: what is procedure for unlock db2012/db2020 by flash patch ? what problems i can meet and how to resolve them ?
a:
terms:
- you can only unlock by flash patch db2012 (k320,w200,etc) and db2020 phones with FLASH CID 49,50,51
- flash CID can be discovered with IDENTIFY button
- you CAN NOT repair phones with damaged/foreign GDFS (red blink when startup)
- you CAN NOT use altbypass on PNX5230 phones (z310 at present) and NEW SECURITY PDA phones (maybe i will do it, maybe will not)
- you will need ONE CREDIT per ONE PHONE.
howto:
1. open setool2, select correct model.
2. go to settings tab.
3. enter your server, user, password
4. mark "use server for csca flash/unlock", "enable alternative security bypass", "unlock after flash"
5. go back to semc tab. PRESS SAVE.
6. i recommend to use dcu60 cable with any db2020 model - it is FAST and STABLE.
7. now, did you download new rest files ? no? then do it.
8. press identify, look for current firmware version and try to find it in new rest files.
9. found ? nice. press unlock now - you will see smth like
Code:
SERVER SUPPORT ENABLED.
ChipID:9900,EMP protocol:0301
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:51
Speed:921600
OTP LOCKED:1 CID:49 PAF:1 IMEI:30000000000000 CERT:RED
FLASH CID:51 COLOR:RED
PATCH:061205 1523 HANCXC9876543210_DB2020_MEM_PATCHER_R2A006 0
Flash ID check:897E
Flash props sent ok
bypassing DB2020 security...
done,restarting...
ChipID:9900,EMP protocol:0301
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:51
Speed:921600
Trying to launch embedded bootloader...
Embedded flashloader:
DB2020_PRELOADER_FOR_SETOOL2
Flash ID check:897E
Flash props sent ok
Restore from:C:\2\setool2\newrest\tems_r1b_k800
full sig complete.
USERCODE reset to "0000"
Searching...
Firmware lock check determined.
Unlock Done
Elapsed:42 secs.and that means your phone is unlocked.
10. if you can't find rest file for yours firmware, nothing to worry !
just select main+fsimage+custpack and press flash
you will get smth like that
Code:
FILE RECOGNIZED AS CUSTOMIZATION PACKAGE.
CDA:CDA102568/8
MODEL:HB1-06 Generic
VARIANT:RUSSIA
LANGUAGE: EN
LANGUAGE: RU
SERVER SUPPORT ENABLED.
ChipID:9900,EMP protocol:0301
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:51
Speed:921600
OTP LOCKED:1 CID:49 PAF:1 IMEI:30000000000000 CERT:RED
FLASH CID:51 COLOR:RED
PATCH:061205 1523 HANCXC9876543210_DB2020_MEM_PATCHER_R2A006 0
Flash ID check:897E
Flash props sent ok
bypassing DB2020 security...
done,restarting...
ChipID:9900,EMP protocol:0301
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:51
Speed:921600
Trying to launch embedded bootloader...
Embedded flashloader:
DB2020_PRELOADER_FOR_SETOOL2
Flash ID check:897E
Flash props sent ok
Nothing found,use manual selection
writing C:\2\k800\cid52\R1JG001_1250210_GENERIC_WI.ssw
CURRENT FLASH FILE CID:52
SSW uses complete hash, hash len is:9200
Will flash 460 blocks...
SSW loading returns:0
writing C:\2\k800\cid52\R1JG001_FS_BALTIC_WI_RED_CID52.ssw
CURRENT FLASH FILE CID:52
SSW uses complete hash, hash len is:4420
Will flash 221 blocks...
SSW loading returns:0
full sig complete.
USERCODE reset to "0000"
Searching...
Firmware lock check determined.
CSloader version:
060426 1726 HANCXC1329133_DB2020_FILESYSTEMLOADER_P5G
loader startup: executed
loader filesystem startup: executed
loader GDFS startup: executed
loader unlock: executed
Writing package...
Directory: tpa/preset/custom/
CONTENT_DOWNLOAD_HOOK.itm (10240)
Customize.xml (962)
FM_PICTURES_HOOK_3.itm (10240)
FM_SOUNDS_HOOK_3.itm (10240)
FM_THEMES_HOOK_3.itm (10240)
FM_VIDEOS_HOOK_3.itm (10240)
GAMES_HOOK_3.itm (10240)
MEDIA_PLAYER_HOOK_3.itm (10240)
ORG_APPLICATIONS_HOOK_3.itm (10240)
preloaded_config.xml (78607)
SETT_RINGTONE_HOOK_1.itm (10240)
SETT_SCREENSAVER_HOOK_1.itm (10240)
SETT_STARTSHOW_HOOK_1.itm (10240)
SETT_WALLPAPER_HOOK_1.itm (10240)
VIDEO_PLAYER_HOOK_1.itm (10240)
Phone detached
Elapsed:415 secs.and that means you have fullflashed and unlocked phone.
if you get
Code:
Flash props sent ok
bypassing DB2020 security...
smth wrong with GDFS format,error is:30
prepare failedthat means you HAVE NOT SELECTED BOTH "USE SERVER" and "USE ALT BYPASS".
re-check settings, not forget to save profile after you selected settings.
if you get
Code:
Firmware lock check determined.
llbug: can't get all data, got:0 expected:1926
processing error when readingwhile using com/ufs cable that mean problem with your cable/drivers.
install latest drivers, play with latency.
but better use dcu60 cable with any db2020 phone.
once again IF YOU GET
Code:
FOUND: R1ED001_CXC1250556_VODAFONE_MW
Restore from:R1ED001_CXC1250556_VODAFONE_MW
can't open file "C:\setool\rest\R1ED001_CXC1250556_VODAFONE_MW "
full sig complete.read that post again, from beginning.
very rare, with some bad cables (thats happens only with some improperly made ufs/com cables),
phone fails to detect interface and you will get following:
Code:
........
bypassing DB2020 security...
done,restarting...
ChipID:9900,EMP protocol:0301
Speed:921600
Trying to launch embedded bootloader...
Abort all operations.
embedded flashloader not responds !on subsequent attempts of flashing with usb
Code:
ChipID:9900,EMP protocol:0301
OLD EROM, OVERRIDING CID
error while reading security units
SECURITY UNITS CAN'T BE READ !
PHONE IS EMPTY OR GDFS IS DAMAGED.and on "identify" it will show
Code:
ChipID:9900,EMP protocol:0301
Speed:921600
Flash ID check:897E
Flash props sent ok
OTP LOCKED:1 CID:49 PAF:1 IMEI:00000000000000 CERT:RED
FLASH CID:49 COLOR:RED
set_gdfs_props failed, exiting
Elapsed:8 secs.solution:
first, get normal 4in1/ufs cable (with both ports soldered and good pinout)
next,
select interface com/ufs
semc tab, select proper model.
settings, check ONLY "use server",
add to flash files ONLY main firmware image, situable for selected model
press flash
check if phone turning on. it should.
redo unlock procedure, read topic for start first.
(remember - dcu60 is fastest and safest way to work with db2020 ph