Any way to flash the X02T? - TG01 General

Just wondering I see info for the other 2 models but not much on the X02T. I want to flash my brothers to an English rom but I also dont want to brick it for him >.<

First,you should have the install file of X02T.Ask softbank to obtain it...

What install file? I am not in Japan my brother is >.< and he said they dont support English at all.

The file is used for setup window phone.
file has the extension as tsd(T01A),tsw(TG01).Maybe in X02T ,it's tss

Hi, Okawa.
I have one idea of X02T.
We have already had the key to Encryption of two models that is TG01 and T01A(great thanks for cotulla).
I checked the key to two models.
There is a key that is actually used as follows.
-------------------------------
TG01 DES Key(Mode ECB)
[(4 or 5)(4 or 5)(4 or 5)(6 or 7)(0 or 1)(0 or 1)(4 or 5)(2 or 3)]
Key = 54470152(Cotulla), 45561043 and 44460042 etc.
T01A DES Key(Mode ECB)
[(4 or 5)(4 or 5)(4 or 5)(6 or 7)(0 or 1)(0 or 1)(4 or 5)(4 or 5)]
Key = 54460044(Cotulla) and 44460044(2channel) etc.
-------------------------------
I suppose the following from these things.
[TG01(Key is 44460042)→ T01A(Key is 44460044)→ X02T?(Key is 44460046 or 8)]
So, I guess X02T DES Key is 44460046 or 44460048, perhaps this Key is tss.
But, we do not have official Softibank ROM.
Therefore, you can not return Softibank ROM from your ROM if you Flashed.
(The method of how to make available ROM from RAW has not found yet. Maybe,)
However, if you try this key to X02T, I yell for you.(not beer )
If this my article is useful for you, I am glad.
Thanks.

I think we need wait for SoftBank ROM update, maybe 6.5.3, but not sure.

I think we need wait for SoftBank ROM update, maybe 6.5.3, but not sure.
Click to expand...
Click to collapse
I confirmed Rebuild is possible that BIN(T01A.bin) from RAW(Part01 and Part02.RAW) by l3v5y-TG01-Kitchen.
Your SoftBank ROM will be able to be made by yourself.
Please try it.

this guy find a way to flash UK orange ROM in the X02T , try this
http://forum.xda-developers.com/showthread.php?t=625198&page=2

yamadori said:
I confirmed Rebuild is possible that BIN(T01A.bin) from RAW(Part01 and Part02.RAW) by l3v5y-TG01-Kitchen.
Your SoftBank ROM will be able to be made by yourself.
Please try it.
Click to expand...
Click to collapse
my phone still have the official softbank rom. i can make a BIN of this rom too? you can link the page for T01A BIN plz.

my phone still have the official softbank rom. i can make a BIN of this rom too? you can link the page for T01A BIN plz.
Click to expand...
Click to collapse
I do not have X02T. It is only T01A that I have.
I dumped Part01.RAW and Part02.RAW from my T01A upgraded to WM6.5.
T01A.BIN that I made from RAW is 252,358,656 bytes.
Data Program
261.16 MB 204.88 MB
32.19 MB 136.34 MB
228.97 MB 68.54 MB
Click to expand...
Click to collapse
Official T01A_to_SP50_wm65.bin is 272,093,184 bytes.
Data Program
260.54 MB 204.88 MB
32.19 MB 135.38 MB
228.35 MB 69.50 MB
Click to expand...
Click to collapse
It operates normally though two are slightly different.
If you want to T01A.BIN, you can make it from official T01A_to_SP50_wm65.tsd by using TGTool.exe.
code:
tgtool -t01a -sp T01A_to_SP50_wm65.tsd os.nb.payload
tgtool -t01a -mp os.nb.payload T01A_to_SP50_wm65.tsd T01A_to_SP50_wm65.bin
Click to expand...
Click to collapse
If you dump RAW files from your X02T, and you gives those to me, I might be able to make X02T.BIN and X02T.TSS(Encryption is 44460046 and 44460048).
But, I am not certain whether Complete SoftBank ROM can be made from RAW files.(I do not know Boot-logo replace. IPL necessary?)
I can cooperate in you.

yamadori said:
I do not have X02T. It is only T01A that I have.
I dumped Part01.RAW and Part02.RAW from my T01A upgraded to WM6.5.
T01A.BIN that I made from RAW is 252,358,656 bytes.
Official T01A_to_SP50_wm65.bin is 272,093,184 bytes.
It operates normally though two are slightly different.
If you want to T01A.BIN, you can make it from official T01A_to_SP50_wm65.tsd by using TGTool.exe.
If you dump RAW files from your X02T, and you gives those to me, I might be able to make X02T.BIN and X02T.TSS(Encryption is 44460046 and 44460048).
But, I am not certain whether Complete SoftBank ROM can be made from RAW files.(I do not know Boot-logo replace. IPL necessary?)
I can cooperate in you.
Click to expand...
Click to collapse
Thanks for you help friend, of course i will give you the files, but first, who i can make the dump RAW files?

Thanks for you help friend, of course i will give you the files, but first, who i can make the dump RAW files?
Click to expand...
Click to collapse
Tanx
You can get RAW files by the following method.
I referred to "HTC Touch Pro DUMP by RezzZ".
1.open a reg editor on your X02T
2.change:
HKLM\Security\Policies\Policies
valuename '00001001'was set to dword:2, change it to dword:1
3.download [itsutilsbin]
extract the zip file and open cmd in that folder
4.ActiveSync
5.run (in cmd):
“pdocread.exe -l > t01a65.txt”(example)
t01a65.txt is this
--------------------------------------
433.13M (0x1b120000) DSK1:
| 1.50M (0x17f000) Part00
| 3.63M (0x3a0000) Part01
| 166.38M (0xa660000) Part02
| 261.63M (0x105a0000) Part03
14.97G (0x3bdd80000) DSK2:
| 14.96G (0x3bd980000) Part00
STRG handles:
handle 4dfe3d3e 14.96G (0x3bd980000)
handle ae3e984a261.63M (0x105a0000)
handle ee4ac79a166.38M (0xa660000)
handle ce4ac776 3.63M (0x3a0000)
handle ee4ac72e 1.50M (0x17f000)
--------------------------------------
6.run (in cmd):
“pdocread -w -h 0xee4ac72e -b 0x800 0 0x17f000 Part00.raw”
“pdocread -w -h 0xce4ac776 -b 0x800 0 0x3a0000 Part01.raw”
“pdocread -w -h 0xee4ac79a -b 0x800 0 0xa660000 Part02.raw”
“pdocread -w -h 0xae3e984a -b 0x800 0 0x105a0000 Part03.raw”
I recommend dump from your X02T after backup and hard reset.

ok i will try this saturday

The X02T-65.txt is:
------------------------------------------------------------------------------------
9.63M (0x9a0000) DSK1:
| 9.62M (0x99f000) Part00
423.00M (0x1a700000) DSK2:
| 1.62M (0x19f000) Part00
| 3.75M (0x3c0000) Part01
| 159.88M (0x9fe0000) Part02
| 257.75M (0x101c0000) Part03
7.42G (0x1daf80000) DSK3:
| 7.42G (0x1dab80000) Part00
STRG handles:
handle#0 8dda3d4a 7.42G (0x1dab80000)
handle#1 6e1e7b2e 257.75M (0x101c0000)
handle#2 ee1ed89e 159.88M (0x9fe0000)
handle#3 4e1ed87a 3.75M (0x3c0000)
handle#4 4e1ed832 1.62M (0x19f000)
handle#5 ee4ac72e 9.62M (0x99f000)
disk 8dda3d4a
0 partitions, 0 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
disk 6e1e7b2e
0 partitions, 0 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
disk ee1ed89e
0 partitions, 0 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
disk 4e1ed87a
0 partitions, 0 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
disk 4e1ed832
0 partitions, 0 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
disk ee4ac72e
0 partitions, 0 binary partitions
customerid=00000000 uniqueid= 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

because the TXT file not is same (x02t have 1 more file) i need increase a Part04.raw
i use this command's:
pdocread -w -h 0xee4ac72e -b 0x800 0 0x17f000 Part00.raw
CopyTFFSToFile(0x0, 0x17f000, Part00.raw)
pdocread -w -h 0x4e1ed832 -b 0x800 0 0x19f000 Part01.raw
CopyTFFSToFile(0x0, 0x19f000, Part01.raw)
pdocread -w -h 0x4e1ed87a -b 0x800 0 0x3c0000 Part02.raw
CopyTFFSToFile(0x0, 0x3c0000, Part02.raw)
pdocread -w -h 0xee1ed89e -b 0x800 0 0x9fe0000 Part03.raw
CopyTFFSToFile(0x0, 0x9fe0000, Part03.raw)
pdocread -w -h 0x6e1e7b2e -b 0x800 0 0x101c0000 Part04.raw
CopyTFFSToFile(0x0, 0x101c0000, Part04.raw)

eekthecat said:
because the TXT file not is same (x02t have 1 more file) i need increase a Part04.raw
i use this command's:
pdocread -w -h 0xee4ac72e -b 0x800 0 0x17f000 Part00.raw
CopyTFFSToFile(0x0, 0x17f000, Part00.raw)
pdocread -w -h 0x4e1ed832 -b 0x800 0 0x19f000 Part01.raw
CopyTFFSToFile(0x0, 0x19f000, Part01.raw)
pdocread -w -h 0x4e1ed87a -b 0x800 0 0x3c0000 Part02.raw
CopyTFFSToFile(0x0, 0x3c0000, Part02.raw)
pdocread -w -h 0xee1ed89e -b 0x800 0 0x9fe0000 Part03.raw
CopyTFFSToFile(0x0, 0x9fe0000, Part03.raw)
pdocread -w -h 0x6e1e7b2e -b 0x800 0 0x101c0000 Part04.raw
CopyTFFSToFile(0x0, 0x101c0000, Part04.raw)
Click to expand...
Click to collapse
i make a mistake in Part00.raw, and do it command for make a new file
pdocread -w -h 0xee4ac72e -b 0x800 0 0x99f000 Part00.raw
CopyTFFSToFile(0x0, 0x99f000, Part00.raw)

RAW files are here.
http://cid-5bf4bd469b8aef18.skydrive.live.com/browse.aspx/X02T
thanks very much

Thanks friend for your work and RAW files.
Your report is very interesting.
The partition is divided in the X02T ROM case. I guess that the first one is used for Extended ROM. (Files necessary for the first setting are stored here, maybe.)
And, if the size of the RAW files from your report is compared, the command is as follows.
pdocread -w -h 0x4e1ed832 -b 0x800 0 0x19f000 Part00.raw
pdocread -w -h 0x4e1ed87a -b 0x800 0 0x3c0000 Part01.raw
pdocread -w -h 0xee1ed89e -b 0x800 0 0x9fe0000 Part02.raw
pdocread -w -h 0x6e1e7b2e -b 0x800 0 0x101c0000 Part03.raw
(pdocread -w -h 0xee4ac72e -b 0x800 0 0x99f000 ExtROM.raw)
Therefore, your RAW files becomes as follows.
Part00.raw → ExtROM.raw (9.62M)
Part01.raw → Part00.raw (1.62M)
Part02.raw → Part01.raw (3.75M)
Part03.raw → Part02.raw (159.88M)
Part04.raw → Part03.raw (257.75M)
By the way,
If you change the Registry Key of your X02T as follows, you can see ExtROM, perhaps.
HKEY_LOCAL_MACHINE\System\StorageManager\AutoLoad\EXT_FLASHDRV
"Bootphase"=dword:00000002
HKEY_LOCAL_MACHINE\System\StorageManager\Profiles\EXT_FLASHDRV
"MountHidden"=dword:00000000
I think that X02T is different from T01A and TG01.
I was going to do that you extracted ROM (from the head of the whole ROM image to just before Part01.RAW by using pmemdump), against your X02T bootloader break by any accident. But, the necessity is lost
In conclusion, I cannot make SoftBank ROM for X02T.
I am regrettable.
However, I will be able to make SoftBank ROM for TG01. OK or not?
If OK, please reply to which Encryption form you hope.
[bin, tsw, tsd or tss?(Encryption is 44460046 and 44460048. However, when this is used for X02T, it can not be returned. )]

But this SoftBank ROM for TG01, will work in my X02T?

By the way,
If you change the Registry Key of your X02T as follows, you can see ExtROM, perhaps.
HKEY_LOCAL_MACHINE\System\StorageManager\AutoLoad\ EXT_FLASHDRV
"Bootphase"=dword:00000002
HKEY_LOCAL_MACHINE\System\StorageManager\Profiles\ EXT_FLASHDRV
"MountHidden"=dword:00000000
I try but i cant create a new folder (EXT_FLASHDRV), i are using PHM RegEdit, have another way to create new folder in registry?

Related

How to backup my French Orange rom V 14.123.2.733 (OS 1.23.73.3 - R 1.06.00.00)

I have in hand a SPV M3100 from orange and would like to backup the rom.
Can someone help me with this ?
I have done those command already, but don't know what to do after. This is new for me and would like to finalyse this has this rom is new.
pdocread -w -d FLASHDR -p Part00 0 0x31fc00 Part00.raw
pdocread -w -d FLASHDR -p Part01 0 0x2e0000 Part01.raw
pdocread -w -d FLASHDR -p Part02 0 0x32e0000 Part02_0.raw
pdocread -w -d FLASHDR -p Part02 0x2610000 0x800 Part02_1.raw
pdocread -w -d FLASHDR -p Part02 0x2610800 0xccf800 Part02_2.raw
Thanks in advance for the one who will help me....
>
Version d'Opérateur : 14.123.2.733
Version de ROM : 1.23.73.3
Version de Radio :1.06.00.00
Read Upgrading FAQs question #8:
http://wiki.xda-developers.com/index.php?pagename=Hermes_UpgradeFAQ
hi,
i got a german orange spv m3100 , is it possible to use a backup from a french spv m3100?
Theoretically you can use pdocwrite to rewrite the OS portion of the ROM, but I think no one has tried this on the hermes.

Niki ROM Dump - Strange Error ?

from what I understand, in order to dump our Niki/Touch Dual ROMs, instructions are similar to the Kaiser procedure, meaning :
1) download pdocread.exe from http://wiki.xda-developers.com/wiki/XdaUtils/pdocread.exe
2) open command prompt on your PC, then run : "pdocread.exe -l"
3) dump NAND partitions :
pdocread -w -d FLASHDR -b 0x800 -p Part00 0 0x31f000 Part00.raw
pdocread -w -d FLASHDR -b 0x800 -p Part01 0 0x380000 Part01.raw
pdocread -w -d FLASHDR -b 0x800 -p Part02 0 0x4560000 Part02.raw
pdocread -w -d FLASHDR -b 0x800 -p Part03 0 0x8660000 Part03.raw
However, when i try to run "pdocread.exe -l", i get the attached windows error pop-up... Anyone got this error also ?
What OS you use?
WinXP 32Bit, WinXP 64Bit or Vista32/64Bit?
NetrunnerAT said:
What OS you use?
WinXP 32Bit, WinXP 64Bit or Vista32/64Bit?
Click to expand...
Click to collapse
I'm using WinXP 32Bit, with admin privileges
mcoquet said:
I'm using WinXP 32Bit, with admin privileges
Click to expand...
Click to collapse
do you have the 16-bit subsystem installed? slimmed down editions of XP found on the internet usually have this removed
Midget_1990 said:
do you have the 16-bit subsystem installed? slimmed down editions of XP found on the internet usually have this removed
Click to expand...
Click to collapse
i have no idea, but this is a work computer, and I assume that my company does not get pirate copies of Windows
it would be good if i could solve this, i could then dump a french rom
please try a other WinXP Mashine ... for test! Try Windows95 Compatiblity Mode. Try to start with a other User!
For Frensh Rom -> netrunnerat.4shared.com possible i have it ... i have 1 OEM Frensh Roms in the moment (unbranded)!
companies don't use pirate versions
But they strip down the installer on their own very often.
i don't have another xp computer with me, but i'll try with a vista 32...

plz help m new to WM

hello ppl m rutz from india have an HTC touch Dual aka p5500(india)
so i get to the pt .
i saw the new rom wm 6.1 like it so wanted to update mine .....
so as per the instruction
Code:
copy sspl-1.16-nike.exe to your device and run it (usb cable must be connected!)
- after a few seconds "USB" appears on the display
- unplug and replug the usb cable
this pajrt runs sucessfully ...i get a new splash screen showin (for test only . not for sale )
the next 2 steps
Code:
- you can now flash the uspl-1.16-nike.nbh by running ROMUpdateUtility.exe from flash-uspl-niki
- you can also flash the hardspl-1.16-nike.nbh by running ROMUpdateUtility.exe from flash-hardspl-nik
gives me some communication error....and the update is at stuck at 0%
ppl m new to WM .....plz let me know asp abt the updation process as m eger to use WM6.1....
thanx in advance
wrong!
if you start sspl you must in the bootloader! then you flash hardspl! dont reset or restart your device ... read the hardspl thread again ... begin @ the first post and read all sides!
can you dump your india rom first? i havent it and possible you need it in some days :->
dude m new to this tell me how to dump it ....willl dump it and upload it ......and plz gimme step by step instrution of installation ......plzzz help m ...i did not undersand a word ...can we talk on IM ...Yahoo or Hotmail....
[email protected]
[email protected]
we will help you doing it. please wait a few minutes ok?
To dump your Niki ROM follow the instructions:
1) READ and download pdocread.exe from http://wiki.xda-developers.com/wiki/...s/pdocread.exe
2) open command prompt on your PC, then run : "pdocread.exe -l"
3) dump NAND partitions :
pdocread -w -d FLASHDR -b 0x800 -p Part00 0 0x31f000 Part00.raw
pdocread -w -d FLASHDR -b 0x800 -p Part01 0 0x380000 Part01.raw
pdocread -w -d FLASHDR -b 0x800 -p Part02 0 0x4560000 Part02.raw
pdocread -w -d FLASHDR -b 0x800 -p Part03 0 0x8660000 Part03.raw

[Begginner] Rom Dump?

Hi,
I have a new UK/EU WWE Raphael:
ROM 1.90.401.1 WWE
Date 08/01/08
Radio 1.02.25.19
Protocol 52.33.25.17H
I would like to know how I can dump my ROM making a safe copy just in case of failures of ugrades.
Thanks.
Take a look here. Just a reminder : pls use search button I'm here as a friend, but get ready to be flamed by others/mods.
Thx,
I searched, but didn't came out anything useful :-(
huh????
the link the guy gave has step by step instructions?
1. First of all is to Dump the ROM from your device.
Here are the proces (thanks to RezzZ)...
HTC Touch Pro DUMP:
Open a reg editor (dooFred TaskManager, TotalCommander or PHM Registry...) on your Touch Pro
Change:
HKLM\Security\Policies\Policies
valuename '00001001'was set to dword:2, change it to dword:1
After this change you need to soft reset your device.
Download itsutilsbin (http://www.xs4all.nl/~itsme/projects/xda/tools.html)
Extract the zip file and copy itsutils.dll to \windows on the Touch Pro (don't do it using ActiveSync, instead copy the file first to SD, and using TotalCommander or Resco Explorer copy from SD to \Windows).
Run (copy paste):
“pdocread.exe -l” (it’s the letter L not a 1)
you get something like:
Code:
457.75M (0x1c9c0000) DSK1:
| 3.12M (0x31f000) Part00
| 4.50M (0x480000) Part01
| 126.50M (0x7e80000) Part02
| 323.63M (0x143a0000) Part03
7.61G (0x1e6e80000) DSK7:
| 7.60G (0x1e6a80000) Part00
.....
Now run:
“pdocread -w -d DSK1: -b 0x800 -p Part00 0 0x31f000 Part00.raw”
“pdocread -w -d DSK1: -b 0x800 -p Part01 0 0x480000 Part01.raw”
“pdocread -w -d DSK1: -b 0x800 -p Part02 0 0x7e80000 Part02.raw”
“pdocread -w -d DSK1: -b 0x800 -p Part03 0 0x143a0000 Part03.raw”
notice the part before Part0X.raw is the same as you got with pdocread.exe –l, same for the name of the disk.
dumping part02 and 03 wil take some time. be patient.
After dumping the ROM you'll have 4 RAW files. Move in one folder the Part01.raw that contains the XIP and Part02.RAW that contains the IMGFS, both needed for the reconstruction process.
2. Download the WWE BaseROM to use in the reconstruction process here http://rapidshare.com/files/138980371/RUU_Raphael_HTC_WWE_1.90.405.1_Radio_Signed_Raphae l_CRC_52.33.25.17_1.02.25.19_Ship.exe
3. Download the Raphael Kitchen v0.61 here, that allows to reconstruct the ROM from the dump. The Raphael Kitchen allows to cook a ROM from a dumped one and from base NBH shipped one. You need to put the NBH file from the step before in the BaseROM folder (the Shipped ROM is a huge EXE file, and you'll need WinRAR to extract the content), and put the RAW files too.
Then execute the RAPHAELKITCHEN.CMD and choose the next options from the menu it this order:
e, b (for dumped ROM),space key, c, a, press BuildOS Play icon and wait to finish, Close BuildOS, close PagePool Changer and press space to go back to main mene. As a result of this process you will have a RUU_Signed.NBH file you can flash on to your Touch Pro to go back using the F option from main menu.
Click to expand...
Click to collapse
if your having any problems with any of this i would post in that thread, i followed the instructions step by step and managed to do it farily easily, try and post what problems and im sure some one will help you (cant promise it would be me as im busy next week but will have a look if you at least try )
thanks to jcespi2005 and hang.tuah for their awesome contributions

HTC Sedna WM6 downgrade

Hi all!
It is possible to downgrade the P6500 from WM6.1 to WM6?
If i have one device with W6.0, can i extract the ROM from it ?
Anyone have a WM6 original shipped french (1.10.406.63) ROM?
Thanks in advance!
Any ideas?
pls
Amokh said:
Any ideas?
pls
Click to expand...
Click to collapse
yes it is..
amokh if you have one device with a rom you want and want to put it on the other device ... yes it can definitely be done...
you need Qmat
and a kaiser kitchen
what works for kaiser works for sedna...
read other post as well as all you need has already been discusssed in other forums on this site... just takes time to find it... everybody had to do it , me included, so happy hunting
ask questions if you need help
ill do what i can...ok
also hard spl your device if you dont want to turn it into an expensive brick!
Thank you gardee005 for your answer...
My first idea was to take a WM6 WWE and trying to translate/ cook it with french files extracted from an WM6.1 french original shipped rom...
I have find the mui files, witch contains the lang, but i dont succeed to add to the OS.nb...
Other idea was to dump the ROM from the device with WM6 french, for that i tried to use itsutils pdocread.exe, according pof`s instructions for dumping Kaiser ROM
but, i have obtain this:
C:\itsutils\build>pdocread.exe -l
210.63M FLASHDR
| 3.12M Part00
| 3.63M Part01
| 78.50M Part02
| 125.38M Part03
980.00M DSK1:
| 980.00M PART00
STRG handles: 474f0f92(980.00M) 87484922(125.38M) 074b3d82( 78.50M) c74b3d5e(3.63M) 874b3aaa( 3.12M)
I don't know, how to dump them, because i don't have obtained the hex addresses, to proceed dumping...
How to do it??
As far as i know, i have to obtain something like:
3.12M (0x31f000) Part00
| 3.50M (0x380000) Part01
| 69.38M (0x4560000) Part02
| 134.38M (0x8660000) Part03
according to pof`s instructions, and i need to dump it like this:
"pdocread -w -d FLASHDR -b 0x800 -p Part00 0 0x31f000 Part00.raw
pdocread -w -d FLASHDR -b 0x800 -p Part01 0 0x380000 Part01.raw
pdocread -w -d FLASHDR -b 0x800 -p Part02 0 0x4560000 Part02.raw
pdocread -w -d FLASHDR -b 0x800 -p Part03 0 0x8660000 Part03.raw"
i have also change :
"HKLM\Security\Policies\Policies
valuename '00001001' was set to dword:2 to dword:1"
and now, what`s next?
http://rapidshare.com/files/85341969/kaiserkitchen_01-20-08.rar.html
get this kitchen... and qmat...
with this kitchen you should be able to extract the ROM and put it in the other device... you have part01 and part02 and get any ROM (.nbh file)
open KAISERKITCHEN.CMD in the kitchen then press m and u will see
let me know if this works..
then for step 9 use qmat to rebuild flashable ROM...
also this is not the kaiser so things wont be exactly the same but all should work...
also the radios on WM6.1 and WM6 dont mix..so u gotta have WM6 complete rom before u flash only WM6 OS rom..
please dont send private messages...ok
thanks for the kitchen.
still unable to extract it...how can i obtain the dumped part01 and part02 files?
I suppose that it must be extracted from device...but how?
here is the menu:
Requires RUU_signed.nbh in BaseROM folder
(1a) Extract NBH Content from shipped ROM
(2a) Extract IMGFS from shipped ROM
(3a) Extract XIP from shipped ROM
Requires RUU_signed.nbh, dumped part01.raw and part02.raw in BaseROM folder
(1b) Extract NBH Content from cooked ROM
(2b) Extract IMGFS from cooked ROM
(3b) Extract XIP from cooked ROM
(4) Copy ROM XIP
(5) PKGTool
(6) Move OEM and SYS
(7) Delete Boot
(8a) BuildOS
(8b) BuildOS+Package_Tools-2.7
(9) Create Kaiser ROM
(10) HTC ROM Tool
(11) Clean Up Temp files
(12) PagePool Changer
none of them cannot extract from device...or i`m doing something wrong?
now i`m confused...
u said you you got Part01 and part02 in your previous post...
but, i have obtain this:
C:\itsutils\build>pdocread.exe -l
210.63M FLASHDR
| 3.12M Part00
| 3.63M Part01
| 78.50M Part02
| 125.38M Part03
is this true .. that you got this ?
search in the kaiser threads ... im like you ..i dont know much! just gotta try and fail many times and search and search ...
but did you get part01 and part01 while you device was connected by activsync ?? You said you did... and if you got them then ur just there..
the kitchen i gave you is for use when you have part01 , 02 and ***.nbh.
I have never extracted a ROM from a device.... i have cooked ROMs but always worked with english ROMs, so i know how to dump , edit and recompile a ROM for flashing...
Also make sure you give things enough time to run.... not just when they say Done... sometimes ther are still running and you will see a flashing _ when its finished...
Amokh said:
but, i have obtain this:
C:\itsutils\build>pdocread.exe -l
210.63M FLASHDR
| 3.12M Part00
| 3.63M Part01
| 78.50M Part02
| 125.38M Part03
980.00M DSK1:
| 980.00M PART00
STRG handles: 474f0f92(980.00M) 87484922(125.38M) 074b3d82( 78.50M) c74b3d5e(3.63M) 874b3aaa( 3.12M)
Click to expand...
Click to collapse
i have obtain the list of the partitions, and i was trying to dump them...
Amokh said:
I don't know, how to dump them, because i don't have obtained the hex addresses, to proceed dumping...
How to do it??
As far as i know, i have to obtain something like:
3.12M (0x31f000) Part00
| 3.50M (0x380000) Part01
| 69.38M (0x4560000) Part02
| 134.38M (0x8660000) Part03
Click to expand...
Click to collapse
it must obtain something like this, for having the "0x31f000, 0x380000...etc " adrreses for start the dumping procedure...
Amokh said:
according to pof`s instructions, i need to dump it like this:
"pdocread -w -d FLASHDR -b 0x800 -p Part00 0 0x31f000 Part00.raw
pdocread -w -d FLASHDR -b 0x800 -p Part01 0 0x380000 Part01.raw
pdocread -w -d FLASHDR -b 0x800 -p Part02 0 0x4560000 Part02.raw
pdocread -w -d FLASHDR -b 0x800 -p Part03 0 0x8660000 Part03.raw"
Click to expand...
Click to collapse
and just after that you get the part01 and part 02...
It`s almost 3 weeks, since i have started to work on this issue, and still no solution...it`s depressive already
i think since i have the part01 and part02, i will able to reconstruct it to a flashable ROM...the only issue is to get them...
have you ever change the language by cooking a ROM?
if i will start extracting the french language from WM6.1 ROM (shipped), and put it to an WM6 WWE (shipped or not) can you help me with some instructions?
It seems like the -l option doesn't quite work, it didn't show the addresses required for dumping, so I followed an other way to get the address described (wiki /index.php?pagename=Hermes_HowtoDumpRom) but also adding the -b 0x800 option (/showthread.php?t=334680).
So basically you are doing -l get the partition names, after one by one get the addresses like this:
pdocread.exe -w -d FLASHDR -b 0x800 -p Part00 -t
real nr of sectors: 1598 - 3.12Mbyte (0x31f000)
pdocread.exe -w -d FLASHDR -b 0x800 -p Part01 -t
real nr of sectors: 1856 - 3.63Mbyte (0x3a0000)
..
now to dump
pdocread.exe -w -d FLASHDR -b 0x800 -p part00 0 0x31f000 part00.raw
pdocread.exe -w -d FLASHDR -b 0x800 -p part01 0 0x3a0000 part01.raw
..
so ur on the way... let me know if its sucessful !!
sorry if i did not help much but i only know a little..
Success!!!
It`s working!!
After i have obtain the part01 and part02.raw,it was not so difficult...using the kaiserkitchen...and finally rebuild .nbh with Psas to a flashable file!
Now i will test it for a few days, to see how stable is...
Thank you gardee005 for the kitchen and for your help, it is very good feeling to cook...
good to hear.... whats Psas?
it not so difficult when you know how, did you use Qmat to rebuild the .nbh file or the kaiser tool? i never use the kaiser tool but qmat only so if u used it and it worked id like to know.
anyway nice to hear you succeded
Psas is the newer version of Qmat...
nice tool .. it has what u needed .. Hardware forensics>WinCE ROM util...
and you get part00 and offseto1x0031f00 etc.
then right click and you can dump..

Categories

Resources