I was recently given an LG Optimus L9 P769BK and decided to try and unlock the bootloader and root it. Most of the guides (such as: http://forum.xda-developers.com/showthread.php?t=2584997) suggest flashing to V10G_00 first before flashing to the EU V20B_00. I was able to flash to V10G (from V20H that was already on the phone using "LG Flash Tool 2014") but now, no matter what tool I use, I am unable to get ANY ROM to flash to the phone.
Methods/Tools used and the results:
1)http://forum.xda-developers.com/showthread.php?t=2085344
1a)Result: The software that is launched in Step 10 crashes before doing any updating
2)http://forum.xda-developers.com/optimus-l9/general/p765-unbrick-using-lg-flash-tool-2014-t2950433
2a) Using CDMA + Diag or Emergency: Goes to 10% of SW Update then fails with an error saying to remove the battery and try again. Doing this does not resolve the problem
2b) Using 3GQCT + Diag or Emergency: Can not connect to phone. Reseating the connection and power cycling the phone does not resolve this.
3) http://forum.xda-developers.com/showthread.php?t=2748384
3a)Using the LGP769_20121004_LGFLASHv1350.dll and a bin from V20B_00 it freezes around 570 seconds with a write error. The phone no longer boots outside of SW Update Mode.
The phone will now only boot into SW Update mode.
System:
OS: Windows 8.1 64bit
Drivers: LGUnitedMobileDriver_S52MAN314AP22_ML_WHQL_Ver_3.14.1
Any thoughts on what to do next?
UPDATE: The LG Flash Tool mentioned in 3) no longer sees the phone. After following the steps mentioned in the guide again
UPDATE2: Reinstalled the drivers. Method 1) still crashes, 2) same results, 3) still not "seeing" the phone when connected.
UPDATE3: (using Win 7 machine). Method 2) gives an odd "Can not connect to server error" when tried. Method 3) gives a write error on "Failed to Write OMAP" (ill get the exact line in a minute)
UPDATE4: Ignoring the error (aka NOT clicking the box) from Method 2) allowed the phone to flash with no problem
Only the very first v10a had an unlockable bootloader. And the first couple of v20ies or all of them. I unlocked and rooted with v20c, later versions could have locked Bls.
My phone actually has an encrypted bootloader so no ROM will work
I have no soldering skills so I ordered a 910k cable and will do the unlock with it.
Hi Everyone,
Well I have an OBI SJ-1-5 SmartPhone which is not working now as I was trying to Flash a Stock ROM via SP Flash Tool.
I was trying to unlock the bootloader via "fastboot oem unlock" command in fastboot mode. The result was "ok". This device also has "allow bootloader to be unlocked" feature in developer options which was set to "on" while I was doing it. During the process of unlocking it shows some warning message that whole device would be reset, I agree and continue. After which it got stuck and I've to use "fastboot reboot" command, which result in continuous boot loop. Then i was not able to go into recovery or do anything.
I then do some google fu and found Stock ROM which aren't compatible to the device as it was showing the error "PMT has changed for the ROM". Which i sort out somehow. In the mean time I forget to unchecked the "Preloader" option, and unfortunately the new Stock ROM* has incompatible preloader with my Device. Resulting in a Complete Brick of my SmartPhone giving me "BROM ERROR: S_FT_ENABLE_DRAM_FAIL (0xFC0)" error both while doing "Format whole Flash" and "Format whole flash except Bootloader", even "Download" option gives me the same error.
Fortunately I have another pair of same Model so I thought to Dump the Stock ROM including the preloader files and Update my brick cellphone with it. I know the procedure of "Readback", so to grab the "scatter" file I used "MTKdroidTools" which again unfortunately unable to create the "root shell" for my device neither I was able to save the scatter file(the save button was disabled) because my device is MediaTek 6580 which is unsupported to use with "MTKdroidTools". My other cellphone is not Rooted and Rooting is the whole reason I now have a Brick Cellphone so I am not gonna take risk again doing something with that new device .
Which leave me the last option of Using a Hardware Device like "Magic Box" or "Volcano Box" to DUMP firmware. And that I don't have and neither I can somehow get my hands onto it.
But I "think" I can get my cellphone back to life if I would find a ROM of a device with Similar board id and Flash its ROM using (Format+Download). After that it would allow me to use "Auto Format except Bootloader". After which I could flash the ROM that was giving me (0xFC0) error (without ticking the preloader).
Details of SJ1-5
Chipset: MediaTek 6580
Root : No
Build Number : Obi_SJ1-5_B1B8_Ver3.6
Kernal Version : 3.10.72
Android Version : 5.1
Android Security Patch Level : 2016-01-01
*The ROM I tried : Obi_SJ1.5_MT6580_5.1_v1.7.1_151014_144940
I hope someone can provide me the DUMPed Stock ROM from a working Device. I would really appreciate that. And please let me know if there is any other Method that I missed. Sorry for my bad English.
Thank you all in Advance.
Same problem here. As always with mtk phones it is problematic and very risky to find working/compatable scatter and rom. Same story, flashed wrong preloader and now the phone in boot loop. Thinking to connect directly to a serial but i need a correct rom for a start. If anyone has a dumb of this phone please contact me at [email protected]
Hi All,
at the beginning I'll write a brief what happened. I'm using Xiaomi MI 5. Last week phone just turn off and after this I was unable to turn it on - no response. I started with checking battery contacts and after pushing plugs device turn on, but unfortunately in bootloop. I started to search for any information how to repair, so at first I tried to wipe all data by recovery mode, but it not helped. At next step I flashed phone with new firmawe - I had to do it by testpoints method, because bootloader is blocked and I was unable to unlock this since device is broken (as I saw in tutorial it's needed to bind device with account by Android which wasn't work obviously). Device with new firmware started to work but not recognizing any SIM card - I've checked in options an there is no IMEI. I found tutorial how to repair IMEI and for now I have ready QCN file to upgrade device by QPST software, but there is a problem with entering a phone in diagnostic mode. I used a code "*#*#717717#*#*" but I have a problem with part listed below, because it's demanding super user account:
"adb shell
su
dd if=/dev/zero of=/dev/block/sde28
dd if=/dev/zero of=/dev/block/sdf3
dd if=/dev/zero of=/dev/block/sdf5"
I don't have a root and for now it isn't possible to root device, because there is still blocked bootloader. I tried to unlock device since Android is working again but because there is no IMEI I get errors during binding, so i suppose it's impossible to do without IMEI.
In QPST device is only visible when it's in EDL mode by testpoints method, but I can't upload QCN file bacause I get error: Phone isn't in diagnostic mode.
So what I need for now is to enter device into diagnostic mode somehow and that's why I decided to make a new topic, because at first I've searched many forums and threads but I was unable to find working solution. Please help me if you have any ideas. Thanks!
Resolved
Hi all,
I've manage this problem.
This is how I succeed - maybe it will be helpful for someone
First of all I found a Thread with Mi 5 qualcolm diagnostic drivers. After installing these drivers device was recognized by QPST as in diagnostic mode. Unfortunately another problem came up. "Invalid command from device". I did quick research and it was related to broken EFS, so I needed reapair/reset EFS - but theorically it was impossible without root and for rooting device unlocked bootloader is needed (my is blocked). So finally I found a dial code for EFS reset:
*#*#25327337#*#*
It helped. After this all what I needed to do was to check box in QPST "Allow ESN mismatch" and it successfully wrote QCN file.
Now my IMEI is back
Regards
Hi, I have a Huawei Mate 10 pro BLA-L29 C432 with unlocked bootloader frp unlocked that is hard bricked.
Reason why it was hard bricked was using HWota and flashing the wrong files
The device shows up in device manager as USB COM 1.0 (COM4) along with COMMUNICATIONS PORT (COM 1).
I have purchased the DC Phoneix + HCU timed license for 3 days ending on 3/4/2019 at 9 AM.
I have downloaded the "BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT.dgtks" board firmware directly from DC Phoenix
I have also downloaded the "BLA-L29C_8.0.0.115(C432)_Firmware_Lithuania_Latvia_Norway_Romania_Hungary_Greece_Austria_Czech_Republic_Bulgaria_Poland_Slovenia_Croatia_Serbia_Nonspecific.app" appfile directly from DC Phoenix
I begin by selecting the "BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT" file in the update file selection. Then i select the "BLA-L29C_8.0.0.115(C432)_Firmware_Lithuania_Latvia_Norway_Romania_Hungary_Greece_Austria_Czech_Republic_Bulgaria_Poland_Slovenia_Croatia_Serbia_Nonspecific.app" file in the update app file selection.
I click update and am provided with the following error message to the left of the screen
File to update: BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT.dgtks
Device detected:
COM4: HUAWEI USB COM 1.0 (COM4)
Writing bootloader...
Writing BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT_3.dtwork...
Error writing Bootloader
3/1/2019 1:09:05 PM Writing device finished - INCOMPLETE
I then proceeded to try the "use bootloader" option under the udpate oeminfo tab and chosen the Kiring970_T2_A8.0_V3
and i have successfully gotten my device to be recognized as follows
Looking for a device in fastboot mode
Device found: AQH7N17B29009368
SN:AQ********************* <- i have censored the following information intentionally
IMEI:866******************* <- i have censored the following information intentionally
IMEI1:86******************* <- i have censored the following information intentionally
MEID:A******************** <- i have censored the following information intentionally
Build number: :BLA-L29 8.0.0.158(C432)
Model: BLA-L29
Battery state: 0
When writing the board file, I get the following
Erasing nvme partition
ERASE partition nvme : FAIL failed to erase partition
Device with unsupported security patch
3/2/2019 11:47:18 AM Writing device finished OK
when writing the update.app file directly from dc-phoenix i get the following error
Extracting partition XLOADER...
Writing XLOADER partition
XLOADER partition UPDATE :FAIL download elf_xloader image verification error
Device with unsupported security patch
3/2/2019 12:02:09 PM Writing device finished - INCOMPLETE
i then though, okay let me try another more rescent .app file, so i downloaded the 8.0.0.158 BLA-L29 c432 "update.zip" file from the internet. I extracted the "UPDATE.APP" file and then selected it in DC-Phoneix and now i get the following message
Attention, this is OTA type file and can't be written via software. Writing it via fastboot may damage the phone. Please use files from our support area.
so I select no, because of this error. I chose to download more "update.zip" files from the internet, and they all give me this attention message.
i then proceeded to use huawei extractor tool to extract kernel,ramdisk,recovery_ramdisk, recovery_vbmeta, and recovery_vendor. I flashed them through fastboot successfully, but no life from the device. As a matter of fact, when i disconnect the device, I have to start from scratch again.
I am really running out of ideas here. =(
Chito307 said:
Hi, I have a Huawei Mate 10 pro BLA-L29 C432 with unlocked bootloader frp unlocked that is hard bricked.
Reason why it was hard bricked was using HWota and flashing the wrong files
The device shows up in device manager as USB COM 1.0 (COM4) along with COMMUNICATIONS PORT (COM 1).
I have purchased the DC Phoneix + HCU timed license for 3 days ending on 3/4/2019 at 9 AM.
I have downloaded the "BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT.dgtks" board firmware directly from DC Phoenix
I have also downloaded the "BLA-L29C_8.0.0.115(C432)_Firmware_Lithuania_Latvia_Norway_Romania_Hungary_Greece_Austria_Czech_Republic_Bulgaria_Poland_Slovenia_Croatia_Serbia_Nonspecific.app" appfile directly from DC Phoenix
I begin by selecting the "BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT" file in the update file selection. Then i select the "BLA-L29C_8.0.0.115(C432)_Firmware_Lithuania_Latvia_Norway_Romania_Hungary_Greece_Austria_Czech_Republic_Bulgaria_Poland_Slovenia_Croatia_Serbia_Nonspecific.app" file in the update app file selection.
I click update and am provided with the following error message to the left of the screen
File to update: BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT.dgtks
Device detected:
COM4: HUAWEI USB COM 1.0 (COM4)
Writing bootloader...
Writing BLA-AL00B_1.0.0.35_Board_Software_China_Nonspecific_An droid_8.0.0_EMUI_8.0.0_05022FPT_3.dtwork...
Error writing Bootloader
3/1/2019 1:09:05 PM Writing device finished - INCOMPLETE
I then proceeded to try the "use bootloader" option under the udpate oeminfo tab and chosen the Kiring970_T2_A8.0_V3
and i have successfully gotten my device to be recognized as follows
Looking for a device in fastboot mode
Device found: AQH7N17B29009368
SN:AQ********************* <- i have censored the following information intentionally
IMEI:866******************* <- i have censored the following information intentionally
IMEI1:86******************* <- i have censored the following information intentionally
MEID:A******************** <- i have censored the following information intentionally
Build number: :BLA-L29 8.0.0.158(C432)
Model: BLA-L29
Battery state: 0
When writing the board file, I get the following
Erasing nvme partition
ERASE partition nvme : FAIL failed to erase partition
Device with unsupported security patch
3/2/2019 11:47:18 AM Writing device finished OK
when writing the update.app file directly from dc-phoenix i get the following error
Extracting partition XLOADER...
Writing XLOADER partition
XLOADER partition UPDATE :FAIL download elf_xloader image verification error
Device with unsupported security patch
3/2/2019 12:02:09 PM Writing device finished - INCOMPLETE
i then though, okay let me try another more rescent .app file, so i downloaded the 8.0.0.158 BLA-L29 c432 "update.zip" file from the internet. I extracted the "UPDATE.APP" file and then selected it in DC-Phoneix and now i get the following message
Attention, this is OTA type file and can't be written via software. Writing it via fastboot may damage the phone. Please use files from our support area.
so I select no, because of this error. I chose to download more "update.zip" files from the internet, and they all give me this attention message.
i then proceeded to use huawei extractor tool to extract kernel,ramdisk,recovery_ramdisk, recovery_vbmeta, and recovery_vendor. I flashed them through fastboot successfully, but no life from the device. As a matter of fact, when i disconnect the device, I have to start from scratch again.
I am really running out of ideas here. =(
Click to expand...
Click to collapse
sorry bro i never ran into situation like this
only pray for you
Anyone? =(
Chito307 said:
Anyone? =(
Click to expand...
Click to collapse
you already done what may be possible to recover
huawei can do it if it is in warranty
It's seems that the error is right there , the security patch isn't supported so it won't finish writing the files, it is stated in DC locker that some devices like mate 10 pro and newer devices are not supported the same reason why there are no new unlocked codes for bootloader on DC unlock and no new unlocked codes for sim also, have your tried flashing those files yourself through fastboot method ? With out the hcu from DC
?
I had same problème
Now phone is OK but IMEI 000000000000
This worked for me, it requires IDT and unencrypted board firmware (these are usually paid). dtgks might work if you only flash board firmware, but you have to be careful so it doesn't wipe oeminfo (if you still want to unlock after. You can still get unlock code through HCU on board firmware so it doesn't really matter).
Edit xml that comes with unencrypted board so it doesn't erase oeminfo.
Flash bootloader files with DC, phone is put in fastboot mode.
Open up IDT.
Select xml in both settings of IDT and in settings of USBMAP. In USBMAP, select com port in the list and click on Skip.
Now start flashing using IDT.
When flashing is done phone will boot to board firmware.
When on board firmware, follow this guide to get your imeis and that stuff back:
1)Flash board (already done)
2)Flash oeminfo from fastboot (own backup if available, if you edited xml you will still have your own oeminfo flashed)
3) Dump modemnvm_system, modemnvm_factory and modemnvm_backup partitions using dd and adb shell ('dd if=/dev/block/bootdevice/by-name/modemnvm_system of=/sdcard/modemnvm_system.img' and so on), board firmware has global root so you don't need to flash Magisk or anything like that (which is impossible anyway, board fw will only accept board or stock images)
4)Flash dumped modemnvm_system, modemnvm_factory and modemnvm_backup using fastboot
5)Modify and brand with HCU (check all checkboxes except the last 2, fill in any missing info)
6)Unlock Sim network with HCU
7)If you previously used HCU to get unlock code you need to generate it again (HCU patches oeminfo so their unlock code works). Also if you forgot to edit xml you'd have to generate a new code, your old code will not work if oeminfo was wiped.
8)Use dload with Service Firmware from androidhost.ru, regular update.zip does not work in dload mode.
And make sure the firmware you dload is newer than GPU Turbo firmware. (XLOADER needs to be 02, else you brick again)
Please note that you only have one shot at this... If you, for example, flash dload but forget to generate unlock code and don't have your own oeminfo flashed you will not be able to repair device without opening it up to get testpoint.
ante0 said:
it requires IDT
Click to expand...
Click to collapse
What is IDT ?
badmania98 said:
What is IDT ?
Click to expand...
Click to collapse
Image Download Tool, some leaked tool (like Odin for Samsung).
It's available on androidhost.ru iirc
I need dload with Service Firmware please
I flashed with many firmware no seccess
ante0 said:
This worked for me, it requires IDT and unencrypted board firmware (these are usually paid). dtgks might work if you only flash board firmware, but you have to be careful so it doesn't wipe oeminfo (if you still want to unlock after. You can still get unlock code through HCU on board firmware so it doesn't really matter).
Edit xml that comes with unencrypted board so it doesn't erase oeminfo.
Flash bootloader files with DC, phone is put in fastboot mode.
Open up IDT.
Select xml in both settings of IDT and in settings of USBMAP. In USBMAP, select com port in the list and click on Skip.
Now start flashing using IDT.
When flashing is done phone will boot to board firmware.
When on board firmware, follow this guide to get your imeis and that stuff back:
1)Flash board (already done)
2)Flash oeminfo from fastboot (own backup if available, if you edited xml you will still have your own oeminfo flashed)
3) Dump modemnvm_system, modemnvm_factory and modemnvm_backup partitions using dd and adb shell ('dd if=/dev/block/bootdevice/by-name/modemnvm_system of=/sdcard/modemnvm_system.img' and so on), board firmware has global root so you don't need to flash Magisk or anything like that (which is impossible anyway, board fw will only accept board or stock images)
4)Flash dumped modemnvm_system, modemnvm_factory and modemnvm_backup using fastboot
5)Modify and brand with HCU (check all checkboxes except the last 2, fill in any missing info)
6)Unlock Sim network with HCU
7)If you previously used HCU to get unlock code you need to generate it again (HCU patches oeminfo so their unlock code works). Also if you forgot to edit xml you'd have to generate a new code, your old code will not work if oeminfo was wiped.
8)Use dload with Service Firmware from androidhost.ru, regular update.zip does not work in dload mode.
And make sure the firmware you dload is newer than GPU Turbo firmware. (XLOADER needs to be 02, else you brick again)
Please note that you only have one shot at this... If you, for example, flash dload but forget to generate unlock code and don't have your own oeminfo flashed you will not be able to repair device without opening it up to get testpoint.
Click to expand...
Click to collapse
Hello
I do every thing on the tuto but i have 1 problem
I have no network it still no service
Hi folks,
my trusty S3 (SM-T825) got broke unexpectedly. It showed "100% battery" in the morning but was unresponsive. A forced shutdown did reboot the device up to the logo-screen - from where it rebooted again. So obviously it's stuck in a boot loop.
Unfortunately, it does not enter "recovery" either (home) (up) (power). However, it DOES enter "ODIN mode" (home) (down) (power). There it shows me that FRP Lock and OEM lock both are still active. This is no wonder as it caught me unprepared. FRP lock wouldn't be a problem, as I'm the owner of the account and can supply credentials once it boots up again.
Everywhere it is STRONGLY advised to turn off OEM lock before flashing anything to not make it even worse. This renders the device essentially dead, right?
The device is still as original as it can be.
Any chance I can revive it or does that more look like a mainboard problem?
I already have ODIN and I even have an actual 4-part "Original ROM" for my region (Samfw.com_SM-T825_ATO_T825XXU3CTD1_fac.zip), but maybe TWRP and Lineage would be the better options.
Before I just go and make things worse, I'd like to ask for a qualified advice ;-)
smallfreak said:
...... There it shows me that FRP Lock and OEM lock both are still active. This is no wonder as it caught me unprepared. FRP lock wouldn't be a problem, as I'm the owner of the account and can supply credentials once it boots up again.
Everywhere it is STRONGLY advised to turn off OEM lock before flashing anything to not make it even worse. This renders the device essentially dead, right?
Click to expand...
Click to collapse
Afaik you should be able to flash stock with OEM lock active BUT idk if FRP will block flashing process.
If that happens it's imo afterwards in the same state as before so at least it won't worsen it.
Gonna loose all your data anyhow.
Got Smartswitch? This might help as well.
smallfreak said:
....... I already have ODIN and I even have an actual 4-part "Original ROM" for my region (Samfw.com_SM-T825_ATO_T825XXU3CTD1_fac.zip), but maybe TWRP and Lineage would be the better options.
Click to expand...
Click to collapse
You can't replace recovery without OEM unlock.
smallfreak said:
Before I just go and make things worse, I'd like to ask for a qualified advice ;-)
Click to expand...
Click to collapse
Dunno if I'm qualified enough
Next turn ...
I tried flashing TWRP into the AP slot with SamFW FRP-Tool (ODIN). This worked so far but got me a note on the tablet "custom recovery blocked due to FRP lock".
Checking boot on the tablet - as before. Boot loop.
Next turn ...
Code:
Select file AP_T825XXU3CTD1_CL17011592_QB30231355_REV00_user_low_ship_MULTI_CERT_meta_OS9.tar.md5
Select file CP_T825XXU3CTA1_CP14962504_CL17011592_QB28791445_REV00_user_low_ship_MULTI_CERT.tar.md5
Select file CSC_ATO_T825ATO3CTD1_CL18361310_QB30233690_REV00_user_low_ship_MULTI_CERT.tar.md5
Reading... OK
Detect mode: Download mode
Model : SM-T825
Bit : 4
Unique number : CBJ100915EAF124
Storage : 32
Vendor : SAMSUNG
Disk : BJNB4R
Firmware : https://samfw.com/firmware/SM-T825/
Analyze files...
Flashing with SAMSUNG Mobile USB Modem (COM5)
Flash failed
Flash time: 00:47
Reading... FAIL
unchecking CP and CSC, leaving only AP.
Code:
Analyze files...
Flashing with SAMSUNG Mobile USB Modem (COM5)
Flash failed
Flash time: 10:00
Reading... FAIL
Reboot tablet in download-mode, next turn: Try BL + AP:
Code:
Select file BL_T825XXU3CTD1_CL17011592_QB30231355_REV00_user_low_ship_MULTI_CERT.tar.md5
Reading... OK
Detect mode: Download mode
Model : SM-T825
Bit : 4
Unique number : CBJ100915EAF124
Storage : 32
Vendor : SAMSUNG
Disk : BJNB4R
Firmware : https://samfw.com/firmware/SM-T825/
Analyze files...
Flashing with SAMSUNG Mobile USB Modem (COM5)
Checking file BL_T825XXU3CTD1_CL17011592_QB30231355_REV00_user_low_ship_MULTI_CERT.tar.md5
Checking file AP_T825XXU3CTD1_CL17011592_QB30231355_REV00_user_low_ship_MULTI_CERT_meta_OS9.tar.md5
Flashing (1/20) emmc_appsboot.mbn.lz4 OK
Flashing (2/20) lksecapp.mbn.lz4 OK
Flashing (3/20) xbl.elf.lz4Flash failed
Flash time: 01:26
Tablet moans about
SW REV CHECK FAIL : [lksecapp] Fused -1 > Binary 0
Click to expand...
Click to collapse
So maybe the firmware revision is different to the currently installed one? The latest file is from 2020 and since I did the usual OTA updates, this should be the version installed. But even if not, it sould not matter to upload a newer one, right?
Anything I can check?
So then obviously "Game Over"
Another piece of expensive waste that otherwise could have served well for years to come. Yes I know, selling something just once is an inferior business model to repeatedly draining my account for the same service.