-
re: Setool Box Updates
q:
when i attaching phone using dcu60 i see following messages:
Code:
erom_readvar: error reading unit 1/725
error while reading security units
SECURITY UNITS CAN'T BE READ !
DAMAGED FIRMWARE/GDFS OR EMPTY PHONE
or
erom_readvar: error reading unit 1/851
error while reading security units
SECURITY UNITS CAN'T BE READ !
DAMAGED FIRMWARE/GDFS OR EMPTY PHONE
and process stops,but phone works normally on com/ufs.
what is root cause and what is solution ?
A:
that phone is tampered by d_reambox software.
during their famous method of "testpoint bypass", they writing patched erom with own custom loader embedded, patching simlock signature check and ... erasing simlock signature without any reason, which prevents setool2 from making backup.
i had write a post on their forum, but they too arrogant even to read it.
fix is extremly simple:
using com/ufs write next script in SIGNED MODE (check ONLY "USE SIGNED MODE" on settings)
for db2020:
Code:
gdfswrite:0001085144554D4D5944415441
for db2012:
Code:
gdfswrite:0001072544554D4D5944415441
alas, they custom loader also breaks alternative bypass support using dcu60 cable,
so you only can use SIGNED MODE with dcu60 after their "testpoint".
maybe i will write program (embed option in setool2) to restore tampered by d_reambox erom to correctly patched.
-
re: Setool Box Updates
q:
when i flashing/completing/etc phone i got error like
Code:
loader startup: executed
Loader refused to start GDFS services,error is:29
loader GDFS startup failed, that is fatal
Elapsed: 734 secs.
what to do ?
a:
that error can be caused by different problems. lets see all of them
1. user has run "executor" application, which was not deleted after "new altbypass unlock".
solution -
select correct model
on settings check only "use preloader security bypass".
execute any operation, say : "read flash"
2. main software somehow has been damaged (cause of free tools, etc)
solution -
select correct model
on settings check only "use signed mode".
add to firmware area only main part of firmware
press flash (use com/ufs or dcu60 with "2+5" keys if phone not connecting with "C" )
after that, phone should show identify normally.
.... and if not....
3. gdfs area has been damaged (bad flash ic, firmware error,etc)
solution -
a) install empty flash chip and do emptyboard fill procedure
b) try to repair gdfs area with VERY complex testpoints
c) change both mcu+flash chip from other phone
-
re: Setool Box Updates
uploaded complete pack of RED53 k610 k610im k618 v630 w710 w850 z610 z710 firmwares and fsimages.
-
uploaded K630-V640-K660 full schematics and repair manual
uploaded K800-K810 full schematics and repair manual
uploaded C702 R3CA033 firmwares and *all_languages_pack*
uploaded C902 R3CA037 firmwares and *all_languages_pack*
-
re: Setool Box Updates
uploaded K630-V640-K660 full schematics and repair manual
uploaded K800-K810 full schematics and repair manual
updated C702 R3CA033 firmwares and all_languages_pack
uploaded C902 R3CA037 firmwares and all_languages_pack
let me remember, that all_languages_pack is .zip file,which should be used as custpack.
of course, nobody stops you from deleting unneeded languages from it.
-
re: Setool Box Updates
uploaded and updated r3ca033, r3ca038 firmwares and custpacks for w980
w760,c702,c902 r3ca037 firmware,fsimages and enormous custpack number uploaded.
also many other firmwares updated, check for "new" icon on support...
-
re: Setool Box Updates
v0.914038
- added SCRC testpoint repair for db2012 phones.
supported CIDs : 50,51,52,53.
(db201x testpoint idea made by dre_ambox team).
usage:
1. it is only and only for professionals.
users,advanced users, please "go away".
2. testpoint is +3.3 voltage, connected to specific pin.
we suggesting to use +3.3v battery
(battery ground MUST be connected with phone's GROUND)
3. go to emptyboard fill & repair.
4. select needed db2012 model.
5. press "TP STAGE #1". read instructions and execute them.
6. phone is BROWN now.
7. now flash CORRECT db201x erom with needed CID.
NOTE, THAT EROM CID SHOULD BE >= OTP CID,OTHERWISE YOU WILL GET DEAD PHONE.
10. phone now retail,repaired and unlocked. fullflash phone as usual.
testpoint pictures (courtesy of drea_mbox team) included.
as all db201x shares same mcu, w200 testpoint picture is good
for all db201x phones.
IF YOU WROTE EROM WITH INCORRECT CID - USE "TP STAGE #2"
PLEASE NOTE, THAT CURRENT IMPLEMENTATION REQUIRES
VALID GDFS STRUCTURE. SO, IT SITUABLE ONLY FOR 5-LOCKS
REPAIR AND FULL STANDALONE UNLOCK.
- added all possible db201x eroms, now users can make cid50/51/52/53
phones from emptyboard phones
(not forget: add to firmware area gdfs_in_ssw FIRST and EROM LATEST)
- minor bugfixes.
RapidShare: Easy Filehosting
-
re: Setool Box Updates
v0.914039
- PDA gdfs write was broken, fixed. thx to infogsmfor report.
RAPIDSHARE RapidShare: Easy Filehosting
-
re: Setool Box Updates
r306,r306a r1ab002 firmware uploaded
c902 r3c038 firmware,fsimages,custpacks updated
uploaded K330 r1cd001 firmware
uploaded t280 r1cb002 (mr1) firmware
uploaded t700 r3da020 firmware,fsimages,custpacks. yes,few, but hot as hell
uploaded k660 r1fa035 firmware,fs images,custpacks.
-
re: Setool Box Updates
w350 r11ca002 firmware added, custpacks updated
w380 r11ca002 firmware added, custpacks updated