Results 1 to 10 of 14

Thread: HOW TO WORK WITH SEMC PDA PHONES

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Administrator
    Join Date
    Feb 2010
    Posts
    18,862

    Default

    q:
    how to repair totally damaged s1 android phones, based on msm7227,qsd8250, using alternative security bypass using testpoint?

    a:
    Here is procedure.

    okay, here is example how to resurrect totally dead x10 phone.
    so, we have x10 phone with totally erased semcboot and trim area.
    phone does not turn on, does not connect to pc anyhow.

    lets resurrect it.

    run setool2, select x10 as model, select com port as interface
    ( one where GPG resurrection cables connected )

    1.
    on options set signed mode,altbypass mode, use testpoint (gnd type)

    2.
    connect GPG x10 resurrection craddle to phone, press RECOVERY
    follow program instructions.

    important notice:
    for msm7227 phones, insert battery in phone after you attached testpoint.
    for x10 phone connect RED dot to GND permanently during all testpoint procedure


    btw, as phone has erased semcboot, you do not need apply testpoint that time.
    however, that is very special case, so for simplicity lets apply testpoint all time.

    here is operation output:

    Code:
    SIGNED MODE (USING SERVER)
    ALTERNATIVE SECURITY BYPASS ENABLED
    CFG:110010000010
     
    DETACH USB CABLE FROM PHONE
    REMOVE BATTERY FROM PHONE
    ATTACH TESTPOINT
    ATTACH USB CABLE TO PHONE,THEN PRESS "READY"
     
    PROCESSING ...
    REMOVE TESTPOINT NOW, THEN PRESS "READY"
     
    RUNNING S1_LOADER VER "R4A024"
    SWITCHING TO "USB" ...
    PLEASE ATTACH TURNED OFF PHONE NOW
     
    RUNNING S1_LOADER VER "R4A024"
    LOADER AID: 0001
    FLASH ID: "002C/00B3"
    LOADER VERSION: "r4A024"
     
     
    WRITING SEMCBOOT ...
    Checking TA ...
    MINOR ERROR [ MISC_CLASS: MISC_ERROR, TA_set_config_failed ]
    Writing config ...
    MINOR ERROR [ MISC_CLASS: MISC_ERROR, TA_invalid,_format_may_be_required ]
    Formatting ...
    Checking MISC TA ...
    MINOR ERROR [ MISC_CLASS: MISC_ERROR, TA_invalid,_format_may_be_required ]
    Writing config ...
    MINOR ERROR [ MISC_CLASS: MISC_ERROR, TA_invalid,_format_may_be_required ]
    Formatting ...
    SUCCESS

    now we recovered semcboot and prepared trim area for loading.
    if phone only had erased semcboot, it will already work after that step.
    but our phone TOTALLY damaged, so lets proceed with second step:

    we need now load trim area.
    Please skip this step, if your phone do not have damaged trim area ( errors like: "TA_invalid,_format_may_be_required" )

    options are same for step1 + "format gdfs when writing" checked,
    select x10.zip in misc.edit and press "write gdfs".
    ( any trim area, read from corresponding model live phone will work )
    follow program instructions.

    here is operation output:

    Code:
    SIGNED MODE (USING SERVER)
    ALTERNATIVE SECURITY BYPASS ENABLED
    CFG:110010000110
    Will write GDFS now.
     
    DETACH USB CABLE FROM PHONE
    REMOVE BATTERY FROM PHONE
    ATTACH TESTPOINT
    ATTACH USB CABLE TO PHONE,THEN PRESS "READY"
     
    PROCESSING ...
    REMOVE TESTPOINT NOW, THEN PRESS "READY"
     
    RUNNING S1_LOADER VER "R4A024"
    SWITCHING TO "USB" ...
    PLEASE ATTACH TURNED OFF PHONE NOW
     
    RUNNING S1_LOADER VER "R4A024"
    LOADER AID: 0001
    FLASH ID: "002C/00B3"
    LOADER VERSION: "r4A024"
     
    Can't get IMEI
    will write 1010 units
    done
    will write 53 units
    done
    Phone detached
    Elapsed: 23 secs.
    finally, we need rebuild imei and security zone.
    for that, check same options as for step1 + "do full unlock instead of usercode reset","allow to change imei when unlocking" checked,
    press "unlock/repair", follow program instructions

    here is operation output:

    Code:
     
    THAT ACTION IS ILLEGAL,IF YOU DOING IT
    FOR ANY PURPOSE, OTHER THAN REPAIR PHONE
     
    SIGNED MODE (USING SERVER)
    ALTERNATIVE SECURITY BYPASS ENABLED
    CFG:110010010010
     
    DETACH USB CABLE FROM PHONE
    REMOVE BATTERY FROM PHONE
    ATTACH TESTPOINT
    ATTACH USB CABLE TO PHONE,THEN PRESS "READY"
     
    PROCESSING ...
    REMOVE TESTPOINT NOW, THEN PRESS "READY"
     
    RUNNING S1_LOADER VER "R4A024"
    SWITCHING TO "USB" ...
    PLEASE ATTACH TURNED OFF PHONE NOW
     
    RUNNING S1_LOADER VER "R4A024"
    LOADER AID: 0001
    FLASH ID: "002C/00B3"
    LOADER VERSION: "r4A024"
     
    Can't get IMEI
    REQUESTED : 359419030xxxxx
    Checking for HWConfig ...
    Waiting for calculation process ...
    RESPONSE: "SUCCESS" [826]
    Checking for signature ...
    signature found, skipping calculation
    WRITING SEMCBOOT ...
    WRITING HWCONFIG ...
    Unlock DONE
    Elapsed: 20 secs.
    from now on, phone is full repaired, testpoint cradle not needed.
    reflash phone with any suitable firmware.

    q:
    how to repair totally damaged s1 android phones, based on qsd8x55, using alternative security bypass using testpoint?

    a:
    operation is very same, just select usb as interface and do not check "use testpoint (gnd type)"


Similar Threads

  1. HOW TO WORK WITH A2-BASED PHONES
    By the_laser in forum F.A.Q.
    Replies: 6
    Last Post: 04-27-2012, 05:11 PM
  2. HOW TO WORK WITH SEMC ODM PHONES
    By the_laser in forum F.A.Q.
    Replies: 7
    Last Post: 03-25-2011, 05:03 PM
  3. HOW TO WORK WITH A1-BASED PHONES
    By the_laser in forum F.A.Q.
    Replies: 5
    Last Post: 02-06-2010, 09:04 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •