!!EXPLAINED!! SETOOL UNLOCK New alternative bypass method

|

!!EXPLAINED!! SETOOL UNLOCK New alternative bypass method
I know that for many English is second language and some people may over-look some little details. So I highlighted some important points all in Blue.

I like The_LAZER very much. But some times he speakes in code, or says very little or he says to much..


YOU AGAIN NEED REST FILES !!!! FOR ALL MODELS, WHICH ARE SUPPORTED FOR ALTBYPASS !!! GET THEM FROM SUPPORT SITE OR DO IT YOURSELF

Procedure of new alternative security bypass :
Edit here and highlighting are in ब्लू



Phone setup unlocked was w300i but is work for all db2010/db2020/pnx5230 cid52/cid53 using new setool2 (>=v0.914029) alternative bypass method.

1. select correct phone model
2. go to settings tab,
3. check BOTH "signed mode (using server)", "enable alternative securitybypass", that is required
4. optionally, check "unlock after flash", "patch otp<>gdfscheck in firmware"+"allow to change IMEI when unlocking" (read precautions)
5. optionally, check "complete phone after flash" (i recommend use custpacks)
6. go back to semc tab
7. if you need, add main+fsimage+custpack (script)
8. press desired operation
* I Pressed Flash(Note the phone does not start flashing only after step 12)
9. when asked, disconnect phone, insert TEST SIM or phones own operator sim card, POWER ON PHONE FULLY and connect again.

Code:
when i say "POWER ON FULLY" - i mean state of phone, when it shows main screen with operator name ("no network" with test sim)

10. HOLD "C" (or "2" for w880/simular) BUTTON ALL THE TIME UNTIL PHONE REBOOTS.
11. try to power on phone. phone must NOT power on. it is OKAY.
Code:
If phone power on, go to phone menu->games,run "executor" application, go to step 11.
12. Disconnect phone, remove battery, insert battery, press "READY", then connect phone while holding corresponding button ('C' or '2' for w880). In 99% cases phone will reboot and connects automatically.


13. turn phone on and check it. delete "executor" from games to save user from regrets of running it.

Code:
after unlock in phone will be application called "executor"(menu->games->executor)it is leftover from unlock procedure, you should delete it ... or....if you run it - it will install preloader in phone and then you able to do any setool2 function without all that long steps... (just check "use preloader security bypass) phone will appear as "dead" for user in preloader mode
To say the truth I do not find "executor" in Phone W300i aftter unlock???


approximate time for unlock by patch using new alternative bypass method is 160-180 seconds on one phone.

precautions:
please take care that there is NO (at least, i can't get) cid52 firmwares for following db2010 phones: k310,k510,w810,z530,z550

luckily, k310,k510 can be flashed with w200 firmware, so we can always return them to original state.

but it is NOT related to w810,z530,z550 phones.
cause there is no firmwares, we can't recover them in case of error.

because of that, one mistake with that phones - and you get deadweight.
you have been warned.

under mistake i mean:
- terminated flash or anything,which prevents phone from starting up
- changed IMEI of phone,which prevents phone from using new alternative bypass method.


End of editing and highlighting
will repeat again:

DO NOT WRITE FOREIGN IMEI IF YOU NOT HAVE BACKUP IN DB2010 CID50/51/52/53 , DB2020 CID49/51/52/53, PNX5230 CID49/CID51/CID52/CID53 PHONE

THINK 10 TIMES BEFORE CHANGE IMEI IN W810/Z530/Z550 CID 52 PHONES
DO NOT EVEN THINK TO MESS UP FIRMWARE IN W810/Z530/Z550 CID52 PHONES

possible problems:

in case of terminated flash/etc you can always return phone to life by flashing any original firmwares into them -
and then it ready for execution again

short info of firmwares we have and have not:

db2012 k310 (via w200),k510 (via w200) ,w200,w300 - CID52 firmwares available.
db201x abnormal CID52 phones Z530,Z550,W810 - NO CID52 firmwares.
db2020 - supported CID52/CID53 firmwares available
pnx5230 - supported CID52/CID53 firmwares available

on "step 12" phone not connecting, but simple turning on (or embedded loader not responding in 15 seconds)

due delicate bypass process such thing is possible, but that happens VERY-VERY rare.
nothing weird happens in that case - you have 4 choices what do :

1. terminate process (press stop) and retry from beginning.
2. as phone powered on now, go to menu->games and run program called "executor". phone should "turn off",sometimes with white screen,sometimes not. Continue procedure then (step 12)
3. if you run "executor",but pressed stop - go to settings, check "enable preloader security bypass" - now you can do any operation with phone, like unlock/etc.
4. reflash phone in "signed mode" and start from step 1. (idiotic, isn't it ? )

ps.
as i already wrote in "steps" - allow phone to FULLY power on to minimize risk of such behaviour.


on step 10 setool2 stucks in loop with message "PHONE NOT READY YET", but phone is turned on okay

well, better ask semc programmers why that happens... anyway - to solve that -
just press "STOP" ONCE - setool2 will continue procedure.

on step 10 i got message "CAN'T START EXECUTOR,RETRYING..."

it is okay to have that message if phone not in "normal mode" or starting up. just switch phone to normal mode and wait।

W300i CID 52 unlock log.

1. select correct phone model
2. go to settings tab,
3. check BOTH "signed mode (using server)", "enable alternative securitybypass", that is required
4. optionally, check "unlock after flash", "patch otp<>gdfscheck in firmware"+"allow to change IMEI when unlocking" (read precautions)
5. optionally, check "complete phone after flash" (i recommend use custpacks)
6. go back to semc tab
7. if you need, add main+fsimage+custpack (script)
8. press desired operation
* I Pressed Flash (Note the phone does not start flashing only after step 9)
5/13/2008 1:24:47 PM SIGNED MODE (USING SERVER).
5/13/2008 1:24:47 PM ALTERNATIVE SECURITY BYPASS ENABLED.
5/13/2008 1:24:56 PM ChipID:8040,EMP protocol:0301
5/13/2008 1:24:56 PM NEW SECURITY MODEL DETECTED
5/13/2008 1:24:56 PM
5/13/2008 1:24:56 PM PHONE IS RED RETAIL PRODUCT
5/13/2008 1:24:56 PM FLASH CID detected:52
5/13/2008 1:24:56 PM Speed:115200
5/13/2008 1:24:57 PM OTP LOCKED:1 CID:51 PAF:1 IMEI:35647801612600 CERT:RED
5/13/2008 1:24:57 PM LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
5/13/2008 1:24:57 PM Flash ID check:2019
5/13/2008 1:24:57 PM Flash props sent ok
5/13/2008 1:25:00 PM LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
5/13/2008 1:25:00 PM loader startup: executed
5/13/2008 1:25:12 PM loader GDFS startup: executed
5/13/2008 1:25:15 PM loader filesystem startup: executed
5/13/2008 1:25:15 PM loader unlock: executed
5/13/2008 1:25:20 PM
5/13/2008 1:25:20 PM DISCONNECT PHONE NOW
5/13/2008 1:25:20 PM INSERT SIM CARD, FULLY TURN PHONE ON AND ATTACH AGAIN
5/13/2008 1:25:20 PM BE SURE THAT YOU SET PHONE IN "PHONE MODE"
5/13/2008 1:25:20 PM IF ASKED, INSTALL PHONE DRIVERS
5/13/2008 1:25:20 PM
Your In Step 9
9. when asked, disconnect phone, insert TEST SIM I dont use Test sim card, I use phones operator sim card. ,POWER ON PHONE FULLYand connect again.
Code:when i say "POWER ON FULLY" - i mean state of phone, when it shows main screen with operator name ("no network" with test sim)

5/13/2008 1:25:20 PM SEARCHING FOR PHONE, "STOP" TO ABORT
5/13/2008 1:52:00 PMPHONE FOUND AT COM9
5/13/2008 1:52:07 PM PHONE READY TO PROCEED
5/13/2008 1:52:15 PM EXECUTOR STARTED
5/13/2008 1:52:15 PM
Flashing Starts at this point
10. HOLD "C" (or "2" for w880/simular) BUTTON ALL THE TIME UNTIL PHONE REBOOTS.
11. try to power on phone. phone must NOT power on. it is OKAY
.
Code: If phone power on, go to phone menu->games,run "executor" application, go to step 11.
12. Disconnect phone, remove battery, insert battery, press "READY", then connect phone while holding corresponding button ('C' or '2' for w880). In 99% cases phone will reboot and connects automatically.

5/13/2008 1:52:15 PM REMOVE CABLE FROM PHONE
5/13/2008 1:52:15 PM REMOVE BATTERY FROM PHONE, THEN INSERT IT BACK
5/13/2008 1:52:15 PM THEN PRESS "READY"
5/13/2008 1:53:30 PM
5/13/2008 1:53:32 PM bypassing security...
5/13/2008 1:53:35 PM ChipID:8040,EMP protocol:0301
5/13/2008 1:53:35 PM NEW SECURITY MODEL DETECTED
5/13/2008 1:53:35 PM
5/13/2008 1:53:35 PM PHONE IS RED RETAIL PRODUCT
5/13/2008 1:53:35 PM FLASH CID detected:52
5/13/2008 1:53:35 PM Speed:115200
5/13/2008 1:53:35 PM Trying to launch embedded bootloader...
5/13/2008 1:53:35 PM INT LDR:COMPACT_ID_LOADER_CRIPPLED_SETOOL2_R2
5/13/2008 1:53:36 PM Flash ID check:2019
5/13/2008 1:53:36 PM Flash props sent ok
5/13/2008 1:53:39 PM FOUND: R4GG001_CXC1123260_GENERIC_JE
5/13/2008 1:53:39 PM Restore from:R4GG001_CXC1123260_GENERIC_JE
5/13/2008 1:53:50 PM writing D:\zz-things\setool3\SE-Flashs\W300\W300CID52\R4GG001_CXC1123260_JE_RED_CI D52.ssw
5/13/2008 1:53:56 PM CURRENT FLASH FILE CID:52
5/13/2008 1:53:56 PM SSW uses complete hash, hash len is:6740
5/13/2008 1:53:56 PM Will flash 337 blocks...
5/13/2008 1:56:44 PM SSW loading returns:0
5/13/2008 1:56:45 PM writing D:\zz-things\setool3\SE-Flashs\W300\W300CID52\R4GG001_FS_AMERICA_2_JE_RED_ CID52.ssw
5/13/2008 1:56:49 PM CURRENT FLASH FILE CID:52
5/13/2008 1:56:49 PM SSW uses complete hash, hash len is:3220
5/13/2008 1:56:49 PM Will flash 161 blocks...
5/13/2008 1:58:10 PM SSW loading returns:0
5/13/2008 1:58:10 PM Searching...
5/13/2008 1:58:16 PM IMEI handler determined.
5/13/2008 1:58:50 PM Searching...
5/13/2008 1:58:55 PM Firmware SIMLOCK check determined.
5/13/2008 1:59:06 PM LDR:COMPACT_SEMC_FS_LOADER_SETOOL2_V26
5/13/2008 1:59:06 PM loader startup: executed
5/13/2008 1:59:17 PM loader GDFS startup: executed
5/13/2008 1:59:33 PM loader filesystem startup: executed
5/13/2008 1:59:33 PM loader unlock: executed
5/13/2008 1:59:33 PM writing tpa/preset/custom/C3_PCA_G3v2.cer
5/13/2008 1:59:33 PM writing tpa/preset/custom/CONTENT_DOWNLOAD_HOOK_2.itm
5/13/2008 1:59:34 PM writing tpa/preset/custom/customize.xml
5/13/2008 1:59:34 PM writing tpa/preset/custom/DESKTOP_HOOK_2.itm
5/13/2008 1:59:34 PM writing tpa/preset/custom/Entrust.net Root Certificate.cer
5/13/2008 1:59:34 PM writing tpa/preset/custom/Entrust.net_WTLS_Root_Certificate.wcrt
5/13/2008 1:59:34 PM writing tpa/preset/custom/FM_PICTURES_HOOK_3.itm
5/13/2008 1:59:34 PM writing tpa/preset/custom/FM_SOUNDS_HOOK_3.itm
5/13/2008 1:59:35 PM writing tpa/preset/custom/FM_THEMES_HOOK_3.itm
5/13/2008 1:59:35 PM writing tpa/preset/custom/FM_VIDEOS_HOOK_3.itm
5/13/2008 1:59:35 PM writing tpa/preset/custom/GAMES_HOOK_3.itm
5/13/2008 1:59:35 PM writing tpa/preset/custom/GTE_CyberTrust_Root.cer
5/13/2008 1:59:35 PM writing tpa/preset/custom/GTE_Cybe_Trust_Root_WTLS.wcrt
5/13/2008 1:59:35 PM writing tpa/preset/custom/Root.cer
5/13/2008 1:59:36 PM writing tpa/preset/custom/SEMC_E2E_Root_CA.crt
5/13/2008 1:59:36 PM writing tpa/preset/custom/SETT_RINGTONE_HOOK_3.itm
5/13/2008 1:59:36 PM writing tpa/preset/custom/ThawtePremium.der
5/13/2008 1:59:36 PM writing tpa/preset/custom/ThawteServerCA.cer
5/13/2008 1:59:37 PM writing tpa/preset/custom/Utiroot.cer
5/13/2008 1:59:37 PM writing tpa/preset/custom/VeriSignClass3Root.cer
5/13/2008 1:59:37 PM writing tpa/preset/custom/Verisign_Class_3_CA_WTLS.wcrt
5/13/2008 1:59:37 PM Phone detached
5/13/2008 1:59:40 PM Elapsed: 2092 secs.

13. turn phone on and check it. delete "executor" from games to save user from regrets of running it.

---- End of edit unlock log --------

To say the truth I do not find "executor" in Phone W300i aftter unlock???
** If the phone is not User code blocked/locked you can use phones operator`s sim card. You do not need (TEST CARD SIM)

0 comments: