Kaiser IMGFS and XIP Here - Tilt, TyTN II, MDA Vario III Windows Mobile ROM De

Enjoy,
I just extracted both. extract, port, graft yadidadida to your device of choice...
IMGFS Details:
[Core OS]
Windows Mobile-based Pocket PCs
[Versions]
SYS: 5.2.17740.200
SYS: 5.2.17938.301
OEM: 1.7.0.0
OEM: 17.6.10701.502
OEM: 0.0.1.0
NET: 2.0.7045.0
OEM: 17.3.10701.502
[Language]
0409 - English (United States)
[DPI]
96
[Certificates]
CN=Microsoft Windows Mobile PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
CN=OEM_UpdateCert
CN=CWS__001
IMGFS & XIP Modules
XIP Files
TOOLS USED Below
extract the ZIP and place the NBH in the folder
then run
> dumpKAISER.bat RUU_Signed.NBH
(files will be stored in the OUTPUTS Folder)
the tools are from this forum. all you had to do is remove a few bytes every so often in the entire OS.nb before you dump the IMGFS (as the locations changed in the Kaiser OS)

gr8 work..

Great!
SYS: 5.2.17938.301
It's new than 17913 build

To my surprised, can't disassemble the new COREDLL.DLL with IDA, what happened?
And what's the CE OS version?

liay said:
To my surprised, can't disassemble the new COREDLL.DLL with IDA, what happened?
And what's the CE OS version?
Click to expand...
Click to collapse
well, if you cannot dissasemble the coredll (kernel) you wont know what the CE kernel version is
unless u port it and flash a ROM

HI jj
jasjamming said:
well, if you cannot dissasemble the coredll (kernel) you wont know what the CE kernel version is
unless u port it and flash a ROM
Click to expand...
Click to collapse
Will you be getting a kaiser soon as i got a distinctive feeling that you already have one testing now

duttythroy said:
Will you be getting a kaiser soon as i got a distinctive feeling that you already have one testing now
Click to expand...
Click to collapse
im in limbo at the moment re: my next device.... leaning towards an IMate Ultimate 7150 (the specs blow HTC away). Although no GPS in the 7150, the GPS in the Kaiser is not anything to brag about. My Globasat BT359 blows any GPS integrated mobile anyways.

jasjamming said:
im in limbo at the moment re: my next device.... leaning towards an IMate Ultimate 7150 (the specs blow HTC away). Although no GPS in the 7150, the GPS in the Kaiser is not anything to brag about. My Globasat BT359 blows any GPS integrated mobile anyways.
Click to expand...
Click to collapse
Hey JJ,
ive been looking at getting a kaiser or ultimate 9150, however ive just been told that imate no longer use htc as a supplier hence 9150 got cancelled so it looks like im leaning towards the kaiser!! any others good 1's? at the moment?

Thanks Jasjamming,
Got your wonderfull Kaiser dump ported to my wizard
Still got the "old" version but with new build number
But that is because I didn't hex-edit the XIP files, maybe something for later.
Thanks again for this new toy.
Will testdrive it for some time, and find the bugs (and hopefully fix them )
Best regards,
EqX

jasjamming said:
I just extracted both. extract, port, graft yadidadida to your device of choice...
Click to expand...
Click to collapse
How you did it? Write please

How did you get it out? Modified tools? Everything I've tried so far has given me a blank.
I'm trying to locate the images etc for the phone skin, but I can't find them in the files you've pulled out.

N2A said:
How did you get it out? Modified tools? Everything I've tried so far has given me a blank.
Click to expand...
Click to collapse
I'm also interested in knowing how to dump Kaiser's OS.nb without actually having a Kaiser to flash it and dump from device. The usual mamaich / tadzio imgfs tools don't work with kaiser's OS.nb, however I've been playing with hex editor and managed to dump some, but not all files.
N2A said:
I'm trying to locate the images etc for the phone skin, but I can't find them in the files you've pulled out.
Click to expand...
Click to collapse
They are in the OEM folder, but this is the Cingular's (AT&T) ROM, I guess what you want is the new kaiser dialer, home plugin, comm manager, etc... that is on HTC's 1.25.405.0 Test ROM.

I noticed the AT&T logo when I was going through the files, wasn't sure if that was what was knocking me off the scent - thanks for pointing it out.
So, we [a] need to get our grubby mitts on a test ROM, and need to get some tools to work with it?
Is the HTC test ROM out in the wild? (I ask because I want to get my mitts on those files, but it's obviously going to take time to work out the format of the new ROM.) I'm assuming they're being split correctly to the OS.nb stage, and they've just tweaked the format again.

first post updated

jasjamming said:
first post updated
Click to expand...
Click to collapse
thanks for sharing man

THX for the new tool! I think there's still something extraordinary on Kaiser, use the Her.exe with blocksize 0x800, imgfs can extract correctly, but XIP lose the filesys.exe, and the coredll.dll cant be disassemble
But use it on the Trinity's newer 1437, it works great! the newer coredll.dll:
Code:
.text:03F6AA84 MOVL R3, 0x59D ; <suspicious>
.text:03F6AA8C MOV R2, #0x114 ; <suspicious>
.text:03F6AA90 MOV R1, #5
.text:03F6AA94 MOV LR, #2
.text:03F6AA98 MOV R4, #3
.text:03F6AA9C MOV R5, #0
.text:03F6AAA0 STR R3, [R0,#0xC]
.text:03F6AAA4 STR R2, [R0]
.text:03F6AAA8 STR R1, [R0,#4]
.text:03F6AAAC STR LR, [R0,#8]
.text:03F6AAB0 STR R4, [R0,#0x10]
.text:03F6AAB4 STRH R5, [R0,#0x14]
.text:03F6AAB8 MOV R0, #1
.text:03F6AABC LDMFD SP!, {R4,R5,LR}

OEM folder of HTC rom here:
http://rapidshare.com/files/42085076/KAISER_OEM.7z.html

For the love of all that is good.. RAPIDSHARE is the worst service ever!! I can never download anything there.. Please get another unpload server! PLEASE!!!

OEM Applications & version included in HTC kaiser rom:
"Adobe Reader"="2.00.288531"
"ArcsoftMMS"="4_0_31_22_R2"
"AudioManager"="1_2_614712_q"
"AVDecDll"="1.00.070207.0"
"BT_FTP"="1_2_30214_1"
"BT_SAP"="2_02_b0925_r3"
"Camera"="4_08_27706_00"
"CyberonVoiceSpeedDial"="1_2_b070612"
"DShow"="2_00_070620_0"
"HTCHome"="1_5_620722_0"
"LockStreamDRM"="1_1_x_070525"
"MHub"="6_42_070531_X0"
"PHONE_CANVAS"="1_50_27795_0"
"PictureEnhancement"="1.20.320717.2"
"RingtonePlugin"="1_00_070419_0"
"QuickGPS"="1_00_615715_00"
"ShareDLL"="2_0_070522_0000"
"SMART_DIALING"="2_5_27647_0"
"StreamingMedia"="2_20_615718_00"
"SymbolPad"="1_0_24876_11"
"TaskManager"="1_51_30229_1"
"VideoTelephony"="2_0_27748_0"
"ZIP"="1_20_27596_0"
"VoiceRecorder"="1_10_611711_0"
"NetworkWizard"="1_0_29982_4"
"BT_BPP"="1_5_0_0"
"Esmertec Jbed"="20070425_1_1"
"ConcurrenceMgr"="1.0.327709.0000"
"BCR_WorldCard_Mobile"="1_0D_0504"

pof said:
OEM Applications & version included in HTC kaiser rom:
"Adobe Reader"="2.00.288531"
"ArcsoftMMS"="4_0_31_22_R2"
"AudioManager"="1_2_614712_q"
"AVDecDll"="1.00.070207.0"
"BT_FTP"="1_2_30214_1"
"BT_SAP"="2_02_b0925_r3"
"Camera"="4_08_27706_00"
"CyberonVoiceSpeedDial"="1_2_b070612"
"DShow"="2_00_070620_0"
"HTCHome"="1_5_620722_0"
"LockStreamDRM"="1_1_x_070525"
"MHub"="6_42_070531_X0"
"PHONE_CANVAS"="1_50_27795_0"
"PictureEnhancement"="1.20.320717.2"
"RingtonePlugin"="1_00_070419_0"
"QuickGPS"="1_00_615715_00"
"ShareDLL"="2_0_070522_0000"
"SMART_DIALING"="2_5_27647_0"
"StreamingMedia"="2_20_615718_00"
"SymbolPad"="1_0_24876_11"
"TaskManager"="1_51_30229_1"
"VideoTelephony"="2_0_27748_0"
"ZIP"="1_20_27596_0"
"VoiceRecorder"="1_10_611711_0"
"NetworkWizard"="1_0_29982_4"
"BT_BPP"="1_5_0_0"
"Esmertec Jbed"="20070425_1_1"
"ConcurrenceMgr"="1.0.327709.0000"
"BCR_WorldCard_Mobile"="1_0D_0504"
Click to expand...
Click to collapse
feel like sharing ??

Related

Vox bootloader

Inspired by some threads in the Hermes and Trinity forums I started to explore the VOX bootloader. You can enter the bootloader by pressing the camera and power button at the same time. You see the tri-color (red/green/blue) bootscreen which shows the bootloader and CPLD version. In connection settings of activesync uncheck "allow USB connections" and connect PC and Vox with a USB cable. The PC will recognize the Vox and install an interface driver.
You need the MTTY to talk with the bootloader and send it commands. The Hermes wiki provides some good information and also has a link to MTTY:
http://wiki.xda-developers.com/index.php?pagename=Hermes_BootLoader
Unfortunately the Vox bootloader (v1.16.0000) doesn't display help information. The first command you should enter is password. I found a password for Trinity and Hermes which also works for Vox:
password BsaD5SeoA
Here are a couple of other commands which work: emapiWlanEERW, emapiInit, emapiWlanMac, emapiPwrDwn, emapiRead, emapiTest, emapi, cpldver, DumpReservoir, CheckImage, calcrccheck, getdevinfo, ruustart, ruurun, progress, wdata, password, mbr, set, atcmd, ResetDevice, BTRouting, BTTestMode, SetDebugMethod, IMEI, ls, lnbs
I would like to find a way to dump the SPL and ROM to SD-card or to PC. I tried a couple of things (r2sd, d2s) to no avail.
Anyone else some ideas?
Update1
I got stuck in the bootloader and luckily found how to boot into the OS again:
http://forum.xda-developers.com/showpost.php?p=1094479&postcount=11
password BsaD5SeoA
ruurun 0
ResetDevice
Update2
I discovered the 'ls' command. Afaik it allows to dump the rom parts like SPL, IPL, splashscreen when the device is CID unlocked. My unbranded S710 is SIM unlocked, but unfortunately not CID unlocked. When I issue 'ls' there's a "not allowed" error
Update3
I found a 'good' VOX ROM upgrade (the ones on the XDA FTP are all corrupt): RUU_Vox_HTC_WWE_1.15.405.2R4_4.1.13.37_02.83.90_Ship
Another upgrade ROM is the Dopod:
RUU_Vox_DOPODASIA_WWE_1.19.707.3_4.1.13.37_02.83.90_Ship
I used NBHextract.exe to extract both ROMs. The SPL bootloaders are attached.
NBHextract shows following info for the 1.15 Vox ROM upgrade:
Code:
Device: VOX010100
CID: HTC__001
Version: 1.15.405.2
Language: UK
Extracting: 00_IPL.nb
Extracting: 01_SPL.nb
Extracting: 02_GSM.nb
Extracting: 03_MainSplash.nb
Encoding: 03_MainSplash.bmp
Extracting: 04_OS.nb
and this for the Dopod upgrade:
Code:
Device: VOX010100
CID: DOPOD001
Version: 1.19.707.3
Language: USA
Extracting: 00_IPL.nb
Extracting: 01_SPL.nb
Extracting: 02_MainSplash.nb
Encoding: 02_MainSplash.bmp
Extracting: 03_GSM.nb
Extracting: 04_OS.nb
Update4
I managed to back up my S710 using itsme's "bkondisk" tool and "prun" from his itsutils suite here and here. Copy bkondisk.exe to /Windows on your device.
After running this on your PC
Code:
prun bkondisk.exe "\Storage Card"
following files are created in \Storage Card and a log file "bkondisk.log" in \
Code:
bk_00_0000.img - IPL : ONBL1 + ONBL2
bk_02_0005.img - GSM + splash + gsmdata + simlock + serialnrs
bk_03_0025.img - OS
bk_06_0001.img - SPL
bk_08_0205.img - userfilesystem
I compared a couple of these .img files with the .nb files extracted by NBHextract from an official RUU. The IPL and SPL look quite okay, but the OS is mapped totally different. So don't think you can just rename for example bk_03_0025.img to OS.nb in order to have a flashable file !! I have attached my dumped SPL which is version 1.16
Next mission is to find a 'good' (not corrupted) version of the RUU_Vox_HTC_WWE_1.15.405.2_4.1.13.37_02.83.90_Test.exe ROM upgrade. See this Excalibur thread. I think the same applies to S710
Update5
With Dark Simpson's htc rom tool here it is possible to create a flashable image file from separate .nb files. There is also Dutty's good NBHtool 1.1 yet, but so far I haven't tried it.
What we still need to have for flashing unsigned ROM images is a SSPL. See here and here.
Alternatively we need a so called Update SPL (USPL) which unlocks CID and then allows flashing any rom to your device. The version for the ELF created by the brilliant moderator pof can be found here. Since the ELF is very similar to VOX, I will study it and see if I can use it to implement a SSPL (software SPL) which allows us to also flash any ROM, but does not require to flash an USPL. I think flashing IPL and SPL is a bit too tricky atm.
Take the Elf USPL, remove the RUU folder (to be sure you don't flash anything by mistake), in the LOADER folder change the .nb file for a Vox bootloader (different version than the one on your device) and use the same name for the .nb file, then run elf-uspl.exe on your PC.
If elf & vox are so similar, this should jump to the bootloader you've placed in the LOADER folder, to check it disable activesync usb connections and go into bootloader with mtty. Do an "info" command or whatever identifies that the bootloader you're seeing is the one you've placed on the LOADER folder and not the one actually on your device.
If you succeed in loading a custom bootloader I can help you with the don't check cid / don't check signatures... patches
Good luck!
Thanks for replying pof. I did as you said and tried it with spl 1.15 (whereas 1.16 is flashed on my S710). First I went through step1 and then went in to step2 where at 75% the screen got blank and it rebooted the phone in my native bootloader 1.16 RUU mode. I suppose that's not what we wanted to see?
Where did you find RUU_Vox_HTC_WWE_1.15.405.2R4_4.1.13.37_02.83.90_Ship? Do you have a link?
Thanks
I found it here:
http://www.leaf.co.za/Members/Member Services/Manage My Profile/
Cant Find The Bootloader For The Life of Me
Tried:
"You can enter the bootloader by pressing the camera and power button at the same time. You see the tri-color (red/green/blue) bootscreen which shows the bootloader and CPLD version."
No Luck. I must be thick. Its gotta be just that easy... but...
The S710 simply boots into my home screen.
Can someone PLEASE post a (little) more detail about how to boot into the bootloader on the s710/vox?
THANKS.
Cheers.
** EDIT **
OK- Better bootloader entry instructions for SP noobs (like myself):
1) Turn device off
2) Unplug power/usb cable from handset
3) Press and hold camera button
4) Plug power/usb cable into handset
5) Be amazed by Blue-Green-Red Bootloader screen.
Yeah, it won't boot in bootloader mode if the usb cable is connected. Well, it's sometimes better to find out things all by yourself
Besides, I don't think anyone other than myself is researching this stuff on Vox. Too many ordinary users and nearly noone in to h*cking.
You don't have 1.04 on your phone by any chance?
RE: older bootloader
No joy.
Sorry.
Its 1.15
My SP has vanilla mods.
Its just out of the box the last 4 days in NYC!
The phones not even available AFAIK in the US yet-- except special order.
Got mine in London last week.
Still working out the kinks.
BTW:
Im looking for info/docs/someone who has forced GSM codec through WM6 to this handset through Asterisk LOCALLY-- Asterisk SIP logs show successful codec negotiation and initial start of audio delivery-- but the stream pukes out on my handset immediately-- ideas? Im begining to think it may be a cpu issue. Thanks.
850mph said:
BTW:
Im looking for info/docs/someone who has forced GSM codec through WM6 to this handset through Asterisk LOCALLY-- Asterisk SIP logs show successful codec negotiation and initial start of audio delivery-- but the stream pukes out on my handset immediately-- ideas? Im begining to think it may be a cpu issue. Thanks.
Click to expand...
Click to collapse
Yeah saw that. I don't think it's a CPU issue, could run GSM codec just fine on a stone old iPaq. Try trunning omap overclocker and set it to 240MHz and see if it makes a difference. Keep using the SIP thread for any replies on this
POF's O2/Nova Solution
jockyw2001-
I suppose youve seen Pof's post #89 (dated 4-8) in the "ELF Update SPL (USPL)" thread which calls for running enable-rapi.cab (on O2 Nova) BEFORE elf-uspl.exe?
Id try it myself but want a few days of joy with my handset BEFORE creating a potential brick.
From my reading if the elf-uspl.exe makes it to 75% in stage 2 before white-screening-- you're close (well, 75% anyway.. wink!). Seems like Pof could have a couple of suggestions at that point. Maybe hell be kind enough to comment?
You're on it.. but I thought Id ask.
Cheers.
Heres something I am trying to work out-- even after many hours of reading:
I understand that there is an exploit in the 1.04 bootloader which can potentially bypass CID and Certs when flashing a new ROM image on both SPs and PPCs..
I also understand that bootloaders 1.09+ cant be downgraded.
So am I right in assuming that potential VOX ROM-chefs have at least ** TWO ** potential paths to solving the bootloader issue:
1) Find a 1.04 bootloader **AND** a tool which will load it successfully
-- Then use the exploit (which I read about-- but cant find) to flash the ROM
-or-
2) Find a way to Flash **ANY** bootloader onto the vox with elf-uspl.exe
-- Then (keeping our fingers crossed) elf-uspl.exe can be patched to defeat the CID&CERT issues with the vox
Now heres the question:
I am right in assuming that we **DONT** need to find a way to flash **SPECIFICALLY** the 1.04 bootloader onto the ROM **BEFORE** we can take advantage of a patched elf-uspl.exe?
Is that correct?
Cheers.
Oh yeah.. AM I right in assuming that the WM5/6 bootloaders are EXACTLY the same code (except for dated revs) across all WM SP and PCC devices-- sort of like the ability to install grub or lilo on **ANY VENDORS PC** no matter what OS or eventual Software Packages end up on the box?
Looked at another way:
When they talk about the 1.15 bootloader in the Blue Angel Board they are talking about the EXACT SAME 1.15 bootloader in the VOX board?
I mean, I know this is gotta be the case but I need a little reassurance here-- As Im still a bit confused on why PPC software should run on SP devices-- even understanding that they use (generally) the same subset (WM5/6) of the CE5/6 API-- But have different CPUs.
850mph: cool to see there actually are brothers in arms
I've tested pof's USPL extensively, but haven't got it to work (yet).
Actually you need to run enable-rapi.cab only if your phone isn't yet application unlocked, i.e. if it doesn't allow to run unsigned apps. Mine is application unlocked so I can skip that step.
The next step is to load a modded SPL in RAM at physical address 0x10000000 and to run it. Once this modded SPL is running another modded SPL can be flashed.
I've tried to load an unmodified SPL in RAM (e.g. SPL 1.15) and to run it. This can be done with following 2 steps:
1) psetmem.exe -f -p 0x10000000 spl.nb
2) run haret.exe on device (can use cecopy & cerun); cerun -b CE:\haret.exe
Note: haret.exe is a linux kernel loader which was modified by pof to run a USPL from 0x10000000
What happens is that my phone reboots into the stock bootloader (SPL 1.16) in RUU mode. I have to use MTTY in order to boot the phone in WM again (see post #1 and #2 in this thread).
Actually I think haret.exe does run the SPL 1.15 which is loaded in RAM, but that at some point the code resets the device.
I'm quite sure we can run a specially prepared USPL or SSPL which allows flashing another specially prepared SPL such that the device is effectively CID unlocked which again means that any vendor's firmware can be flashed. I also think we don't absolutely need the SPL 1.04 for that purpose.
This is good info.
I see what you are trying to do now.
Im gonna take some time to get up to speed on Dumping/Reading/Flashing from the Trinity Hermes and Elf pages. Until then Im afraid Ill be of little use.
Until now Ive strictly been a Linux/GCC-guy. Im tempted (but not convinced) that I want to take the time to learn Microsofts WM5/6 IDE. Its a time issue (obviously).
But I will spend some time on the whole S710 ROM-cooking (and bootloader) issue this week. It looks manageable.
I see you have basically been mixing and matching the various ROM cooking tools-- including using Msofts CE powerToys. Is there no single suite (besides the ImagefsTools) which you can recommend I look at first (With the understanding we need to solve the bootloader issue specifically for the vox first)-- I see various kitchens for various devices. Do any of them see plausible as a starting point for an HTC/Vox kitchen suite?
GOOD LUCK.
Cheers.
** EDIT **
I REALLY think the S710/S730spec are GREAT devices-- couple of minor issues-- but just fantastic form-factors.
new in the sandbox
Hi guys,
I just got my XPA 1415 some days ago (for info, it's just the same than the others (HTC S710, SPV E650 and Vodafone V1415, VOX, ...) but from Swisscom (Swiss provider).
I've been reading around and found this thread that was the most related. I actually tried to use the techniques provided by jockyw2001 with no luck.
Doing a prun bkondisk does not work, neither any of the itsutil tools. I do think that my device is somehow protected, but I've no clues how to proceed next. I'm going to continue searching, but if any of you has an idea, it's more than welcome.
If I manage to dump that *damned* ROM, I'll make it available...
I've currently (on booloader ONBL 1.23.0000, SPL 1.23.0000, CPLD 04)
Cheers,
Nick
Nevermind...
I think I've been able to proceed with the backup (I've used the Microsoft Security Configuration Manager) when I realized that my system (Windows 2003 x64) the tool was not working.
Which made me think that maybe the procread and the other prun bkondisk might also have been blocked by the x64.
I've tested on my laptop (regular XP) and it works fine... just FYI !
** EDIT **
I've also tested the ELF haret with a downoaded SPL and I got the same result as jockyw2001...
BTW, jocky, did you find a way to re-create a proper nh from the bkondisk end result (bk_##_####.img) ?
nwaelti said:
BTW, jocky, did you find a way to re-create a proper nh from the bkondisk end result (bk_##_####.img) ?
Click to expand...
Click to collapse
The IPL and SPL are useable. The radio dump called bk_02_0005.img is from offset 0xA0000 identical to the radio rom. The first 0xA0000 bytes are other parts, probably splash + gsmdata + simlock + serialnrs. The OS file seems not directly useable and must be reordered somehow. More interesting is the ROM reconstruction method described here. Of course first we need to be able to flash unlock the Vox. I think the SSPL is most suitable for this purpose, this may need some reversing of the SPL with IDA Pro.
Thanks for those info, I'll try to go in that direction. Would be nice to find which one is splash, which one is gsm and the others below 0xA000.
I know we need to rev. SSPL. Don't exactly know where to start though I can't flash mine with any original ROM as Swisscom is not providing any.
BTW. viewimgfs gives me back a "packing DLL not found" (or some similar). Anyone had that also ?
I'll try to download IDA Pro...
It's below 0xA0000
I will do some testing again with the Vox today. I will see if I can paint the screen with a few instructions @0x10000000
I think I can not just run the SPL on VOX in the same way as you can on the ELF. The IPL on the VOX is 128kB, whereas on ELF it is only 2kB. So I think I will have to patch the IPL and run that first. I'm afraid that it will take a bit more time. Basically it will then be a SSPL (search forum for SSPL and user 'des') with both IPL and SPL patched and running in RAM.
But maybe it is also possible to patch just the SPL, because it could be that the default action initiated by IPL is to reset the device in RUU bootloader mode.
Given some time it can all be done I'm sure

HTC Kaiser SSPL v1 (or flashing any rom 4 free)

* THIS WILL WORK ON KAISER ONLY - FOR GENERIC METHOD SEE JumpSPL *
This tool allow to flash any Kaiser ROM bypassing CID and signature check.
You'll be able to change the ROM language, flash cooked roms, custom splash screens, etc...
FEATURES
Code:
1. SuperCID / Security Level=0
2. Does not check NBH signatures
3. Based on 0.92 Shipped SPL
4. Accept any Model ID
5. Disabled initial SD card loading to prevent hang
INSTRUCTIONS
Transfer SSPL-KAIS.exe to your Kaiser
Connect the USB cable and run SSPL-KAIS.exe (on kaiser, not on PC!)
Click "Continue", the Bootloader tri-color screen should appear
Check SPL version number: if it ends in ".JumpSPL" then everything is fine.
Unplug the USB cable and re-plug it
Device is ready to flash any ROM, you don't need ActiveSync at all.
DISCLAIMER
This software is free to use but at your own risk, I take no responsiblity for any conflict, fault, or damage caused by this unlocking procedure. No warranties of any kind are given.
DONATIONS
Your donations are a strong incentive to continue research on new devices, if you find JumpSPL useful please cosider making a PayPal donation. Any donation amount is greatly appreciated ​​
Enjoy!
--------------------
UPDATE: Found a problem on SSPL where it will hang when flashing a full ROM with a new RUU due to the NBH buffer being smaller in SPL-0.92, I removed the link and will update Kaiser SSPL version when I have some free time. At the moment, please use Kaiser Hard-SPL, this is safe
For those of you had the phone stuck in bootloader mode after flash with SSPL stopping at 16%, follow these instructions to unbrick your phone:
1. Download mtty.exe
2. Disable activesync (connection settings -> uncheck "allow usb connections")
3. Connect your Kaiser to PC using USB cable.
4. Open mtty, select USB port and click OK.
5. Hit ENTER twice, you should see the "Cmd>" prompt.
6. Type the command "boot", you should see something like this:
Code:
Cmd> [B]boot[/B]
InitDisplay: Display_Chip=1
No card inserted
OSSIReadBack ++
Read SI data from flash success
tail signature match
Checksum match
UserStorageSIPreload ++
After that device should boot WM6 again, you can now re-enable USB connections in activesync and flash HardSPL
[- reserved -]
OMG thank you POF!!! You are truly the MASTER!!
Question how do we go about dumping and using Imgfs tools in Kaiser ROMS?
Can you give us a basic run down since its different than the Hermes please
Okay, excuse my ignorance, but when you say Kaiser, do you mean all versions of the Kaiser, like the ATT Tilt (8925), or just the HTC Kaiser? Please don't beat me up
austinsnyc said:
Question how do we go about dumping and using Imgfs tools in Kaiser ROMS?
Click to expand...
Click to collapse
See here how to dump the ROM: http://forum.xda-developers.com/showthread.php?t=334680
I've not researched yet on how to use ImgfsTools, reconstruct dumped roms, etc... but should not be very different from what you already know from hermes, just be creative
kman79 said:
when you say Kaiser, do you mean all versions of the Kaiser, like the ATT Tilt (8925), or just the HTC Kaiser?
Click to expand...
Click to collapse
All versions
now the race is on for who comes out with the first ultra lite, mega storage space slim downed rom, who will it be.......
pof! you are tha MAN!
Thanks!
Donation to follow...
-Syrius
pof said:
* THIS WILL WORK ON KAISER ONLY - FOR GENERIC METHOD SEE JumpSPL *
3. Based on 0.92 Shipped SPL
Click to expand...
Click to collapse
was this from me??
- Syrius
Syrius_B said:
was this from me??
Click to expand...
Click to collapse
Yes Thanks mate!
pof said:
Yes Thanks mate!
Click to expand...
Click to collapse
anytime
- Syrius
HI Pof,
Does this also SIM unlock the device?
Or if I use this CID unlock and load the HTC rom will that SIM unlock the device?
Thanks
OMG, wonderfull.... now only need some research on how to repack dumped /modified ROMs... any aproach?
THANKS Pof you are incredible...
botap said:
HI Pof,
Does this also SIM unlock the device?
Or if I use this CID unlock and load the HTC rom will that SIM unlock the device?
Thanks
Click to expand...
Click to collapse
Only CIDUnlock.... SIM Unlok is not ready...
pof said:
See here how to dump the ROM: http://forum.xda-developers.com/showthread.php?t=334680
I've not researched yet on how to use ImgfsTools, reconstruct dumped roms, etc... but should not be very different from what you already know from hermes, just be creative
All versions
Click to expand...
Click to collapse
HI POF Ihave tried the above method using pdocread but keep getting an error , not sure if its because im using windows vista ultimate.
duttythroy said:
HI POF Ihave tried the above method using pdocread but keep getting an error , not sure if its because im using windows vista ultimate.
Click to expand...
Click to collapse
I manage to dump mine without problems using Vista Ultimate too ... if you get this error when executing pdocread
Code:
[I]
C:\itsutils>pdocread.exe -l
Copying C:\itsutils\itsutils.dll to WCE:\windows\itsutils.dll
Could not update itsutils.dll to the current version, maybe it is inuse?
try restarting your device, or restart ActiveSync [/I]
You have to modify this registry key, and then softreset using power button:
[B]HKLM\Security\Policies\Policies
[/B] valuename '[B]00001001[/B]' was set to dword:2, change it to dword:1
dword: any thing other than 1 disallows unsigned
dword: 1 allows unsigned
(extracted from Hermes wiki and tested on Kaiser)
jcespi2005 said:
I manage to dump mine without problems using Vista Ultimate too ... if you get this error when executing pdocread
Code:
C:\itsutils>pdocread.exe -l
Copying C:\itsutils\itsutils.dll to WCE:\windows\itsutils.dll
Could not update itsutils.dll to the current version, maybe it is inuse?
try restarting your device, or restart ActiveSync You have to modify this registry key, and then softreset using power button:
HKLM\Security\Policies\Policies
valuename '00001001' was set to dword:2, change it to dword:1
dword: any thing other than 1 disallows unsigned
dword: 1 allows unsigned
(extracted from Hermes wiki and tested on Kaiser)
Click to expand...
Click to collapse
just fount it on the wiki, thanks
help
@jcespi2005 just tired it change policies to dword 1 tried the same command but now getting this error.
c:\itsutils\pdocread.exe is not a valid Win32 application
what to do
duttythroy said:
@jcespi2005 just tired it change policies to dword 1 tried the same command but now getting this error.
c:\itsutils\pdocread.exe is not a valid Win32 application
what to do
Click to expand...
Click to collapse
Works fine for me... Try to download latest version of pdcoread here...
http://www.xs4all.nl/~itsme/projects/xda/tools.html
Big problem
Hi all I have a big problem I have try to flash my kaiser from SRF and using kaiser_JumpSPL_pof_v1. at 16% my the copy hanged and the Rom wizzard told me to remove the kaiser battery.
and after that I lost my old rom and I have the SPL from the factory ! and I dont have any copy from my old Rom.
and My phone is locked...
so How I can do to copy and execute the kaiser_JumpSPL_pof_v1 to my devis to try to flush the kaiser again
thx for you help
Titosa
Instructions to unbrick posted in the first post.
I'm closing this thread until I have time to post an updated and hopefully working version...

error 244. when i flash my rom with CustomRUU.What's the matter?

helloooo,everybody
i used ImgfsTools 2.1rc1 and followed bro Tadzio's introduction to cook my rom based on helmi_c's rom~
everything goes well
after NBMerge, i used dutty's tool to generate the os-new.nbh
and flashed it with pof's KaiserCustomRUUv1
but just 1%,my device rebooted and the KaiserCustomRUUv1 tells:
error 244: INVALID MODEL ID
it was still though i didnt modify anything in 'dump' directory
if i flash helmi_c's rom directly,that would be successful
what's wrong i have done? any tips?
forgive my broken Englsh pls...
REGARDS
Sheng
did you flash HardSPL to your Kaiser first?
heh... I had the exact same problem as yours (invalid model id). Using HTC Rom tool, I forgot to set Kaiser as the target ID for the nbh & it defaulted to hermes (I've since edited the ini file to change this).
yea.
i've got HSPL already and i have flashed the other roms many times, thats no problem.
fortunately that error just made my tytnII reboot and i can enter today screen,nothing change at all.
regards
Sheng
i believe your question was just answerd above and i also take it as SLEUTH getting a kaiser? thats cool man welcome to the new club house
woohyuksheng said:
helloooo,everybody
i used ImgfsTools 2.1rc1 and followed bro Tadzio's introduction to cook my rom based on helmi_c's rom~
everything goes well
after NBMerge, i used dutty's tool to generate the os-new.nbh
and flashed it with pof's KaiserCustomRUUv1
but just 1%,my device rebooted and the KaiserCustomRUUv1 tells:
error 244: INVALID MODEL ID
it was still though i didnt modify anything in 'dump' directory
if i flash helmi_c's rom directly,that would be successful
what's wrong i have done? any tips?
forgive my broken Englsh pls...
REGARDS
Sheng
Click to expand...
Click to collapse
Better than dutty's NBH tool, get the Dark Simpsons tool here with Kaiser support...
http://forum.xda-developers.com/showthread.php?t=311909
Cheers.
austinsnyc said:
i believe your question was just answerd above and i also take it as SLEUTH getting a kaiser? thats cool man welcome to the new club house
Click to expand...
Click to collapse
Thanks.... the Hermes was getting too reliable (boring)
Seems thats also now the case with the Kaisers lol... Tazdio's tools work great now after about 2 weeks of flashing roms that didnt work lol...
Oh I dunno... that pesky gps acquisition bug needs fixing and the PIE scroll freeze issue is a cooked in only patch so far. Tadzio is going to send me an updated toolset too itnf hopefully.... I'm itching to flash up a quick personal version with reghacks/PIE fix & maybe a different External GPS app. I may even adapt the hermes GPS RIL shim to express the Kaiser GPS on COM7 so the hermes external GPS applet can handle it.
so that scroll freeze issue in PIE doesn't just happen to me?! what a freakin relief!!!!
It's a real PITA for sure.... I've tried to make a cab to fix it but my initial attempt trashed my phone's RIL for some reason. I'll look at the dependencies more soon...

Windows Mobile 6.1 Hot Fix for Sending POP and IMAP E-mail

If anyone got problem with thier message sending and receiving
here a fix
THANK for this
Could this fix when Gmail just decides to stop sending all of a sudden? I know that this happens frequently for me and for my g/f's mom (who owns a Samsung Blackjack II).
Jason
myrandex said:
Could this fix when Gmail just decides to stop sending all of a sudden? I know that this happens frequently for me and for my g/f's mom (who owns a Samsung Blackjack II).
Jason
Click to expand...
Click to collapse
yes it does...more details:
http://support.microsoft.com/kb/958639
myrandex said:
Could this fix when Gmail just decides to stop sending all of a sudden? I know that this happens frequently for me and for my g/f's mom (who owns a Samsung Blackjack II).
Jason
Click to expand...
Click to collapse
it sure does
THANKS for this!!! Note to Chefs: can we get this cooked in, perhaps?
thedrizzle said:
THANKS for this!!! Note to Chefs: can we get this cooked in, perhaps?
Click to expand...
Click to collapse
This would be good and on a side issue it could help us (me...) understand how the remodule thing works if the experienced chefs (or at least the ones who now how to remodule stuff?) showed us how to remodule a .dll. The original 'mailtrns.dll' dumped from an official ROM is moduled, this hotfix is just a file so I would be really grateful of an explanation on how to rework this file into a module for cooking into a ROM.
Andy
Re-worked new 'mailtrns.dll' into ROM and re-moduled it....
I currently use Alex's Kitchen (V5) to cook my ROMs and it has been excellent. I dumped the original official HTC 5.2.19212 ROM and use this as a base. As I said I wanted to cook this MS update into my ROM but remodule the new 'mailtrns.dll' file (and obviously just overwriting the mail-providers.mxl file).
I attempted to use the 'package-creator-v2.7' tool which converts the .cab to an OEM and gives you the option to remodule .exe, .dll and .mui files which it did. However just relpacing the files in the \SYS\BaseApps folder didn't work. So I had another search on the whole module thing and still couldn't find any tutorials I could understand, but I did find some posts on the BuildOS and PkgTools. I noticed in the 'PkgToolsBuildos-4.3b1.exe' there is the option to Remodule Packages. So as an experiment I deleted the original 'mailtrns.dll' folder (module) and 'Mail-Providers.xml' file from the \SYS\BaseApps folder and copied in the replacement files 'mailtrns.dll' and 'Mail-Providers.xml'. I then used the 'PkgToolsBuildos-4.3b1.exe' to remodule the files in this folder and then used the older tools and batch files (buildos+package_tools-2.7.exe) to create a new ROM - and it all works
I have since used the same technique to remodule other packags and again they are all working. I still don't know why or how, or what the benefits of modules over files in the packages are, however I seem to recall modules were better due to how memory is allocated or something
If anyone wants to explain all this or post a link to somewhere that does I would be grateful.
The short version is I have re-worked this update into my kitchen based on the official HTC 5.2.19212 ROM and have remoduled it like the original file (mailtrns.dll) it replaces.
Andy
Setup Error
ron999 said:
If anyone got problem with thier message sending and receiving
here a fix
Click to expand...
Click to collapse
I tried to install this fix on CE OS 5.2.20757 (Build 20757.1.4.0) what I believe is HyperDragon_III_BlackStone_WWE_20081203
Setup Error:
This update cannot be installed on this version of Windows Mobile.
Current: 6.1 AKU 1.4.0.0
Build 20273 Platform 2
Any ideas?
Rip Torn said:
I tried to install this fix on CE OS 5.2.20757 (Build 20757.1.4.0) what I believe is HyperDragon_III_BlackStone_WWE_20081203
Setup Error:
This update cannot be installed on this version of Windows Mobile.
Current: 6.1 AKU 1.4.0.0
Build 20273 Platform 2
Any ideas?
Click to expand...
Click to collapse
very interesting but this is the latest release version 1
but like I say mine running well rom base 334 721.2
you maybe missing some file or something
hope this helps

[17 march 2009] mATTE's ROM v1--try for be fast!

hi to all.
I wanna speack about my work.
this ROM it's not ordinary ROM, you can update without flash(yes you have understand)!
the ROM mATTE's had:
-all program that you need(see pictures), all removable as you like!!!
-OVERCLOCK TO CPU
-FREE RAM 61 MB
ABOUT mATTE's:
wm6.1professional CE OS 5.2.19188(built 19188.1.0.0)
this ROM born for "replace" the UDK rom for kaiser.
I,like UDK, love fast and stable ROM, and I had created a beautiful ROM based on framework.net 3.5
CAN DO:
-quickly internet with opera mini
-full internet with Opera
-messsenger with fix
-youtube, google video etcwith WVD
-read divX with TMCMP
-play music with S2P AND WMP
-see photos with S2V and camera album
-navitate with TT6.032 or google maps and gps tools
-office 2007 and scientific calculator
-wake up with G-allarm
-icontact x more fingerfriendly contact
-lock with S2u2
-winrar for every archive
-card export for read your microSD as pen drive
-spb backup to create the backup file in .exe like mine
-java manager
-kasiser tweak
-regedit
-quick menu...never be slow...menu like windows XP or vista in your start menu
YOU CAN REMOVE EVERY OF THIS PROGRAMS AS A NORMAL CABs!!
I leave you a little tutorial to flash and upgrade my rom(upgrade by kaiser with .exe file withoup use a pc)
download this file:
http://www.megaupload.com/?d=DOWFZFW3
http://www.megaupload.com/?d=88X62IGY
http://www.megaupload.com/?d=2LZFUSUT
then:
-flash my rom mATTE's(IT'S VERY UGLY...DON'T WORRY!!)
-flash my radio KAIS_Radinly_1.64.08.21_CustomRUU
-copy mattes1o.exe on device and ignore the file Backup_20090317.exe with RADIO ROM
-run mattes1o.exe--CLICK AVANTI AVANTI AVANTI(NEXT NEXT NEXT...)
-wait after reset and perform a soft reset
KNOW BUG:MY ROM IS A MANUAL SOFT RESET ONLY, WHEN REQUEST SOFT RESET, PLS APPLY MANUALLY
USED SPL 1.0 OLIPOF
TEST ON KAIS130 V1615 VODAFONE
some scrennshot:
please pay me a beer with paypal:
mail: mark4cops at yahoo.it
donators:
next update: the used .cab files of this ROM
please post your feedback
wow, this week we've got a bunch of new chefs
congratulations mate
Soooo, can any kind soul please explain me what's this besides a standard HTC ROM (build number uknown) with a few programs (tomtom, Google maps, etc). bundled into an exe that installs them after flash?.
Hey, I can get the cabs I want and install software on my device myself.
welcome new chef....
man am i glad i have a kaiser...
umm...maybe u should have reserved some posts?
vcespon said:
Soooo, can any kind soul please explain me what's this besides a standard HTC ROM (build number uknown) with a few programs (tomtom, Google maps, etc). bundled into an exe that installs them after flash?.
Hey, I can get the cabs I want and install software on my device myself.
Click to expand...
Click to collapse
Because he take it and sharing for everyone,however....i think that is WM6.0.
this night I update all information.
the rom is wm6.1
I had a kaiser from 2 year...never tried a fast ROM like the mine! please verify if i do something wrong.
do you understand wath you must do for had my rom??
flash rom - flash radio - execute the file mattes1o.exe from kaiser
it's a "new" way to upgrade rom features without flash...
I'm here for all!
what exactly does mattes1o.exe do?
installs pharm Parn, lol kidding, Congrats dude on the first release
Peace,
Josh
mbarvian said:
what exactly does mattes1o.exe do?
Click to expand...
Click to collapse
configure your kaiser and install many programs(removeable as you want).
if you don't run mattes1o.exe you have a basic rom without programs and very ugly, if you run...you have MY ROM
in this way i can create another mattesXX.exe for upgrade program automatically, resolve bug or change skin...you must only run my future mattesXX.exe
Andre_Santarell said:
configure your kaiser and install many programs(removeable as you want).
if you don't run mattes1o.exe you have a basic rom without programs and very ugly, if you run...you have MY ROM
in this way i can create another mattesXX.exe for upgrade program automatically, resolve bug or change skin...you must only run my future mattesXX.exe
Click to expand...
Click to collapse
why not include the packages/configuration as OEM Packages? Also, how would you uninstall?
You would un-install them like regular CABs I think. As in going to Start/Settings/System/Remove Programs.
mbarvian said:
why not include the packages/configuration as OEM Packages? Also, how would you uninstall?
Click to expand...
Click to collapse
if I not include you can unistall programs as you want, and I can modify ROM without use the ROMkitchen
kaiserii101 said:
you would un-install them like regular cabs i think. As in going to start/settings/system/remove programs.
Click to expand...
Click to collapse
exactly...as you like!!
Andre_Santarell,
So there is a ROM that is a base ROM, then the .exe is one of a mass .cabs and settings installer? we as users had been asking about a program to do this may i ask what it is you use?
Sorry for all the questions
stylez.
stylez said:
Andre_Santarell,
So there is a ROM that is a base ROM, then the .exe is one of a mass .cabs and settings installer? we as users had been asking about a program to do this may i ask what it is you use?
Sorry for all the questions
stylez.
Click to expand...
Click to collapse
HI
I create a base ugly rom ultra light, then I modify all rom with programs and skins, I make a backup of my work with sbp backup 2.0 that create an .exe file.
then if you want my work you must flash my rom(ugly and light) and then run my backup file that automatically install all...YOU DON'T DO NOTTHING ELSE
Andre_Santarell said:
hi to all.
I wanna speack about my work.
this ROM it's not ordinary ROM, you can update without flash(yes you have understand)!
the ROM mATTE's had:
-all program that you need(see pictures), all removable as you like!!!
-OVERCLOCK TO CPU
-FREE RAM 61 MB
ABOUT mATTE's:
wm6.1professional CE OS 5.2.19188(built 19188.1.0.0)
this ROM born for "replace" the UDK rom for kaiser.
I,like UDK, love fast and stable ROM, and I had created a beautiful ROM based on framework.net 3.5
CAN DO:
-quickly internet with opera mini
-full internet with Opera
-messsenger with fix
-youtube, google video etcwith WVD
-read divX with TMCMP
-play music with S2P AND WMP
-see photos with S2V and camera album
-navitate with TT6.032 or google maps and gps tools
-office 2007 and scientific calculator
-wake up with G-allarm
-icontact x more fingerfriendly contact
-lock with S2u2
-winrar for every archive
-card export for read your microSD as pen drive
-spb backup to create the backup file in .exe like mine
-java manager
-kasiser tweak
-regedit
-quick menu...never be slow...menu like windows XP or vista in your start menu
YOU CAN REMOVE EVERY OF THIS PROGRAMS AS A NORMAL CABs!!
I leave you a little tutorial to flash and upgrade my rom(upgrade by kaiser with .exe file withoup use a pc)
download this file:
http://www.megaupload.com/?d=DOWFZFW3
http://www.megaupload.com/?d=88X62IGY
http://www.megaupload.com/?d=2LZFUSUT
then:
-flash my rom mATTE's(IT'S VERY UGLY...DON'T WORRY!!)
-flash my radio KAIS_Radinly_1.64.08.21_CustomRUU
-copy mattes1o.exe on device and ignore the file Backup_20090317.exe with RADIO ROM
-run mattes1o.exe--CLICK AVANTI AVANTI AVANTI(NEXT NEXT NEXT...)
-wait after reset and perform a soft reset
KNOW BUG:MY ROM IS A MANUAL SOFT RESET ONLY, WHEN REQUEST SOFT RESET, PLS APPLY MANUALLY
USED SPL 1.0 OLIPOF
TEST ON KAIS130 V1615 VODAFONE
some scrennshot:
please pay me a beer with paypal:
mail: mark4cops at yahoo.it
donators:
next update: the used .cab files of this ROM
please post your feedback
Click to expand...
Click to collapse
U telling me you can overclock the cpu?
apatcas said:
U telling me you can overclock the cpu?
Click to expand...
Click to collapse
yes I found this in wiki of kaiser
http://forum.xda-developers.com/showthread.php?t=394384
http://forum.xda-developers.com/showpost.php?p=2232922&postcount=532
Andre_Santarell said:
yes I found this in wiki of kaiser
http://forum.xda-developers.com/showthread.php?t=394384
http://forum.xda-developers.com/showpost.php?p=2232922&postcount=532
Click to expand...
Click to collapse
I thought this was debated before and concluded as making your Kaiser not very stable??
biscuits1978 said:
I thought this was debated before and concluded as making your Kaiser not very stable??
Click to expand...
Click to collapse
it was and i've tried it on MANY roms and can't tell it makes any difference other than taking up space
Hey....congrats!!!!!......um......anyone tried the new rom yet? And how's the speed?....fast I hope!!

Categories

Resources