* THIS WILL WORK ON KAISER ONLY - FOR GENERIC METHOD SEE JumpSPL *
This tool allow to flash any Kaiser ROM bypassing CID and signature check.
You'll be able to change the ROM language, flash cooked roms, custom splash screens, etc...
FEATURES
Code:
1. SuperCID / Security Level=0
2. Does not check NBH signatures
3. Based on 0.92 Shipped SPL
4. Accept any Model ID
5. Disabled initial SD card loading to prevent hang
INSTRUCTIONS
Transfer SSPL-KAIS.exe to your Kaiser
Connect the USB cable and run SSPL-KAIS.exe (on kaiser, not on PC!)
Click "Continue", the Bootloader tri-color screen should appear
Check SPL version number: if it ends in ".JumpSPL" then everything is fine.
Unplug the USB cable and re-plug it
Device is ready to flash any ROM, you don't need ActiveSync at all.
DISCLAIMER
This software is free to use but at your own risk, I take no responsiblity for any conflict, fault, or damage caused by this unlocking procedure. No warranties of any kind are given.
DONATIONS
Your donations are a strong incentive to continue research on new devices, if you find JumpSPL useful please cosider making a PayPal donation. Any donation amount is greatly appreciated
Enjoy!
--------------------
UPDATE: Found a problem on SSPL where it will hang when flashing a full ROM with a new RUU due to the NBH buffer being smaller in SPL-0.92, I removed the link and will update Kaiser SSPL version when I have some free time. At the moment, please use Kaiser Hard-SPL, this is safe
For those of you had the phone stuck in bootloader mode after flash with SSPL stopping at 16%, follow these instructions to unbrick your phone:
1. Download mtty.exe
2. Disable activesync (connection settings -> uncheck "allow usb connections")
3. Connect your Kaiser to PC using USB cable.
4. Open mtty, select USB port and click OK.
5. Hit ENTER twice, you should see the "Cmd>" prompt.
6. Type the command "boot", you should see something like this:
Code:
Cmd> [B]boot[/B]
InitDisplay: Display_Chip=1
No card inserted
OSSIReadBack ++
Read SI data from flash success
tail signature match
Checksum match
UserStorageSIPreload ++
After that device should boot WM6 again, you can now re-enable USB connections in activesync and flash HardSPL
[- reserved -]
OMG thank you POF!!! You are truly the MASTER!!
Question how do we go about dumping and using Imgfs tools in Kaiser ROMS?
Can you give us a basic run down since its different than the Hermes please
Okay, excuse my ignorance, but when you say Kaiser, do you mean all versions of the Kaiser, like the ATT Tilt (8925), or just the HTC Kaiser? Please don't beat me up
austinsnyc said:
Question how do we go about dumping and using Imgfs tools in Kaiser ROMS?
Click to expand...
Click to collapse
See here how to dump the ROM: http://forum.xda-developers.com/showthread.php?t=334680
I've not researched yet on how to use ImgfsTools, reconstruct dumped roms, etc... but should not be very different from what you already know from hermes, just be creative
kman79 said:
when you say Kaiser, do you mean all versions of the Kaiser, like the ATT Tilt (8925), or just the HTC Kaiser?
Click to expand...
Click to collapse
All versions
now the race is on for who comes out with the first ultra lite, mega storage space slim downed rom, who will it be.......
pof! you are tha MAN!
Thanks!
Donation to follow...
-Syrius
pof said:
* THIS WILL WORK ON KAISER ONLY - FOR GENERIC METHOD SEE JumpSPL *
3. Based on 0.92 Shipped SPL
Click to expand...
Click to collapse
was this from me??
- Syrius
Syrius_B said:
was this from me??
Click to expand...
Click to collapse
Yes Thanks mate!
pof said:
Yes Thanks mate!
Click to expand...
Click to collapse
anytime
- Syrius
HI Pof,
Does this also SIM unlock the device?
Or if I use this CID unlock and load the HTC rom will that SIM unlock the device?
Thanks
OMG, wonderfull.... now only need some research on how to repack dumped /modified ROMs... any aproach?
THANKS Pof you are incredible...
botap said:
HI Pof,
Does this also SIM unlock the device?
Or if I use this CID unlock and load the HTC rom will that SIM unlock the device?
Thanks
Click to expand...
Click to collapse
Only CIDUnlock.... SIM Unlok is not ready...
pof said:
See here how to dump the ROM: http://forum.xda-developers.com/showthread.php?t=334680
I've not researched yet on how to use ImgfsTools, reconstruct dumped roms, etc... but should not be very different from what you already know from hermes, just be creative
All versions
Click to expand...
Click to collapse
HI POF Ihave tried the above method using pdocread but keep getting an error , not sure if its because im using windows vista ultimate.
duttythroy said:
HI POF Ihave tried the above method using pdocread but keep getting an error , not sure if its because im using windows vista ultimate.
Click to expand...
Click to collapse
I manage to dump mine without problems using Vista Ultimate too ... if you get this error when executing pdocread
Code:
[I]
C:\itsutils>pdocread.exe -l
Copying C:\itsutils\itsutils.dll to WCE:\windows\itsutils.dll
Could not update itsutils.dll to the current version, maybe it is inuse?
try restarting your device, or restart ActiveSync [/I]
You have to modify this registry key, and then softreset using power button:
[B]HKLM\Security\Policies\Policies
[/B] valuename '[B]00001001[/B]' was set to dword:2, change it to dword:1
dword: any thing other than 1 disallows unsigned
dword: 1 allows unsigned
(extracted from Hermes wiki and tested on Kaiser)
jcespi2005 said:
I manage to dump mine without problems using Vista Ultimate too ... if you get this error when executing pdocread
Code:
C:\itsutils>pdocread.exe -l
Copying C:\itsutils\itsutils.dll to WCE:\windows\itsutils.dll
Could not update itsutils.dll to the current version, maybe it is inuse?
try restarting your device, or restart ActiveSync You have to modify this registry key, and then softreset using power button:
HKLM\Security\Policies\Policies
valuename '00001001' was set to dword:2, change it to dword:1
dword: any thing other than 1 disallows unsigned
dword: 1 allows unsigned
(extracted from Hermes wiki and tested on Kaiser)
Click to expand...
Click to collapse
just fount it on the wiki, thanks
help
@jcespi2005 just tired it change policies to dword 1 tried the same command but now getting this error.
c:\itsutils\pdocread.exe is not a valid Win32 application
what to do
duttythroy said:
@jcespi2005 just tired it change policies to dword 1 tried the same command but now getting this error.
c:\itsutils\pdocread.exe is not a valid Win32 application
what to do
Click to expand...
Click to collapse
Works fine for me... Try to download latest version of pdcoread here...
http://www.xs4all.nl/~itsme/projects/xda/tools.html
Big problem
Hi all I have a big problem I have try to flash my kaiser from SRF and using kaiser_JumpSPL_pof_v1. at 16% my the copy hanged and the Rom wizzard told me to remove the kaiser battery.
and after that I lost my old rom and I have the SPL from the factory ! and I dont have any copy from my old Rom.
and My phone is locked...
so How I can do to copy and execute the kaiser_JumpSPL_pof_v1 to my devis to try to flush the kaiser again
thx for you help
Titosa
Instructions to unbrick posted in the first post.
I'm closing this thread until I have time to post an updated and hopefully working version...
Related
Hi, I've a vodefone v1240 (HTC Tornado), i've tried to flash wm6 flash to it... but... i haven't super cid unlock... the flash is ok but phone always star in muticolor screen (botloader screen), i've tried to flash a lot of flashes but always get invalid vendor id or "only upgrade"... i've tried too with TyphoonNbfTool to edit nbf and change vendor id.. but always get the same mensaje ("invalid vendor id" or "only upgrade")...
How can i recover my phone? :S
Thanks
Sendoa
Determine your original CID first, to do this type:
Code:
info 2
into mtty or teratermpro and paste the output in the thread
Phil
Ahh, there you are ! Are you or duke_Stix still planning to cook some newer ROMs or remove bugs from the existing one ? We hardly see you guys around there days
i get this... what is the original CID? ¿?
info 2
GetDeviceInfo=0x00000002
+ SD Controller init
- SD Controller init
+StorageInit
***** user area size = 0x3CE40000 Bytes
HTCSVODA0504 㱍dHTCE
Cmd>
@anandoc: I've been fairly busy lately what with Jury Service etc but I've got a beta version in progress
Changelog:
HTC Task Manager inc
HTC File Manager inc
Application Unlocked
Fixed WiFi
HTC Comm Manager inc
Removed Wireless Manager
Removed Debug Apps
Removed Marketplace
Removed Office
Removed Voice Command,
Removed Windows Update,
Added Bluetooth DUN support for TomTom compatibility
Added Bluetooth FTP protocol
Extra's (as a separate download)
Office
MMS (semi working)
HTC Clear Storage
Jeodek Java
Button fixes
xT9 (for those who prefer it over standard T9)
xT9 lang packs (split into separate languages)
TCPMP
wm5torage
VoIp
Localisations:
Polish
Czech
Russian
However at the moment I'm having issues with initflashfiles.dat, once these are sorted, it will probably be released the same day.
Back to the topic:
Ok, using typhoonnbftool v0.41 open up a tornado nbf (wm6 or official, it doesnt matter) and then edit the header data so that the Operator field reads:
Code:
VODA0504
That is your original CID
Then save the nbf and flash it to your device
Phil
done but...
Hi, i've done but... always get a "only upgrade"... only let me to reflash wm6 flash.. but it always return to bootloader screen :S what am i doing wrong? :S
Thanks anyway
Sendoa
Try adjusting the version numbers to something ridiculous like 99.99.99.99 as well
Phil
jm012a9749 said:
@anandoc: I've been fairly busy lately what with Jury Service etc but I've got a beta version in progress
Phil
Click to expand...
Click to collapse
Hey Phil, Thanks very much for the update ! Your hard work is much appreciated here !!
Me too
I'm having the same problem as Sendoa. I flashed the WM6 ROM to my 8310but after 100% completion, the phone re-started in bootloader mode.
I can flash it again with the WM6 but the same thing happens each time (bootloader mode). I've tried to flash with several other ROMs but each time I get the "Invalid Vendor ID" error before flashing begins.
I've tried the Typhoonnbftool tool to change the header as suggested earlier in this thread but without any success. My CID is 'DNG_0501'. I'm still stuck in bootloader mode.
I'd appreciate any assistance.
Thanks,
Straker.
Sorted
Sorted. Found another ROM (the fifth I've tried) that would flash without the 'Invalid Vendor' message. It let me get back to a standard WM5 setup.
Solved
Thanks to all
I flash it with a cingular flash with version changed to 79.79.79.79 and operator changed to VODA0504, and work again.. then i've unlock the cid and flash wm6 flash and it is working with it
Thanks again
Wow, that's cool, means I can flash my phone to WM6 without voiding my warranty ( I still got 5 months left )
lomanasq said:
Here, here they are:
cancer awareness ribbon
Click to expand...
Click to collapse
ban this MOTHA F**&&
Straker said:
Sorted. Found another ROM (the fifth I've tried) that would flash without the 'Invalid Vendor' message. It let me get back to a standard WM5 setup.
Click to expand...
Click to collapse
where did you get your flash from?
typhoonnbftool is creating only 1kb file of nk.nbf
Hi,
I have the new typhoonnbftool got it from sourceforge when i try to edit headers of a Imate rom to make it for xpa swisscom v1240 with the CID "VODA0505" i get only 1kb nbf file i try lots of thinks but no luck at all.
kind regards
Fakbrenjeri
Similar problem
I've used Typhoonnbftool to change header, but the resulting file is only ever 1kb or smaller! What am I doing wrong?
Small nbf
Straker,
Where did you get the rom that worked?
timwb said:
I've used Typhoonnbftool to change header, but the resulting file is only ever 1kb or smaller! What am I doing wrong?
Click to expand...
Click to collapse
use typhoon tools 0.4.1...
ftp://ftp.xda-developers.com/Uploads/Smartphone/Tornado/Shipped_Complete_Updates/I-mate
use the rom from here..
Stuck on BootLoader
I there!
I've tried everything that I could find here and still no luck...:-\
I've an SPV C600 and when I upload the Imate ROM it stays stuck on the BootLoader.
It only works if I upload the Orange Upgrade ROM...
I can't SuperCID it, since no app as worked till now...
What can I do?
Thank you!
try this:
http://forum.xda-developers.com/showthread.php?t=285344
Inspired by some threads in the Hermes and Trinity forums I started to explore the VOX bootloader. You can enter the bootloader by pressing the camera and power button at the same time. You see the tri-color (red/green/blue) bootscreen which shows the bootloader and CPLD version. In connection settings of activesync uncheck "allow USB connections" and connect PC and Vox with a USB cable. The PC will recognize the Vox and install an interface driver.
You need the MTTY to talk with the bootloader and send it commands. The Hermes wiki provides some good information and also has a link to MTTY:
http://wiki.xda-developers.com/index.php?pagename=Hermes_BootLoader
Unfortunately the Vox bootloader (v1.16.0000) doesn't display help information. The first command you should enter is password. I found a password for Trinity and Hermes which also works for Vox:
password BsaD5SeoA
Here are a couple of other commands which work: emapiWlanEERW, emapiInit, emapiWlanMac, emapiPwrDwn, emapiRead, emapiTest, emapi, cpldver, DumpReservoir, CheckImage, calcrccheck, getdevinfo, ruustart, ruurun, progress, wdata, password, mbr, set, atcmd, ResetDevice, BTRouting, BTTestMode, SetDebugMethod, IMEI, ls, lnbs
I would like to find a way to dump the SPL and ROM to SD-card or to PC. I tried a couple of things (r2sd, d2s) to no avail.
Anyone else some ideas?
Update1
I got stuck in the bootloader and luckily found how to boot into the OS again:
http://forum.xda-developers.com/showpost.php?p=1094479&postcount=11
password BsaD5SeoA
ruurun 0
ResetDevice
Update2
I discovered the 'ls' command. Afaik it allows to dump the rom parts like SPL, IPL, splashscreen when the device is CID unlocked. My unbranded S710 is SIM unlocked, but unfortunately not CID unlocked. When I issue 'ls' there's a "not allowed" error
Update3
I found a 'good' VOX ROM upgrade (the ones on the XDA FTP are all corrupt): RUU_Vox_HTC_WWE_1.15.405.2R4_4.1.13.37_02.83.90_Ship
Another upgrade ROM is the Dopod:
RUU_Vox_DOPODASIA_WWE_1.19.707.3_4.1.13.37_02.83.90_Ship
I used NBHextract.exe to extract both ROMs. The SPL bootloaders are attached.
NBHextract shows following info for the 1.15 Vox ROM upgrade:
Code:
Device: VOX010100
CID: HTC__001
Version: 1.15.405.2
Language: UK
Extracting: 00_IPL.nb
Extracting: 01_SPL.nb
Extracting: 02_GSM.nb
Extracting: 03_MainSplash.nb
Encoding: 03_MainSplash.bmp
Extracting: 04_OS.nb
and this for the Dopod upgrade:
Code:
Device: VOX010100
CID: DOPOD001
Version: 1.19.707.3
Language: USA
Extracting: 00_IPL.nb
Extracting: 01_SPL.nb
Extracting: 02_MainSplash.nb
Encoding: 02_MainSplash.bmp
Extracting: 03_GSM.nb
Extracting: 04_OS.nb
Update4
I managed to back up my S710 using itsme's "bkondisk" tool and "prun" from his itsutils suite here and here. Copy bkondisk.exe to /Windows on your device.
After running this on your PC
Code:
prun bkondisk.exe "\Storage Card"
following files are created in \Storage Card and a log file "bkondisk.log" in \
Code:
bk_00_0000.img - IPL : ONBL1 + ONBL2
bk_02_0005.img - GSM + splash + gsmdata + simlock + serialnrs
bk_03_0025.img - OS
bk_06_0001.img - SPL
bk_08_0205.img - userfilesystem
I compared a couple of these .img files with the .nb files extracted by NBHextract from an official RUU. The IPL and SPL look quite okay, but the OS is mapped totally different. So don't think you can just rename for example bk_03_0025.img to OS.nb in order to have a flashable file !! I have attached my dumped SPL which is version 1.16
Next mission is to find a 'good' (not corrupted) version of the RUU_Vox_HTC_WWE_1.15.405.2_4.1.13.37_02.83.90_Test.exe ROM upgrade. See this Excalibur thread. I think the same applies to S710
Update5
With Dark Simpson's htc rom tool here it is possible to create a flashable image file from separate .nb files. There is also Dutty's good NBHtool 1.1 yet, but so far I haven't tried it.
What we still need to have for flashing unsigned ROM images is a SSPL. See here and here.
Alternatively we need a so called Update SPL (USPL) which unlocks CID and then allows flashing any rom to your device. The version for the ELF created by the brilliant moderator pof can be found here. Since the ELF is very similar to VOX, I will study it and see if I can use it to implement a SSPL (software SPL) which allows us to also flash any ROM, but does not require to flash an USPL. I think flashing IPL and SPL is a bit too tricky atm.
Take the Elf USPL, remove the RUU folder (to be sure you don't flash anything by mistake), in the LOADER folder change the .nb file for a Vox bootloader (different version than the one on your device) and use the same name for the .nb file, then run elf-uspl.exe on your PC.
If elf & vox are so similar, this should jump to the bootloader you've placed in the LOADER folder, to check it disable activesync usb connections and go into bootloader with mtty. Do an "info" command or whatever identifies that the bootloader you're seeing is the one you've placed on the LOADER folder and not the one actually on your device.
If you succeed in loading a custom bootloader I can help you with the don't check cid / don't check signatures... patches
Good luck!
Thanks for replying pof. I did as you said and tried it with spl 1.15 (whereas 1.16 is flashed on my S710). First I went through step1 and then went in to step2 where at 75% the screen got blank and it rebooted the phone in my native bootloader 1.16 RUU mode. I suppose that's not what we wanted to see?
Where did you find RUU_Vox_HTC_WWE_1.15.405.2R4_4.1.13.37_02.83.90_Ship? Do you have a link?
Thanks
I found it here:
http://www.leaf.co.za/Members/Member Services/Manage My Profile/
Cant Find The Bootloader For The Life of Me
Tried:
"You can enter the bootloader by pressing the camera and power button at the same time. You see the tri-color (red/green/blue) bootscreen which shows the bootloader and CPLD version."
No Luck. I must be thick. Its gotta be just that easy... but...
The S710 simply boots into my home screen.
Can someone PLEASE post a (little) more detail about how to boot into the bootloader on the s710/vox?
THANKS.
Cheers.
** EDIT **
OK- Better bootloader entry instructions for SP noobs (like myself):
1) Turn device off
2) Unplug power/usb cable from handset
3) Press and hold camera button
4) Plug power/usb cable into handset
5) Be amazed by Blue-Green-Red Bootloader screen.
Yeah, it won't boot in bootloader mode if the usb cable is connected. Well, it's sometimes better to find out things all by yourself
Besides, I don't think anyone other than myself is researching this stuff on Vox. Too many ordinary users and nearly noone in to h*cking.
You don't have 1.04 on your phone by any chance?
RE: older bootloader
No joy.
Sorry.
Its 1.15
My SP has vanilla mods.
Its just out of the box the last 4 days in NYC!
The phones not even available AFAIK in the US yet-- except special order.
Got mine in London last week.
Still working out the kinks.
BTW:
Im looking for info/docs/someone who has forced GSM codec through WM6 to this handset through Asterisk LOCALLY-- Asterisk SIP logs show successful codec negotiation and initial start of audio delivery-- but the stream pukes out on my handset immediately-- ideas? Im begining to think it may be a cpu issue. Thanks.
850mph said:
BTW:
Im looking for info/docs/someone who has forced GSM codec through WM6 to this handset through Asterisk LOCALLY-- Asterisk SIP logs show successful codec negotiation and initial start of audio delivery-- but the stream pukes out on my handset immediately-- ideas? Im begining to think it may be a cpu issue. Thanks.
Click to expand...
Click to collapse
Yeah saw that. I don't think it's a CPU issue, could run GSM codec just fine on a stone old iPaq. Try trunning omap overclocker and set it to 240MHz and see if it makes a difference. Keep using the SIP thread for any replies on this
POF's O2/Nova Solution
jockyw2001-
I suppose youve seen Pof's post #89 (dated 4-8) in the "ELF Update SPL (USPL)" thread which calls for running enable-rapi.cab (on O2 Nova) BEFORE elf-uspl.exe?
Id try it myself but want a few days of joy with my handset BEFORE creating a potential brick.
From my reading if the elf-uspl.exe makes it to 75% in stage 2 before white-screening-- you're close (well, 75% anyway.. wink!). Seems like Pof could have a couple of suggestions at that point. Maybe hell be kind enough to comment?
You're on it.. but I thought Id ask.
Cheers.
Heres something I am trying to work out-- even after many hours of reading:
I understand that there is an exploit in the 1.04 bootloader which can potentially bypass CID and Certs when flashing a new ROM image on both SPs and PPCs..
I also understand that bootloaders 1.09+ cant be downgraded.
So am I right in assuming that potential VOX ROM-chefs have at least ** TWO ** potential paths to solving the bootloader issue:
1) Find a 1.04 bootloader **AND** a tool which will load it successfully
-- Then use the exploit (which I read about-- but cant find) to flash the ROM
-or-
2) Find a way to Flash **ANY** bootloader onto the vox with elf-uspl.exe
-- Then (keeping our fingers crossed) elf-uspl.exe can be patched to defeat the CID&CERT issues with the vox
Now heres the question:
I am right in assuming that we **DONT** need to find a way to flash **SPECIFICALLY** the 1.04 bootloader onto the ROM **BEFORE** we can take advantage of a patched elf-uspl.exe?
Is that correct?
Cheers.
Oh yeah.. AM I right in assuming that the WM5/6 bootloaders are EXACTLY the same code (except for dated revs) across all WM SP and PCC devices-- sort of like the ability to install grub or lilo on **ANY VENDORS PC** no matter what OS or eventual Software Packages end up on the box?
Looked at another way:
When they talk about the 1.15 bootloader in the Blue Angel Board they are talking about the EXACT SAME 1.15 bootloader in the VOX board?
I mean, I know this is gotta be the case but I need a little reassurance here-- As Im still a bit confused on why PPC software should run on SP devices-- even understanding that they use (generally) the same subset (WM5/6) of the CE5/6 API-- But have different CPUs.
850mph: cool to see there actually are brothers in arms
I've tested pof's USPL extensively, but haven't got it to work (yet).
Actually you need to run enable-rapi.cab only if your phone isn't yet application unlocked, i.e. if it doesn't allow to run unsigned apps. Mine is application unlocked so I can skip that step.
The next step is to load a modded SPL in RAM at physical address 0x10000000 and to run it. Once this modded SPL is running another modded SPL can be flashed.
I've tried to load an unmodified SPL in RAM (e.g. SPL 1.15) and to run it. This can be done with following 2 steps:
1) psetmem.exe -f -p 0x10000000 spl.nb
2) run haret.exe on device (can use cecopy & cerun); cerun -b CE:\haret.exe
Note: haret.exe is a linux kernel loader which was modified by pof to run a USPL from 0x10000000
What happens is that my phone reboots into the stock bootloader (SPL 1.16) in RUU mode. I have to use MTTY in order to boot the phone in WM again (see post #1 and #2 in this thread).
Actually I think haret.exe does run the SPL 1.15 which is loaded in RAM, but that at some point the code resets the device.
I'm quite sure we can run a specially prepared USPL or SSPL which allows flashing another specially prepared SPL such that the device is effectively CID unlocked which again means that any vendor's firmware can be flashed. I also think we don't absolutely need the SPL 1.04 for that purpose.
This is good info.
I see what you are trying to do now.
Im gonna take some time to get up to speed on Dumping/Reading/Flashing from the Trinity Hermes and Elf pages. Until then Im afraid Ill be of little use.
Until now Ive strictly been a Linux/GCC-guy. Im tempted (but not convinced) that I want to take the time to learn Microsofts WM5/6 IDE. Its a time issue (obviously).
But I will spend some time on the whole S710 ROM-cooking (and bootloader) issue this week. It looks manageable.
I see you have basically been mixing and matching the various ROM cooking tools-- including using Msofts CE powerToys. Is there no single suite (besides the ImagefsTools) which you can recommend I look at first (With the understanding we need to solve the bootloader issue specifically for the vox first)-- I see various kitchens for various devices. Do any of them see plausible as a starting point for an HTC/Vox kitchen suite?
GOOD LUCK.
Cheers.
** EDIT **
I REALLY think the S710/S730spec are GREAT devices-- couple of minor issues-- but just fantastic form-factors.
new in the sandbox
Hi guys,
I just got my XPA 1415 some days ago (for info, it's just the same than the others (HTC S710, SPV E650 and Vodafone V1415, VOX, ...) but from Swisscom (Swiss provider).
I've been reading around and found this thread that was the most related. I actually tried to use the techniques provided by jockyw2001 with no luck.
Doing a prun bkondisk does not work, neither any of the itsutil tools. I do think that my device is somehow protected, but I've no clues how to proceed next. I'm going to continue searching, but if any of you has an idea, it's more than welcome.
If I manage to dump that *damned* ROM, I'll make it available...
I've currently (on booloader ONBL 1.23.0000, SPL 1.23.0000, CPLD 04)
Cheers,
Nick
Nevermind...
I think I've been able to proceed with the backup (I've used the Microsoft Security Configuration Manager) when I realized that my system (Windows 2003 x64) the tool was not working.
Which made me think that maybe the procread and the other prun bkondisk might also have been blocked by the x64.
I've tested on my laptop (regular XP) and it works fine... just FYI !
** EDIT **
I've also tested the ELF haret with a downoaded SPL and I got the same result as jockyw2001...
BTW, jocky, did you find a way to re-create a proper nh from the bkondisk end result (bk_##_####.img) ?
nwaelti said:
BTW, jocky, did you find a way to re-create a proper nh from the bkondisk end result (bk_##_####.img) ?
Click to expand...
Click to collapse
The IPL and SPL are useable. The radio dump called bk_02_0005.img is from offset 0xA0000 identical to the radio rom. The first 0xA0000 bytes are other parts, probably splash + gsmdata + simlock + serialnrs. The OS file seems not directly useable and must be reordered somehow. More interesting is the ROM reconstruction method described here. Of course first we need to be able to flash unlock the Vox. I think the SSPL is most suitable for this purpose, this may need some reversing of the SPL with IDA Pro.
Thanks for those info, I'll try to go in that direction. Would be nice to find which one is splash, which one is gsm and the others below 0xA000.
I know we need to rev. SSPL. Don't exactly know where to start though I can't flash mine with any original ROM as Swisscom is not providing any.
BTW. viewimgfs gives me back a "packing DLL not found" (or some similar). Anyone had that also ?
I'll try to download IDA Pro...
It's below 0xA0000
I will do some testing again with the Vox today. I will see if I can paint the screen with a few instructions @0x10000000
I think I can not just run the SPL on VOX in the same way as you can on the ELF. The IPL on the VOX is 128kB, whereas on ELF it is only 2kB. So I think I will have to patch the IPL and run that first. I'm afraid that it will take a bit more time. Basically it will then be a SSPL (search forum for SSPL and user 'des') with both IPL and SPL patched and running in RAM.
But maybe it is also possible to patch just the SPL, because it could be that the default action initiated by IPL is to reset the device in RUU bootloader mode.
Given some time it can all be done I'm sure
WM6 for HTC Tornado
BETA RELEASE!
Note: We take no responsibility for any catastrophies that might occur eg. you brick your phone, your dog dies, your girlfriend gets pregnant etc. etc.
This ROM was developed entirely in our free time between college and university, there's no need to pay us for that, but a donation would be nice. If you wish to do so, then please click HERE
Details:
RAM on cold boot:
Total: 49.69MB
Free: 31.31MB
Storage on cold boot:
Total: 19.95MB
Free: 17.91MB
Added:
HTC File Manager
HTC Comm Manager
HTC Task Manager
HTC Camera V4 Build 23355
Bluetooth Dial-up Networking
Removed:
Wireless Manager
Windows Update
Windows Marketplace
HTC Debug Apps
Office Mobile
Windows Live Mobile
Tweaked:
No red text on boot
Application Unlocked
Animated Menu's
Cache tweaks to improve performance
Modified splash screen
Modified Boot screen
7MB Page Pool
Modified ROMUpdateUtility.exe slightly
Extras:
Agile Messegner
Arcsoft MMS 4.0.40.1 (tweaked so that it is now possible to send up to 1000K in an MMS under WAP2.0 so long as your network supports it)
Bluetooth Dial-Up Networking
Call filter
Call Record
Charge via USB toggler
Cyberion Voice Commander
English xT9
Flashlite 2.1
HTC Audio Manager
HTC Camera V4 Build 23355
HTC Clear Storage
HTC Comm Manager
HTC File Manager 1.41
HTC Task Manager
moBlue
MoDaCo xT9 Language Pack (haven't had time to split these into different languages)
Office Mobile
SDK Certificates
SIM Contact Manager
Sim Tool Kit
Smart Explorer 2.1.4
SmartSS
SP5 Button Fix
SP5m Button Fix (not entirely working yet)
Smartphone Bluetooth FTP Explorer
TCPMP V0.81
Tornado Power Control 2.0 BETA 4
Vito CopyPaste
VoIP
Windows Live Mobile
WM5torage 1.75
Localisations:
Czech
French
Greek
Italian
Polish
Russian
Phil
Flashing instructions are as follows:
NOTE: This will work on vista providing you have followed the Vista RUU guide HERE or HERE
If you are flashing from WM5 to WM6, you MUST download WM6GSMUPDATE.zip and flash that FIRST to avoid GPRS issues
For those getting the "Not Allow Operation" error in TeraTermPro, or, even worse, getting stuck in bootloader after flashing. You MUST superCID your device using the SPV-Sevices client! This step is NOT optional and could result in your phone becoming a brick if anything goes wrong
1. Make sure you device is SuperCID, you can check using the SPV Services client, if on reading the CID it displays 3131313131313131 in a long string of numbers then it IS CID unlocked, if not, the click the CID = 11111111 button and reset your device
2. Download the ROM linked in the first post
3. Download the attached TeraTermPro.zip
4. Disable USB connections in ActiveSync (right click the icon in the systray, then select connection settings and untick the USB connections box), turn off your device, hold camera ad plug the device into the USB port to enter bootloader mode.
5. Extract TeraTermPro.zip and run ttermpro.exe, then select Serial and then USB in the drop down box. Then type:
Code:
info 2
You will then probably get the following output:
Code:
info 2
GetDeviceInfo=0x00000002
+ SD Controller init
- SD Controller init
+StorageInit
CMD55 failed
+ SD Controller init
- SD Controller init
+StorageInit
CMD55 failed
HTCSSuperCID ' HTCE
Cmd>
If you don't see HTCSSuperCID ' HTCE above the Cmd> prompt then your device isn't SuperCID. You must use the SPV Services Client to make your device SuperCID as instructed in step 1
6. Type
Code:
format BINFS
This will then output:
Code:
Cmd>format BINFS
Format BinFS partition.
Format is completed!!
Cmd>
7. Now type:
Code:
ResetDevice
You device will then reboot, display the splash screen for around 2 seconds before running into the bootloader again. This is normal.
8. Extract WM6TornadoBETA.zip then run ROMUpdateUtility.exe
9. Wait while it flashes your device
10. After flashing and the inital cold boot setup (entering the time and date), you MUST delete Voice Command.lnk in /Windows/Start Menu/ and soft reset! Wierd things happen if you don't!
11. Install all the extra stuff you want from the extras file
12. Done
Phil
Thanks go to:
duke_stix
Faria
c4software
tadzio
anichillus
molski
bepe
Beta testers (who did a great job ):
pyrorob
bogdi1988
nedge2k
Special thanks to anandoc for his unrelenting support both technically and morally
And last but certainly by no means the least, our anonymous sources, who, without their trust, we would have never got anything to cook
Phil
Sick of reading?
DOWNLOAD IT ALREADY!
WM6 GSM UPDATE
WM6 HTC Tornado BETA
Extras
AFTER FLASHING THIS ROM YOU MUST CHANGE THE FOLLOWING REG ENTRIES AND SOFT RESET!!!
Code:
Delete: HKEY_Local_Machine\Services\BTT
Change: HKEY_Local_Machine\System\StorageManager\FATFS\CacheSize = 4096
Change: HKEY_Local_Machine\System\StorageManager\Filters\fsreplxfilt\ReplStoreCacheSize = 4096
THIS FIXES ALL OF THE POWER DRAIN AND RAM ISSUES!!!
IF YOU WISH TO LINK TO THIS ROM, PLEASE LINK TO THIS SUPPORT TOPIC AND DO NOT LINK DIRECTLY TO IT! THIS IS NOT ANYTHING PERSONAL, IT'S BECAUSE THERE WILL BE A SOLUTION FOR MOST OF THE PROBLEMS YOU FIND WITH THE ROM IN THIS THREAD!
This ROM was developed entirely in our free time between college and university, there's no need to pay us for that, but a donation would be nice. If you wish to do so, then please click HERE
Phil
1st one to test... downloading
What's the GSM radio version???.. Is it the same which was with alpha one???
downloading too
Yep same as the alpha
Phil
jm012a9749 said:
Yep same as the alpha
Phil
Click to expand...
Click to collapse
so no need to update..
Like i said, only flash WM6GSMUPDRAGE if your going from WM5 to WM6
Phil
Anybody like what i've done to the RUU?
Phil
Downloading too and thk for all , can you describe the
procedure to be followed to upgrade from ALPHA version, please.
wow Flashed and works great ..... Briliant work Phil THX
Flashed. Let's rock!
flashing. RUU looks cool!
phil, you lied ! u said approx 1000GSM !!! but u posted 30mins earlier ! haha
99%....................................................................................................................................................................................................................................................................................................................whew!!! takes a long time......................................................................................................................................yeah 100%...................................................................................................................................................................................................................................................................................................cool restarting....
HTC screen rocks!!!!...
melgurth said:
Flashed. Let's rock!
Click to expand...
Click to collapse
Which start splash screen have been used?
How works your phone now?
I actually posted it around 10:30 GMT, took longer to upload than i expected
You ready to void your warranty karhoe?
Phil
flashed, very good job, thanks!
To use only if IPL/SPL it is not less 4.00.0000!!!
Использовать только если IPL/SPL не меньше 4.00.0000 !!!
Radio for Herald:
GSM-02.94.90
GSM-02.97.90
GSM-03.07.90
GSM-03.08.90
GSM-03.12.90
GSM-03.07.90 - Reception is much better, but consumes a lot of energy.
We test further..
ASerg said:
GSM-03.07.90 - Reception is much better, but consumes a lot of energy.
We test further..
Click to expand...
Click to collapse
QUESTION? will these work on the wing??
And what difference? WING it also is 4350!
ASerg said:
And what difference? WING it also is 4350!
Click to expand...
Click to collapse
thats what i thought but hey its always better to play it safe right??
ok so my question is how do i flash the new radio?? im kind of a newb when it comes to flashing things other than the os.
Hi there,
You download one of the files on the first post, open the zip file and read the How To Upgrade.txt file. In there you have all of the information required.
Cheers
Responses about work of new radio already are?
ASerg said:
To use only if IPL/SPL it is not less 4.00.0000!!!
Использовать только если IPL/SPL не меньше 4.00.0000 !!!
Radio for Herald:
GSM-02.94.90
GSM-02.97.90
GSM-03.07.90
Click to expand...
Click to collapse
Rapidshare is always booked for free downloads. Do you know of any other place I can download these? Uploading them to the FTP would also be great. My Radio (02.94.90) is totally dead and I'm willing to test any of the 02.97.90 or 03.07.90.
What are the possible downfalls to upgrading the radio version? If the new version doesn't work, is there a chance that the phone can be put back to the original version?
is there a english version of this somewhere? and will this over wright my touch-it 2.3 rom i have? i'm really confused on how to get a radio program for my phone so i can listen to the radio on my t-mobile wing. any advice is welcome thank you
Wassona said:
What are the possible downfalls to upgrading the radio version? If the new version doesn't work, is there a chance that the phone can be put back to the original version?
Click to expand...
Click to collapse
1. Radio works 100 %
2. If it is not pleasant, it is possible to return on old having established GSM-02.94.90.
flyinbird93 said:
is there a english version of this somewhere?
Click to expand...
Click to collapse
Radio is not adhered to language.
Hi every one Im kind of a noob here...Is this like a better reception Radio or wat
flyinbird93 said:
is there a english version of this somewhere? and will this over wright my touch-it 2.3 rom i have? i'm really confused on how to get a radio program for my phone so i can listen to the radio on my t-mobile wing. any advice is welcome thank you
Click to expand...
Click to collapse
This is an upgrade to the cellular radio for possibly better reception.
Wassona said:
This is an upgrade to the cellular radio for possibly better reception.
Click to expand...
Click to collapse
well I feel dumb lol. still sounds interesting but I can't read the installation directions.
Instructions in english .. hope this helps
***********************
The instruction on an insertion:
***********************
1. To unpack in a root directory contents of archive
2. To reload the device
3. To connect the device to a computer through ActiveSync,
To be convinced that icon ActiveSync green, i.e. connection successful.
4. Start herald-uspl.exe and follow instructions of the program,
Everywhere we answer in the affirmative (the Insertion consists of three steps)
5. In the end of the third step there will be a white screen, press Enter
6. Will appear standard интерейс official прошивальщика,
We put the necessary ticks, we answer in the affirmative
7. We wait for completion of an insertion, after completion the device itself презагрузится
(XP to do it is not necessary)
8. We enjoy...
*******************
PPSmartChanger.exe
*******************
The script allows to replace size PagePool from 2.00х up to 16.00ти mbyte
Without перепрошивки devices and losses of data.
