
Originally Posted by
sharan_123
here"S a method of testpointing v3i withoput opening ur phone.
thanks to dev.meena and maverick who converted it into english.
From what I understand we have to do this:
1. Open CG1 in a hex editor. Change the first four bytes to 00 00 00 00
2. Search for hex string: 12FE0000
Replace it with: 100049BC (For bootloader 0A.30).
Replace it with: 10004C78 (For bootloader 0A.52)
Its different for every bootloader. I will find for the other bootloaders later on.
3. RSA Patch the firmware if its not already RSA Patched. Testing has shown that this step is desirable. Ofcourse this would mean that you will need to get CG3, 7 and 18 with CG1 too.
4. Flash this patched and edited CG1+CG3+CG7+CG18 with P2k Easy Tools v3.9
5. After successful flashing and hence removal of firmware from your phone, remove battery and cable from your phone.
6. Now put in the battery and connect the cable. Your phone should be detected as S Blank Neptune LTE2. In other words it has been "soft" testpointed
7. To get the phone working again, reflash the phone with CG1+CG3+CG7+CG18 (not the one you edited in steps 1,2 and 3, but some other)
Do not use RSDLite for flashing here.
For those who don't understand, here are the autopatchers for doing step 1 and 2 for you:
For Bootloader 0A.30:
i have attached the bootloader in exe version.
Open CG1 in it and click on Start.
we are looking for some testers who can test this method on their v3i"s
this method has worked for one guy
"vermsky"
Okay here's what i did.
1 Backup CG1+CG3+CG7+CG18 with FB3
2 Open CG1+CG3+CG7+CG18 in FB3 and remove RSA with new method in FB3.
3 Patch CG1 with "softTP_boot_0A.30.exe"
4 Replace CG1 from step2 with CG1 from step3
5 Open CG1+CG3+CG7+CG18 (with patched cg1 from step4) in FB3 save as one SHX
6 Flash with P2KEasyTool 3.9 Cracked
7 Remove cable & battery
8 Reconnect cable & battery, phone is not detected by pc as S Blank Neptune LTE2. No reaction from WinXP.
9 FB3 says phone is connected (without detecting what phone it is)
Extracting data from firmware file...
Sending the loader...
Done.
Executing JUMP...
Error!
Erasing memory... (Progress of this process is not shown)
Error!
Sending code group: CG1
Error!
Sending code group: CG3
Error!
Sending code group: CG7
Error!
Sending code group: CG18
Error!
Operation done.
MotoRocker_300 Cracked
Split input file in codegroups
Processed 8 codegroups
Major Boot version supported by RAMLDR: 0A43
Establish connection to handset
FLASH Interface established ok
Read handset bootcore version
Bootcore version on handset: 0300
Sending RAMDLD to handset
RAMDLD started ok in handset
Erase flash...
Err no: 1120004
Err no: 1210004
What have i done wrong and what do need to do now to:
A: Make phone work
B: Unlock it (if it's not unlocked now in some f&%cked-ish way)
just in case this info is needed in helping to solve this issue, i provide short phone history:
Code:
bootloader 0A.30
sw version r479_g08.b4.85r
then after i fooled around with fws and accidentally locked it it became
Code:
bootloader 0A.30
sw version r4441_xxxxx (don't remember what the xxs was and can't look now)
it's still connectable some how: