Dump SPL and Radio from Device (TP2) - Touch Pro2 CDMA

Can anyone give me some guidance on this? I am looking to dump the SPL and Radio from the device (not an NBH file ... that is easy).
Can someone running a stock ROM attempt to extract the SPL using the command pmemdump 0x9a000000 0x80000 spl.nb ... If I can get a copy of this from a stock ROM, I can compare it to the SPL included in the stock ROM NBH file.
pmemdump is part of ITSUTILS.

I also would like to attempt this.
I have just received a new TP2 and discovered it has a newer radio 2.18.02WV and would like to see if it can be extracted from the device.
Suggestions anyone??

diamondfuel said:
I also would like to attempt this.
I have just received a new TP2 and discovered it has a newer radio 2.18.02WV and would like to see if it can be extracted from the device.
Suggestions anyone??
Click to expand...
Click to collapse
Can you run the command listed in post 1 and post the output file? I can compare this output file to the 2.18.02WV radio to verify that the addresses are correct.
Thanks.
DJ

Hi, have you already got this?
I can do it for you.

Related

how to unlock rom on treo 750v - made by htc

we are trying to unlock and or dump the rom on the treo 750v. this is a newly released treo made by htc. the treo has an awesome feature called theeaded sms which does chat style sms.
we have tried the grab it program that was on this site with no luck.
does anyone no of a way to get this done? does any have any ideas of why the grab it program doesn't work. does anyone want to help?
thanks, cody
So far we've manage to get someone to try the grab_it tool from
http://forum.xda-developers.com/showthread.php?t=238945
But they are getting a write error. I assumed since the Treo 750v uses a mini-sd card the appropriate version of grab_it would be grab_it_128_minisd_468.exe. I'm trying to get someone to try the grab_it_128_150.exe version to see if that works, since that is the version BeyondTheTech used to extract the Treo 700w rom. The 700w uses a regular sd card though.
I asked the guy that tried grab_it_128_minisd_468.exe what the storage card folder name was set to and they verified that the registry was set to "Storage Card". So it's unclear to me why they are getting a write error. Maybe the minisd version expects something else? The card used was a 2GB minisd so it should have plenty of room for the rom.
Anyone familiar with grab_it know what is different about the minisd version? I read through the thread but it wasn't clear to me what the difference is.
Ok, I'm the one who's run the grabit tool on a 750v
It runs Ok and creates a 128Mb dump.bin file but the file appears to be mostly empty. If I zip the file up it only takes 147Kb which seems to confirm this. Am I doing something wrong or is it a bug in the tool
i have hope 750v user and appreciate your efforts
750v_User said:
Ok, I'm the one who's run the grabit tool on a 750v
It runs Ok and creates a 128Mb dump.bin file but the file appears to be mostly empty. If I zip the file up it only takes 147Kb which seems to confirm this. Am I doing something wrong or is it a bug in the tool
Click to expand...
Click to collapse
Can you upload the bin file please. I think someone here may be able to figure this out by looking at the contents of it.
If anyone has a source for a unlocked 750v let me know i really need one.
File and registry dump.
750v_User said:
Ok, I'm the one who's run the grabit tool on a 750v
It runs Ok and creates a 128Mb dump.bin file but the file appears to be mostly empty. If I zip the file up it only takes 147Kb which seems to confirm this. Am I doing something wrong or is it a bug in the tool
Click to expand...
Click to collapse
Hi, please can you do me favor? I have idea which can help us get SMS threading application and other palm features as well. If isn't possible dump ROM in this moment can you download Total Commander (freeware) http://www.ghisler.com/pocketpc.htm and do following.
1, Create foder on memory card and go to the Total commander.
2, go to the root of your device and copy to SD everything what is possible specially from Windows folder and Program Files (rest will be fine as well)
- this will take some time and in case of problem with file just skip that file.
3, When this will be done please go into the "\\" in the root and then to "registry"
4, now select registry tree one by one and copy again to card.
This will give us most probably files which will be required for hack and registry keys which will be required as well i think.
Thank you very much for your help.
Here's a zipped up copy of the dump.bin file, hope it helps
I extracted that dump.bin and it looks like a 256 byte block of data that is repeated at each 16 meg boundary 8 times.
Does this ring any bells to the experts?
The only readable text is "CHEETAH IPL EVT".
wow! that's great!
I don't have a Cheetah, but there's some info on the hermes forum that might be of interest to you:
http://forum.xda-developers.com/showpost.php?p=1019171&postcount=22
750v_User please try this program to extract the rom image.
unzip and copy TestDump.exe to your device and run it. In the "Path to file" enter the path for the dump file (i.e. \Storage Card\dump.bin). In the "Mbytes to dump" enter 128. Then press the "Dump" button. It should make a dump of the ROM file.
Zip it up and upload here. Thanks!
pof said:
I don't have a Cheetah, but there's some info on the hermes forum that might be of interest to you:
http://forum.xda-developers.com/showpost.php?p=1019171&postcount=22
Click to expand...
Click to collapse
Thanks. That post appears to be for updating the rom. I wonder if there is some key combo like this to extract the rom.
hannip said:
Thanks. That post appears to be for updating the rom. I wonder if there is some key combo like this to extract the rom.
Click to expand...
Click to collapse
Based on the Hermes experience, there's no knonw way yet to extract it in a form that after is flashable on another device, but you can follow these instructions to dump some parts:
http://wiki.xda-developers.com/index.php?pagename=Hermes_HowtoDumpRom
You can also use pmemdump to copy some of the ROM contents to a file. Once you've dumped SPL you can search for strings on it and you'll see the bootloader commands.
HTC has removed all the "d2s, s2d, r2sd..." and like commands in the hermes bootloader, probably you are lucky and you have some command to dump the rom to sd in your bootloader.
Hope that helps
The ROM dump // extract discussion is over my head...one question though has anyone sorted out how to unlock this device?
codyppc said:
we are trying to unlock and or dump the rom on the treo 750v. this is a newly released treo made by htc. the treo has an awesome feature called theeaded sms which does chat style sms.
we have tried the grab it program that was on this site with no luck.
does anyone no of a way to get this done? does any have any ideas of why the grab it program doesn't work. does anyone want to help?
thanks, cody
Click to expand...
Click to collapse
im just a noob but cant we use the combination of StyleTap and AdvBackup to create a complete rom backup of the treo 750v and then grab what we want from that?
will that work????
just tryin to help........
what if someone get the .nbh file..can that be extracted??
750v ROM dump uploaded
I put a rom dump from the TestDump.exe tool on ftp.xda-developers.com. userid: xdaupload pw: xda
file: treo750v_dump_rom.zip
I used the dumprom tool to extract files, but it looks like it's only extracting the first rom section it finds and stops. Can one of the experts take a look at the dump and see if you can extract the other sections please.
Thanks.
What are you getting from the first rom section?
Sounds weird... was the dump complete?
It looked like a bunch of system files. The kernel, img.dll, filesystem drivers and the like.
There is 59MB of data in the dump so there has to be more stuff in there.

Cingular Faraday ROM radio?

hey folks,
Does anyone know if anyone has extracted the radio from the latest Cingular 2125 (Faraday) ROM (version 2.0.13.0, from the HTCamerica website)?
I like the qtek 2.0.9.0 ROM, but I am running on Cingular network, and it would be nice to try that radio version. I'd rather not use the ROM, because I'd have to fool with it to reactivate wifi and a whole lot of other modifications.
thanks!
Do you have the download address? Please show me the address, I can extract the radio for you.
wow! thank you very much, here is the link...
http://www.america.htc.com/support/2125/software-downloads.html
good luck, and thanks again!
bluehanson said:
Do you have the download address? Please show me the address, I can extract the radio for you.
Click to expand...
Click to collapse
can you post the instructions please? It can be helpfull for others.
instructions...
Hey,
in a previous post/different thread, sp3dev posted the following instructions to extract the radio ROM from a full update, and reinsert the file into an updating package to install...I have never done anything of this nature, but I have used extracted ROMs to update a smartphone. The tools are all posted on xda-developers, and spv-developers, but I am just not sure how to use any of them.
Instructions:
so, goto spv-developers, find info how to setup perl and typhoonnbfdecode.pl. then, unpack the update with winrar, open nk.nbf with typhoonnbftools 0.4, select gsm, select extract decrypted, then save as gsm.n_d
then, use
typhoonnbfdecode.pl -r gsm=gsm.n_d -t -c radio.nbf. then, open radio.nbf with nbf tools and remove cdl___02 and save nbf into the folder with romupdate.exe enterbootloader.exe ruugetinfo.exe ruuresource.dll. run romupdate.exe and flash.
and i advise you to set supercid.
Here are more instructions for setting up perl and typhoonnbfdecode:
http://wiki.xda-developers.com/index.php?pagename=RomTools/typhoonnbfdecode.pl
Can you post the extracted radio rom Plz...
hardcore technie help needed
hey, ok I got the tools working. I have extracted radio roms from a couple of old qtek ROM updates. however, I am having problems with the cingular 2.0.13.0 ROM. I can extract the GSM component using typhoonnbftools, when I try to convert using typhoonnbfdecode.pl, the resulting file is empty. Any ideas?
Sorry I cant give you an answer to your question but I take advantage of your post to ask you one:
when I try to run the Perl script, it gives me runtime error when it tries to load the DES dll:
"R6034 An application has made an attempt to load the C runtime library incorrectily"
Did you had any similar problems to run the tool ?
Hello,
I did get a similar error, though I can't remember the exact syntax. If you are using Activeperl, add the following PPM repository, and install all the packages there. I think that should clear up this particular error...
http://www.soulcage.net/ppds/ppds.58/
I don't know, though...maybe this repository is bad? I have absolutely no experience with perl or programming, so I don't know how to tell. It might be worth trying to find a different repository with the crypt/des package?
Thanks. The repo link solved my problem !
dragonii said:
Thanks. The repo link solved my problem !
Click to expand...
Click to collapse
Hey, were you able to create a radio.nbf from the cingular ROM? Even after isntalling those perl packages, the resulting radio.nbf file was empty . If you've got it, would you mind please posting it?
Hello All,
Please post the radio rom if any one has extracted... Thanks...

CustomRUU for Kaiser

By popular demand I've created HTC Kaiser CustomRUU, it is basically the same as the HTC RUU, but packed in one single exe file and slightly patched to perform a 'task 32' instead of a 'task 28' after flashing an NBH, so it will not format your device if you just flash a radio or a Splash screen.
Note: This CustomRUU will not allow you to flash unsigned files unless you have HardSPL installed, it will not push SSPL.
Instructions as always: Drop the NBH file of your choice in the same folder as CustomRUU and start flashing
Recommended tools for handling NBH files:
NBHextract - Extract contents from NBH files
htc rom tool - Repack NBH files from *.nb files
Enjoy
Oh you tease we are so close to cooking so close just need to figure out the imgfs tools!
will this work in Vista as someone had posted a ruu that works in vista for the Hermes I believe.
I don't know, I don't use Vista. Try it and report if it works or not
It works for Vista!
Thanks
great job pof, keep it going
But it's for the wrong phone :Cry: now we just need this for the Athena...
Sorry for the noob question, but what does this customRUU do? I've already hardSPL'ed my tilt and load the kaiser ROM.
pof said:
By popular demand I've created HTC Kaiser CustomRUU, it is basically the same as the HTC RUU, but packed in one single exe file and slightly patched to perform a 'task 32' instead of a 'task 28' after flashing an NBH, so it will not format your device if you just flash a radio or a Splash screen.
Click to expand...
Click to collapse
Do I understand this good (translate in my brains)?
In the original situation with original ROM, when you update the RadioROM the device will format? Strange!
kjones2k1 said:
Sorry for the noob question, but what does this customRUU do? I've already hardSPL'ed my tilt and load the kaiser ROM.
Click to expand...
Click to collapse
Re-read the first post. It's there. If you don't understand it, you probably won't be using it so I wouldn't worry about it.
-Mc
Man you are fabulous, great work much appreciated
Hyins said:
Thanks
Click to expand...
Click to collapse
Hi friend, is possibile extract your radio rom only?
Thanks in advance, bye
Invalid applciation ?
Hello,
May be obvious ...
Why do I get and invalid pocket pc application when trying to run the kaiserCustomRUU.exe on my kaiser ?
Edit my-stupid-self : it runs from the PC
I am using Duttys 6.1 beta rom and I have flashed my device using KAIS_Radinly_1.64.08.21_CustomRUU and now the device just sits there at the HTC screen. Of course in this state I can't flash the old radio back as it isn't getting into the main part of the OS to sync. I have tried hard resetting and that takes me to the set up pages but then it takes me back to the HTC locked page again.
Is there anyway to get it back?
I am a bit worried that I have bricked it.
yeah guy above me im new here todays my 3rd day but ive picked up a few tips and tricks while STILL trying to unlock my phone "can somebody please help me"
anyway try holding the camera button while soft reseting your phone the tri color screen should pop up the try installing the same rom or different one or you can just Hard spl o something like that PLZ someone correct me if im wrong i did say im new but just tryin to help
Nevermind, please delete this post.
XP SP3?
Has anyone tried flashing on a Windows XP SP3 ?
Tried using any RUU and having a problem whereby it gives the error "The application failed to initialize properly (0xc000007b)"
Is it me or has anyone else had this issue?
mystikal87 said:
Has anyone tried flashing on a Windows XP SP3 ?
Tried using any RUU and having a problem whereby it gives the error "The application failed to initialize properly (0xc000007b)"
Is it me or has anyone else had this issue?
Click to expand...
Click to collapse
No problems here flashing with XP Pro SP3 (ENG).
pof said:
By popular demand I've created HTC Kaiser CustomRUU, it is basically the same as the HTC RUU, but packed in one single exe file and slightly patched to perform a 'task 32' instead of a 'task 28' after flashing an NBH, so it will not format your device if you just flash a radio or a Splash screen.
Note: This CustomRUU will not allow you to flash unsigned files unless you have HardSPL installed, it will not push SSPL.
Instructions as always: Drop the NBH file of your choice in the same folder as CustomRUU and start flashing
Recommended tools for handling NBH files:
NBHextract - Extract contents from NBH files
htc rom tool - Repack NBH files from *.nb files
Enjoy
Click to expand...
Click to collapse
I am trying to just flash my Radio. I have downloaded KAIS_Radinly_1.65.17.56_CustomRUU and when I try and upgrade my radio it says do you want to update your ROM from 3.14.405.0 to 1.0.0.0. Should I just OK this so it will continue to the Radio Update? I do not want to change my ROM

File need from stock OEM ROM

Would anyone be able to strip a file from the OEM rom?
I need the TIInit_4_2_38.bts file (not the hotfix one) but the OEM one that came with the stock rom?
I am trying to get this script to work with the HTC Dream HERO build. This might solve the BT issues its been having. If anyone can provide me with some assistance it would be greatly appreciated!!
Thanks!
(I do not own a TyTN or Kaiser type device, if i did i would flash it and rip the file)
Do a search for a application called rom image editor and grab the file out of the nbh with this.
Closing thread
Peace,
Josh

extract the radio from the t-mobile 2.0.6.531.4

Hi, never extracted a radio before, and I am totally blind so I can't use windows 6.5 yet, so just want the radio from the 6.5 rom, I extracted the .nb files from the spl.nbh and the ru_signed.nbh and they both have a 22.1 mb file which I asume is the radio, however two things, I don't know which is the correct one and even tried both but get an error that invalid model id when using the ru, do I need to sign the nb before converting it back to an nbh or please give me some guidence in this process.
gigawatt said:
Hi, never extracted a radio before, and I am totally blind so I can't use windows 6.5 yet, so just want the radio from the 6.5 rom, I extracted the .nb files from the spl.nbh and the ru_signed.nbh and they both have a 22.1 mb file which I asume is the radio, however two things, I don't know which is the correct one and even tried both but get an error that invalid model id when using the ru, do I need to sign the nb before converting it back to an nbh or please give me some guidence in this process.
Click to expand...
Click to collapse
Take a look at this post, I alreaday did it.
http://forum.xda-developers.com/showthread.php?t=550863
the radio you did was the one from the t-mobile 6.5 windows mobile and is it the thrd post with radio 3.47.25.29 because I thought the radio was higher then that, and if I wanted to do it myself how could I?
Dash 3G, Snap ROM V 122209 can used in C720W?

Categories

Resources