After work of a script it is enough to make a software ресет to the device,
If it has not occured automatically. In some cases of guest connection
To the personal computer it is not enough device. I.e. the device should be синхронизированно.
robosiris said:
Instructions in english .. hope this helps
***********************
The instruction on an insertion:
***********************
1. To unpack in a root directory contents of archive
2. To reload the device
3. To connect the device to a computer through ActiveSync,
To be convinced that icon ActiveSync green, i.e. connection successful.
4. Start herald-uspl.exe and follow instructions of the program,
Everywhere we answer in the affirmative (the Insertion consists of three steps)
5. In the end of the third step there will be a white screen, press Enter
6. Will appear standard интерейс official прошивальщика,
We put the necessary ticks, we answer in the affirmative
7. We wait for completion of an insertion, after completion the device itself презагрузится
(XP to do it is not necessary)
8. We enjoy...
*******************
PPSmartChanger.exe
*******************
The script allows to replace size PagePool from 2.00х up to 16.00ти mbyte
Without перепрошивки devices and losses of data.
After work of a script it is enough to make a software ресет to the device,
If it has not occured automatically. In some cases of guest connection
To the personal computer it is not enough device. I.e. the device should be синхронизированно.
Click to expand...
Click to collapse
I can upgrade 02.94.90 ROM RADIO with 03.07.90 in my Herald HTC official 4.17.408.2 ITA ROM? Tks an advance.
stedass said:
I can upgrade 02.94.90 ROM RADIO with 03.07.90 in my Herald HTC official 4.17.408.2 ITA ROM? Tks an advance.
Click to expand...
Click to collapse
Yes, it is possible.
ASerg said:
Yes, it is possible.
Click to expand...
Click to collapse
Upgrade doesn't work: ERROR 270 :UPDATE ERROR
THE IMMAGE IS CORRUPTED
any sugestion?
Please I need a help!
I buy a o2 stellar and I tryed to update Rom (wm 6 to dutch 6.1)
my steps:
1) I used Dutty's TouchFlo Final Rom - I made the steps:
- REMOVE SIM and SD CARDS !!
- copy JumpSPL1.56-KAIS.exe to your device and run it
- after a few seconds "USB" appears on the display
- unplug and replug the usb cable
- if you want to see if this works you can flash a Splash screen by running KaiserCustomRUU.exe from flash-splash.zip on your PC
2) when 99% my stellar frozen and I tried to restore and now I have:
triband colours with this message:
Kai130
SPL-1.82.0000
CPLD-8
right top RUUNBH
3) SORRY I tried:
a) RUU_Kaiser_HTC_WWE_1.56.405.5_radio_sign_22.45.88.07_1.27.12.11_Ship
but when 1% - vendor error
(I tried to change the original htc files to stellar o2 files in local temp install but don`t work)
b) Duttys Dualtouch v4 RTM
c) Duttys_DualTouch_V3_Final
d) KAIS_Radinly_1.27.12.11_CustomRUU
e) KAIS_Radinly_1.27.12.11_CustomRUU
f) NIKI_Radinly_1.58.16.27
g) o2 stellar rom
h) KaiserKitchen_v0.3 (make every steps - But doesn't work)
i) flash-hardSPL
**** same error - (262)
I tried to unplug and repluged 3.. 4... 10.... but the problem is the same!
I saw in another tips the JumpSPL1.93-KAIS - but I can't have access to storage in my stellar to copy it (and not have way to execute it - 'cause have only triband colour screen or a white screen
Anyone have a easy tools to make my stellar live again??
I`m not a developer or programmer - ok (It`s like a chinese for me: itsutilsbin-20080313 tools)
thanks in advanced
d2k
can you see your device in windows?
Have you tried to flash your phone from the microSD card? There is a thread here on how to do that and its saved a number of people. I'd recommend getting an official rom for your phone and try to flash that one. Make sure you format your microSD card to FAT32 first and then follow the instructions in that thread on how to do that.
did you just tried to flash a rom using jumpspl? why oh why did you not install hardspl first?? contact gsleon3 and he'll help you unbrick your device
Look for me on MSN/Live Messenger. ([email protected])
GSLEON3 said:
Look for me on MSN/Live Messenger. ([email protected])
Click to expand...
Click to collapse
Ahh the brick master is here
not, I dont see my stellar on my explorer - only
my active sync work when I try to update the ROM.
--------------------------------------------------------------------------------
Look for me on MSN/Live Messenger. ([email protected])
__________________
Gsleon3
CLICK HERE 2 Buy me a pint if you see fit!
ok, 2, 4 , 8 pints
AllTheWay said:
Ahh the brick master is here
Click to expand...
Click to collapse
Ahhh, I am but a lowly brick Jedi in training. All I have learned has come from the reading of years worth of posts from Jedi Master Olipro & Jocky One-Canobi, both of whom double as Yoda from time to time.
if I were you, I would charge this person $100 to unbrick it for him being ignorant and careless.
GSLEON3 said:
Ahhh, I am but a lowly brick Jedi in training. All I have learned has come from the reading of years worth of posts from Jedi Master Olipro & Jocky One-Canobi, both of whom double as Yoda from time to time.
Click to expand...
Click to collapse
Well, no matter. The force is strong with you.
Close this thread!!!
Another notch in my belt. Vista flashing & Unbricking easy as pie!
People, please don't try flashing radios using sspl especially 6.1 radios over 6.0 roms.
everything is working fine!
Thanks Gsleon3 - you`re The Man!
CIAO