Hermes Extended ROM Unlocker & Unhider - works on new roms! - 8525, TyTN, MDA Vario II, JasJam Software Upgradin

Unlocking the Extended ROM is now possible again on new HTC Hermes ROMs
Download:
Hermes Extended ROM Unlocker & Unhider v3
Works in ALL ROM versions, but you need to CID Unlock your Hermes first if you want to UNLOCK the Extended ROM (you don't need to CID Unlock if you just want to unhide the ExtROM):
HERMES_MountALLExtROM.cab​
Instructions:
CID-Unlock your Hermes (NOTE: This step is only needed if you are using a NEW rom and want to UNLOCK the Extended ROM)
Install cab file on your device
Power off the device for 10 seconds
soft reset with stylus
Before asking questions:
Read the wiki:
How to Unlock and Unhide Extended ROM
Available Extended ROM Versions (please post yours if it's not already there!)
Upgrading FAQs (see #11 to #14)
Notes:
All cab files you put on the ExtROM need to be signed with a valid certificate to install after a hard reset (there's no known way to circunvent that yet).
You can use the ExtROM folder as extra storage space (~10Mb).
Enjoy!

pof said:
Those having problems unlocking ExtROM on newer roms, please try this cab file:
HERMES_MountExtROM_v2.cab
Remember you have to power off the device for 10 seconds after installing the cab, then soft reset.
First person trying please post a comment and report if it works
Click to expand...
Click to collapse
Ow my golly Pof!!! You are a true GENIUS!!! Thank you very very very much!!! It works flawlessly with the Cingular AKU2.6 Rom!!! Another 9.5MB saved!!! Very grateful!
PERFECTION!!! Now I dont need to go back to the shipped TyTn Rom for the saved Ext_Rom space!!!

pof said:
Those having problems unlocking ExtROM on newer roms, please try this cab file:
HERMES_MountExtROM_v2.cab
Remember you have to power off the device for 10 seconds after installing the cab, then soft reset.
First person trying please post a comment and report if it works
Click to expand...
Click to collapse
i just thought i'd try it and i did, it worked! you did it again pof!

pof said:
Those having problems unlocking ExtROM on newer roms, please try this cab file:
HERMES_MountExtROM_v2.cab
Remember you have to power off the device for 10 seconds after installing the cab, then soft reset.
First person trying please post a comment and report if it works
Click to expand...
Click to collapse
Is this unlocker easily reversible (translation: how does one lock again)?

pof let me get this right, it is now possible to unlock the extended rom with bootloader 1.06 like the RUU_HER_Cingular_1.34.502.1_1.16.00.00_wwe_cws_ship.exe

Thanks guys for your comments and beta-testing
As you may have seen I splited the old sticky thread about ExtROM unlocking and made this new one, to avoid confussion on new people.
Now to your questions:
goestoeleven said:
Is this unlocker easily reversible (translation: how does one lock again)?
Click to expand...
Click to collapse
It's just a registry hack (see the cab file is just 4kb), very easy to hide/lock again. I will post instructions on the wiki later, so it can be integrated on the next version of fit4cat hermes tweaker too
neomanxda said:
pof let me get this right, it is now possible to unlock the extended rom with bootloader 1.06 like the RUU_HER_Cingular_1.34.502.1_1.16.00.00_wwe_cws_ship.exe
Click to expand...
Click to collapse
Yes it is posible to unlock the ExtROM on this ROM too, bootloader has nothing to do here... (this is an ExtROM unlocker, not a CID / SIM unlocker).

I ran the v2 unlocker on my 8525 and can see the Extended ROM, but whenever I try to install programs to Extended ROM I get an error that they could not be installed.
Am I doing something wrong? I've done this a bunch on my Apache without any issues.

URPREY: I installed some programs on mine and it's working fine, i'm running cingular's 1.31 rom now, haven't tried with 1.34.
Try running the v2 CAB file again, make sure you power off the device for a while for the registry settings to keep, and then soft reset it, see if it works this time.

I did do that pof
I doublechecked the registry keys, and they correspond to the LOCKED description in the wiki:
LOCKED:
HKEY_LOCAL_MACHINE\SOFTWARE\Drivers\MSYSEXT
"Background"=0x0 (0)
"Foreground"=0x0 (0)
When I looked at setup.xml in the cab file, it appears that those are the values specified? Is that the correct value or should they be changed to something different to unlock?

Yes, this is how it should be... the registry keys on the wiki are still not updated, the info there is from the old cab. Can you try to install the old cab first, and then the new one? tell me if it works this way

Hi pof,
I had used this on RUU_HER_ChungHwa_1.25.751.4_1.07.03.10_CHT_SHIP, but it seems doesn't work, it can unhidden the Extended ROM, but can't unlock.

newbie question: what benefits are there to unlocking the extrom?

As URPREY and shaliuxin reported that the new CAB was not working for them I flashed the cingular 1.34 ROM on my Hermes to see if it was any difference.
Without using the CAB, just installed a registry editor and added / modified the following registry keys / values:
Code:
[HKEY_LOCAL_MACHINE\System\StorageManager\Profiles\EXT_FLASHDRV]
"MountHidden"=dword:00000000
"Bootphase"=dword:00000002
[HKEY_LOCAL_MACHINE\System\StorageManager\AutoLoad\EXT_FLASHDRV]
"MountHidden"=dword:00000000
[HKEY_LOCAL_MACHINE\System\StorageManager\Profiles\MSFlash]
"MountHidden"=dword:00000000
My ExtROM is unlocked and visible in File explorer. I have installed 3 cabs and can run programs from ExtROM without problems. So if the CAB doesn't work for you, you may try setting the registry keys manually and see if you get better results...
I tested this with Cingular 1.31 and Cingular 1.34 ROMs and worked fine for me.

Thanks pof! I'll give it a go this morning once I get to work by manually editing the registry keys and report back here.

I manually edited my registry to include the above keys, but my ExtROM is still write-protected. I'll email you my reg dump for Storage Manager to see if you see anything causing the issue. Thanks for all your help and hard work on this.

AT POF...so you just copy the cabs then run them from the extended ROM? This will work? I know in the wizard you had to pack it up and do all those fun little step then hard reset your device and have it install automatically. Is this the case. or am I just confused?

slimsaturn: This is just for unhide / unlock the Extended ROM, not for cooking it. Cooking the extrom is only possible with signed cabs.

Those of you having problems unlocking the extended ROM please try this new CAB and report if it works. I think this should work for all ROMs and devices, I've tested with 2 different Hermes without problems on ROMs 1.18 and 1.34.
HERMES_MountALLExtROM.cab​

Still not working. Should the installation show up under installed programs?
I emailed you my registry dump a little while ago. Let me know what else I can do to help

pof said:
slimsaturn: This is just for unhide / unlock the Extended ROM, not for cooking it. Cooking the extrom is only possible with signed cabs.
Click to expand...
Click to collapse
I know this will unhide the ext rom. but are you running the cabs from the exit rom after you unhide and copy them there? Or are you cooking the EXT ROM

Related

Upgrad Vario II Radio ROM with Cinglar ROM image.

i could hack Radio rom from Cinglar,and make Flashable file.
2 of them,,Version 1.10 and 1.16 were tested on my VarioII.
i tried to upload them onto xda-FTP many times but fialed.
so i uploaded to my FTP for you guys.
instruction of upgrade also there.
Please got to get them if you interested in.
http://asukal.net/blog/2006/09/radio_upgrade_hermes_form_cing.html
Good luck
Asukaly yours!
WTF! This is _VERY_ good news!! :shock:
How did you manage to cook the type 2 radio rom??
Is Ma_Upgrade_NoID working with the hermes bootloader?? AFAIK the bootloader lacks wdata command... (replaced by 'wdatah')
Is it that you need only rwdata but not wdata to flash radio?
An explanation of the process to create the working nbf out of the extracted .nb files would be very useful!
Thanks!!
EDIT: I uploaded the files to xda-dev FTP and make a new wiki page:
http://wiki.xda-developers.com/index.php?pagename=Hermes_ExtractedRadioRoms
Thanks for the new Radio update. Just updated my MDA Vario II. Will test if there's any improvements!
Seems to work like a charm!
ROM 1.18.255.3
ROM date: 07/22/06
Protocol version: 32.53.7018.01H
Ext ROM 1.18.255.106
Radio 1.16.00.00
And my Bootloader remains at V1.04 :!:
(I'd have pasted a bitmap, but I couldn't figure out how!).
Major kudos to Asukal!!!!!!!
Now if we could only find a new TyTN System ROM to go along with this spiffy new radio...
super Asukal, great news!!!
about the screen alignment problem, if you have some free time, could you please translate whats is the problem and how they do to fix the screen alignment problem please
http://inuchanbt.blog54.fc2.com/blog-entry-86.html
thanks you so much Asukal!
I am receiving country id error : 120 while attempting to upgrade the radio from Cingular 1.31 ( radio 1.13). Even when i ran the upgrade second time device seems to go into radio update screen but just sits there and doing nothing.
then the radio updare error comes up. following the soft reset I have checked device information and radio version is still: 1.13
device is HTC TyTN, originally shipped with Italian ROM.
any ideas?
@superduper: I guess you need a 1.04 bootloader to perform the radio only rom upgrade from Asukal, but your current rom has bootloader 1.06
Let's see if anyone else with Cingular 1.31 rom can do the radio only upgrade or has the same problem you reported...
@Asukal: please give us details on how you did to extract the "radio_.nbf" from shipped Hermimg Cingular NBH file
this is super excellent. Now all we need is a rom image update then we can make our own aku 3.2 version.
Good job Asukal.
vua777 said:
super Asukal, great news!!!
about the screen alignment problem, if you have some free time, could you please translate whats is the problem and how they do to fix the screen alignment problem please
http://inuchanbt.blog54.fc2.com/blog-entry-86.html
thanks you so much Asukal!
Click to expand...
Click to collapse
he did ...pls see a picture
Summary to extract and convert nbh, pls wait a while.
i will make report after finish all my project of this,
now i am trying to flash Only Splash, and only OS, only Extrom separately.
PLS patient!
and thanks report guys!.
if no_id_upgrade can not work on Bootloader 1.06,
can u try with Hermes Upgrade.exe with this nbf?
(you must remove nbh before that, i didnt try that so i am not sure it work or not) :?
thanks a lot Asukal!!!
no luck. file open error : 240 :?
Asukal said:
if no_id_upgrade can not work on Bootloader 1.06,
can u try with Hermes Upgrade.exe with this nbf?
(you must remove nbh before that, i didnt try that so i am not sure it work or not) :?
Click to expand...
Click to collapse
Is it any better?
So, a question for those of you who've done the upgrade - does it make any difference you can notice? Just wondering if it's worth doing the upgrade at the moment, or waiting for new HTC rom when it finally appears.
Tried this on a Orange M3100 with the 1.31 Cingular ROM, but it doesn work. Just sites at 0% and then you eventually get an error. Seems like you need bootloader 1.04 for this to work...
are there any improvements using these new radio roms? also, what's the difference between 1.10 and 1.16?
thanks
I wasn't having any radio problems previously, and so far, I haven't seen any issues with 1.16, either.
Bluetooth works fine, UMTS/GSM calls work fine, WLAN works fine, and UMTS data works fine...
If I see any strange behaviors, I'll be sure to point them out...
Asukal said:
Summary to extract and convert nbh, pls wait a while.
i will make report after finish all my project of this,
now i am trying to flash Only Splash, and only OS, only Extrom separately.
PLS patient!
Click to expand...
Click to collapse
Aaaaghhh! I can't wait
Please tell me if this process is correct to create the radio_.nbf:
Code:
nbh2dbh.pl HERMIMG.nbh HERMIMG.dbh
dbhdecode.pl HERMIMG.dbh
alpinenbfdecode.pl -e ./GSM.nb radio_.nbf
My radio_.nbf and yours differ, is it because of headers?
Thanks!
Just tried the procedure on mine.
Hardware = Dopod 838Pro
ROM = imate
Upgraded to radio version 1.16, the procedure worked fine! Except that after the flashing was complete the PC displayed "upgrade failed" but after a soft reset of the PDA, it worked.
You did a great job, Asukal!!!
I can see some improvement that I can see more wireless bar on my title bar after I upgrade radio ROM.
Thsi is cingular ROM, so I don't know somebody who lives outside US can see this improvement, but I can see it in my rural US state.
In addition, as you said, I can see OS runs smoothly than my original ROM.
I was usually stuck when I run "menu" or "button" applet in control panet. But after I upgrade to Radio 1.16, I don't have it.
I don't know why, but it is real.
I appreciate your effot!!
works great, thanks..
guys who can not flash Radio
One of my friends try to flash 1.16.and faild in that.
But could flash 1.11.
then tried 1.16 again, finally he could flash 1.16.
Please try this step.<this is not to guarantee can do, just a possibility>
And i will prepare 1.13 also soon.

Question - ExtendedROM files can not be deleted...

Ok...first and foremost, I don't consider myself a technical idiot, but I feel like one at the moment...I'm sure that my problem will end up being something simple, but I just can not figure this out.
I can not delete the files in my ExtendedROM folder. Using Resco Explorer, I keep getting "The media is write protected" error message.
Phone - Cingular 8525
I paid for and ran the the SuperCID unlock from that "imei.uk" company back in early January.
I've installed the Fit4Cat software to unlock in the security page. I've tried both versions that are out there. - That doesn't work.
I've tried POF's Hermes_MountAllExtrom.cab file - That doesn't work.
I've check the Registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Drivers\MSYSEXT
and it shows the correct unlocked numbers, but this still does not allow me to delete the ROM files.
About a month ago, I was able to delete the files and I installed several various cooked ROMs and then I downloaded an earlier version of the Cingular ROM that had the 1.04 bootloader.
Since then, the ROM has been locked, unable to be manually changed.
I have since reflashed with the new Vanilla WM6 - which looks really good by the way...and then reflashed the original Cingular 1.34 ROM from the HTC.com web page.
After this last flashing, I again, installed all of the Unlocking/unhiding cab files that I had, in an effort to unlock and delete the files located in the ExtendedROM folder. But, I still am not able to do it.
My goal is to delete the files located in my ExtendedROM folder, so I can insert my own collection of ROM parts and reflash the way I want it. I know there are other ways to do this, but this is the way I prefer, and honestly, I'm curious now to find out why it is behaving this way.
Any ideas would be very much appreciated, cause I'm stumped.
Thanks,
EdinAthens,GA
If your device is not SuperCID, you can only see files on extrom (unhide) but not ad/delete or modify them (unlock).
Make your device SuperCID first, then your problem is solved.
Hola pof,
He wrote that he ran the imei cid unlock.
Regards and thanks for your work here!
Ben
Super CID...
Pof / Ben...
Thanks for the info. Pof - I found your CID unlocker and ran it and that fixed my problem. I've sent a donation to express my appreciation...
What I find confusing, is the fact that it had "relocked" after I had purchased and applied the "imei-uk" code that I had bought.
I didn't think that was possible...
I did re-run the "imei-uk" unlocker at some point, is it possible that I re-locked the 8525?
-Ed
imei-check unlocker only makes the device supercid temporarily, when a new radio (or full rom containing radio) is flashed on the device SuperCID is lost.

Unable to unlock Extended ROM / extrom poll .. Let's find a solution.

Hello all,
I'm creating this poll to try and figure out why some of us can't unlock our Extended ROM / extrom.
By the way, I'd like to thank all the developers on this forum who contribute software for our Hermes... this thread is in no way a complaint or cut down to their software and guides. All I'm trying to do is just figure out why some of us can't unlock our Extended ROM. Do not Flame or Complain about any developer's software in this thread!!!!!
If you have questions on how to unlock your Extended Rom go to the following links:
http://wiki.xda-developers.com/index.php?pagename=Hermes_Unhide_Extrom
http://forum.xda-developers.com/showthread.php?t=283750
Here's my situation:
- I had a stock Cingular 8525 with a 1.06 bootloader and 1.34 ROM
- I then did an unlock sim and super cid and had no problems
- I then used HTweaC 2.1b to Unhide and Unlock my Extended ROM and was successful.
- I then followed Mr.Vanx's guide to upgrade to LVSW WM6
http://www.mrvanx.myzen.co.uk/hermes_guide/lvsw/
- Following the guide, I upgraded my Bootloader to Olipro HardSPL 1.40, upgraded my Radio ROM to 1.38.00.10, and then successfully installed LVSW WM6
At this point, my Extended ROM was unhidden but locked. I've read posts saying that it was because WM6 doesn't allow you to write to the Extended ROM so I assumed it was a limitation of WM6.
I then installed Black 2.0 WM6 and again, my Extended ROM was unhidden but locked.... again assuming it's a WM6 issue....
After tinkering around WM6, I decided to revert back to my Cingular stock 1.34 ROM since I was having trouble using WM6's Internet Sharing to tether my laptop to my 8525.... I find it easier using WM5's DUN since I don't have to muck around with proxy server settings on my laptop when using WM6's Internet Sharing.
Anyways, after using:
http://wiki.xda-developers.com/index.php?pagename=Hermes_UpgradeGuide
I stripped out the OS.nb of the stock Cingular 1.34 ROM, created a new .nbh and then used ruuwrapper.exe to load the stock Cingular 1.34 ROM.
So now, I'm back at the Cingular 1.34 ROM but after using all the methods I used previously to unhide and unlock my Extended ROM, I'm only able to unhide my Extended ROM but not unlock it. I hope this is not permanent . I really liked having the additional 10MB
Anyways... I hope some of us can figure out a solution to how to unlock our Extended ROM
By the way, I did try to reformat my extended rom using this post but was unsuccessful since the Extended ROM is write protected.
http://forum.xda-developers.com/showthread.php?t=290132
For those of you who can't unlock, can you post what you tried to use to Unhide and Unlock your Extended ROM to try to find a pattern on our problem?
joel32137 said:
Hello all,
I'm creating this poll to try and figure out why some of us can't unlock our Extended ROM / extrom.
By the way, I'd like to thank all the developers on this forum who contribute software for our Hermes... this thread is in no way a complaint or cut down to their software and guides. All I'm trying to do is just figure out why some of us can't unlock our Extended ROM. Do not Flame or Complain about any developer's software in this thread!!!!!
If you have questions on how to unlock your Extended Rom go to the following links:
http://wiki.xda-developers.com/index.php?pagename=Hermes_Unhide_Extrom
http://forum.xda-developers.com/showthread.php?t=283750
Here's my situation:
- I had a stock Cingular 8525 with a 1.06 bootloader and 1.34 ROM
- I then did an unlock sim and super cid and had no problems
- I then used HTweaC 2.1b to Unhide and Unlock my Extended ROM and was successful.
- I then followed Mr.Vanx's guide to upgrade to LVSW WM6
http://www.mrvanx.myzen.co.uk/hermes_guide/lvsw/
- Following the guide, I upgraded my Bootloader to Olipro HardSPL 1.40, upgraded my Radio ROM to 1.38.00.10, and then successfully installed LVSW WM6
At this point, my Extended ROM was unhidden but locked. I've read posts saying that it was because WM6 doesn't allow you to write to the Extended ROM so I assumed it was a limitation of WM6.
I then installed Black 2.0 WM6 and again, my Extended ROM was unhidden but locked.... again assuming it's a WM6 issue....
After tinkering around WM6, I decided to revert back to my Cingular stock 1.34 ROM since I was having trouble using WM6's Internet Sharing to tether my laptop to my 8525.... I find it easier using WM5's DUN since I don't have to muck around with proxy server settings on my laptop when using WM6's Internet Sharing.
Anyways, after using:
http://wiki.xda-developers.com/index.php?pagename=Hermes_UpgradeGuide
I stripped out the OS.nb of the stock Cingular 1.34 ROM, created a new .nbh and then used ruuwrapper.exe to load the stock Cingular 1.34 ROM.
So now, I'm back at the Cingular 1.34 ROM but after using all the methods I used previously to unhide and unlock my Extended ROM, I'm only able to unhide my Extended ROM but not unlock it. I hope this is not permanent . I really liked having the additional 10MB
Anyways... I hope some of us can figure out a solution to how to unlock our Extended ROM
By the way, I did try to reformat my extended rom using this post but was unsuccessful since the Extended ROM is write protected.
http://forum.xda-developers.com/showthread.php?t=290132
For those of you who can't unlock, can you post what you tried to use to Unhide and Unlock your Extended ROM to try to find a pattern on our problem?
Click to expand...
Click to collapse
I created a patch for the ExtROM for those who aren't SuperCID, you need the developer certificates for it to work, and it's only proven (by me) to be working under WM6, technically it should work with WM5 but we've found that WM5 could possibly have extra security that prevents the dll running, although I don't see how personally.
Hmmm ... I followed the guide except I installed the latest Oli and radio, then reflashed to Black 2.0, and then ran the SuperCID/SIM unlocker doing both.
Able to unlock the extrom and clear it no probs.
Thanks Olipro and Chachi for your input, I'll give it a whirl and hope to unlock my Extended ROM and post my results.
By the way, here's a link to Olipro's patch mentioned above:
http://forum.xda-developers.com/showthread.php?t=297085
Just read the Olipro Unlocking ExtRom method / thread from the link below, then ran the ExtROMPatcher.exe on my 8525. Patch ran successfully. After a soft reset, I couldn't see the Extended ROM partition. So, I then installed the sdkcerts.cab as well as installed the Security Configuration Manager (for the noobs: downloaded from M$ ... it's a Powertoy for WM5) and made sure Security was turned off for my 8525. I then did a soft reset..... however..... like many others from the thread below, I was unsuccessful. I have to say... Olipro was more than patient trying to help everyone in the thread
joel32137 said:
Thanks Olipro and Chachi for your input, I'll give it a whirl and hope to unlock my Extended ROM and post my results.
By the way, here's a link to Olipro's patch mentioned above:
http://forum.xda-developers.com/showthread.php?t=297085
Click to expand...
Click to collapse
joel32137 said:
Just read the Olipro Unlocking ExtRom method / thread from the link below, then ran the ExtROMPatcher.exe on my 8525. Patch ran successfully. After a soft reset, I couldn't see the Extended ROM partition. So, I then installed the sdkcerts.cab as well as installed the Security Configuration Manager (for the noobs: downloaded from M$ ... it's a Powertoy for WM5) and made sure Security was turned off for my 8525. I then did a soft reset..... however..... like many others from the thread below, I was unsuccessful. I have to say... Olipro was more than patient trying to help everyone in the thread
Click to expand...
Click to collapse
you could try renaming OEM_FLASHDRV.dll to something else (like OEM_FLASHDRV2.dll) and then changing the registry to use the new OEM driver.
currently I'm using WM6 with the patch with no problems. since you're on the WM5 ROM it might not work; but as I say, try the above suggestion and see if you get any joy.
After each ROM upgrade I run 2 files... First I run MountExtROM_v2.cab then ExtROMPatcher.exe In that order. The ExtROMPatcher resets the device and my Ext ROM is visible and I can write to it.
This has worked for every WM6 ROM and also some of the WM5 ROMS (but can't remember which except one of the Dopods).
Hi Olipro, thanks for the tip but I tried renaming OEM_FLASHDRV.dll to OEM_FLASHDRV2.dll and updated the corresponding registry key but still no luck.
Hi ach2, thanks for the tip as well but I've definitely ran MountExtROM_v2.cab and then ExtROMPatcher.exe In that order but still no luck....
What's interesting is that only 2 people are not able to unlock their Extended ROM but from reading all the posts related to this issue, it would seem there was more people encountering this problem....
joel32137 said:
Hi Olipro, thanks for the tip but I tried renaming OEM_FLASHDRV.dll to OEM_FLASHDRV2.dll and updated the corresponding registry key but still no luck.
Hi ach2, thanks for the tip as well but I've definitely ran MountExtROM_v2.cab and then ExtROMPatcher.exe In that order but still no luck....
What's interesting is that only 2 people are not able to unlock their Extended ROM but from reading all the posts related to this issue, it would seem there was more people encountering this problem....
Click to expand...
Click to collapse
you also installed the SDK certificates?
Definitely installed the SDK certificates you attached from the previous thread.
I followed everything you suggested from the previous thread.
Could I have in someway screwed up the Extended ROM partition during my WM6 flashing?
What's odd is that whenever I flash a new ROM (with an Extended ROM), the Extended ROM gets overwritten so I know it is able to be unlocked.
Olipro said:
you also installed the SDK certificates?
Click to expand...
Click to collapse
I think I figured out a solution to this problem.
I was able to unlock my Extended ROM by re-doing pof's SIM & CID Unlocker
http://forum.xda-developers.com/showthread.php?t=293665
You'll have to do the entire procedure again using the Instructions.txt
That means going through the process of copying the SSPL-HERM.exe to your Hermes and running from your Hermes. Then run the ROMUpgradeUt.exe from your computer. After the upgrade completes (around 20 min), copy the Herm_Unlock_v3.exe to your PDA and run it. That's what I did to unlock my Ext. Rom.
Please note that I did run a previous version of pof's unlocker and was successful in unlocking my Ext. Rom. It was only after I upgraded to HardSPL V5 and installed WM6 is when I lost write access to my Extended ROM. I'm still not sure if it was the install of HardSPL v5 or WM6 that locked my Extended ROM but I'm just happy it's now unlocked.
Hope this thread helps some noobs.

[solution] G4 SoftSPL Flash any ROM to CID locked G4 [UPDATED]

HTC Wizard SoftSPL (sSPL) For G4 Wizards
FAQ:
What is SoftSPL?
-SoftSPL is a patched SPL that will temporary unlock your CID (untill reboot).
-It will be copied to your device and loaded (BUT NOT FLASHED!), the device is tricked to believe it has SuperCID (More accuratly g_cKeyCardSecurityLevel will be 0 ).
Why Temporary?
-1st because of warranty, since there is no CID block written, warranty isn't void
-2nd with this tool it's not necesarry to have a permanently unlocked CID.
-3rd it's safe, it doesn't flash CID block or IPL/SPL by it's own, but choose your ROM you want to flash wisely!
Isn't shelltool the same?
-no shelltool will strip the rom, and then flash it with pdocwrite, where sSPL is a bootloader which says it has supercid, thus tricking the RomUpdateUtility.
But can I make it permanent?
-Yes it can make it semi permanent, with HardSPL (it's the same trick, but now a patched SPL is flashed to device).
What does Soft SPL change on my device?
-nothing, it's loaded into memory. Only the ROM you choose to flash with the RUU will change your device.
USE AT OWN RISK
How To use?
If you don't know what a G4 safe ROM is, don't even try to upgrade!
WILL NOT WORK IN VISTA
-Unzip SoftSPL.zip
-copy the nk.nbf file from desired G4 safe ROM to the SoftSPL folder
-Fully Connect to ActiveSync
-Run START-sSPL.exe
-the Screen of your Device will turn white, don't panic, this is normal
-SoftSPL will now run the RUU, proceed as usual (the screen of the wizard will stay white during whole process, again don't panic!)
DO NOT PROCEED WITH RUU if the screen isn't WHITE, OR when in bootloader SPL version isn't 2.21.olip
G4 Safe means:
-No IPL/SPL and no Extended ROM.
Many Thanks Go to:
Olipro: For patching the latest SPL
SAA044: For testing all the versions, and keeping his head cool when the first hardSPL killed his Wizard (beyond repair!), and for keeping on testing the new versions with his brand new Wizard!
Whiterat: For all his technical and moral support, without him it wouldn't have excisted.
Pof & Des: From whom I took the idea, and some of the scripts.
NB. This sSPL is not for G3, it will proceed with updating, but in the end OS will not be written, tested it with my own G3. Beware of the SPL/IPL (there is danger to flash G4 spl on your G3 due to the fact you are using a G4 sSPL, the RUU will probably think it's running from a G4 device!).
NB.2 If you want to mtty in stead of flashing a ROM, place mtty in the folder and rename it 2.exe
[EDIT:12-september 19:54] I updated the file for a confirmed working RC1 (v0.1) WITH the missing dll [/EDIT]
[edit] 23.09.07
Some people reported that enable rapi does not always work, if that is the case for you, you can try to replace the original enable-rapi with the one attached here.
[/edit]
Well Done Eqx and Well Done to everybody else involved.
I look forward to giving this a go.
This is great work.. I will try this first thing in the morning..
Many Thanks
First of all many thanks for ur effort.
second-should i back to the love room befor flashing this room or i can flash directly from any room?
third - with shell tool if any problems happend i can back to love room and retry again. is it possible here also?
forth - is soft room = new room without spl & ipl?
awaiting ur reply & thanks again for ur hard work
First of all many thanks for ur effort.
second-should i back to the love room befor flashing this room or i can flash directly from any ROM?
third - with shell tool if any problems happend i can back to love room and retry again. is it possible here also?
forth - is soft (safe?) ROM = new ROM without spl & ipl?
awaiting ur reply & thanks again for ur hard work
Click to expand...
Click to collapse
First, you're welcome.
2nd Please keep in mind you need IPL/SPL 2.xx.00001 for WM6 (use the latest officcial one from your provider)
3rd It's not different from an ordinary flash, you can go back to any ROM that is G4 safe.
4rd G4 safe means no IPL/SPL (Extended ROM hasn't been tested yet)
Thanks bro
thanks bro for ur quick reply & i will try it as soon as TNT5 release.(inshaa-allah)
it's sound pretty easy ... i'mma try it 2marow as well .
thanks for everything
where r u guys?
42 person's were downloded without any comments. your feedback is very important to other's.
yalla come on
[solution] G4 SoftSPL Flash any ROM to CID locked device
Thanks!! I wil post the results a soon as i flash a new ROM
Thanks!! It's 2:33 in the morning where I live and I just found this. Am trying now. Will report results.
I tried it and it didn't work. But it was probaly my fault.
Would anyone be so friendly posting some G4 Save-Roms. I think a lot of us guys aren't sure wich are save and wich aren't.
Thank you
thomme
My way
For anyone interested i did it like this!!!!
1. Flashed back to latest origenal rom.
2. Copied the file into shelltool directory to verify the ipl/spl status. (Normally most roms here dont have ipl/spl in it, never hurts to check though.
3. Used wizard service tool to make sure the enable rapi command is installed on device.
4. Copied the desired nk.nbf file into softspl (root) folder.
5. Ran the main exe file without errors and had wm6 flashed successfully.
saa044 said:
For anyone interested i did it like this!!!!
1. Flashed back to latest origenal rom.
2. Copied the file into shelltool directory to verify the ipl/spl status. (Normally most roms here dont have ipl/spl in it, never hurts to check though.
3. Used wizard service tool to make sure the enable rapi command is installed on device.
4. Copied the desired nk.nbf file into softspl (root) folder.
5. Ran the main exe file without errors and had wm6 flashed successfully.
Click to expand...
Click to collapse
The only difference now is that there is a ROM folder now
hmmm
thomme said:
I tried it and it didn't work. But it was probaly my fault.
Would anyone be so friendly posting some G4 Save-Roms. I think a lot of us guys aren't sure wich are save and wich aren't.
Thank you
thomme
Click to expand...
Click to collapse
Most of the roms on this page should be G4 safe.
http://wiki.xda-developers.com/index.php?pagename=wizard_WM_6
The ones I have tested up till now is the wrcx, TNT and SNE 3 ones. Try what I said in my previous post, that might also work for you. What error did you get by the way, a 620 errors that said it could not communicate with device?
the-equinoxe said:
The only difference now is that there is a ROM folder now
Click to expand...
Click to collapse
yup, that is nice.
I tried and it didn't work at all. I tried 3 times already from the time I downloaded the rar and still no success.
First time I tried it I had Titanium 2 installed and it was a no go even though the IPL/SPL were 2.26.0001
Then I tried twice using the official T-Mobile rom with IPL/SPL 2.26.0001 and followed the directions provided to a t and no success...
I am going to try once more tonight since it is 3:25am and then im giving up for the night.
Oh and I am trying to flash faria's rom. Think that might have something to do with it?
dharvey4651 said:
I tried and it didn't work at all. I tried 3 times already from the time I downloaded the rar and still no success.
First time I tried it I had Titanium 2 installed and it was a no go even though the IPL/SPL were 2.26.0001
Then I tried twice using the official T-Mobile rom with IPL/SPL 2.26.0001 and followed the directions provided to a t and no success...
I am going to try once more tonight since it is 3:25am and then im giving up for the night.
Oh and I am trying to flash faria's rom. Think that might have something to do with it?
Click to expand...
Click to collapse
Can you give us more detail to where you get the error and what it is? Also did you flash origenal rom with softspl or bootloader? Oh and if your device asks for permission to load the dll files it wont work.
the-equinoxe said:
4rd G4 safe means no IPL/SPL (Extended ROM hasn't been tested yet)
Click to expand...
Click to collapse
I have a CID Locked G4 and I can flash using RUU any ExtendedRom
contact me
dharvey4651 said:
I tried and it didn't work at all. I tried 3 times already from the time I downloaded the rar and still no success.
First time I tried it I had Titanium 2 installed and it was a no go even though the IPL/SPL were 2.26.0001
Then I tried twice using the official T-Mobile rom with IPL/SPL 2.26.0001 and followed the directions provided to a t and no success...
I am going to try once more tonight since it is 3:25am and then im giving up for the night.
Oh and I am trying to flash faria's rom. Think that might have something to do with it?
Click to expand...
Click to collapse
Contact me via msn at [email protected] I will try me best to help u, but eventually EquinoXe is the master here.
saa044 said:
Can you give us more detail to where you get the error and what it is? Also did you flash origenal rom with softspl or bootloader? Oh and if your device asks for permission to load the dll files it wont work.
Click to expand...
Click to collapse
Here is exactly what my device is doing:
I flash back to the official T-Mobile WM5 rom for the 2.26.0001 IPL/SPL adn then let customization finish and then try to softSpl but with no success. On my MDA, it asks me to confirm something and the screen never turns white like it is supposed to do.
I have tried this several ways and on 2 different roms.
I have tried flashing back to T-Mobile official but skip customization 2 times and use softSpl to flash faria's rom and it failed. I tried once after waiting untill customization is complete and installing faria's rom and it failed once again.
I also tried installing cert_SPCS.cab and installing enablerapi.cab prior to running softSpl 2 different times, once before customization and once after customization. both times failed. this time I was using Black Diamond 2.0 instead of faria's rom to see if it was just the rom.
Not once did I ever get the white screen and not once did it flash successfully using this method.(At least not for me)

How to remove SPL/IPL from an official ROM?

I installed Olipro Hard SPL and am now able to try any wm6 ROM without SPL.
After having tried many of them, I would like to downgrade and try the last Qtek shipped ROM for wizard: QT_FR_9100_2170706_21707106_20710_180406.
But no matter how I try, I'm now unable to install that wm5 ROM.
Even my former SPV M3000 shipped ROM refuse to re-install.
I guess it's either a problem of RUU, or more probably a problem of SPL on those ROM.
I'd like to remove their SPL, but I don't know how to do.
Any tutorial, advice, or special no ID RUU that fits well those wm5 ROM?
The actual problem with this Rom is the RUU.
It won't let you downgrade.
However it is wise to get rid of the IPL/SPL, for safety and for keeping the hard SPL.
You can use typho5.exe to disassemble the ROM in parts, and use nbftool to re-assemble it without using the IPL/SPL.
They are available in the ROM kitchens.
Use the ruu in the hard spl thread for flashing.
Thanks for the reply, Equinoxe.
Actually I've already tried many RUU, not only the Ruu already included in the official ROM.
Mun RUU etc. But no luck, all kind of error occured but the the flashing remains impossible.
I'll try to find the tools you told me about and see whether removing IPL/SPL makes it easier to flash those ROM.
If you know any special RUU suitable for such a downgrade, please, let me know.
riri22 said:
Thanks for the reply, Equinoxe.
Actually I've already tried many RUU, not only the Ruu already included in the official ROM.
Mun RUU etc. But no luck, all kind of error occured but the the flashing remains impossible.
I'll try to find the tools you told me about and see whether removing IPL/SPL makes it easier to flash those ROM.
If you know any special RUU suitable for such a downgrade, please, let me know.
Click to expand...
Click to collapse
If Mun's RUU didn't do the trick, you better use the CORE pro kitchen.
You can extract the parts with typho5.exe
usage:
typho5.exe -x nk.nbf
all the parts will be created/extracted
Delete all the IPL_1 IPL_2 SPL_1 and SPL_2 parts
use nbftool to reassemble the ROM. (read the PDf to see the starting addresses, although nbftool should be patched to show the right addresses)
Good luck
EquinoXe
the-equinoxe said:
If Mun's RUU didn't do the trick, you better use the CORE pro kitchen.
You can extract the parts with typho5.exe
usage:
typho5.exe -x nk.nbf
all the parts will be created/extracted
Delete all the IPL_1 IPL_2 SPL_1 and SPL_2 parts
use nbftool to reassemble the ROM. (read the PDf to see the starting addresses, although nbftool should be patched to show the right addresses)
Good luck
EquinoXe
Click to expand...
Click to collapse
Hi Equinox, thanks for the reply.
I started trying to get typho working, but all I could see was a brief command prompt and nothing else.
Finally, I ended up using Molski DevPack, which already includes those tools, in quite an ergonomic way.
After finding a guide about using those tools, It took me, no kidding about 10 mn for the whole process and 5 more to do the flashing.
I used nb2nbf_wizard to reassemble the ROM with only the parts I wanted to keep, including the extended ROM.
Regarding the address, it did it automatically, except for the HTC logo that I did manually, and also for the name of the Extended and Logo I renamed according to the sample jpeg showing that soft in action.
Since I kept the extended ROM and the original splash and logo screen, and I now have an authentic Qtek Wizard, just for fun.
But the most important is the feeling of building one's own ROM, according to your own taste and choice. Wonderful.
You were right: after having removed SPL/IPL and rebuilt the ROM, the Mun RUU worked flawlessly to flash my so called Qtek ROM onto my wizard.
In the meantime, It got rid of the pile of miscellanous splash screens and logos that were left since the install of all previous wm6 ROM.
Thanks again for the tips.
P.S.: the guide I used to understand how to use the Molski DevPack:
http://forum.xda-developers.com/showthread.php?t=320910&highlight=RUU_2001
Can't update rom anymore
Info about phone
WIZA200
IPL 2.21.0001
SPL 2.21.olip
GSM 02.19.11
OS 6.0.0.0
TNT_5.0_Wizard_TouchFLO
Windows XP
Active Sync 4.5 (Works Fine)
When i try to install another ROM i get communication error[224] : DEVICE NOT RESPONDING
When i try to install Cert_SPCS.cab or EnableRapi.cab or TomTom i get installation of xxxx.cab was unsuccessful.
Please help

Categories

Resources