Problem with Nokia Lumia 630 flashing - General Questions and Answers

How can I flash my Nokia Lumia 630?
I tried on WPInternals, but it says:
Flash failed! Error 0x1106: Security header validation failed
I also tried THOR2, which also failed. It says:
Initiating FFU flash operation
WinUSB in use.
isDeviceInNcsdMode
isDeviceInNcsdMode is false
Device mode 6 Uefi mode
[THOR2_flash_state] Pre-programming operations
Disable timeouts
Detecting UEFI responder
Lumia UEFI Application did not respond to version info query
Device is not in Lumia UEFI mode
Device mode get failed, mode is 6
Connection lost, trying to re-connect
Rebooting to the normal mode...
Rebooting from the WP/MMOS failed.
Operation took about 16.00 seconds.
THOR2_ERROR_TO_COMMUNICATE_WITH_DEVICE
THOR2 1.8.2.18 exited with error code 84102 (0x14886)
Can someone help me?

I'm also having issues unbricking my Nokia 630 (RM-979),
It's completely bricked. Nothing shows on the screen. Completely black.
It is detected on Windows Device Manager as QDLoader 9008 (COM7), but I'm not being able to flash it.
I have tried:
- Windows Phone Internals
- Windows Device Recovery Tool
- NaviFirm
- Thor
Result from thor:
> thor2 -mode ffureader -ffufile "C:\rm-914\XXX.ffu" -dump_gpt -filedir C:\dump
THOR2 1.8.2.18
Built for Windows @ 13:36:46 Jun 16 2015
Thor2 is running on Windows of version 6.2
thor2 -mode ffureader -ffufile C:\rm-914\XXX.ffu -dump_gpt -filedir C:\dump
Process started Wed Dec 29 17:13:00 2021
Logging to file C:\Users\Angelo\AppData\Local\Temp\thor2_win_20211229171300_ThreadId-13244.log
Debugging enabled for ffureader
Initiating do FFUReader operations
Version of FfuReader is 2015061501
Parsing FFU... Please wait...
Failed to parse FFU file. Header size: 0x00000000, Payload size: 0x0000000000000000, Chunk size: 0x00000000, Header offset: 0x00000000, Payload offset: 0x0000000000000000
File open failed
THOR2_ERROR_FFUREAD_CORRUPTED_FFU
THOR2 1.8.2.18 exited with error code 84204 (0x148EC)
Any ideas?

Angelo Marzolla said:
I'm also having issues unbricking my Nokia 630 (RM-979),
It's completely bricked. Nothing shows on the screen. Completely black.
It is detected on Windows Device Manager as QDLoader 9008 (COM7), but I'm not being able to flash it.
I have tried:
- Windows Phone Internals...
Click to expand...
Click to collapse
I don't have bricked Nokia, but did you format the whole phone storage when Windows said it's broken? Because it can be the reason why your phone is bricked.

Related

Cannot get to recovery mode

Hi Everyone,
At the moment, I cannot get my LG G2X to boot into Cyanogen Mod. I cannot get it to boot into recovery mode. I cannot get it to do anything but sit at the second LG logo. This is a problem.
If I allow it to boot with no special button-pressing, it will get to the second LG logo, and stall there until the battery runs out. If I hold the VOLUME DOWN and POWER buttons, it will get as far as the first (white) LG logo and stall there (holding VOLUME DOWN and POWER for a full 60 seconds).
History:
A few weeks ago, I had flashed my G2X and installed CyanogenMod 7 (specifically 7.2.0) from here: http://download.cyanogenmod.com/?type=stable&device=p999. I accomplished this through the excellent One-Click NvFlasher ClockWorkMod provided by TGA_Gunnman (found here: http://forum.xda-developers.com/showthread.php?t=1056847). Once in a while, I would have to clear the caches after a reboot, but that was my biggest problem, and one I was prepared to live with. Until now.
Things I've tried:
Most fixes start with reflashing CWM. I did that, using the aforementioned One-Click NvFlasher ClockWorkMod tool. It stalls as follows:
Code:
===============================================================
===============================================================
One Click ClockWorkMod Recovery Flash for T-Mobile G2x
External SD Support by Koushik Dutta
Version 5.0.2.0
===============================================================
===============================================================
Nvflash started
rcm version 0X20001
System Information:
chip name: unknown
chip id: 0x20 major: 1 minor: 3
chip sku: 0xf
chip uid: 0x033c20824360c4d7
macrovision: disabled
hdcp: enabled
sbk burned: false
dk burned: false
boot device: emmc
operating mode: 3
device config strap: 0
device config fuse: 17
sdram config strap: 0
downloading bootloader -- load address: 0x108000 entry point: 0x108000
sending file: fastboot.bin
/ 1024992/1024992 bytes sent
fastboot.bin sent successfully
waiting for bootloader to initialize
bootloader downloaded successfully
sending file: CWM-5020.img
- 65536/3563520 bytes sent
-------------------------------------------------------------------------------------
...and won't do anything else.
So, for whatever reasons, it will not send CWM-5020.img. To check, I tried nvflash.exe directly. Same general result. I tried with a different file (recovery-clockwork-5.0.2.0-p999.img), same result. I also tried the advice here: http://forum.xda-developers.com/showthread.php?t=1590523&highlight=bricked+help and tried to wipe out my partitions. While that tool runs successfully, it does not change the results with One-Click NvFlasher ClockWorkMod
Summary:
Can't boot. Can't boot into recovery. Can't flash the ROM.
Any ideas? Anyone?
Thanks!
I forgot to add: when I unplug from the one-click updater, I get the following error message:
Code:
sending file: CWM-5020.img
- 65536/3563520 bytes sentdata send failed NvError 0x30012
command failure: partition download failed
===============================================================
===============================================================
*****Once nvflash has completed successfully then hit any key to close.*****
****If any step failed then repeat the process****
For when my partitions are messed up
http://forum.xda-developers.com/showthread.php?p=17258229
Sent from my LG-P999 using Tapatalk 2
djvoleur said:
For when my partitions are messed up
http://forum.xda-developers.com/showthread.php?p=17258229
Sent from my LG-P999 using Tapatalk 2
Click to expand...
Click to collapse
Thanks, djvoleur, but when I try that, I get this:
Code:
.\nvflash.exe
--bct E1108_Hynix_512MB_H8TBR00U0MLR-0DM_300MHz_final_emmc_x8.bct --setbct --odm
data 0xC8000 --configfile android_fastboot_emmc_full.cfg --create --bl fastboot.
bin --go
Nvflash started
rcm version 0X20001
System Information:
chip name: unknown
chip id: 0x20 major: 1 minor: 3
chip sku: 0xf
chip uid: 0x033c20824360c4d7
macrovision: disabled
hdcp: enabled
sbk burned: false
dk burned: false
boot device: emmc
operating mode: 3
device config strap: 0
device config fuse: 17
sdram config strap: 0
sending file: E1108_Hynix_512MB_H8TBR00U0MLR-0DM_300MHz_final_emmc_x8.bct
- 4080/4080 bytes sent
E1108_Hynix_512MB_H8TBR00U0MLR-0DM_300MHz_final_emmc_x8.bct sent successfully
odm data: 0xc8000
downloading bootloader -- load address: 0x108000 entry point: 0x108000
sending file: fastboot.bin
\ 888548/888548 bytes sent
fastboot.bin sent successfully
waiting for bootloader to initialize
bootloader downloaded successfully
setting device: 2 3
creating partition: BCT
creating partition: PT
creating partition: EBT
creating partition: SOS
creating partition: MBR
creating partition: APP
creating partition: CAC
creating partition: MSC
creating partition: EB1
creating partition: LNX
creating partition: EB2
creating partition: DRM
creating partition: EB3
creating partition: UDA
creating partition: EB4
creating partition: UDB
failed executing command 12 NvError 0x120002
command failure: create failed (bad data)
bootloader status: fatal failure to read / write to mass storage (code: 9) messa
ge: nverror:0x42008 (0x19042008) flags: 0
So it seems that this doesn't help. I scanned through the thread and didn't see anything that seemed like it might address this issue.
It may be driver related. Reinstall drivers then follow the instructions to resurrect your phone.
Core Memory said:
It may be driver related. Reinstall drivers then follow the instructions to resurrect your phone.
Click to expand...
Click to collapse
Would you recommend reinstalling both the LG USB drivers and the ATX drivers for nVidia? (I'm probably going to do both anyway.)
I've forced a reinstall of the NVIDIA USB Boot-recovery driver, using the same files included in the one-click recovery tool. After that, I attempted to run the tool and had the same failure listed above (command failure: partition download failed). For laughs, I tried djvoleur's solution as well, and got the same error again. So it doesn't seem to be a driver issue.
When you do the NVFlash recovery, did you take out the battery, hold the up and down volume buttons in, while holding the buttons in plug in the usb cable, while holding the buttons in run the recovery until it is completed.
Just for ****s, try flashing twrp. I also have another idea, but I can't get it set-up tonight.
Sent from my LG-P999 using xda premium
Core Memory said:
When you do the NVFlash recovery, did you take out the battery, hold the up and down volume buttons in, while holding the buttons in plug in the usb cable, while holding the buttons in run the recovery until it is completed.
Click to expand...
Click to collapse
Yes. The battery was out the whole time. Held the buttons down, plugged in the USB cable, ran recovery, recovery stalls at 65536 bytes. Held it for about five minutes, just to make sure.
Волк said:
Just for ****s, try flashing twrp. I also have another idea, but I can't get it set-up tonight.
Sent from my LG-P999 using xda premium
Click to expand...
Click to collapse
Same result as each of the others: stalls at 65536 bytes sent. I don't think it's an issue with any of the actual recovery mods, at this point. I think it's something wrong with getting data onto my phone, perhaps?
How about trying to update the phone with one of the KDZ updates? Use Emergency mode. There's an offline updater which uses an http server to fool the LG updater into not accessing the LG update website then doing the update. It runs with a VB script which does everything. I once used that with the V21Y_00.kdz file when my phone wouldn't restore.
http://forum.xda-developers.com/showthread.php?t=1601918
http://forum.xda-developers.com/showpost.php?p=22189294&postcount=30
Core Memory said:
How about trying to update the phone with one of the KDZ updates? Use Emergency mode. There's an offline updater which uses an http server to fool the LG updater into not accessing the LG update website then doing the update. It runs with a VB script which does everything. I once used that with the V21Y_00.kdz file when my phone wouldn't restore.
http://forum.xda-developers.com/showthread.php?t=1601918
http://forum.xda-developers.com/showpost.php?p=22189294&postcount=30
Click to expand...
Click to collapse
Tried this. First tried the second link (the all in one with the offline web server). That didn't work because the zipfile with the webserver and other software had a virus which specifically infected the web server.
Followed the directions in the first post, then. These seem to presume that you can get to USB debugging mode (which I can't, because the phone won't boot). Got as far as Step 3 in that post. When I click on "Upgrade Start" I should get a pop-up for "Select Country & Language". I do not. Instead, it starts the LG Mobile Support Tool directly. (I should mention at this point that I'm on WIndows 7, if it matters). The updater checks the connection with the phone, and finds an acceptable connection. Since it was supposed to go into the Updater anyway, I hit "Start Updating". After a while, this fails with some sort of connection problem with the phone. I've tried re-running the LG Updater under several conditions (in Upgrade mode, not in Upgrade mode, etc.). No luck.
Doesn't seem like this is a solution I can get to work. Should I try something else?
The virus warning is false. Disconnect from the internet and/or turn off your wireless connection then run it. Also, if it stalls, let it wait.
If it doesn't continue within 10 minutes, try it again.
---------- Post added at 11:51 AM ---------- Previous post was at 11:46 AM ----------
Also, I made sure that all of the applications in the substitute web-server update package were allowed to run as administrator before I ran the script. If that doesn't work, try running the apps individually without the script in the order they're required to be initiated which is in the instructions that come with that package.
Core Memory said:
The virus warning is false. Disconnect from the internet and/or turn off your wireless connection then run it. Also, if it stalls, let it wait.
If it doesn't continue within 10 minutes, try it again.
---------- Post added at 11:51 AM ---------- Previous post was at 11:46 AM ----------
Also, I made sure that all of the applications in the substitute web-server update package were allowed to run as administrator before I ran the script. If that doesn't work, try running the apps individually without the script in the order they're required to be initiated which is in the instructions that come with that package.
Click to expand...
Click to collapse
I'm having exactly the same problem as that person right now. Using the offline update, I got up to "Normal MTK Upgrade start" but then the program crashed right afterwards. It also doesn't help that the phone keeps on rebooting. For the online update, I can get up to 32% before the phone reboots and I have to restart the update process.
mbamg said:
I'm having exactly the same problem as that person right now. Using the offline update, I got up to "Normal MTK Upgrade start" but then the program crashed right afterwards. It also doesn't help that the phone keeps on rebooting. For the online update, I can get up to 32% before the phone reboots and I have to restart the update process.
Click to expand...
Click to collapse
If it got to 32%, it has installed the baseband, that gets installed first then the Android. Try doing a restore/recovery of just Android that's compatible with the baseband.
Have you tried running the flash with the battery in? I know all the instructions say take the battery out, but im having similar issues with my phone, and once the phone is recognized in Device manager in APX mode, insert the battery, then run the flash. That seemed to work for me.
Core Memory said:
How about trying to update the phone with one of the KDZ updates? Use Emergency mode. There's an offline updater which uses an http server to fool the LG updater into not accessing the LG update website then doing the update. It runs with a VB script which does everything. I once used that with the V21Y_00.kdz file when my phone wouldn't restore.
http://forum.xda-developers.com/showthread.php?t=1601918
http://forum.xda-developers.com/showpost.php?p=22189294&postcount=30
Click to expand...
Click to collapse
Nothing will work in this Case i try all most everything. I thnk 99% Partition or Flash Chip is Damaged
See Reports:
While try with KDZ File
Trying to Flash Recovery
Code:
===============================================================
===============================================================
One Click ClockWorkMod Recovery Flash for T-Mobile G2x
External SD Support by Koushik Dutta
Version 5.0.2.0
===============================================================
===============================================================
Nvflash started
rcm version 0X20001
System Information:
chip name: unknown
chip id: 0x20 major: 1 minor: 3
chip sku: 0xf
chip uid: 0x033c208240ff9497
macrovision: disabled
hdcp: enabled
sbk burned: false
dk burned: false
boot device: emmc
operating mode: 3
device config strap: 0
device config fuse: 17
sdram config strap: 0
downloading bootloader -- load address: 0x108000 entry point: 0x108000
sending file: fastboot.bin
/ 1024992/1024992 bytes sent
fastboot.bin sent successfully
waiting for bootloader to initialize
bootloader downloaded successfully
sending file: CWM-5020.img
- 65536/3563520 bytes sent
Recovery Stock
Code:
===============================================================
===============================================================
One Click ClockWorkMod Recovery Flash for T-Mobile G2x
External SD Support by Koushik Dutta
Version 5.0.2.0
===============================================================
===============================================================
Nvflash started
rcm version 0X20001
System Information:
chip name: unknown
chip id: 0x20 major: 1 minor: 3
chip sku: 0xf
chip uid: 0x033c208240ff9497
macrovision: disabled
hdcp: enabled
sbk burned: false
dk burned: false
boot device: emmc
operating mode: 3
device config strap: 0
device config fuse: 17
sdram config strap: 0
downloading bootloader -- load address: 0x108000 entry point: 0x108000
sending file: fastboot.bin
/ 1024992/1024992 bytes sent
fastboot.bin sent successfully
waiting for bootloader to initialize
bootloader downloaded successfully
sending file: CWM-5020.img
- 65536/3563520 bytes sent
Phone Information
Code:
Nvflash started
rcm version 0X20001
System Information:
[COLOR="Red"] [B]chip name: unknown[/B][/COLOR]
chip id: 0x20 major: 1 minor: 3
chip sku: 0xf
chip uid: 0x033c208240ff9497
macrovision: disabled
hdcp: enabled
sbk burned: false
dk burned: false
boot device: emmc
operating mode: 3
device config strap: 0
device config fuse: 17
sdram config strap: 0
Rad Flash
Code:
[R&D Test Tools Log File]
00:54:52 : Start fn_StartUpgrade
00:54:52 : Extract kdz file
00:55:01 : kdz decrypt Success
00:55:05 : Extract file Success.
00:55:05 : LGMobileDL Load.
00:55:05 : Port = -1
00:55:05 : Connection check start.
00:55:05 : Port(or Device) Not Found!
00:55:07 : Finish All test
So to Flash with KDZ ect u need phone on Recovery mode and phone will not steep into recovery mode with vol - + Power
All we have is boot Recovery mode and phone hang on SW Upgrade Please Wait
I Try to Format partition manually via NVFlash but same thing its hang
Best Regards from me i am giving up after 2 days working on it, For me its simply Hardware Problem
In my experience when that happened to me.... It was my firewall/virus scanner. Try disabling those before attempting another flash.

Qualcomm Product Support Tool (QPST) Errog Log Debugging

Qualcomm based chipset phones are fixed through QPST tool. One of the software provided QPST is eMMC software download which helps to fix corrupt bootloader and emmc partitions. BUT SOMETIMES THE BOOTLOADER REPAIR IS NOT SUCCESSFUL.
The PURPOSE OF THIS THREAD is to know what is causing the errors and provide solutions.
The eMMC software creates log files like Dload_COMxx.dbg which can be found under C:\ProgramData\Qualcomm\QPST in Windows 7 PC.
I am encoutring "Image Download Failed. Cookie (if present) not received" error in eMMC download. Here is the log file:
2013/07/03 14:15:55.095 Restart timeout set to 10 seconds
2013/07/03 14:15:55.095 StartSB2Download
2013/07/03 14:15:55.095 Begin SB2.0 Software Download
2013/07/03 14:15:55.095 Skip Reset: 1
2013/07/03 14:15:55.095 Lock phone
2013/07/03 14:15:55.095 Examine phone mode
2013/07/03 14:15:55.111 Get partition file name
2013/07/03 14:15:55.111 User specified flash programmer:
2013/07/03 14:15:55.111 Flash Programmer file:
2013/07/03 14:15:55.126 Examine phone mode
2013/07/03 14:15:55.126 Mobile not in download mode!
2013/07/03 14:15:55.126 SynchronizeConnection starting...
2013/07/03 14:15:55.126 Sending Hello to flash programmer...
2013/07/03 14:15:55.126 Disabling automatic polling.
2013/07/03 14:15:55.189 Try Hello with polling disabled...
2013/07/03 14:15:55.189 Try Hello with polling disabled...
2013/07/03 14:15:55.189 Try Hello with polling disabled...
2013/07/03 14:15:55.189 SynchronizeConnection succeeded.
2013/07/03 14:15:55.189 Sending Hello Packet
2013/07/03 14:15:55.204 Version info = 5 2
2013/07/03 14:15:55.204 Block size = 400
2013/07/03 14:15:55.204 Flash base = 0
2013/07/03 14:15:55.204 Device Name=eMMC:
2013/07/03 14:15:55.204 Flash ID size= 4
2013/07/03 14:15:55.204 Sectors = 128
2013/07/03 14:15:55.204 Feature mask = 0x09
2013/07/03 14:15:55.204 Sending Close 0
2013/07/03 14:15:55.204 Log: Cannot close when not previously opened
2013/07/03 14:15:55.204 ARMPRG error: 15, text: Cannot close when not previously opened
2013/07/03 14:15:55.204 CloseDownloader error
2013/07/03 14:15:55.204 Sending Security Mode 1
2013/07/03 14:15:55.204 eMMC user image present - skipping partition table
2013/07/03 14:15:55.220 eMMC user image: C:\flare repair files\8X25_msimage.mbn
2013/07/03 14:15:55.220 Opening eMMC USER file
2013/07/03 14:15:55.220 Opening eMMC USER mode
2013/07/03 14:15:55.220 Sending MI Open mode 33 size 0
2013/07/03 14:15:55.579 Log: Open multi failed, unknown error
2013/07/03 14:15:55.579 ARMPRG error: 7, text: Open multi failed, unknown error
2013/07/03 14:15:55.579 Download end, status 103, error 852
2013/07/03 14:15:55.579 Exit SB 2.0 download with status 0x00000000
a have a htc one m8s where do i get the xml file and the patch please
To load raw images to a device you will likely need a signature. Even low level tools like QFIL, for example, require MBN files which are essentially keys to the device.

Debrand Nokia 1020

Hi I have just fixed the screen on my mates Nokia 1020, he wants me to debrand it, I have read a tutorial here on how to do this but nothing happens the following is a screen dump on my cmd prompt.
C:\Program Files (x86)\Microsoft Care Suite\Windows Device Recovery Tool>thor2 -mode vpl -vplfile "%HomePath%\Desktop\Package\RM875_059T1V6_3051.50009.1424.0003_435.vpl
THOR2 1.8.2.18
Built for Windows @ 13:36:46 Jun 16 2015
Thor2 is running on Windows of version 6.2
thor2 -mode vpl -vplfile \Users\alist\Desktop\Package\RM875_059T1V6_3051.50009.1424.0003_435.vpl
Process started Tue Apr 12 20:46:08 2016
Logging to file C:\Users\alist\AppData\Local\Temp\thor2_win_20160412204608_ThreadId-1272.log
Parsing VPL file \Users\alist\Desktop\Package\RM875_059T1V6_3051.50009.1424.0003_435.vpl
Successfully parsed VPL
Flashing .ffu file RM875_3051.50009.1424.0003_RETAIL_eu_euro1_211_03_447991_prd_signed.ffu (SW version 3051.50009.1424.0003)
Debugging enabled for uefiflash
Initiating FFU flash operation
WinUSB in use.
Operation took about 1 minute, 0 seconds.
THOR2_ERROR_NO_DEVICE_WITHIN_TIMEOUT
THOR2 1.8.2.18 exited with error code 84003 (0x14823)
Click to expand...
Click to collapse

