app if you'd like; I think we have interop-based registry functions for WP8 Lumias, which would allow (for example) making SamWP8 Tools work on your Nokia as well.
Click to expand...
Click to collapse
isn't it better to put FCROUTER and other samsung dlls in Windows folder?
as far as i know ID_CAP_INTEROPSERVICES allow it

Universal ReadBack Extractor for mtk feature watchphones

Update Mar-12/2016: as long as on the market appeared a long line of new types of mtk6260 mtk6261 mtk2502C mtk2502A (etc) watches equipped with strange new PCB or flash_ID parameters, the new release <Readback Extractor mtk 2.0> now has the capacity to identify, to read, check, rebuild firmware and collect and insert in the .cfg files the flash_ID's coded inside the ROM dump for almost all types of mtk watchphones or smartwatches based on RTOS Nucleus
NOTE: being tested already for mtk6260 mtk6261 mtk2502C and mtk2502A
In short - if you intend to install in your smartwatch new firmwares, mods etc, before to initiate any flashing with the Flash Tool app (pushing that goddamn < Download > button) think twice, 'bove all better DO a backup for the original firmware, why so? because it's containing all original drivers hence you'll be able to recover 100% your watch in case of bricking.
How to:
First you have need of a full dump of your ROM. Assuming that you already got a Flash Tool 5.15.16 and drivers, and you were at the point of flashing something (already chose the download agent and scatter file)
preparations:
a. Set options/backup and restore on no action
b. load the download agent (you find this file inside the flash tool folder)
c. load a scatter firmware - for initialization flash tool needs a scatter file (.cfg) - for dz09 you get this one - for any other than mtk6260A get here and get a firmware compatible with your PCB
d. in case you have W10 - go to the start menu and click on power and hold down the shift key while clicking on restart. A screen then comes up and you need to choose troubleshooting and then startup options. It will then reboot and give you a menu. press 7 which is ignore signed drivers and then when windows comes up, you will be able to install the drivers.
for instance let's say you have a DZ09 smartwatch:
1 - press < Readback > in upper menu and so < Add > in the middle menu
2 - click twice on the item appears in the main window, set name as ROM_DZ choose in browser the path and save
3 - set as Physical start address 0x00000000 and as Length 0x01000000 or 0x00800000 or 00400000 (try them in this order) then ok
4 - turn off the watch, press < Readback > in the middle menu wait 2 seconds and connect through USB your watch
5 - wait until the upload is complete (big green ring)
Now second stage:
1 - download the app I've built attached here (Readback Extractor mtk) and unzip it
2 - create a folder where you intend to keep in safe the original firmware and name it for instance DZ09-Orig
3 - do a copy of Readback Extractor mtk 2.0.exe and place it inside the DZ09-Orig folder then click twice on it
4 - press <Load Readback file> and browse after the ROM_DZ file created before with the Flash Tool then open
5 - Wait about a minute while the app will check bit by bit the integrity of your file
6 - If everything went ok and your file is healthy then app will show " health 100% " so you can proceed to the next step
7 - Press <Rebuild Firmware> and wait about one minute (it shows a progress counter)
8 - When appears the message " - ALL DONE!!!" close app and go back in the DZ09-Orig folder, now you'll find there a set of new files which are the original firmware kit ready to be flashed back in your phone anytime you want
9 - Enjoy flashing anything you like without any fear that something bad can happen
Some tricks for writing IMEI in your watch NVRAM:
you connect to usb your watch (turned on this time) and set the com port on the watch screen, go in device manager and check the port number your watch is connected, then you open Tera Term hyperterminal (google for this app), connect it as serial com on watch com port and then give the command:
AT + EGMR = 1, 7, " imei number "
if on screen appears OK then ready, you've changed your imei
AFTERWARDS READ ME story - Anywhere you search, there is no one to tell you explicitly how to extract from your mtk smartwatch the firmware kit
All says a halfmouth: Do a full < Readback > in Flash Tool, you'll do it being confident that from now on you say goodbye to any risk because you have A BACKUP hence you start flashing new firmwares. And the Big Brick is coming , you smile and get back to your < Readback > backup discovering that, sadly, you have a binary bulk at first sight good for nothing. It cannot be so useless, isn't it? after all it contains full dump of your ROM! I was in exactly the same situation, so 'cause I didn't find any answer I've started reverse engineering . . . and it worked, first I did it manually for guys being in the same situation, 've noticed that is a common issue so I had to choose how to help, simpler but dangerous (for you) way, to create a tutorial <how to> or the hard way (hard for me), to develop an app which will do all "cooking" automatically and I choose the second because in manually way there is a quite big "chance" to mess up with your primary bootloader which could get to a real tragedy - no modem - brickest brick you saw in your entire life
Readback extractor mtk 2.1 beta
Flash Tool and drivers
Lil to late for me XD.... *just ordered a new one btw*
franc33s said:
Lil to late for me XD.... *just ordered a new one btw*
Click to expand...
Click to collapse
Sorry man, couldn't earlier because I have mine either of two weeks or so. . . still a beginner
Look at the bright side, best lessons we learn from our own mistakes, best part is that if you buy the new one from the same seller, you'll have the firmware hence two working watches!
Are there apps in the works to change watch faces without flashing?
kyitech said:
Are there apps in the works to change watch faces without flashing?
Click to expand...
Click to collapse
Unfortunately, yet, there is no way to get in contact with the watch else than through proprietary mediatek drivers so that the only ways to communicate for now are Flash Tool app and bluetooth modem proprietary commands (the most important of them being secret as well)
To do such a reverse engineering is way way way over my pay grade
Still I'm working for an app which could replace any media in the watch (backgrounds, icons) but through flashing method of course
Thanks for the info...I just think this watch have great potential
Golem_ said:
Unfortunately, yet, there is no way to get in contact with the watch else than through proprietary mediatek drivers so that the only ways to communicate for now are Flash Tool app and bluetooth modem proprietary commands (the most important of them being secret as well)
To do such a reverse engineering is way way way over my pay grade
Still I'm working for an app which could replace any media in the watch (backgrounds, icons) but through flashing method of course
Click to expand...
Click to collapse
Sorry for not knowing, but what about bluetooth app transfer in the Google play store. How can they be used on dz09-?
kyitech said:
Sorry for not knowing, but what about bluetooth app transfer in the Google play store. How can they be used on dz09-?
Click to expand...
Click to collapse
. . . bluetooth modem AT commands, just I told this before, generally speaking, in this way all bluetooth app are working, in our case they are proprietary and most of them SECRET. For more information please check this link, it is an older tutorial posted by me on that site
franc33s said:
Lil to late for me XD.... *just ordered a new one btw*
Click to expand...
Click to collapse
I'm almost sure you found these before me, still, here link you have more than 10 versions of dz09 firmwares (others than we checked before)
It looks like they made a firmware for each phone ) very prolific guys when about dz09
Hope this time you catch the right one!
Golem_ said:
I'm almost sure you found these before me, still, here link you have more than 10 versions of dz09 firmwares (others than we checked before)
It looks like they made a firmware for each phone ) very prolific guys when about dz09
Hope this time you catch the right one!
Click to expand...
Click to collapse
yup already did try them all, they boot fine, just no luck getting the Padgene (padgeME) one yet (so my touchscreen driver would work), the guy is still uploading more firmwares tough *fingers crossed*
Golem_ is a hero!
Thanks for all the time you spend with the gt08
flashtool
Hy ,
I am trying to search for the wright flashtool to make my backup.
And where can i find a tutorial?
I have a gv08s.
Wich drivers do i need, and wich version of flashtool?
Thanks in advance
xeph20 said:
Golem_ is a hero!
Thanks for all the time you spend with the gt08
Click to expand...
Click to collapse
thank you for kind words!
Golem_ said:
thank you for kind words!
Click to expand...
Click to collapse
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
carlospaco said:
Hy ,
I am trying to search for the wright flashtool to make my backup.
And where can i find a tutorial?
I have a gv08s.
Wich drivers do i need, and wich version of flashtool?
Thanks in advance
Click to expand...
Click to collapse
here link you find a good tutorial but instead <download> you have to use <readback>
Golem_ said:
here link you find a good tutorial but instead <download> you have to use <readback>
Click to expand...
Click to collapse
Yes , i have done everything like its said, for couple off days, but i keep getting this error always.
lashtool error: S_BROM_DOWNLOAD_EPP_FAIL (2036)
[EPP] FlashTool environment preparation failed
It May be caused from DRAM initialization failed
Pleace check the EMI information of the MAUI load is correct and fit the target.
Hope that someone can help me with this, i am desperated.
Thanks
carlospaco said:
Yes , i have done everything like its said, for couple off days, but i keep getting this error always.
lashtool error: S_BROM_DOWNLOAD_EPP_FAIL (2036)
[EPP] FlashTool environment preparation failed
It May be caused from DRAM initialization failed
Pleace check the EMI information of the MAUI load is correct and fit the target.
Hope that someone can help me with this, i am desperated.
Thanks
Click to expand...
Click to collapse
give me in PM a skype ID
Golem_ said:
give me in PM a skype ID
Click to expand...
Click to collapse
Oh, i am sorry, but i don't have a skype id.
carlospaco said:
Oh, i am sorry, but i don't have a skype id.
Click to expand...
Click to collapse
Alternatives for live screen sharing like, for instance TeamViewer?
Golem_ said:
Alternatives for live screen sharing like, for instance TeamViewer?
Click to expand...
Click to collapse
i have send you id teamviewer

Categories

Resources