Related
So i downloaded WM6 Black 2.0, and its constantly crashing, so i wanted to re-install it and see if that helped.
now whenever i try to launch the file, i get an error message that states
"custom RUU has encountered a problem and needs to close. we are sorry for the inconvenience."
So im wondering what changed that wont allow me to run the ruu file? Im kinda freaking out here because i need to get my phone working! its constantly crashing on me!
i hope someone knows a fix for this, i tried to search but came up with nothing
newnoise1024 said:
So i downloaded WM6 Black 2.0, and its constantly crashing, so i wanted to re-install it and see if that helped.
now whenever i try to launch the file, i get an error message that states
"custom RUU has encountered a problem and needs to close. we are sorry for the inconvenience."
So im wondering what changed that wont allow me to run the ruu file? Im kinda freaking out here because i need to get my phone working! its constantly crashing on me!
i hope someone knows a fix for this, i tried to search but came up with nothing
Click to expand...
Click to collapse
Looks like a problem on your PC... (I mena for the Customruu crashing)
newnoise1024 said:
So i downloaded WM6 Black 2.0, and its constantly crashing, so i wanted to re-install it and see if that helped.
now whenever i try to launch the file, i get an error message that states
"custom RUU has encountered a problem and needs to close. we are sorry for the inconvenience."
So im wondering what changed that wont allow me to run the ruu file? Im kinda freaking out here because i need to get my phone working! its constantly crashing on me!
i hope someone knows a fix for this, i tried to search but came up with nothing
Click to expand...
Click to collapse
Had this happen to me. I downloaded .net framework 3.0 from the M$ site and then it worked fine.
Maybe that will help you.
Jim
Need more info?
newnoise1024 said:
So i downloaded WM6 Black 2.0, and its constantly crashing, so i wanted to re-install it and see if that helped.
now whenever i try to launch the file, i get an error message that states
"custom RUU has encountered a problem and needs to close. we are sorry for the inconvenience."
So im wondering what changed that wont allow me to run the ruu file? Im kinda freaking out here because i need to get my phone working! its constantly crashing on me!
i hope someone knows a fix for this, i tried to search but came up with nothing
Click to expand...
Click to collapse
Ok, first off, this is not a flame. It's an education, ok?
When posting a problem, it's best practice to let us know your:
Model of phone
Radio version
Boot Loader version
OS on your PC
ActiveSync version (s/b 4.5 by now)
Then, and only then, will you be able to get some intelligent answers. You also need to follow the link in my signature and there you will find answers.
If you're still stuck, usually re-downloading the RUU will result in a working ROM patch, unless you have other PC issues. You really need to fix that first, and the guides posted here are FULL of the diagnostic and troubleshooting steps that will propel you to a successful resolution.
Please read those posts, add your info, and you may be extremely pleased with the results.
Good reading!
newnoise1024 said:
So i downloaded WM6 Black 2.0, and its constantly crashing, so i wanted to re-install it and see if that helped.
now whenever i try to launch the file, i get an error message that states
"custom RUU has encountered a problem and needs to close. we are sorry for the inconvenience."
So im wondering what changed that wont allow me to run the ruu file? Im kinda freaking out here because i need to get my phone working! its constantly crashing on me!
i hope someone knows a fix for this, i tried to search but came up with nothing
Click to expand...
Click to collapse
First off; relax. At least the problem isn't with your phone. It's a heck of a lot easier to fix a PC.
I assume you've already tried to re-download the file?
Did you completely reboot your PC? Shut it down to power down, then restart. Make sure you don't have any extra USB stuff plugged in (like cameras, etc). If you have a PS/2 mouse and KB, use those, and not USB versions. One trick is to have the USB bus on your computer completely empty except for your phone.
Head over to Microsoft's site and download a fresh version of Compact Framework .NET (3.0 is the current version). Reboot after installing it -- even though it doesn't tell you to.
Run Windows Update. Make sure you're OK on those.
If that doesn't work, try downloading another ROM (OS only) -- like the Cingular Black 2.02 or the LVSM ROM, and see if that works.
You can also strip it apart -- use WinRAR to open the EXE file that you've been executing and extract the .nbh file from the EXE. Then go and download this guy: http://wiki.xda-developers.com/index.php?pagename=Hermes_CustomRUU and extract it into its own folder. Copy that .nbh file into that directory, and execute the executable -- it will flash your phone with a known good flasher.
But.... stepping all of the way back ... if the ROM doesn't work on your phone, it's very likely reflashing it won't help a single bit. Those ROM's are checksummed when they go on the phone -- if they're corrupted, they won't load right in the first place (and you'd end up with a boot-loader only phone). Soo... uh.. first, reboot/clean USB, then try a different ROM.
Last resort will be completely reinstalling Windows XP. I've had to do this several times because Windows will get in some weird state and it refuses to flash my phone. I finally gave up and started flashing on my Mac using a Windows virtual machine -- it's a lot easier to restore my Windows system to a working point when I do that.
Thanks to everyone who gave a response!
Here's all the information i was asked to post ( i will remember this for next time)
Cingular 8525 HERM100
Radio version: 1.40.30.00
Boot Loader version: (Not quite sure what this is?)
OS on your PC: Pro Black 2.0
ActiveSync version 4.5
I have redownloaded the ruu about 3 times and it has failed everytime.
Restarted the PC, disconnected everything from my laptop, realized that i havent installed Framework .NET 3.0, ( although i have it on my phone as i needed it to run hitchhiker)
So i'm going to download framework .NEt 3.0 and run it.
As for my phone, i uninstalled all the apps, hard resetted and everything is working fine right now, hasn't froze at all since yesteray, so im going to wait it out and see if something happens again.
Thanks again to everyone!! This forum is really really helpful.
-Matthew
How to determine the bootloader version
newnoise1024 said:
Boot Loader version: (Not quite sure what this is?)
-Matthew
Click to expand...
Click to collapse
You need to have a look at your user guide, as it states how to enter bootloader and check the version. Otherwise press and hold the left OK button and the power button at the same time, then hit the reset button with your stylus. You will enter a tri-color screen. This is bootloader mode. Jot down the numbers and compare against the below link.
Exiting is simple, press the reset button with your stylus.
Here's a valuable link for updating your bootloader.
Bootloader Version: SPL-1.40.01pro
IPL-1.01
i just tried to install Framework .NET 3.0 and got this error message
[04/20/07,08:50:20] Windows Communication Foundation: [2] Error: Installation failed for component Windows Communication Foundation. MSI returned error code 1603
[04/20/07,08:57:35] Windows Communication Foundation: [2] Error: Installation failed for component Windows Communication Foundation. MSI returned error code 1603
[04/20/07,08:57:54] WapUI: [2] DepCheck indicates Windows Communication Foundation is not installed.
[04/20/07,08:57:54] WapUI: [2] DepCheck indicates Microsoft .NET Framework 3.0 was not attempted to be installed.
i uninstalled any previous version, is there something i'm missing?
.Net Framework co-existence
newnoise1024 said:
Bootloader Version: SPL-1.40.01pro
IPL-1.01
i just tried to install Framework .NET 3.0 and got this error message
[04/20/07,08:50:20] Windows Communication Foundation: [2] Error: Installation failed for component Windows Communication Foundation. MSI returned error code 1603
[04/20/07,08:57:35] Windows Communication Foundation: [2] Error: Installation failed for component Windows Communication Foundation. MSI returned error code 1603
[04/20/07,08:57:54] WapUI: [2] DepCheck indicates Windows Communication Foundation is not installed.
[04/20/07,08:57:54] WapUI: [2] DepCheck indicates Microsoft .NET Framework 3.0 was not attempted to be installed.
i uninstalled any previous version, is there something i'm missing?
Click to expand...
Click to collapse
You're probably missing version 2.0 of the .NET framework. .NET Framework is to be left in place once installed. You should have left V 2.0 installed and added .NET 3.0. Go to www.microsoft.com/net and get version 2.0 redistributable re-installed on your machine. (If you can). If you cannot, search the KB and you may get by without rebuilding your OS.
"Head over to Microsoft's site and download a fresh version of Compact Framework .NET (3.0 is the current version). To be extra safe, go into Add/Remove Programs and uninstall any existing versions -- reboot -- then install the new CF Framework. Reboot after installing it -- even though it doesn't tell you to."
this is the advice i was given in this thread, so i uninstalled version 2.0 before installing version 3.0.
So am i screwed now? lol
Well, version 3.0 just installed successfully... does that mean i still need to install 2.0? or am i fine just running 3.0?
Sorry for all the questions, i just want this fixed :/
You should be good. Give it a go.
If not, just dl .Net CF2 and install that. I think you are fine now though.
Edit: never mind
version 2.0 installed fine
Thanks everyone
Hi to all! I installed a new cooked great rom to my trinity a month ago and it worked fine. it is this rom
[ROM][ITA]WM 6.1 Elegance edition 2.14 (OS 5.2.19213 Build 19213.1.0.0)[ONLINE]
today I got a strange error and the phone was stuck. I unplugged the battery and when I started again it was stuck on the calibration screen. if I tap on the screen nothing happens but the backlight turns on if it was off so it still catches the taps. I connected the phone via usb to delete from the autostart menu the link to the configuration screen (welcome.exe) but the phone is not deteced by activesync so no way to browse folders on my device or use a program like SOTI to control the ppc. I want to bring it back to life as I know that my files hasn't been deleted. in fact if I press the right soft button I get a menu of a program I put in the ppc and it's not included in the elegance rom so I'm sure my files and my configuration and everything are still there.
if i get a phone call the phone rings (with the default ringtone anyway, but the name of the caller is displayed correctly, that's why I'm sure my device still has all my contacts and more)
what could I do?
is there a way to edit files from bootloader? does mtty work for this? (I have no idea how to use mtty so I might be wrong) could I make a full dump, edit the startup folder and reflash the phone with all my data?
I tried to use mortscript witht the autorun feature to read a part of the register regarding the welcome file and deleting it's link in the startup folder but the sd card driver is not loaded I think as the files are not launched, while in another phone the same script works fine.
thanks in advance to all who will have time and will to help me
pcwizzul
as far as i know (not that much), reading files from bootloader is pretty impossible.
You can always just reflash. If the touchscreen problem persists, it's possible that the problem is hardware related.
Your computer should detect your device when in bootloader, and failing that, you should be able to SD flash (assuming you're HardSPL'd or equivalent, thats just what we have in the herald forum)
Thanks for your help
I'm quite sure the hardware is fine as all my problems started after a crash of the OS.
Anyone has an idea to get access to my ppc?
pcwizzul said:
Hi to all! I installed a new cooked great rom to my trinity a month ago and it worked fine. it is this rom
[ROM][ITA]WM 6.1 Elegance edition 2.14 (OS 5.2.19213 Build 19213.1.0.0)[ONLINE]
today I got a strange error and the phone was stuck. I unplugged the battery and when I started again it was stuck on the calibration screen. if I tap on the screen nothing happens but the backlight turns on if it was off so it still catches the taps. I connected the phone via usb to delete from the autostart menu the link to the configuration screen (welcome.exe) but the phone is not deteced by activesync so no way to browse folders on my device or use a program like SOTI to control the ppc. I want to bring it back to life as I know that my files hasn't been deleted. in fact if I press the right soft button I get a menu of a program I put in the ppc and it's not included in the elegance rom so I'm sure my files and my configuration and everything are still there.
if i get a phone call the phone rings (with the default ringtone anyway, but the name of the caller is displayed correctly, that's why I'm sure my device still has all my contacts and more)
what could I do?
is there a way to edit files from bootloader? does mtty work for this? (I have no idea how to use mtty so I might be wrong) could I make a full dump, edit the startup folder and reflash the phone with all my data?
I tried to use mortscript witht the autorun feature to read a part of the register regarding the welcome file and deleting it's link in the startup folder but the sd card driver is not loaded I think as the files are not launched, while in another phone the same script works fine.
thanks in advance to all who will have time and will to help me
pcwizzul
Click to expand...
Click to collapse
if the sdcarddriver is not loaded then the following will not work but give it a try anyways. make a text file "whatever.txt" no quotes then rename it to "welcome.not" no quotes then put it in the root of your storage card and it should skip the whole startup process. that is if it loads the sd card driver or you might want to think about flashing another rom
I already tried the "welcome.not" trick but got no results. I'm afraid that the sd card driver is not loaded then.
Thanks for the hint irus anyway!
Really there's no way to read files from bootloader or something similar?
not that i know of
but the fact that your issue was noticed during a rom flash
dont mean it's not hardware related
much like a heart attack which happens during a thunderstorm
dont need be related to the thunderstorm
Wait! The error never happened during a flash. I never said it. I had that rom on my trinity since a month and it worked like a charm. Then suddenly I got an error and the phone was stuck.
I have understood what you mean but at least I hope it's not a hardware failure!
I can say that my Diamond jailbreak the PS3 at first boot "everytime".
I use HERMES V4 and OPEN MANAGER 2.1
The solution that I found is simple (with XDAndroid 2.2 RC 2.1 + System RC 2.2).
The first time:
-check to have replace zImage
-check to have put modules-2.6.27.46-01162-g741ab49-dirty.tar.gz in the directory of xdandroid (delete the old modules)
-put psfreedom.ko in the root of memory
-download payload from attachment
-put payload_hermesV4.bin in the root of memory
-overclock the phone (in startup.txt add inside "set cmdline": acpuclock.oc_freq_khz=680000) or download my STARTUP.TXT from attachment (only DIAM100)
-edit "froyo.user.conf" in the conf directory and replace the section "# custom shell commands, these commands run last" with this:
# custom shell commands, these commands run last
custom_shells{
rm -f /sdcard/fsck*.rec
echo ""
echo ""
echo "*************************************"
echo "*************************************"
echo "******D i s c o n n e c t ****** U S B ******"
echo "*************************************"
echo "*************************************"
echo ""
echo ""
sleep 3
insmod /sdcard/psfreedom.ko
sleep 2
echo "**********************************"
echo "**********************************"
echo "********P a y l o a d ****************"
echo "**********************************"
echo "**********************************"
cat /sdcard/payload_hermesV4.bin > /proc/psfreedom/payload
}
or download my conf file from attachment and put the file in the conf directory (only DIAM100)
-launch haret with USB connected to PC
-disconnect cable when the message "Disconnect USB from PC" is display
-put the phone to airplane mode
-install Advanced Task Killer Free (ATK)
-launch ATK
-change setting and set security to LOW (kill more application)
-kill all application (after I have 50Mb free)
-connect to PS3
jailbreak in normal way
The next time you just:
-launch haret with USB connected to PC
-disconnect cable when the message "Disconnect USB from PC" is display
-launch ATK and kill all application
-connect PS3
jailbreak in normal way
I hope this can help everyone who jailbreak with Diamond
UPDATE(only for DIAM100):
The STARTUP.TXT attached contains my path.
Change the name of the directory: "rel_path=your directory"
EXAMPLE: "rel_path=andboot"
HELP1:
If you don't have 50 Mb of free memory from ATK try:
-remove all widget from all the android desktop
-set as background of the desktop a simple color (not an image)
-disable the animation of the video (in the configuration of android you can find video option)
-etc... (all other simple procedure to free more memory)
HELP2:
If you don't find where to set security level LOW:
-open ATK
-press HOME button
-press Setting
-press Security Level
-select Low
-press BACK button (turn back)
-press BACK button (turn back)
-KILL selected apps
I have more than 50Mb free after this operation.
ALL-IN ONE solution: (thanks to Gonsi)
HTC_Diamond_PSFreedom_Hermes_V4b.rar
All-In-One Solution: PSFreedom 3.41 v1.3.1 PL3 Hermes v4b with PSN Patch
HTC_Diamond_PSFreedom_3.41_v1.3.1_Hermes_V4b_PSN_Patch.rar
Download this file and decompress it on your root.This file contains already ALL that you need.(include HermesV4)
It is ready for Diam100.
Change the startup.txt file if you have other phone.
NB: If you change the startup.txt file remember to edit it to set rel_path=xdandroid
Last payload:
For the last payload visit the HTC HERO psfreedom wiki page
Download the payload that you want and then change the conf file to load it (replace payload_hermesV4.bin with the name of the new payload)
Good day.
Works great!
Great solution, i tried a similar procedure (by me) but yours is great!
Now I've only the same problem as described in other post.
When i try to load backup of my game (original) from an external disk (2,5"), it returns always on xmb and not load nothing.
Any idea?
worked first time for me too, i've got psfreedom auto loading in the init file, so all you have todo is kill apps and jail break.
[one thing left to try is set ATK to autoload and set it to aggressive autokill and hopefully all you'll need todo is boot into andriod and jailbreak.] - scratch this bit as auto kill smallest interval is 30 mins
edit: tried a second time and the jailbreak didn't work first time... actually tried several times and then eventually rebooted phone and tried again, worked on second attempt (got unknown usb device on first try)
Ok, now works perfect.
It was an hard disk problem (external 2.5" samsung model 0804h hd 80gb), it is not fully supported.
Now i use another hard disk and it works
zulm said:
worked first time for me too, i've got psfreedom auto loading in the init file, so all you have todo is kill apps and jail break.
[one thing left to try is set ATK to autoload and set it to aggressive autokill and hopefully all you'll need todo is boot into andriod and jailbreak.] - scratch this bit as auto kill smallest interval is 30 mins
edit: tried a second time and the jailbreak didn't work first time... actually tried several times and then eventually rebooted phone and tried again, worked on second attempt (got unknown usb device on first try)
Click to expand...
Click to collapse
control the memory free (on ATK)
I have 50Mb and I jailbreak everytime at first boot
I did also:
-in settings/display disable all effect
-in desktop load like background a single color (and not a picture)
-remove ALL the gadget from all the desktop
...
it works great
ATTENTION: Autoload psfreedom.ko
I think that initrd.gz is not the right place where insert the insmod command.
Try to edit "froyo.user.conf" in the conf directory and insert in the section # custom shell commands, these commands run last
insmod /sdcard/psfreedom.ko
obviously before the } that end the list of commands...
You must have something like
# custom shell commands, these commands run last
custom_shells{
rm -f /sdcard/fsck*.rec
insmod /sdcard/psfreedom.ko
}
This for two reasons:
1.is more simple to modify (is a plain text file in XDAndroid directories, so you don't need Linux)
2.you load the module "after" the other modules that psfreedom.ko need
Now I am at work, I will try this solution this afternoon... but if someone can test... is simple to modify the conf file.
EDIT:
Ok, it works
You can edit the conf file and then when xdandroid boot you have only to launch ATK and kill all application
@bastard: You're spreading FUD. PSF module does not depend on any module which is loaded in conjunction with XDandroid. Why are you claiming this?
And you consider booting a full blown OS (which IS Linux by the way), installing apps and configuring a lot of other stuff more simple than booting another Linux (or just using your main OS if it's Linux compatible) and modify initrd once?
Anyway, have a good day!
Chatty said:
@bastard: You're spreading FUD. PSF module does not depend on any module which is loaded in conjunction with XDandroid. Why are you claiming this?
Click to expand...
Click to collapse
PSfreedom depend on the modules that you load on boot.
In particolary g_android.ko that enable debugging via USB
This is why on the psfreedom procedure you find to "copy" the modules in xdandroid directory
Now, i don't know if you have to load before or after...
But the psfreedom procedure say to load psfreedom.ko in terminal so I think this is the right order:
1.modules
2.psfreedom.ko
in this way it work... in the other... i don't know
Chatty said:
And you consider booting a full blown OS (which IS Linux by the way), installing apps and configuring a lot of other stuff more simple than booting another Linux (or just using your main OS if it's Linux compatible) and modify initrd once?
Anyway, have a good day!
Click to expand...
Click to collapse
I didn't say this...
I think (and wrote) that is "more simple" to modify a text file (the conf file) directly on phone rather than copy initrd.gz, boot to Linux, expand initrd.gz, edit init file, recompile to initrd.gz and then put it again on phone ONLY to autoload psfreedom on startup... (and allways do the rest of stuff)
Then I think (and wrote) that to have the order 1.modules 2.psfreedom.ko
modify the conf is better than modify initrd.gz
I don't understand why you have to enter into a debate...
if you don't like my procedure... use another.
Anyway, have a good day!
2 issues.
-overclock the phone (in startup.txt put the line acpuclock.oc_freq_khz=700000)
I can't put 700000, the phone crash when I start Android, I can put 680000, but no more.
-change setting and set security to LOW (kill more application)
I don't understand this, how can I change this setting?
I've tried the trick and it works like before for me, not better...
sexto said:
2 issues.
-overclock the phone (in startup.txt put the line acpuclock.oc_freq_khz=700000)
I can't put 700000, the phone crash when I start Android, I can put 680000, but no more.
Click to expand...
Click to collapse
I use 700000 and works fine for me, but I think it's normal... on the xdandroid you can find:
Overclocking
acpuclock.oc_freq_khz=XXXXXX ( i personally use 600000-640000 )
but it very unstable if you try to get higher than 650000-700000
Use the value that works for you.
sexto said:
2 issues.
-change setting and set security to LOW (kill more application)
I don't understand this, how can I change this setting?
I've tried the trick and it works like before for me, not better...
Click to expand...
Click to collapse
-open ATK
-press HOME button
-press Setting
-press Security Level
-select Low
-press BACK button (turn back)
-press BACK button (turn back)
-KILL selected apps
I have more than 50Mb free
With this I jailbreak every time at first time.
Have you change the phone to airplane mode? It use less cpu...
Yeah.
I have done the security think and now yes, it always works, at the moment, I've tried twice, but works both.
Thanks for the trick, you are my hero!!
By the way, I am spanish, it's possible that I wrote some word or sentence incorrectly, but I try do it well ^^
could someone upload these modified files? i can't find in my phone,thanks
I did everything you said but still it doesnt run every time on first boot it takes like 5 to 10 times to boot
any new version psfreedom for openmanager v1.13?
That would be awesome
agreed, I really want no bluray disc needed.
Also with the hermes payload, they will eventually create some custom firmware, no more psfreedom!
Thank you for opening this thread! But...
I did everything u recommended but still receiving the "unknown USB device connected". So, the same problem persists: It only works after the first boot!
Any other suggestions so we can solve the diamond problem once for all?
PS: PS3 jailbreak USBs are not available in my country so i have to count on the diamond jailbreak
UPDATE 1: After switching to Windows mobile--->Reconnect to PC in active sync mode--->Disconnect when the message appears--->Connect to PS3 and apply Jailbreak! It REALLY WORKS!
Do Note that using HTC Diamond is tricky when it comes to Jailbreaking the PS3 since it's not 100% compatible So take real care of the time between the power and eject buttons: YOU SHOULD WAIT LIKE 1/2 A SECOND TO PRESS THE EJECT AFTER THE POWER & IT WILL WORK WITH A RATE OF 1 OVER 2
UPDATE 2 : After Rebooting the phone from Win Mobile to Android (While connected to PC) if the JB doesn't work with the error "Unknown USB device connected", Just shut down the phone, reboot in win mobile reconnect to PC and boot back to Android then try again it should work!
Hope this helps!
Recheck procedure
codvisp said:
I did everything u recommended but still receiving the "unknown USB device connected". So, the same problem persists: It only works after the first boot!
Any other suggestions so we can solve the diamond problem once for all?
PS: PS3 jailbreak USBs are not available in my country so i have to count on the diamond jailbreak
UPDATE 1: After switching to Windows mobile--->Reconnect to PC in active sync mode--->Disconnect when the message appears--->Connect to PS3 and apply Jailbreak! It REALLY WORKS!
Do Note that using HTC Diamond is tricky when it comes to Jailbreaking the PS3 since it's not 100% compatible So take real care of the time between the power and eject buttons: YOU SHOULD WAIT LIKE 1/2 A SECOND TO PRESS THE EJECT AFTER THE POWER & IT WILL WORK WITH A RATE OF 1 OVER 2
UPDATE 2 : After Rebooting the phone from Win Mobile to Android (While connected to PC) if the JB doesn't work with the error "Unknown USB device connected", Just shut down the phone, reboot in win mobile reconnect to PC and boot back to Android then try again it should work!
Hope this helps!
Click to expand...
Click to collapse
I reply to you, but it's ok for everyone who have some troubles:
-you don't need to reboot to windows mobile
-you don't need to reboot the phone
If you have "unknown USB device connected" simply retry the jailbreak (leave the phone connect to PS3).
NOW
For my procedure...
It works ALLWAYS at first boot (not AFTER first boot)
If you have some problem check all the step, particolary:
-overclock (700000 or 680000 works fine, try which one works for you)
-phone in airplane mode
-security level LOW in ATK
-memory after kill all the application MUST be more than 50Mb
If you don't have this value of free memory try:
-remove all widget from all the android desktop
-set as background of the desktop a simple color (not an image)
-disable the animation of the video (in the configuration of android you can find video option)
-etc... (all other simple procedure to free more memory)
I wrote this guide becouse I NEVER try two time to jailbreak my PS3 after this trick... NEVER
So, eventually you can try different timing from press Power button and Eject button, but the REAL problem is the free memory and the speed of Diamond.
So I suggest:
- re-check the speed of overclock (try 680000 maybe is more stable)
- re-check alll the step of my guide
- re-check this list of trick to free more memory
I hope to help everyone with DIAMOND (DIAM100)
bastardociccio said:
I reply to you, but it's ok for everyone who have some troubles:
-you don't need to reboot to windows mobile
-you don't need to reboot the phone
If you have "unknown USB device connected" simply retry the jailbreak (leave the phone connect to PS3).
NOW
For my procedure...
It works ALLWAYS at first boot (not AFTER first boot)
If you have some problem check all the step, particolary:
-overclock (700000 or 680000 works fine, try which one works for you)
-phone in airplane mode
-security level LOW in ATK
-memory after kill all the application MUST be more than 50Mb
If you don't have this value of free memory try:
-remove all widget from all the android desktop
-set as background of the desktop a simple color (not an image)
-disable the animation of the video (in the configuration of android you can find video option)
-etc... (all other simple procedure to free more memory)
I wrote this guide becouse I NEVER try two time to jailbreak my PS3 after this trick... NEVER
So, eventually you can try different timing from press Power button and Eject button, but the REAL problem is the free memory and the speed of Diamond.
So I suggest:
- re-check the speed of overclock (try 680000 maybe is more stable)
- re-check alll the step of my guide
- re-check this list of trick to free more memory
I hope to help everyone with DIAMOND (DIAM100)
Click to expand...
Click to collapse
It is WORKING with a 99% rate!
1. The Overclocking to 7,000 is working at its best.
2. I am not using ATK.
3. Phone in airplane mode is a must, i agree.
4. Disabling the animation is a must also.
5. I need to boot in WinMobile so i can use my phone normally...
6. I really noticed that one of the most important points is: the lapse of time between the Power & Eject buttons. It has to be larger than other devices at 1/2 sec. aprox. (as compared to HTC HD2 or others...)
Regards
codvisp said:
It is WORKING with a 99% rate!
1. The Overclocking to 7,000 is working at its best.
2. I am not using ATK.
3. Phone in airplane mode is a must, i agree.
4. Disabling the animation is a must also.
5. I need to boot in WinMobile so i can use my phone normally...
6. I really noticed that one of the most important points is: the lapse of time between the Power & Eject buttons. It has to be larger than other devices at 1/2 sec. aprox. (as compared to HTC HD2 or others...)
Regards
Click to expand...
Click to collapse
if you don't use ATK, you don't use my procedure!
Try to use ATK and it will work with 100% rate!
I repeat that timing between power and eject is less important...
Try ATK and then you never try two time!!!
(ATK free that you can download free on the internet. You can put the apk directly on xdandroid directory and it autoinstall )
htcinho said:
Works great!
Great solution, i tried a similar procedure (by me) but yours is great!
Now I've only the same problem as described in other post.
When i try to load backup of my game (original) from an external disk (2,5"), it returns always on xmb and not load nothing.
Any idea?
Click to expand...
Click to collapse
Try deleting Backup Manager and reinstalling. I had the same problem and that worked for me. Good luck.
I was posting some questions in the "Rooted Jeep Cherokee '14 Uconnect" thread but I've started this new thread for the 17.xx versions because the methods (if we are able to identify them) aren't the same as the 16.33.29 and earlier firmwares...
I am still trying to crack into that unit with the 17.11.07 software. I have a D-Link USB Ethernet but its a HW revision D and I believe I would need a B if we can get ethernet enabled at all.
Also, if we can get Ethernet enabled we will still need to get SSH password or key.
devmihkel said:
For good or for bad NOT everything appears correct, except the running 17.x version... As of now neither the "commercial jailbreak" supports new versions (well yes they were using exactly the same file to start with Also 16.51.x or newer appears to be no go: uconnect-8-4-8-4an-update
EDIT: haven't got 17.09.07 to try, but on 17.11.07 manifest.lua has changed and the last block/ search keyword is "ota_update" instead. Otherwise all the same, image valid after the edit and script.sh gets fired - at least on 16.33.29 that is @HanJ67 Did you actually try to mount installer.iso after the edit and checked /etc/manifest.lua for the end result before?
Click to expand...
Click to collapse
devmihkel said:
Yeah, 2nd attempt is much better as last lua block is correctly terminated and your script might actually run, but unfortunately no successful 17.x runs have been reported so far SWF scripts are not involved in update/jail-breaking run, these ones become relevant only once you are in (and need to enable some app or wifi or navi features etc). Afaik 17.x blocks ethernet dongle usage as well, but let's see if even the USB driver/link gets activated at all?
Click to expand...
Click to collapse
Do you have a 16.33.29 version I can try this on? I'm wondering if it will get me far enough to execute the "manifest.lua HD_Update" hack you and @HanJ67 were discussing.
I've used the 17.43.01, then finally found a 17.11.07 and had no luck there either.
In my latest attempts on the 17.11.07, I was able to hex edit the "ifs-cmc.bin" on the UPD and replaced the SSH-RSA key with my own. I think this bin will be flashed to the MMC during an update.
That SWDL.UPD got past the initial check and rebooted into update mode, but then it fails the second ISO check and loops. I had to use an unmodified image to finish the update and get back up and running.
I keep reading about making changes only after the 2048 Byte mark in the older versions with the "S" at 0x80. Is this still relevant
in later ISO/UPD images and to the second ISO check?
Right now, I'm looking to find a way to disable that check so that my modified .bin will be written to disk? I think this route would work to also modifying and getting WiFi enabled after a flash of the edited image.
If I had I 16.33.29 or similar older UPD version to attempt the HD_UPDATE hack in the Manifest.lua file I would give that a shot to be thorough.
Do You have an idea how to connect by USB2LAN adapter to uConnect ?
Do You know if there is an UART pins on the mainboard ?
itsJRod said:
I was posting some questions in the "Rooted Jeep Cherokee '14 Uconnect" thread but I've started this new thread for the 17.xx versions because the methods (if we are able to identify them) aren't the same as the 16.33.29 and earlier firmwares...
I am still trying to crack into that unit with the 17.11.07 software. I have a D-Link USB Ethernet but its a HW revision D and I believe I would need a B if we can get ethernet enabled at all.
Also, if we can get Ethernet enabled we will still need to get SSH password or key.
Do you have a 16.33.29 version I can try this on? I'm wondering if it will get me far enough to execute the "manifest.lua HD_Update" hack you and @HanJ67 were discussing.
I've used the 17.43.01, then finally found a 17.11.07 and had no luck there either.
In my latest attempts on the 17.11.07, I was able to hex edit the "ifs-cmc.bin" on the UPD and replaced the SSH-RSA key with my own. I think this bin will be flashed to the MMC during an update.
That SWDL.UPD got past the initial check and rebooted into update mode, but then it fails the second ISO check and loops. I had to use an unmodified image to finish the update and get back up and running.
I keep reading about making changes only after the 2048 Byte mark in the older versions with the "S" at 0x80. Is this still relevant
in later ISO/UPD images and to the second ISO check?
Right now, I'm looking to find a way to disable that check so that my modified .bin will be written to disk? I think this route would work to also modifying and getting WiFi enabled after a flash of the edited image.
If I had I 16.33.29 or similar older UPD version to attempt the HD_UPDATE hack in the Manifest.lua file I would give that a shot to be thorough.
Click to expand...
Click to collapse
Hello, any news about it?
hi,
can you explain how to change SSH key in "ifs-cmc.bin" file?
thanks a lot
itsJRod said:
I was posting some questions in the "Rooted Jeep Cherokee '14 Uconnect" thread but I've started this new thread for the 17.xx versions because the methods (if we are able to identify them) aren't the same as the 16.33.29 and earlier firmwares...
I am still trying to crack into that unit with the 17.11.07 software. I have a D-Link USB Ethernet but its a HW revision D and I believe I would need a B if we can get ethernet enabled at all.
Also, if we can get Ethernet enabled we will still need to get SSH password or key.
Do you have a 16.33.29 version I can try this on? I'm wondering if it will get me far enough to execute the "manifest.lua HD_Update" hack you and @HanJ67 were discussing.
I've used the 17.43.01, then finally found a 17.11.07 and had no luck there either.
In my latest attempts on the 17.11.07, I was able to hex edit the "ifs-cmc.bin" on the UPD and replaced the SSH-RSA key with my own. I think this bin will be flashed to the MMC during an update.
That SWDL.UPD got past the initial check and rebooted into update mode, but then it fails the second ISO check and loops. I had to use an unmodified image to finish the update and get back up and running.
I keep reading about making changes only after the 2048 Byte mark in the older versions with the "S" at 0x80. Is this still relevant
in later ISO/UPD images and to the second ISO check?
Right now, I'm looking to find a way to disable that check so that my modified .bin will be written to disk? I think this route would work to also modifying and getting WiFi enabled after a flash of the edited image.
If I had I 16.33.29 or similar older UPD version to attempt the HD_UPDATE hack in the Manifest.lua file I would give that a shot to be thorough.
Click to expand...
Click to collapse
sofro1988 said:
Hello, any news about it?
Click to expand...
Click to collapse
I have not had had much time to work on this.
I actually had an idea last week that brought me back to this. I plan to use a custom flash drive to present an unmodified ISO for verification, then swap nand to an identical image that has been he's edited to enable usb Ethernet and add a custom key for ssh access.
I thought to stack a NAND on top of the original on a is flash drive, then breakout the Chip Enable pin to a switch. I've seen this done for with guys modifying game consoles to be able to run modified firmware.
Once the 2nd NAND is in place I will restore an image of the original nand containing the unmodified update, then hex edit the required portions to allow access after updating.
If this method works, I should be able to pass the verification with the original nand chip, then switch it (hopefully there's a big enough window to do this by hand) then present the modified nand before it begins the flash procedure.
Hopefully someone more intimately familiar with the update scripts can verify I'm not missing anything in the process
Tajadela said:
hi,
can you explain how to change SSH key in "ifs-cmc.bin" file?
thanks a lot
Click to expand...
Click to collapse
I used a hex editor to find the Ssh RSA key and replace it. This passed the initial check to reboot into update mode, but wouldn't pass the full check in update mode. I'm hoping my attempt below will pass that check and still update with the modifications.
itsJRod said:
I used a hex editor to find the Ssh RSA key and replace it. This passed the initial check to reboot into update mode, but wouldn't pass the full check in update mode. I'm hoping my attempt below will pass that check and still update with the modifications.
Click to expand...
Click to collapse
thanks for answer.
I saw an ssh key with the hex editor, but I would like to see exactly what you have replaced.
if it's not too much trouble, it would be interesting to see with some screenshots the changes you've made.
So we could work on two fronts. The idea of the double nand is good, but not very simple to make ...
Just thinking out loud here, when you say it passes the initial check, does it then give you any confirmation of that or any message on the screen before rebooting to upgrade mode?
Sent from my CLT-L09 using Tapatalk
SquithyX said:
Just thinking out loud here, when you say it passes the initial check, does it then give you any confirmation of that or any message on the screen before rebooting to upgrade mode?
Sent from my CLT-L09 using Tapatalk
Click to expand...
Click to collapse
I tried much the same thing -- the swdl.upd is another CDROM filesystem:
martinb$ file swdl.upd
swdl.upd: ISO 9660 CD-ROM filesystem data 'CDROM'
It contains three more .iso files : installer.iso, primary.iso, and secondary.iso
installer.iso is a CDROM image, but is not mountable on my linux system
primary.iso is a CDROM image, and has the usual /bin, /etc/, and /usr filesystem for an install
the /bin directory has one file - update_nand
the /etc directory has the usual mfgVersiontxt, nand_partion.txt, system_etfs_postinstall.txt, system_mmc_postinstall.txt and version.txt
the /usr/share directory is all the firmware for various components - EQ, HD_FIRMWARE, IFS, MMC_IFS_EXTENSION,OTA,SIERRA_WIRELESS,V850, and XM_FIRMWARE
What's interesting to me is that they did update the SIERRA_WIRELESS firmware -- and have done some housecleaning:
Code:
#---------------------------------
# sierra_wireless_disable_flowcontrol.file
# \d == 1 second delay
SAY " Send AT \n"
'' AT\r
OK \d
SAY "Disable flow control\n"
'' at+ifc=0,0\r
OK \d
SAY "Send SMS command CNMI\n"
'' at+cnmi=2,1,0,1,0\r
OK \d
SAY "Clear emergency number list\n"
'' AT!NVENUM=0\r
OK \d
SAY "Set emergency number to 911\n"
'' AT!NVENUM=1,"911"\r
OK \d
SAY "Save Setting\n"
'' at&w\r
OK \d
#---------------------------------
Also in the IFS directory, when you hexedit the ifs-cmc.bin file it reveals another little treat... an SSH root public key ( not as nice as a private key, but hey )
(Sorry about the formatting, this is cut/paste right out of the hex editor)
Code:
ssh-rsa [email protected]
2E..IwU.Q....njle8r9nrJ7h8atg4WfqswU0C0Rk/Ezs/sQs5ZA6ES82MQONjHBd7mw
uo8h0xfj3KeeSHMXCEBpmU26guNE4EqfvdioLFCDUxtvMYswlUZjsvd/NYz9lnUZg2hy
pwzFQjXgSzmHVrHjkKKvq7Rak/85vGZrJKxlvHnowA8JIl1tVNVQjPMNgDDJabaETtfw
LL1KlvAzI81cKOG/3IRn9lU6qyYqyG+zYoza0nN\..7/AtxdL481k81Go5c3NQTnkl2U
68lbu8CpnwrYCU098owLmxdI4kF5UOL4R61ItJuwz30JSESgT..!8RDgM6XEiHUpK9yW
vvRg+vbGWT/oQn0GQ== [email protected]
in /usr/share/MMC_IFS_EXTENSION/bin/cisco.sh and dlink.sh there's another good hint - what adapter you need for USB ethernet
Code:
#!/bin/sh
# Handle an Ethernet connection via the CISCO Linksys USB300M adapter
or
Code:
#!/bin/sh
# Handle an Ethernet connection via the D-Link DUB-E100 adapter
The static IP it brings up if no DHCP is offered is : 192.168.6.1
There's tons more in there -- like the V850 chip has access to the Sierra Wireless CDMA modem, but can configure it for voice calls through the car speakers:
"AT!AVSETPROFILE=8,1,1,0,5" ( embedded in the cmcioc.bin update file )
secondary.iso is a CDROM image and only has /etc/ and /usr
the /etc/ directory has speech_mmc_preinstall.txt and xlets_mmc1_preinstall.txt
the /usr/ directory has /usr/share/speech and /usr/share/xlets ( tons of information about sensors in the car, etc in xlets )
martinbogo1 said:
I tried much the same thing -- the swdl.upd is another CDROM filesystem:
martinb$ file swdl.upd
swdl.upd: ISO 9660 CD-ROM filesystem data 'CDROM'
It contains three more .iso files : installer.iso, primary.iso, and secondary.iso
installer.iso is a CDROM image, but is not mountable on my linux system
primary.iso is a CDROM image, and has the usual /bin, /etc/, and /usr filesystem for an install
the /bin directory has one file - update_nand
the /etc directory has the usual mfgVersiontxt, nand_partion.txt, system_etfs_postinstall.txt, system_mmc_postinstall.txt and version.txt
the /usr/share directory is all the firmware for various components - EQ, HD_FIRMWARE, IFS, MMC_IFS_EXTENSION,OTA,SIERRA_WIRELESS,V850, and XM_FIRMWARE
What's interesting to me is that they did update the SIERRA_WIRELESS firmware -- and have done some housecleaning:
Code:
#---------------------------------
# sierra_wireless_disable_flowcontrol.file
# \d == 1 second delay
SAY " Send AT \n"
'' AT\r
OK \d
SAY "Disable flow control\n"
'' at+ifc=0,0\r
OK \d
SAY "Send SMS command CNMI\n"
'' at+cnmi=2,1,0,1,0\r
OK \d
SAY "Clear emergency number list\n"
'' AT!NVENUM=0\r
OK \d
SAY "Set emergency number to 911\n"
'' AT!NVENUM=1,"911"\r
OK \d
SAY "Save Setting\n"
'' at&w\r
OK \d
#---------------------------------
Also in the IFS directory, when you hexedit the ifs-cmc.bin file it reveals another little treat... an SSH root public key ( not as nice as a private key, but hey )
(Sorry about the formatting, this is cut/paste right out of the hex editor)
Code:
ssh-rsa [email protected]
2E..IwU.Q....njle8r9nrJ7h8atg4WfqswU0C0Rk/Ezs/sQs5ZA6ES82MQONjHBd7mw
uo8h0xfj3KeeSHMXCEBpmU26guNE4EqfvdioLFCDUxtvMYswlUZjsvd/NYz9lnUZg2hy
pwzFQjXgSzmHVrHjkKKvq7Rak/85vGZrJKxlvHnowA8JIl1tVNVQjPMNgDDJabaETtfw
LL1KlvAzI81cKOG/3IRn9lU6qyYqyG+zYoza0nN\..7/AtxdL481k81Go5c3NQTnkl2U
68lbu8CpnwrYCU098owLmxdI4kF5UOL4R61ItJuwz30JSESgT..!8RDgM6XEiHUpK9yW
vvRg+vbGWT/oQn0GQ== [email protected]
in /usr/share/MMC_IFS_EXTENSION/bin/cisco.sh and dlink.sh there's another good hint - what adapter you need for USB ethernet
Code:
#!/bin/sh
# Handle an Ethernet connection via the CISCO Linksys USB300M adapter
or
Code:
#!/bin/sh
# Handle an Ethernet connection via the D-Link DUB-E100 adapter
The static IP it brings up if no DHCP is offered is : 192.168.6.1
There's tons more in there -- like the V850 chip has access to the Sierra Wireless CDMA modem, but can configure it for voice calls through the car speakers:
"AT!AVSETPROFILE=8,1,1,0,5" ( embedded in the cmcioc.bin update file )
secondary.iso is a CDROM image and only has /etc/ and /usr
the /etc/ directory has speech_mmc_preinstall.txt and xlets_mmc1_preinstall.txt
the /usr/ directory has /usr/share/speech and /usr/share/xlets ( tons of information about sensors in the car, etc in xlets )
Click to expand...
Click to collapse
Have you tried connecting to it?
Sent from my iPhone using Tapatalk
sofro1988 said:
Have you tried connecting to it?
Sent from my iPhone using Tapatalk
Click to expand...
Click to collapse
I managed to connect with the cisco adapter (usb / ethernet), but I don't know the root password. is the problem at the moment insurmountable ..
Using a cisco connector, I have gotten the ethernet to come up, but that's it. At the moment, there doesn't seem to be anything I can connect to.
@Tajadela - sounds like you at least were able to either SSH or telnet in to a port... I'm on software version 17.43.01 .. which are you on, and what year vehicle? ( Jeep Grand Cherokee, 2015, Uconnect 8.4AN with the 3G Sierra Aircard modem for Sprint )
martinbogo1 said:
Using a cisco connector, I have gotten the ethernet to come up, but that's it. At the moment, there doesn't seem to be anything I can connect to.
@Tajadela - sounds like you at least were able to either SSH or telnet in to a port... I'm on software version 17.43.01 .. which are you on, and what year vehicle? ( Jeep Grand Cherokee, 2015, Uconnect 8.4AN with the 3G Sierra Aircard modem for Sprint )
Click to expand...
Click to collapse
I connected in telnet on a uconnect 6.5 with firmware 15.xx.xx. You can connect to Uconnect with static IP it brings up if no DHCP is offered is: 192.168.6.1
itsJRod said:
I used a hex editor to find the Ssh RSA key and replace it. This passed the initial check to reboot into update mode, but wouldn't pass the full check in update mode. I'm hoping my attempt below will pass that check and still update with the modifications.
Click to expand...
Click to collapse
after rsa key replaced, do you have recalculate the checksum of UPD file?
have you replaced the first 64 bytes of the file?
thanks
@itsJRod, isn't it that you would like to explain the procedure to replace the RSA key in the swdl file? thank you
Hello,
have you made any progress? I am a bit lost. I put the EU uconnect MY15 to US dodge charger MY16 and Perf Pages were working fine even on 16.16.13, although after upgrade to 17.x (17.46.0.1 right now) I am meeting the problem of expired subscription (which is not possible to have on EU radio).
I am considering basically three solutions:
a) going back to US radio, but modify the language pack/nav/FM frequencies (it is doable, but I do not know how, although I can pay for it relatively less than time invested)
b) downgrade to 16.16.13 - I have no clue how to do it, I tried to put swdl.upd with swdl.iso as and installer.iso with no luck of course.
c) take xlets from KIM2/ of 16.16.13 to KIM23 of 17.46.0.1 secondary.iso - this is probably preferred way but I do not know how to make it to pass ISO validation.
Of course root on uconnect is extremely nice to have but I will be fully satisfied with Perf Pages working again.
Hello.
I'm hoping the community can help me out. I have a RAM 1500 with the RA4 (was running the 17.11.07 software that I got pushed to me OTS style a couple years ago. Since them problems, radio turn on delay, no GPS and cellular phone warning popup.
I was told to do the 18.45 update which I got from driveuconnect.com, but this has essentially bricked my radio with the "bolo update failed" error and it is looping continuously
I have tried many ways to modify the update software's manifest.lua script to try to get rid of the sierra wireless portion by manually editing, hex editing, etc but always get the "please insert the USB card" screen.
Uconnect is obviously completely worthless to help me and the dealer wants me to pay them money to tell me what I already know. I know I can pay 300 and send my radio to infotainemnt.com to get it repaired, but I would like to solve this on my own is possible, because I would like to further modify the software to make it more custom and unique.
From my reading the 17x version keeps you from downgrading to a version that can be hacked easily.
Everything seems like it should be pretty straight forward as I have a lot of experience in programming and embedded devices.
It seems they are validating the ISOs using some mechanism, I believe I have tried all of tricks/methods
I have searched the code to see if I can find the iso MD5 or SHA256 hashes that ioc_check is probably using to figure out I changed somethign but nothing work.
I have even tried the swapping the flash drives after validation but it seems they are using the ISos they already copied to continue the process, I then end u getting some invalid errors or the update just crashes out
I got other updates from the link: http://www.mydrive.ch/
http://www.mydrive.ch/http://www.mydrive.ch/
username: [email protected]
Password: gasolio
Havent tried all of them yet, but pretty sure they wont work, due to the 17x security changes.
Any help would be appreciated grealty, I really dont want to shell out any cash for something a company told me to to and due to their screw up with bricking modems, this is now bricking my radio.
Thanks to all in advance !!!
djmjr77 said:
Hello.
I'm hoping the community can help me out. I have a RAM 1500 with the RA4 (was running the 17.11.07 software that I got pushed to me OTS style a couple years ago. Since them problems, radio turn on delay, no GPS and cellular phone warning popup.
I was told to do the 18.45 update which I got from driveuconnect.com, but this has essentially bricked my radio with the "bolo update failed" error and it is looping continuously
I have tried many ways to modify the update software's manifest.lua script to try to get rid of the sierra wireless portion by manually editing, hex editing, etc but always get the "please insert the USB card" screen.
Uconnect is obviously completely worthless to help me and the dealer wants me to pay them money to tell me what I already know. I know I can pay 300 and send my radio to infotainemnt.com to get it repaired, but I would like to solve this on my own is possible, because I would like to further modify the software to make it more custom and unique.
From my reading the 17x version keeps you from downgrading to a version that can be hacked easily.
Everything seems like it should be pretty straight forward as I have a lot of experience in programming and embedded devices.
It seems they are validating the ISOs using some mechanism, I believe I have tried all of tricks/methods
I have searched the code to see if I can find the iso MD5 or SHA256 hashes that ioc_check is probably using to figure out I changed somethign but nothing work.
I have even tried the swapping the flash drives after validation but it seems they are using the ISos they already copied to continue the process, I then end u getting some invalid errors or the update just crashes out
I got other updates from the link: http://www.mydrive.ch/
http://www.mydrive.ch/http://www.mydrive.ch/
username: [email protected]
Password: gasolio
Havent tried all of them yet, but pretty sure they wont work, due to the 17x security changes.
Any help would be appreciated grealty, I really dont want to shell out any cash for something a company told me to to and due to their screw up with bricking modems, this is now bricking my radio.
Thanks to all in advance !!!
Click to expand...
Click to collapse
Just to follow up for anyone who reads this in the future.
I was able to get my uconnect working again a few minutes ago.
As my previous post stated I got stuck in the "bolo update failed" loop.
I downloaded the UCONNECT_8.4AN_RA4_16.33.29_MY16.exe update from the url posted in my previous comment.
I did the S Byte HEX Mod to the swdl.iso file, loaded it and the swdl.upd file on a thumb drive. Used Hxd on windows. Followed the section in the Uconnect exploitation PDF:
https://www.google.com/url?sa=t&source=web&rct=j&url=http://illmatics.com/Remote%2520Car%2520Hacking.pdf&ved=2ahUKEwjZsOGNl5nyAhWhGVkFHZy2AnAQFnoECAcQAg&usg=AOvVaw0NAi3a1eh-IRd3n1VHv-ys
When I plugged it in, it started with the update process, after the first unit, the screen said the Uconnect had to restart, please wait..
And whalaa my radio worked again!!! It even says it has the 18.45 firmware on it.. go figure.. Navigation still does not work, but thats most likely because the sierra wireless card is bad.
I cannot say for sure the S Byte thing did anything, because I'm not messing with this anymore, almost had to buy a new radio.
I would say try it with out, then with it if it doesn't work.
This could also be a fluke with my particular unit, but at least its something else to try than pay 600+ dollars!!
Good luck to anyone else who goes through this mess!!!
djmjr77 said:
Just to follow up for anyone who reads this in the future.
I was able to get my uconnect working again a few minutes ago.
As my previous post stated I got stuck in the "bolo update failed" loop.
I downloaded the UCONNECT_8.4AN_RA4_16.33.29_MY16.exe update from the url posted in my previous comment.
I did the S Byte HEX Mod to the swdl.iso file, loaded it and the swdl.upd file on a thumb drive. Used Hxd on windows. Followed the section in the Uconnect exploitation PDF:
https://www.google.com/url?sa=t&source=web&rct=j&url=http://illmatics.com/Remote%2520Car%2520Hacking.pdf&ved=2ahUKEwjZsOGNl5nyAhWhGVkFHZy2AnAQFnoECAcQAg&usg=AOvVaw0NAi3a1eh-IRd3n1VHv-ys
When I plugged it in, it started with the update process, after the first unit, the screen said the Uconnect had to restart, please wait..
And whalaa my radio worked again!!! It even says it has the 18.45 firmware on it.. go figure.. Navigation still does not work, but thats most likely because the sierra wireless card is bad.
I cannot say for sure the S Byte thing did anything, because I'm not messing with this anymore, almost had to buy a new radio.
I would say try it with out, then with it if it doesn't work.
This could also be a fluke with my particular unit, but at least its something else to try than pay 600+ dollars!!
Good luck to anyone else who goes through this mess!!!
Click to expand...
Click to collapse
I created an account just to reply to this and All I have to say is you're literally an absolute life saver. I've been working on this every day for two weeks now, trying every trick people said, trying every USB, every format, every version and nothing ever worked from me. Uconnect support was absolutely no help and it was a lot of back-and-forth finger pointing and no you need to reach out to this person between them and the dealership. Dealership tried to charge me for a Proxy Alignment when I asked to just update my damn radio stuck in this loop.
I have a 2015 Jeep Cherokee 8.4AN VP4 NA Head Unit 68238619AJ. I was updating from 17.11.07 to 18.45.01 and got stuck at the step 11 1% and would get a failed sierra wireless every time and then got in that "bolo update failed" loop..Well to fix it just now all I did was download the UCONNECT_8.4AN_RA4_16.33.29_MY16.exe update from the url posted in the previous comment and quick format to FAT32 on a 16GB Micro Center USB extracted the files from 16.33.29 to the USB with 7ZIP, plugged in like normal and BOOM it ran the first step restarted and I had a working radio again showing update 18.45.01.
(So i'm assuming you don't have to do the S Byte thing I didn't even mess with it I just used the 16.33.29 to bypass step 11 since that version only has 14 steps and 18.45.01 was already preloaded from attempting before. My navigation still is the wrong address but I don't care about all that just thankful to have my radio back before my wife killed me for trying to update it by myself. )
I hope this helps someone else one day because it took some deep research and hours on hours of forum hoping to finally find the solution. <3
djmjr77 said:
Just to follow up for anyone who reads this in the future.
I was able to get my uconnect working again a few minutes ago.
As my previous post stated I got stuck in the "bolo update failed" loop.
I downloaded the UCONNECT_8.4AN_RA4_16.33.29_MY16.exe update from the url posted in my previous comment.
I did the S Byte HEX Mod to the swdl.iso file, loaded it and the swdl.upd file on a thumb drive. Used Hxd on windows. Followed the section in the Uconnect exploitation PDF:
https://www.google.com/url?sa=t&source=web&rct=j&url=http://illmatics.com/Remote%2520Car%2520Hacking.pdf&ved=2ahUKEwjZsOGNl5nyAhWhGVkFHZy2AnAQFnoECAcQAg&usg=AOvVaw0NAi3a1eh-IRd3n1VHv-ys
When I plugged it in, it started with the update process, after the first unit, the screen said the Uconnect had to restart, please wait..
And whalaa my radio worked again!!! It even says it has the 18.45 firmware on it.. go figure.. Navigation still does not work, but thats most likely because the sierra wireless card is bad.
I cannot say for sure the S Byte thing did anything, because I'm not messing with this anymore, almost had to buy a new radio.
I would say try it with out, then with it if it doesn't work.
This could also be a fluke with my particular unit, but at least its something else to try than pay 600+ dollars!!
Good luck to anyone else who goes through this mess!!!
Click to expand...
Click to collapse
Do you have another link to download the UCONNECT_8.4AN_RA4_16.33.29_MY16.exe files? I am trying to help a friend of mine they way this helped me. Thank you again for this!
I recently bought Asus Zenfone, because here in Ukraine is war, so I want small device with Windows (electricity often is off here because rockets fall on our electrric infrastructure etc).
So I've bought Asus Zenfone 2 used (it costed 16,25$). It came without accumulator, and 1/3 screen working. So I went to radio-market to buy new battery, it costed + ~10.25$ + 2,5$ to install battery. Then I've bought new touchscreen for it for ~22,5$, plus payed ~6,25$ to install it. Then around 7,5$ to restore battery connectors (on device and accumulator). So finally it worked, and wanted to see how to install Windows on Zenfone. Sure, if I had possibility to buy anywhere Zenfone better, new, not used, - I'ld do it, but it is not that easily available, just like any other Intel smartphone.
So, I started reading - how to make my device rooted. I don't understand how to get root. I found on wikipedia, that rooting is different from unlocking bootloader, and realized - yes. I need to unlock bootloader, and to boot from external flash-disk and install windows, or at least - new kernel with KVM support. I used pn my Android (non intel) Limbo x86 emulator, it can run some old windows 98 etc, maybe even xp, never win 2000, and if it runs win-7 or win-8 - it is so terribly slow. So I decided to buy Asus Zenfone. As in KVM mode I can send commands to CPU directly, and hope this Windows works much faster than in emulator. I hope just at least to run Windows XP on it, I need to code some C# code, so that Andorid phone is not only for mp3-playing, internet on the go and make calls, but to learn, study and to work. I don't know why Microsot, Intel and other companies don't like Intel CPUs in mobiles. They could do it if they wanted. I like WIndows because most programs are for Windows. And I want desktop x86 windows also on every mobile, intead of all Androids.
Anyway, What I tried to with my Zenfone. I found one amazing experience - that our hero and inspirer (ley God blesses him, maybe he will work in Intel/AMD/Asus/Microsoft etc to make more newer KVM kernels for future x86 phones with windows) - so Ycavan made KVM for Asus Zenfone 2. Great, I've read his thread - https://forum.xda-developers.com/t/...0-with-kvm-bridge-compiled-need-help.3145055/ - completely, with pen and paper writing down important information, downloaded all the files, and decided to start flashing.
I copied them to root of my Zenfone, unpacked tars and converted them into ZIPs. I also unpacked .img files to root of phone (I mean its folder which is visible if I connect it thorught USB, I know it is not "/" root of file system of Andoird, but anyway it is visible even inside CWM... sorry, was visible)...
So, I made some mistakes. I downloaded the kernel, tried to flash it using commands like :
fastboot flash boot boot_fhd_2.19_kvm_bridge_20150710.img
fastboot flash boot boot_fhd_2.19_kvm_bridge_20150714.img
fastboot flash boot boot_fhd_2.19_kvm_bridge_20150717.img
fastboot flash boot boot_fhd_2.20_kvm_bridge_20150820.img
fastboot flash boot boot_2.19_kvm_bridge.img
fastboot flash boot boot_fhd_2.20_kvm_bridge_20150820.img
but non of them produced bootable Zenfone. So I had to revert to previous bootloader using the CWM tool.
In fact I liked this CWM most. I found this thread - https://forum.xda-developers.com/t/...root-ze500-ze550-ze551-temporary-cwm.3114063/
or similar here on forum, and it worked amazingly. I attached Zen-phone to USB, turned it off, then on while pressing, keeping pressed volume-up key, and after Asus logo appeared and some "zzz" vibration, again it blinked and I saw bootloader with Android robot, and possibility to scroll through menu using volume up-down, to choose normal boot, or reboot/power off, or to run restore etc.
For some reason, Restore there not worked. So anyway, I understood that I can use tool like ADB (Android debug bridge) and fastboot to copy new firmwares/kernels/bootloaders etc to it, so I guessed I can do it myself, and was ready for risks... And this what bad can happen - it happened.
So, I runned in CWM - file cai_dat_CWM.bat - which asked to type ACCEPT and then T4, and phone started to go into amazing mode, some "clouds" started appearing on phone, and it loaded into special secret menu, from which I could select what to do next. To me it looked like default boot manager which I wanted to see like in Dos/Windows machines - so I can choose to run into safe mode windows, or set some settings before booting, or even use "reanimator dvd" etc to load Windows and other tools to do partitioning, passwrods recovery etc. So it looked like on desktops, and very nice. I went inside the menu, and found good option to make backup. I did it all. Then in same CWM tool (I think it is called SuperSU for Android), I finally choose to restore bootloader/kernel/boot (custom recovery), and this saved my from bricking the first time after I followed the manual from Ycavan. Well, I know I can read a lot more threads how to do this and that, but there is always risk that something wrong can happen. So I tried to read as much as I could, and follow manuals as precisely as I could understand. But my phone is kind of "bricked".
Now it shows some scfreen like TV which can't catch any tv program. So it is some random colors - see attached picture. It is good that it shows at least this. But in worse situation - it doesn't show anything. So let me tell how I achieved this, and if you can tell me how to avoid this mistake and to recover it. I hope to get help from anyone here who installed KVM kernel(s) and acheieved running Windows on their zenfone 2 (or maybe anyone who has XPerience with other x86 phones may help, or if it is general issue how to unbrick - then also non x86 users please help).
So, CWM made backup, I became more non-scared to make more experiments with firmware. But main problem is that I don't know which firmware to use. I ideally suggested that when I change kernel to KVM-supported from Ycavan - that it will work with my Andorid 5.0 (it was installed when I bought it). So, but unfortunately, after installing any of KVM kernels of Ycavan - I was unable to understand which OS to install, which version. So even I tried to try to flash whole 1GB+ image (I have downloaded UL-Z00A-WW-2.20.40.59-user.zip from official asus.com - https://www.asus.com/ua-ua/supportonly/asus zenfone 2 (ze551ml)/helpdesk_bios/ - but. I was unable to upload it to zenfone (flash it), as it said it is older than installed version.
Anyway, now it doesn't matter as I cannot run into ANdroid at all. Worse - I cannot even get Bootloader working in Android, as I see after turning phone on - only "white screen" with non-working TV-like image (see attached picture of my Zenfone 2).
So, to make this happen, I did this: I found some information about TWRP. I tried to install as recovery tool. Even though it was flashed into mobile, and I installed it from apk from Google-Play, still, I was unable to run it... So then I found even cooler tool - which was too risky to install. I was good, but Andorid stopped running at all.
This tool is called - preroot601. I runned in it preroot.bat, and then it did something similar to CWM, but several times it restartd the phone _ i have added screenshots of how it looked like on PC / Windows. So after several restarts, it did a lot of changes - Android didn't start after it. Phone always was able to start into recovery mode - into TWRP (I downloaded its .img and flased it as recovery for phone). But in TWRP I think I did something wrong. I made backup of all files (syste,, bootloader, everything). I saw it is cool - to see there terminal, ability so set attributes for files, mount partitions ... even USB -hey, can I run from flash-disk? or from external DVD/Bluray which I have in this mode? I have USB-hub, and can connect to it keyboard, mouse, flash-usb, ssd/hdd - all through Microusb-usb adapter and to usb-hub. So what I wanted to do is to try to see flash-disk, mount it on my android zenfone. And then after restart - I had black screen or this 'non-working analog-TV screen when no program/channel/wave is caught for signal"...
So, I don't even understand what I did, and why this all happened, and why I have to do to restore bootloader at least.
My aim is to have KVM enabled in the kernel. I don't mind if it is old Windows like XP working on this Zenfone, but I like windows to be my main OS on every phone which I may use in future (and hope they all be x86-64 and not ARM). So as I don't have Steamdect now (it has also AMD x86 CPU, like Zenfone), I want to do this, achieve it - having Windows on mobile - Zenfone.
I can carry it in pocket everywhere, so why not people like having desktop Windows x86-64 in each and every mobile? Even Lenovo are collaborating with IBM - then why not make also IBM-Mobile / IBM-smartphone, which will also be as good as PC - to unassemble it, change any part like on desktop, why not do it? I think everyone will enjoy it, and it will boost everything to better hights, levels.
So, please. If anyone here has similar experience of going to same screen like I have (see screenshot), or like that - black screen - indeed my device also may not even show any thing - even no ASUS logo, no bootloader (even if I press Volume-UP after powering and after flash it usually showed bootloader with robot - no... not now)...
So I don't see anything on screen of Android Zenfone now. no text, no bootloader, no recovery even - no TWRP menu. I think I am ready to format whole zenfone, and install there maybe some partition manager (like you know there is Partition magic on PCs, when I can split HDD/SSD nto two parts, one for Windows, and say other for Unix - Ubuntu or Android x 86 - all on same physical drive)... So I want some re-partitioning for intern SD memory, and be able to install there some ISOs, say with DOS, Win3.11, win 95, 98, 2000, xp, 7, 8,1 and maybe even 10. But guess last will be slow. I think Windows XP would be ideal OS for my Zenfone, if it can run fast. Win 7/8 maybe will be slow. But for some sceintific aims - like I just write some algorythm in Visual studio, and can do it even in WinXP, so why don't do it on my Zenfone? I don't like many Andorids, as they are not for work much - they are used by many people to play games, watch videos on phones, surf social networks, but not for real work. Real work is usually on WIndows, and no laptop can replace "Windows x86 in pocket" (on mobile). And I wonder why Microsoft develops "Windows for ARM" instead of investing millions into efforts like which Ycavan did - to make Windows run in KVM mode fast on x86 smartphones.
Ok, So, any ideas? What should I do now? I need some special tool to fix my phone first. Fix its loader. I think I need to bypass fastboot.exe restriction, which shows "waiting for device". Command in cmd like this: ADB.exe devices -L --- shows device from time to time - it shows:
c:\adb>adb devices -l
List of devices attached
0123456789ABCDEF device
c:\adb>fastboot flash boot boot_2.19_kvm_bridge.img
< waiting for device >
So, I cannot even flash some recovery device in this way. In devices manager I see "ADB interface" in "USB devices" category in devices treeview. And sometimes Moorefield appears, but with exclaimation mark - I have no idea how to make it disappear. I found here some info that I can install tool - xFSTK_Downloader_v1.7.0.zip - I downloaded it, installe,d but it doesn't run (I have win10 x64bit). hm... And driver required - iSOC_USB_Driver_Setup_v1.2.0.zip - I installed - but nothing.
So, what to do? How to make bootloader appear again? And how to write there prob=per bootloader with KVM kernel, and which firmware to flash so I can use KVM fast there with fast Windows...? Is it possible at all to make it run WIndows natively on Zenfone? or it will always be only in virtual machine inside some ArchLinux or in Limbo x86 on Android?
I read that Ycavan used this ArchLinux, but I don't understand why. Is he installing it over Android? Then also which version he uses? I need to know each and every version whcih he uses to make everything works. I 'ld require all the firmwares which he uses to make it work also - to make some Windows iso run on my Zenfone 2.
Did anyone achieved this successfully, except for Ycavan - to run Windows on Zenfone? Or except for him noone was able to install KVM kernel, and it was similar to mine situation? And maybe this is the reason why manufacturers of phons don't like x86 phones? I don't know. Any ideas?
See screenshots. What to do in this state?
IF anyone can please upload to somewhere whole pack of files ("WIndows on Zenfone starter kit") to make anyone able to just follow instaructions which will work in all cases to install WIndows there like Ycavan has - it would be great. There is lack of more detailed information - which .img files, .zips, firmwares etc, which OSes are supported by Ycavan's KVM kernels?
I have no idea. if anyone passed this path, and achieved Windows on Zenfone, please share your experiences, Ireally need it. Here in Ukraine when electricity disappears almost daily, we need devices like x86 phones almost for everyone. And mo matter if Windows is a bit old. KVM mode I guess must be much faster, almost native speed, so (like on tablet PCs), so please help...
Thank you all in advance, whoever will answer me.
indubhushan said:
c:\adb>adb devices -l
List of devices attached
0123456789ABCDEF device
c:\adb>fastboot flash boot boot_2.19_kvm_bridge.img
< waiting for device >
Click to expand...
Click to collapse
wrong mode. adb is only working in
- normal/boot mode
- recovery mode
fastboot is only working in
- bootloader mode
- fastboot mode
You can see 0123456789ABCDEF device in adb devices, therefore you are either in TWRP or in Android (Win?)
type adb shell and check the prompt is either $ (shell) or # (root shell)
in root shell you can flash partitions from cmd line. you can also reboot into bootloader/fastboot mode from cmd line.
Code:
adb reboot bootloader
I had success in restoring my bootloader (logo with android robot) - I intalled xFSTK, so somehow I had success to make it run, and I added threee files (1, 2, and 4th) and tried to flash it. Phone was visible as Moorefield. Then I tried to use Asus flash tool to flash big RAW image, but for some reason I don't know why - I had even whole day left it to flash, it didn't do the task - Android stopped booting - no logo showing at all - have to use xFSTK to recover. Maybe I use wrong RAW image (from official site it is .zip, so have no idea where to get those raw files).
When try to flash using flashboot - I get error: - flash cmd error.
As for devices list. My device rarely appear there. It may appear for some seconds, and then xfstk can have success to flash it, and maybe even make it runnable into Android robot scren (bootloader).
I am thinking that I need to install maybe ArchLinux, which Ycavan is using, but have no idea where to get RAW file for it, and how to flash it. Maybe some problem with my USB port on old laptop, or maybe even with USB cable (though have few good almost new cables, even new 4Amperes one). So maybe even problem in port of Zenfone itself (to change it). No idea. Because even when I tried to flash it (that huge 1GB file), phone disconnected, or showed "ready for commands", instead of showing process of ownloading RAW image/Android into phone's memory.
Flashboot/adb almost unusable. Well, I'll try, maybe it'll work.
My hope is try to go into CWM, run from it into "secret menu" on phone, and from it - to access internal memory of phone, and restore phone from backup. But when I tried to load into it once - it hanged on "clouds". I don't know...
And I don't think I'm ready now to format internal memory of phone or to repartition. At least I don't have backup on some external card (sd-card) etc.
as for adb. maybe it can't see my device, even if it is "recovery mode" (when see in devices manager in Windows - Moorefield). Now I'm stuck on xFSTK and can't go anywhere further like adding TWRP into phone, or foing into backup/restore menu on phone, and of course there is no Android. Even when I see Android robot (boot menu) - I feel happy, that at least phone shows anything, so at least bootloader workds. Maybe difference is in drivers - when I have Moorefield driver, then maybe it contradicts with Zenfone driver, and I have to reinstall them? Or use other OS? I have dual-boot (two Windowses on my laptop), so maybe I need to use one Windows - to work with Moorefield (xfstk) - when phone is in "worst" situation when no logo shows / no bootloader. And the other Windows I have to run on laptop - with Zenfone driver installed (I think it shows something like Asus device in device manager). But they seem to use contradicting drivers, I am not sure. And maybe it's some problem with my usb ports, but hope no. They seem to be ok... Maybe I'll have to go some day to give phone for diagnostics to repairing center again ;-(