F1s bricked need help

Hello
I've bricked Oppo F1s when I've tried to flash it
this is infinity read info log
Wait for phone...
Phone found! [ 1087 ]
Sync...
Inital Boot Ok!
BB_CPU_PID : 6755
BB_CPU_NME : [MediaTek] Helio[P10]|MT6755_S00
BB_CPU_EXT : 0xCB00 , 0x8A00 , 0x0000
Processing BROM stage
Settings for BROM configured!
SecCfgVal : 0x01000000
BromVer : 0x0005
BLVersion : 0x00FE
PreLoader : NOT Active [ Erased ]
BootLdrSS : SIGNED with SPRELOADER
Processing DA stage
DA Select done, will use MTK_AllInOne_DA_v5.1624.16.07
Sending and initialize DA ...
DAgent configured successfully
Connection agent : BROM
[DA_ERROR] : DRAM Configure failed!
ErroCode : 0x2122and I get this message error if I try to flash it with MT6750
Error: STATUS_INSUFFICIENT_BUFFER
EMICFG_NOT_ACCEPTED_CONFIG
Boot Error!
Operation Failed
Elapsed: 00:00:52
Reconnect Power/Cable!
Click to expand...
Click to collapse
it says that's an MT6755 processor , but when I try to flash it with Mt6755 with sp flashtool and NCK mtk soft it says that's version mismatch and it's and MT6750 device
Can you help to choose the right firmware please ?
octopus82 said:
Hello
I've bricked Oppo F1s when I've tried to flash it
this is infinity read info log
it says that's an MT6755 processor , but when I try to flash it with Mt6755 with sp flashtool and NCK mtk soft it says that's version mismatch and it's and MT6750 device
Can you help to choose the right firmware please ?
Click to expand...
Click to collapse
I have pretty much the same problem with my MOTO M (XT1662). It happened after I did the "Format whole flash" in SP flash tool.
Now the SP flash tool is giving me the following,
Chip Info
=======
Chip name: MT6755
Chip Version: 0x0000cb00
Ext Clock: EXT_26M
Extern RAM Type: DRAM
Extern RAM Size: 0xc0000000 (!!!)
SRAM Size: 0x00040000
EMMC Flash
=========
Boot 1 Size: 0x400000
Boot 2 Size: 0x400000
RPMB Size: 0x400000
GP1 Size: 0x0 (same for GP2, GP3 and GP4)
UA Size: 0x747c00000
No matter what ROM I'm trying to flash (stock or custom) , I always get the error "STATUS_INSUFFICIENT_BUFFER (0xC0010007)".
It looks like it has to do something with the External RAM Size (0xc0000000).
I found this firmware "XT1662_Kungfu_m_MT6755_USR_S0924_1612291517_mp7V2.3_CN (RepairMyMobile.in)", which seems to be what I need but I can't get pass this error.
Any help will be greatly appreciated.
i have the same problem
STATUS_INSUFFICIENT_BUFFER (0xC0010007)
i try to update with OTA and failed too
anyone can help ?

Asus Zenfone Max Plus M1 [X018D] bricked - some advice to recover data ?

Hello XDA community !
To be honest I'm a newbie here, and not really experienced on mobile phone technical stuff
My Zenfone suddenly stopped working last week, without any particular reason.
The only thing I can see when I on the device is the "Powered by Android" logo. But nothing else happens after.
Then I wanted to start the recovery menu, but even when I select "recovery mode" or "fastboot" nothing happens, it's still showing "Powered by Android" logo and no more
See this screenshot :
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
I tried to plug the device with USB to my linux laptop with android studio installed, but adb devices show nothing
I also tried to create a microSD card, bootable, with exFAT partition and put the phone firmware on the root of the card (as described https://www.asus.com/supportonly/zenfone max plus (m1)(zb570tl)/helpdesk_download/). Even with it, recovery or fastboot options give the same screen as above
My idea was to be able to boot from sd card and be able to "revive" somehow the phone, and at least being able to download user data from it with the help of adb
I'm not sure if it's possible of if I should prepare the microsd with another format or partition layout
Any idea to guide me ?
Don't think you can recover any user-data this because probably bootloader completely got corrupted. Re-flash Stock ROM.
Thanks for your answer.
Sorry also because I made a mistake : I think fastboot mode is active
What I did : In the menu above, I selected "Fastboot mode"
then I got an output : "CSC FASTBOOT mode"
Then I plugged the phone on my laptop USB
The "lsusb" command returned an additionnal device :
Code:
Bus 001 Device 004: ID 0bb4:0c01 HTC (High Tech Computer Corp.) Dream / ADP1 / G1 / Magic / Tattoo / FP1
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x0bb4 HTC (High Tech Computer Corp.)
idProduct 0x0c01 Dream / ADP1 / G1 / Magic / Tattoo / FP1
bcdDevice 1.00
iManufacturer 1 MediaTek
iProduct 2 Android
iSerial 3 J1AXJR04D658EJ6
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 0x0020
bNumInterfaces 1
bConfigurationValue 1
iConfiguration 0
bmAttributes 0x80
(Bus Powered)
MaxPower 256mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 255 Vendor Specific Class
bInterfaceSubClass 66
bInterfaceProtocol 3
iInterface 4 fastboot
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x01 EP 1 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 1
Device Status: 0x0001
Self Powered
"adb devices" still returns nothing but "fastboot devices" does :
J1AXJR04D658EJ6 fastboot
"fastboot reboot" does also reboot the phone ...
From there I guess at least I can do something. I don't know if I'll be able to recover some data, but anyway if I can recover my phone that would be fine too.
you can unlock bootloader with mtkclient (do a backup beforehand) and flash TWRP from fastboot, to see if that leads to something.
ok thanks a lot. I'll have a look to mtkclient / TWRP and try to manage !
Will let you know soon.
keep in mind unlocking from fastboot forces factory reset. It will flush keystore in TEE, don't try this even with full backup. TEE can't backed up.
unlocking from mtkclient afaik does not wipe userdata. but do a backup of userdata + metadata + seccfg (or even better full dump) just in case.
you can try to boot into EDL mode with both vol keys + usb, modified fastboot, DIY deep flash cable or test point method.
[GUIDE][TOOL] Reboot to EDL mode from FASTBOOT! No More "Test Point Method"! [kenzo]
[GUIDE][TOOL] Reboot to EDL mode from FASTBOOT! No More "Test Point Method"! [kenzo] Reboot to EDL mode from FASTBOOT! No more Test Point Method needed ;) Technical Details: Redmi Note 3 support rebooting to EDL in Android Bootloader aboot...
forum.xda-developers.com
also please note TWRP is maybe not able to decrypt, because encryption keys are bonded to bootloader lock state.
however some people claim it's possible, maybe due the fact that seccfg is patched in way to circumvent this (untested).
if you can't boot into recovery from bootloader, you can boot into file from fastboot (requires bootable slot)
Code:
fastboot boot twrp.img
thanks Alecxs for all the information. I'll take some time to read carefully everything.
In the meantime, I installed successfully mtkclient on my laptop. I didn't know about this tool before
I used first the read partition tool, which went fine for almost all partitions except userdata :-(
it started but stopped after 9 GB (over 52) with the following message
Failed to dump sector 12517376 with sector count 109592543 as MyZenfone-partition dump/userdata.bin
18.0% Read (Sector 0x12D6C80 of 0x6883FDF, 42m:19s left) 18.67 MB/sDAXFlash
DAXFlash - [LIB]: Error on reading data: MMC error (0xc0040030)
looks like game over ...
well.. if this is game over, then you have nothing to lose I guess? so backup all partitions excluding userdata (--skip=userdata) then only try to unlock seccfg (do not erase any partition ignore instructions) then boot into fastboot and check if TWRP can boot
TRY AT OWN RISK YOU MAY CORRUPT USERDATA ENCRYPTION OR ERASE USERDATA​
Code:
python3 mtk da seccfg unlock
python3 mtk payload --metamode FASTBOOT
fastboot boot path/to/twrp.img
might be possible to dump userdata excluding unreadable sectors. but you need to read the instructions. nevertheless the dump (even if healthy) is impossible to decrypt on PC, can only be decrypted on the origin phone itself...
thanks alecxs, I think I'll try to boot into twrp
My concern is to find a suitable twrp for my device. There is no official port for Asus X018D
I tried to find it by googling and found this on "unofficial twrp" site
twrp 3.2.3 For Mediatek MT6750 Phone
which could be ok for mine maybe except they it's for android 8 and 8.1, while I was still on Nougat 7
I don't know if trying this could work or not ?
you need TWRP for the Plus variant. can you share boot.img + recovery.img read off device?
yes I can share the dumped partitions from mtkclient (the extension is .bin)
boot.bin :
boot.bin
drive.google.com
recovery.bin
recovery.bin
drive.google.com
okay let me try to port generic TWRP. you can meanwhile try that Oreo+recovery+tested.img (login required)
edit: X018D_TWRP.img for android 9 (no login required)
So I tried to unlock bootloader from mtkclient, which resulted in :
sej - HACC init
sej - HACC run
sej - HACC terminate
sej - HACC init
sej - HACC run
sej - HACC terminate
Done |--------------------------------------------------| 0.0% Write (Sector 0x0 of 0x1) 0.00 MB/sDAXFlash
DAXFlash - [LIB]: Error on writeflash: MMC error (0xc0040030)
and then after (maybe I shouldn't have ...)
python3 mtk payload --metamode FASTBOOT
I think I did something wrong, because now I cannot list GPT
python mtk printgpt
gives
Code:
Port - Device detected :)
Preloader - CPU: MT6755/MT6750/M/T/S(Helio P10/P15/P18)
Preloader - HW version: 0x0
Preloader - WDT: 0x10007000
Preloader - Uart: 0x11002000
Preloader - Brom payload addr: 0x100a00
Preloader - DA payload addr: 0x201000
Preloader - CQ_DMA addr: 0x10212c00
Preloader - Var1: 0xa
Preloader - Disabling Watchdog...
Preloader - HW code: 0x326
Preloader - Target config: 0x5
Preloader - SBC enabled: True
Preloader - SLA enabled: False
Preloader - DAA enabled: True
Preloader - SWJTAG enabled: True
Preloader - EPP_PARAM at 0x600 after EMMC_BOOT/SDMMC_BOOT: False
Preloader - Root cert required: False
Preloader - Mem read auth: False
Preloader - Mem write auth: False
Preloader - Cmd 0xC8 blocked: False
Preloader - Get Target info
Preloader - BROM mode detected.
Preloader - HW subcode: 0x8a00
Preloader - HW Ver: 0xcb00
Preloader - SW Ver: 0x1
Preloader - ME_ID: 10A8E97D4708BDEB74D8D7B3C7E0EBFA
PLTools - Loading payload from mt6755_payload.bin, 0x258 bytes
PLTools - Kamakiri / DA Run
Kamakiri - Trying kamakiri2..
Kamakiri - Done sending payload...
PLTools - Successfully sent payload: /home/laurent/Applications/DevOps/Android/mtkclient/mtkclient/payloads/mt6755_payload.bin
Port - Device detected :)
DA_handler - Device is protected.
DA_handler - Device is in BROM mode. Trying to dump preloader.
DAXFlash - Uploading xflash stage 1 from MTK_AllInOne_DA_5.2136.bin
xflashext - Patching da1 ...
Mtk - Patched "Patched loader msg" in preloader
xflashext
xflashext - [LIB]: Error on patching da1 version check...
Mtk - Patched "Patched loader msg" in preloader
xflashext - Patching da2 ...
DAXFlash - Successfully uploaded stage 1, jumping ..
Preloader - Jumping to 0x200000
Preloader - Jumping to 0x200000: ok.
DAXFlash
DAXFlash - [LIB]: xread error: unpack requires a buffer of 12 bytes
DAXFlash
DAXFlash - [LIB]: Error jumping to DA: -1
actually, the second command was just to exit preloader mode and switch into fastboot... sorry for the confusion. I have also attached the android 7 version of twrp for testing.. (see above)
If I got this right, unlocking was trying to write Sector 0x0 of 0x1 but it deny writing anything because eMMC is not writeable at 0xc0040030. But isn't that in userdata area?
however, on android 7 for some mediatek devices it's possible to boot into TWRP on locked bootloader. but needs flashing. you can try another flash tool, but it requires windows
edit:
@arthur.levene I got it wrong, seems there is also linux version. Anyway, please read golden rules for SP Flash Tool.
I recommend to create your own scatter file based on the current partition table, either with mtkclient or with WwR MTK v2.51 (most likely you can use the one that already comes with that twrp as the recovery start address is at 0x8000 on many devices, but I personally generally don't trust any scatter file just random downloaded).
lol thought 0xc0040030 was the address of the unreadable sector. turns out it is a fault code. so that could mean eMMC error (most likely) or insufficient permissions.
So any flashing attempts will probably fail no matter what tool used. maybe there is a cheat with heating gun or refrigerator (just guesswork, beware of condensating water)
thanks again alecxs for your time and advice.
I will continue my investigations based on your informations. If i understand your comment about eMMC error, this is not good news.
I will try also the flashing solution in case it could work, though not very skilled on that part too
actually I have never used mtkclient myself but according to documention flashing looks quite easy.
Code:
python3 mtk w recovery twrp.img
However, as you stated in OP you can't enter recovery mode from bootloader menu, so this could be bigger challenge.
I tried but currently I have an error
DAXFlash - Upload data was accepted. Jumping to stage 2...
DAXFlash - DA Extensions successfully added
Done |--------------------------------------------------| 0.0% Write (Sector 0x0Progress: |███████-------------------------------------------| 14.0% Write (SectProgress: |██████████████------------------------------------| 28.0% Write (Sector 0x2000 of 0x7254, 01s left) 6.74 MB/s
DAXFlash
DAXFlash - [LIB]: unpack requires a buffer of 12 bytes
quick search gives hint is might be driver issue. but you're on linux right? you could try again with libusb-1.0-0-dev_1.0.26-1_amd64.deb
https://github.com/bkerler/mtkclient/issues/192

Categories

Resources