CDMA GSM-Forum
CDMA GSM-Forum heartfelt "welcome" to all visitors.We're very friendly, with any questions or comments you may have. As a visitor, you're not permitted to post comments of your own, but once you've registered with the site by clicking on the word 'Register' , you have full access to the forum. We do not share your information with any other sites! Registration is free and private.. After registering, you'll receive an email, go to your mail-inbox and click the link to activate your account. Your account will then have to be activated by the Forum Administrator.


GSM & CDMA FORUM
 
HomeHome  Portal*Portal*  SearchSearch  Log inLog in  RegisterRegister  



Share
 

 HTI On USB, what this box can do?

Go down 
AuthorMessage
CDMA GSM-Forum
Admin
Admin
CDMA GSM-Forum


HTI On USB, what this box can do? Empty
PostSubject: HTI On USB, what this box can do?   HTI On USB, what this box can do? Empty17/6/2012, 11:36 am

For those who didn't noticed.
HTI can do BACKUP/RESTORE RPL, SX4 AUTH, SUPER SD AUTH, REPAIR SD, BB5 SL3 phones by using only USB cable.

Support USB just like on FBUS for RAPUv1, RAPUv2, BCM21351, RAP3Gv4.


Example, let's play with backup-erase-downgrade.

Step 1.
Connect phone ALIVE to USB. Select phonet device as interface.
Launch Nokia Module, press SCAN

[You must be registered and logged in to see this image.]

!! Make sure flash files are loaded after phone scanned !!

Step 2.
After phone is scanned, Read PM


[You must be registered and logged in to see this image.]

Step 3.
Preceed to Backup RPL


[You must be registered and logged in to see this image.]

Disconnect phone. Close phonet. Choose Nokia USB ROM

Step 4.
Do erase phone.



[You must be registered and logged in to see this image.]

Click ABORT after erasing is done.

That erase file is nasty, will erase the flash chip fully. Applicable for all BB5 single CPU with NAND flash chip.

After this, you will need to close mobileex, and re-open it. Or simply right click on title bar, choose "Restart App"
Now choose USB ROM as interface


:::: Phone is erased. Now flash any version ::::::



Code: MXKEY [MxKey Team HTI PLUS Flasher Interface 0], SN: C0696666
Using device: USB ROM and HTI, FW ver: 00.50, SN: 01001EF9
Connection status: NUSB3XHC:NUSB3HUB::USB 2.00 (High-speed)
Driver: NMWCD, ver: 7.1.32.73
Module ver: 1.0.0.20454(13-03-2012), Library ver: 1.0.0.13962(12-03-2012)
Processing MCU file: rm614__03.35.mcusw
[BB5,XSR 1.6] size: 27.66 MB
Supported Ids: 2200050920030000, 22000509200C0000
Make sure USB cable, Battery and charger are removed from device.
Insert USB cable, Battery back to device(make sure to have fully charged battery).
Insert Charger or Press phone's power button(if flashing doesnt start automatically)
Waiting for USB ROM device ...
CMT SYSTEM ASIC ID: 000000000000000022000509200C0000 [BCM213x1 ver: 1.0]
CMT EM0 ID: 00005361
CMT PUBLIC ID: 0000000000104BBD512FD69E4686046DD0DBD26F
CMT ASIC MODE ID: 00
CMT ROOT KEY HASH: 1B0D74C532CA1C6133940C740E8C786E
CMT ROM ID: DE56D582BDDE7A3A
Loading CMT secondary boot code
SecondaryBoot: BCM21351_usb2nd.fg [BB5] version: 11.14.0 revision: 2.1 size: 0x3940
Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
eBB5ProtocolType: NEW
Secondary boot loaded.
Storage0: 0000 0000 - 0000 0000 type: RAM, asic:CMT
Storage1: FFFF 0000 - 0000 0000 type: MMC, asic:CMT
Storage2: FFFF FFFF - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage3: 0000 0001 - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage4: 00EC 0030 - 0000 0431 [Samsung K5W1G13ACM-DJ60,1 Gbits] type: FLASH,MuxOneNAND, asic:CMT
Suggested algorithm: XSR 1.6
Loading CMT update server data
Algorithm: BCM21351_XSR16_usbalg.fg [XSR 1.6] version: 11.14.0 revision: 2.1 size: 0x8FC7D
Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
Update server code loaded.
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
Device connected: nmwcdnsucx64\Nokia USB Flashing Generic, PORT_ID: 106B0A9
FUR: Adding Asic CMT as client OK.
CMT PAPUBKEYS is blank/erased.
Storing certificate [NPC, CCC, HWC, RND, R&D] ...OK
Partitioning....
Partitioning complete
Erase size: 33.88 MB
CMT FLASH,MuxOneNAND area [00000000-0001FFFF]
CMT FLASH,MuxOneNAND area [00020000-000203FF]
CMT FLASH,MuxOneNAND area [00060000-012FFFFF]
CMT FLASH,MuxOneNAND area [01300000-01DFFFFF]
CMT FLASH,MuxOneNAND area [02600000-029FFFFF]
Formating partition ...
Flash programming ...
CMT KEYS block sent
CMT ADA block sent
CMT PRIMAPP block sent
CMT RAP3NAND block sent
CMT PASUBTOC block sent
Selecting first CMT PAPUB block with matching RootKey.
CMT PAPUBKEYS: 697F7477 [RAP Certificate v1 232] sent
CMT UPDAPP block sent
CMT MCUSW block sent
CMT MCUSW1 block sent
CMT GENIO_INIT block sent
CMT ISA+DYNSW block sent
Programming completed in 5.842 s
Processing PPM file: rm614__03.35.ppm_x
[BB5,XSR 1.6] size: 7.16 MB
Supported Ids: 2200050920030000, 22000509200C0000
Erase size: 8 MB
CMT FLASH,MuxOneNAND area [01E00000-025FFFFF]
Flash programming ...
Programming completed in 1.489 s
Processing CNT file: rm614__03.35.image_x_0598883
[BB5,XSR 1.6] size: 12.36 MB
Supported Ids: 2200050920030000, 22000509200C0000
Erase size: 75.31 MB
CMT FLASH,MuxOneNAND area [02A00000-0753FFFF]
Formating partition ...
Flash programming ...
Programming completed in 2.723 s
Total time for flashing process(boot+erase+write) was 18.090 s
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
[RebootFromFlashMode] Please press "OK" or "Accept" on your phone (if SIM Card is not inserted to the phone) !

Waiting for device boot up ...
Device connected: nmwcdc\Nokia C3-00 USB Phonet, PORT_ID: 1FCB7364
Verifying communication to device OK.


Phone type: RM-614 (C3-00)
SW version: V 03.35 15-05-10 RM-614 (c) Nokia
Imei plain: 12345610654321-?
Product code: 059G6Z1
Battery voltage: 3983 mV, current: 162 mA
Language Pack:
- not available.

SLPA ver[4]: PA_SL3/PA_SIMLOC30 (15 digit NCK)
warning: avoid SW Downgrade & manual erase to this phone !
Camera config: NI00BC0000040102F201, ver: 001.006

SIMLOCK invalid!
SUPERDONGLE_KEY seems to be valid
WMDRM_PD seems to be valid
SIMLOCK_TEST passed
SECURITY_TEST passed


Imei plain is invalid !!!
SIMLOCK_DATA corrupted!
SIMLOCK_DATA corrupted! [You must be registered and logged in to see this image.]


Step 5.
Phone is alive, with corrupted security. Time to restore.
Write readed PM backup on first step.


[You must be registered and logged in to see this image.]

LAST STEP
Restore IMEI




Code: RPL: "C:\mobileEx\3.5\data\backup\BB5_35536604659684_BACK.rpl"
Imei: 35536604659684
Updating PRODUCTCODE (059G6Z1)... OK
Updating PSN (752E236AI)... OK
Updating HWID (2009)... OK
Updating SIMLOCK(PA_SL3)...error 0x17
Trying to write SIMLOCK as PM(PA_SL3)...OK
Updating WMDRM_PD ...OK
MXKEY [MxKey Team HTI PLUS Flasher Interface 0], SN: C0696666
Using device: USB Phonet and HTI, FW ver: 00.50, SN: 01001EF9
Connection status: NUSB3XHC:NUSB3HUB:USB 2.00 (High-speed)
Driver: nmwcdc, ver: 7.1.32.73
Module ver: 1.0.0.20454(13-03-2012), Library ver: 1.0.0.13962(12-03-2012)
Battery voltage: 4011 mV
Phone type: RM-614 (Nokia C3-00)
Product code: 059G6Z1
SW version: V 03.35 - 15-05-10 - RM-614 - (c) Nokia
LanguagePkg version: 5 - 15-05-10 - RM-614 - (c) Nokia - X
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
CMT SYSTEM ASIC ID: 000000000000000022000509200C0000 [BCM213x1 ver: 1.0]
CMT EM0 ID: 00005361
CMT PUBLIC ID: 0000000000104BBD512FD69E4686046DD0DBD26F
CMT ASIC MODE ID: 00
CMT ROOT KEY HASH: 1B0D74C532CA1C6133940C740E8C786E
CMT ROM ID: DE56D582BDDE7A3A
Loading CMT secondary boot code
SecondaryBoot: BCM21351_usb2nd.fg [BB5] version: 11.14.0 revision: 2.1 size: 0x3940
Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
eBB5ProtocolType: NEW
Secondary boot loaded.
Storage0: 0000 0000 - 0000 0000 type: RAM, asic:CMT
Storage1: FFFF 0000 - 0000 0000 type: MMC, asic:CMT
Storage2: 0000 0000 - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage3: 0000 0001 - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage4: 00EC 0030 - 0000 0431 [Samsung K5W1G13ACM-DJ60,1 Gbits] type: FLASH,MuxOneNAND, asic:CMT
Suggested algorithm: XSR 1.6
Loading CMT update server data
Algorithm: BCM21351_XSR16_usbalg.fg [XSR 1.6] version: 11.14.0 revision: 2.1 size: 0x8FC7D
Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
Update server code loaded.
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
Device connected: nmwcdnsucx64\Nokia USB Flashing Generic, PORT_ID: 106B0A9
FUR: Adding Asic CMT as client OK.
Updating CMT NPC ...OK
Updating CMT CCC ...OK
Updating CMT HWC ...OK
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
[RebootFromFlashMode] Please press "OK" or "Accept" on your phone (if SIM Card is not inserted to the phone) !

Waiting for device boot up ...
Device connected: nmwcdnsucx64\Nokia USB Flashing Generic, PORT_ID: 106B0A9
Waiting for USB device removal ...
Device connected: nmwcdc\Nokia C3-00 USB Phonet, PORT_ID: 18ECCDC1
Verifying communication to device OK.


Phone type: RM-614 (C3-00)
SW version: V 03.35 15-05-10 RM-614 (c) Nokia
Imei plain: 35536604659684-3
Product code: 059G6Z1
Battery voltage: 4011 mV, current: 1 mA
Language Pack:
- not available.

SLPA ver[4]: PA_SL3/PA_SIMLOC30 (15 digit NCK)
warning: avoid SW Downgrade & manual erase to this phone !
Camera config: NI00BC0000040102F201, ver: 001.006

SIMLOCK seems to be valid
SUPERDONGLE_KEY seems to be valid
WMDRM_PD seems to be valid
SIMLOCK_TEST passed
SECURITY_TEST passed


Imei net: 355366046596843
Version: SIMLOCK SERVER
Counter: 0/3, 0/10

CONFIG_DATA: 2440700000000000
PROFILE_BITS: 0000000000000000

BLOCK1: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK2: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK3: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK4: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK5: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK6: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK7: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN [You must be registered and logged in to see this image.]

:::::::::: BACKUP-ERASE-DOWNGRADE-RESTORE DONE ::::::::::::


Can i Repair SD by USB? YES! You can!

How to repair SD by USB

[You must be registered and logged in to see this image.]

Step 1.
Connect phone ALIVE to USB. Select phonet device as interface.
Launch Nokia Module, press SCAN

!! Make sure flash files are loaded after phone scanned !!

Step 2.
As usual, nothing special [You must be registered and logged in to see this image.]


[You must be registered and logged in to see this image.]

ALL DONE

[You must be registered and logged in to see this image.]
limited to using 10 images


All mentioned functions above are actually exist long time ago. Made this post for those who didn't noticed

These work applicable for RAPUv1, RAPUv2, BCM21351, RAP3Gv4.
Precaution on RAP phone with DCC, you might be will need FBUS to write DCC in this version.
Back to top Go down
 
HTI On USB, what this box can do?
Back to top 
Page 1 of 1

Permissions in this forum:You cannot reply to topics in this forum
CDMA GSM-Forum :: Product Support Sections :: Hard/Software-Products (official/non official- support) :: MXKEY (by Alim Hape)-
Jump to: