Unbrick hard bricked Motorola Moto E - Moto E General

This DevDB project and it's related files are by Aravind V. Nair. I'm stating this because so many people are trying to impersonate me. For example, @Balaji Sriram More info: Balaji Sriram impersonating Aravind V. Nair
Most of you are probably facing battery issues. Please check what I have to say regarding that before proceeding. So many people have reported success after fixing the battery issue. Details are available at the bottom of the post
Click to expand...
Click to collapse
If your eMMC storage controller is corrupted, no method will work. You need to replace the motherboard. I'm sorry, I can't help you with that.
Click to expand...
Click to collapse
Big thanks to @ariel.buszczak for his continuous support in every way he could!
Big thanks to @waulliano for uploading the backup.img for XT1022! Download from here
Please upvote the TWRP time issue on GitHub here: TWRP 3.0.2-0 build to 3.1.1-0 build time miscalculation on so many devices.
Click to expand...
Click to collapse
Introduction?
Yes, of course. Hi there!
I have a bricked Motorola Moto E 1st Generation XT1022 condor. I watched so many threads on various forums to try and unbrick, but unfortunately all threads just got abandoned. Hence, I have come up with a DevDB project to try and unbrick Motorola Moto E 1st Generation XT1022 condor if possible. Please note, this project is only for Motorola Moto E 1st Generation XT1022, XT1021 and XT1025 condor. Between, I also have an unbricked working Motorola Moto E 1st Generation XT1022 condor along with the bricked one for test purposes.
This XDA DevDB project is aimed at developers mainly to gather all possible ways to unbrick a hard-bricked Motorola Moto E 1st Generation XT1022 condor, but not restricted to people who want to try their luck at unbricking their Motorola Moto E. Please don't post 3-line request like "my device is bricked, please help" as you will be ignored. If you can't do the research required to provide the right details plus finding the correct files required then, this DevDB project is not for you. The programs, its associated files & threads, etc are NOT going to be being actively developed very soon (July 10th 2017) as I get busy and involved with other things. But the thread remains open for user to post more information, additional files, updates from the public, etc. It's not here for lazy people to scream fix my device, can those type of users please speak to your retailer, cell phone service shop??
I will reiterate again, THIS IS A DEVELOPMENT THREAD AND NOT A REQUEST PAGE FOR "fix my device"
Click to expand...
Click to collapse
I haven't stopped working on this. I do update this XDA DevDB and my GitHub repository for the as I get time.
Please go through this DevDB post thoroughly.
Click to expand...
Click to collapse
Rules and regulations:
Please click the 'Follow Project' button to get notifications every time I update files or make any other changes instead of asking me manually via PM or in thread replies. I won't reply to unsolicited spam messages. So, DO NOT waste your time crafting them.
Click to expand...
Click to collapse
Obey all XDA rules posted here along with CODE_OF_CONDUCT.md posted by me here.
Click to expand...
Click to collapse
Please read through this post and also go through the README.MD file on my GitHub repository for this project carefully and thoroughly. They are created for a reason. I won't reply to unsolicited spam messages, tags, quotes, replies, etc. So, DO NOT waste your time crafting.
Click to expand...
Click to collapse
Warning: I am in no way responsible for your actions. You are on your own. Please undertake all actions at your own risk.
Click to expand...
Click to collapse
Please compress all files before uploading to the cloud after removing personal data. I'm not going to check otherwise.
Click to expand...
Click to collapse
Please attach error codes and other additional information is separate files to avoid clutter. I'm NOT going to check otherwise.
Click to expand...
Click to collapse
DO NOT share anything from this thread. DO NOT mirror anything without prior permission. I have recently busted so many people who have tried to do so despite my warning and even got them banned.
How can I get in touch with you?
My personal blog (All social media profiles link are available):
About Aravind V. Nair
Click to expand...
Click to collapse
Or
Just Search Google for 'Aravind V. Nair' and you can find me.
Click to expand...
Click to collapse
Or
My website: Get to know Aravind V. Nair
Click to expand...
Click to collapse
Or
XDA: Aravind V. Nair - XDA Developers
Click to expand...
Click to collapse
Where can I find the files and instructions?
Please check here: Motorola Moto E XT1022 condor files - GitHub (Aravind V. Nair)
How do I support you?
Hit the thanks button below and the 5-star button above to show your support. Also, you can 'star' and 'watch' my GitHub repository Motorola Moto E XT1022 condor files - GitHub (Aravind V. Nair).
Follow me on social media networking sites if you wish.
Donate to me if you wish by clicking here
What is the goal of this project?
The goal of this project is to gather all possible ways to unbrick a hard bricked Motorola Moto E 1st Generation XT1022 condor. Methods 3, 5, 6, 7 and 8 are perfectly working. Your mileage will vary with other methods. Please don't give up on first try. You need to try a lot of times and test your luck.
What is the proof that this has worked?
I have attached photos to this DevDB post. Please have a look at them.
Will this work for everyone?
As long as you haven't corrupted any of your phone's hardware, you do have chances of unbricking. If the NAND adapter or related parts are not functional, don't even expect to unbrick. A lot of you have tried weird files on the internet, so chances will reduce accordingly.
Where can I find the changelog?
I frequently update and patch things in my GitHub repository as I get time. Be sure to check the changelog here.
How do I find out which bootloader I have?
Sorry, I don't think that's possible when the phone is bricked. I'm not sure though. But definitely, your bootloader version would be the version from your last working stock OS (or custom OS, only if you flashed the motoboot.img or any other equivalent bootloader image).
If fastboot works,
Code:
fastboot getvar all
Can I restore factory aka original firmware if my bootloader is locked?
Yes, you can. However attempting to downgrade to an older version of Android may fail and isn't a good idea. Even with an unlocked bootloader, downgrading cannot be guaranteed. It's also important to be aware that flashing the wrong bootloader (motoboot.img) for your model can have serious consequences. Always identify your model of Moto E and verify the files before flashing.
If you downgrade your phone, it is advised to avoid all OTA updates. These updates can result in a hard-brick (phone will not turn on) if you have a newer bootloader than the one expected. For example, most of you had the Lollipop bootloader, but have downgraded to Android KitKat and thus bricking your phones.
How to disable OTA Updates?
Without root access
Settings > Apps > [swipe left to 'All'] > MotorolaOTA (or Motorola Update Services or something similarly named) > Disable​
With root access
Google Play Store has many apps that will allow you to 'freeze' the OTA Update service. Titanium Backup is a common example.
Alternatively, with a 'root access' file explorer, you can delete or rename the following files:
/system/etc/security/otacerts.zip
/system/priv-app/3c_ota/3c_ota.apk​
These additional files can be removed or renamed: (If you still get an OTA Update notification)
/system/priv-app/3c_checkin/3c_checkin.apk
/system/priv-app/3c_devicemanagement/3c_devicemanagement.apk
/system/priv-app/3c_notification/3c_notification.apk​
I'm a developer or programmer or want to help. Could you please give some reference links?
Yes, of course. All contributions are welcome! Code, documentation, graphics or even design suggestions are welcome; use GitHub to its fullest. Submit pull requests, contribute tutorials or other wiki content -- whatever you have to offer, it would be appreciated!
Please feel free to get in touch with me. I'll always be available even after the deadline. Refer CONTRIBUTING.md on my GitHub repository for reference material and other things.
What are the possible methods of unbricking?
Refer Unbrick methods.md on my GitHub repository.
Where can I download the firmware files?
Check my GitHub README.md file for all files for all models or alterantively Moto E Factory Firmware Images by @lost101
Moto E won't power on. Only white light LED comes up when connecting powers source. Can I charge on AC, etc.
This has nothing to do with clearing cache, recovery and other nonsense. It is just a problem of overly discharged battery when the battery voltage drops below the 3.8 V, which is the minimum voltage of LiPo aka Lithium ion Polymer battery. Unlike other phones, all Motorola devices come with LiPo batteries.
When the battery reaches less than 0%, i.e., less than 3.8 V the phone will not allow it to turn on, as it is harmful for the battery and it might burst. So for these physical security reasons, the phone's adapter chipset/regulator stops the battery from charging. I faced the same problem many times while bricking and unbricking. One thing you could try is to jumpstart the battery by providing excessive power at your own risk, or consider replacing the battery. It is advisable, to never let the battery fall below 10 %. Below 0 %, the internal resistance or rather the impedance of the battery increases to a very very high constant, thus rendering the battery in a 'cannot be charged state'. I won't by trying to fix via firmware as it is very dangerous to charge a battery in such a state. We do not want another bomb apart from the already existing Samsung Galaxy Note 7, do we? :laugh:
Please check your battery voltage using a multimeter or voltmeter and contact me with the same. Please be very careful when removing the battery as Moto E has a loose pin and is easy to break. Caution advised!! For checking using multimeter, set to DC 20 Volts and use the correct input pins. For voltmeter, just use any DC voltmeter having a range of 0-5 Volts.
If the voltage is below 3.8 V, you have to replace the battery. If it is between 3.3 - 3.5 V, you have chances of resurrecting the battery. So try using a above 2 A charger (connecting to laptop won't work as that is just 0.5 A) and leave it like that for about 5 days continuous. Below 3.3 V, please replace the battery. It's not advisable to try and jumpstart.
For the prerequisites, you need a T4 Torx screwdriver and a new Moto E battery. Please buy genuine things. You could have a look at Amazon, Flipkart, eBay, IFIXIT, Snapdeal, etc and also offline stores. Search with the model number of the battery. For XT1022, XT1021 and XT1025, it is Motorola EL40 manufactured by SONY Electronics with a typical mAh of 1980 and minimum of 1860 mAh aka 1860/1980 mAh (min/typ) and 7.1/7.5 Wh (min/typ).
PLEASE DO NOT USE AC TO CHARGE DC BATTERIES DIRECTLY.
You have a high risk of causing serious damage. You might end up killing yourself! Please do not try this. To charge in this manner, you need a bridge rectifier. Noobs, please don't even venture here or think of making it. The battery will not get charged because AC supply changes its polarity after each half cycle. In India, it changes 50 times per second, Brazil 60. Therefore, the battery will be charged in one half cycle and discharged in the next half cycle. So basically, you are damaging the battery due to frequent charging and discharging cycles. Please do not try this!! There is high risk of fire damage and explosion. Those of you who already tried this, please discard the battery immediately to a recycling firm or any other relevant organisation for your country or city. It is not advisable to keep a spoilt battery at home. Using a resistor is not a good idea either as a resistor obeys Ohm's Law which states that the current flowing through any conductor, in this case the battery, is directly proportional to the potential difference across the terminals. So you wouldn't have a steady output. A diode would be preferable. Those who have no clue about these, please do not venture here. I reiterate, I won't be held accountable for any damage caused by you to yourself or your belongings or to anything else.
I was using the Moto E and it suddenly died. What do I do?
Step 1: Open up the phone as I have mentioned earlier. (If you read whatever I have written, you should be knowing what I'm talking about.)
Step 2: Detach the battery. Be very careful not to destroy any internal parts such as the connector which is very fragile.
Step 3: Connect the official charger. (Other chargers didn't work for me always during my testing.)
Step 4: Wait for the screen to say 0% or battery not connected or even if the screen turns on, consider yourself lucky.
Step 5: Attach the battery and reassemble the phone without removing the Moto charger.
Step 6: Go to fastboot, unlock the bootloader and use my fastboot unbrick script for your OS (I have made for Linux, Windows and MacOS). Leave it on charger for a day or two after this.
Step 7: Voila!
This is caused due to undercharging, overcharging or excessive battery drain cycles. In case the phone doesn't power on after connecting battery, check that the EMF of the battery is above 2.9 V with a multimeter as mentioned before.
How to power on Moto E without charger and unbrick?
Safest way is to use the original Motorola charger. As far as I have seen, all the original Motorola chargers have the 4th pin available. For the geeks:
Pin 1: VDD (+5V)
Pin 2: D- (Data-)
Pin 3: D+ (Data+)
Pin 4: ID (ID)
Pin 5: GND (Ground)
The additional pin added to the conventional USB port is the ID pin added to the 4th electrical pin which allows to recognize the device. The technical name is micro USB - B for the one on the charger and mini USB - A for the one on the charger. You can bypass power using this concept. This too is strictly not for noobs.
Errors:
Code:
Preflash validation failed
Buy a new phone. I doubt anyone can help you now...
Code:
Not able to flash GPT / Motoboot
You are not using the right firmware. Try another firmware.
Code:
FAILED (blank-flash: sdl-transfer-image: sdl-hello: invalid HDLC frame)
or
Code:
FAILED (blank-flash: sdl-transfer-image: sdl-hello: error sending packet)
Your bootloader files do not match your bootloader version, use another bootloader.
Code:
Stuck on Opening device: . COM ??
or
Code:
Greeting device for command (Or any other) mode
or
Code:
Switch To FireHose (Or any other) mode
Press and hold power button until detection or until flashing begins.
I'm fed up!! Nothing is working for me!!
Calm down!! Replace your motherboard and/or battery and/or screen, whichever is spoilt. That's the easiest option. But it wouldn't be a good choice to buy new parts now. The phone is quite old. I suggest you buy a new phone instead. That would be a wiser idea. Methods 3, 5, 6, 7 and 8 are perfectly working. Your mileage will vary with other methods. Please don't give up on first try. You need to try a lot of times and test your luck. You are the one who brought your device to this condition. Only you can help yourself.
Does this project have a website?
Yes, a very basic one though. Check here.
Please go through this XDA DevDB main post and my GitHub repository for the same before commenting, messaging or posting.
XDA:DevDB Information
Unbrick hard bricked Motorola Moto E, Tool/Utility for the Moto E
Contributors
aravindvnair99, Thanks for all support!
Source Code: https://github.com/aravindvnair99/Motorola-Moto-E-XT1022-condor-unbrick
Version Information
Status: Stable
Current Stable Version: 309
Stable Release Date: 2018-05-29
Current Beta Version: 309
Beta Release Date: 2018-05-29
Created 2017-05-01
Last Updated 2018-05-29

Reserved
By @kyocell
I am currently getting some SAHARA Port errors I'm trying to install and uninstall drivers and trying.
Will keep updating if it works.
Edit- Fixed SAHARA Port errors but now experiencing different ones.
Edit2- Now experiencing some kind of SAHARA Protocol errors.
Fixed errors guide- If you get any kind of SAHARA Port error then follow this easy guide.
1) First off, delete all the preinstalled drivers
2) disable your machine's driver signature enforcement by doing this -
Click the Start menu and select Settings.
Click Update and Security.
Click on Recovery.
Click Restart now under Advanced Startup.
Click Troubleshoot.
Click Advanced options.
Click Startup Settings.
Click on Restart.
On the Startup Settings screen press 7 or F7 to disable driver signature enforcement.
3) After you enter your machine with driver enforcement disabled, Now go to the folder "Drivers" and extract the Qualcomm drivers and install them.
4) Here comes the tricky part. Now open your "moto e unbrick folder". Provided by @aravindvnair99 at his GitHub page and open the folders patch0.xml , prog_emmc_firehose_8x10 , rawprogram0.xml and copy all the contents into a new folder called "unbrick".
5) Now install the QPST tool. (installer in the unbrick folder provided by @aravindvnair99 at his GitHub.
6) Once you have this installed, go to the location of the installation of Qualcomm--> QPST --> Bin --> and copy this folder we made called "unbrick" into "bin" folder.
7) Now run Qfil.exe file which is located in the "bin" folder as well.
8) Now, plug your moto e with USB to your pc. If any drivers start installing, let them install.
9) Now select the port. Then browse the path for Programmer. For this click browse --> locate to the "unbrick" folder and select on "All files (*.*)" located at the bottom right of the browse window (dropdown).
10) Now select the file "programmer_8x10.mbn" and click ok.
11) Now click on load XML and locate to the "unbrick" folder and select the "rawprogram0.xml" file then another browse box will open and this time select "patch0.xml" and click ok.
12) You are now all set!
13) Finally click the "download" box and watch your phone come alive!
Hope this guide was easy. @aravindvnair99 you can use these instructions for method 1 as they are more elaborated & also it will save up your time so that you wont have to type so much data instructions. Its all up to you! i only wanna help all those people with this 'Dead moto e' problem and show them that there is still hope!
Much love! Hope it helped!
<3
P.S @aravindvnair99 please correct me if i have told anything wrong anywhere.
Edit - The following error still persists for me
20:39:51: ERROR: function: sahara_rx_data:194 Unable to read packet header. Only read 0 bytes.
20:39:51: ERROR: function: sahara_main:854 Sahara protocol error
20:39:51: ERROR: function: main:265 Uploading Image using Sahara protocol failed
EDIT - FIX FOR THE SAHARA ERROR
1) right as you plug in your phone to your pc and hear that sound (when device is plugged in to pc) right away click the download button without any waste of time.

Reserved

Happy to see this thread. I also have a bricked Moto E XT1022. After searching in many websites , i found that only flashing emmc using EasyJtag box has sloved the problem. Can you do anything with that flash file which flash the bootloader.

arputhatonyking said:
Happy to see this thread. I also have a bricked Moto E XT1022. After searching in many websites , i found that only flashing emmc using EasyJtag box has sloved the problem. Can you do anything with that flash file which flash the bootloader.
Click to expand...
Click to collapse
@arputhatonyking Thanks for the positive response. Sorry to hear that you too have a bricked condor. Yes, for hard bricked only JTag seems to work now. I don't see any other methods. For soft bricked, it is easy to recover. I am trying to find a solution (if possible) using blankflash or any such similar flashing procedures.
Stay tuned as you might be of help to us.

aravindvnair99 said:
@arputhatonyking Thanks for the positive response. Sorry to hear that you too have a bricked condor. Yes, for hard bricked only JTag seems to work now. I don't see any other methods. For soft bricked, it is easy to recover. Me and @Balaji Sriram are trying to find a solution (if possible) using blankflash or any such similar flashing procedures.
Stay tuned as you might be of help to us.
Click to expand...
Click to collapse
Hope to get a successful one..

i flash emmc backuped from eazy jtag with old riff box 1 but, not enter to fastboot. need read from worked phone and try flash to dead one. i look it to ebay but not find with low price phone/ if find and buy one, i will try read it and post here. i have hard bricked XT1021. it flashed customer from XT1022 firmware, now it dead.

VIPER_GE said:
i flash emmc backuped from eazy jtag with old riff box 1 but, not enter to fastboot. need read from worked phone and try flash to dead one. i look it to ebay but not find with low price phone/ if find and buy one, i will try read it and post here. i have hard bricked XT1021. it flashed customer from XT1022 firmware, now it dead.
Click to expand...
Click to collapse
I didn't quite understand what you were trying to say. As far as I understood:
You should have never flashed wrong firmware even though the only difference is the modem files between XT1022 and XT1021. Sure, will wait for your reply. Thanks for your time @VIPER_GE :good:

has XT1021 flashed as XT1022, now it dead. flashed with customer. i try restore with emmc isp flashing with riff box but not work. need try with Z3X easy jtag, not have this one

VIPER_GE said:
has XT1021 flashed as XT1022, now it dead. flashed with customer. i try restore with emmc isp flashing with riff box but not work. need try with Z3X easy jtag, not have this one
Click to expand...
Click to collapse
Oh, okay. Now I understand. Thanks a lot for the clarification @VIPER_GE !
Actually, Riff Box is mainly for selected Samsung devices. Apart from those, only for the ancient (first few) Motorola and HTC devices. Z3X I heard works for recent devices. I am not sure though. Give it a try. There was another JTag thing. I don't remember the name now. It works for all devices having Qualcomm chipset. Let me see if I can find or remember it. I'll send you the link. Between, are you a technician or something? Or just another curious one like us?

just another curious one like us

Anyone know how to generate BlankFlash Files

Can anyone just give the method to flash in bootloader
And is the file listed in the thread is enough or need some more things to unbrick

https://www.youtube.com/watch?v=Qf7kG3qnyx0 https://www.youtube.com/watch?v=_KRFxtz4h24

Do you guys have jtag ?

i have only FIFF Box 1,

We need RawPatch And Programmer Files for QFIL Flash.

mannu233 said:
Can anyone just give the method to flash in bootloader
And is the file listed in the thread is enough or need some more things to unbrick
Click to expand...
Click to collapse
@mannu233 Some more things are required. You can try though with whatever is uploaded. I'm constantly updating the files. I'm working on this day and night. Waiting for @Balaji Sriram to join me soon.

If I replace the "prom_emmc" file in the "blankflash" folder, can I test if flashing works? Thank you!

aravindvnair99 said:
@mannu233 Some more things are required. You can try though with whatever is uploaded. I'm constantly updating the files. I'm working on this day and night. Waiting for @Balaji Sriram to join me soon.
Click to expand...
Click to collapse
cAN you please do me a favour that i wanted to know how to use these files i haven't got any clue how to use them
---------- Post added at 05:19 PM ---------- Previous post was at 05:05 PM ----------
Can someone list up all files whatever is founded in the thread it would be easy for those who are looking for the files

Related

[Q] Can I just pay someone to fix this Acer A500 brick?

OK - total noobie here.
Bought my first tablet - Acer A500 off craigslist for $100. Worked like a charm for six months then went to brick status - locked on Acer Screen. BOO! HOO!
I've read and done the factory reset with the paper clip, and the Power Volume+, with no results.
Then I said to myself - "Hey, there's got to be a EASY way to do this. Probably download some software to my PC, plug in via USB, probably some sequence to boot from PC, and I'll be done!"
WRONG!
Apparently, I've got to know my CPUID - is that an acronym for Confused Person Undoubtably and IDiot - cause I got NO CLUE on that one.
And I've got to get an EUU - European United Union?
And I've got to get a Russian DeCrypter?
And.... well, you get the idea.
So, I've decided to exercise my capitalistic privileges!
IF SOMEONE THINKS THEY CAN FIX THIS DANG THING - I'LL PAY YOU!
I figure it'll take me days to figure out what I need to do and download and do it. Or, I can just ship this to someone who wants to make a few bucks and we'll both be happy.
So, if someone wants to help me do some additional diagnostics and make a buck or two in the process - email me at my public site of
rainbow 4 jd @excite. com (obviously no spaces there in the actual email address).
rainbow4 said:
OK - total noobie here.
Bought my first tablet - Acer A500 off craigslist for $100. Worked like a charm for six months then went to brick status - locked on Acer Screen. BOO! HOO!
I've read and done the factory reset with the paper clip, and the Power Volume+, with no results.
Then I said to myself - "Hey, there's got to be a EASY way to do this. Probably download some software to my PC, plug in via USB, probably some sequence to boot from PC, and I'll be done!"
WRONG!
Apparently, I've got to know my CPUID - is that an acronym for Confused Person Undoubtably and IDiot - cause I got NO CLUE on that one.
And I've got to get an EUU - European United Union?
And I've got to get a Russian DeCrypter?
And.... well, you get the idea.
So, I've decided to exercise my capitalistic privileges!
IF SOMEONE THINKS THEY CAN FIX THIS DANG THING - I'LL PAY YOU!
I figure it'll take me days to figure out what I need to do and download and do it. Or, I can just ship this to someone who wants to make a few bucks and we'll both be happy.
So, if someone wants to help me do some additional diagnostics and make a buck or two in the process - email me at my public site of
rainbow 4 jd @excite. com (obviously no spaces there in the actual email address).
Click to expand...
Click to collapse
Eh, personally we like to keep things in the forums, as other people may want to chime in and offer some steps others haven't thought of.
For some info, I'll try to explain a couple of things;
1. UID number. This is a number specifically assigned to your CPU. (CUID) which allows us (with a secure bootloader key, SBK) do a low level NVFlash of bootloaders. The issue, is that the bootloader (the first thing that loads) is secure and prevents us from flashing things. Pretty much locked. Unless you have your SBK. Then we can get into what we call APX mode which allows us to bypass security (in easy english terms). And yes, we have a tool that converts UID to an SBK.
If you do not have your UID number, all is not lost. Rumor has it that after ICS, the UID sometimes is the serial number you'll find on your Ext SD cover. Now some people confirmed this, and some say no. But it's worth a shot to use that number when trying to run an EUU file. If not, you will have to install Ubuntu on your PC and use the Linux method of getting it. More later.
2. Also, an EUU which is basically nothing more than an Acer maintenance rom which you run from your PC, requires this UID number because it uses NVFlash. That's why it's important to have it.
3. A Decrypter (not Russian I can assure you ) is sometimes required to install factory roms and updates, as Acer delivers these encrypted. You shouldn't have to worry about this yet, as most of the things we have posted are already de-crypted. For reference, you will find the tool in the Themes and Apps Forum.
For starters, I would like to know which bootloader version you currently have installed. You will find this in the upper left corner when you start the tablet. Should be a series of numbers and letters. Use a magnifying glass if you can't read it... :laugh:
Followup to a bricked Acer A500 - and if anyone can repair?
Moscow Desire said:
Eh, personally we like to keep things in the forums, as other people may want to chime in and offer some steps others haven't thought of.
For some info, I'll try to explain a couple of things;
1. UID number. This is a number specifically assigned to your CPU. (CUID) which allows us (with a secure bootloader key, SBK) do a low level NVFlash of bootloaders. The issue, is that the bootloader (the first thing that loads) is secure and prevents us from flashing things. Pretty much locked. Unless you have your SBK. Then we can get into what we call APX mode which allows us to bypass security (in easy english terms). And yes, we have a tool that converts UID to an SBK.
If you do not have your UID number, all is not lost. Rumor has it that after ICS, the UID sometimes is the serial number you'll find on your Ext SD cover. Now some people confirmed this, and some say no. But it's worth a shot to use that number when trying to run an EUU file. If not, you will have to install Ubuntu on your PC and use the Linux method of getting it. More later.
2. Also, an EUU which is basically nothing more than an Acer maintenance rom which you run from your PC, requires this UID number because it uses NVFlash. That's why it's important to have it.
3. A Decrypter (not Russian I can assure you ) is sometimes required to install factory roms and updates, as Acer delivers these encrypted. You shouldn't have to worry about this yet, as most of the things we have posted are already de-crypted. For reference, you will find the tool in the Themes and Apps Forum.
For starters, I would like to know which bootloader version you currently have installed. You will find this in the upper left corner when you start the tablet. Should be a series of numbers and letters. Use a magnifying glass if you can't read it... :laugh:
Click to expand...
Click to collapse
First - thanks for the reply - it was VERY NICE OF YOU.
And just so you know - I spent $100 on ebay and bought a replacement! So, now I can totally devote myself to learning what (if anything) can be done to unbrick my old one.
1. There is no external markings on this tablet AT ALL. No stickers, no nothing.
2. When I open up the SD card slot - I do get a SNID of 13001360415
3. When I do Power Volume+ slide - I get "erasing user data" and immediately below it "erasing cache"
4. It then goes to ACER logo screen and stops.
Logic tells me that A) the motherboard (or whatever passes for a motherboard on this tablet) might be bad. It's trying to go through its boot sequence and there's a physical fault or B) the motherboard could be good, but the inherent "boot disk" software is now corrupted - its locking up - and never getting to the OS software.
Or I could be wrong.
In either case - I feel like I have insufficient knowledge to properly diagnose AND determine if this is repairable at all. And that being said, IF someone has experienced this before, gone through the trial and error, and can say.... "Hey, I've fixed twenty of these, no problems" - I will happily defer to their experience.
Anyway - based on symptoms - if you think I have a fighting chance of salvaging this - I am game!
rainbow4 said:
First - thanks for the reply - it was VERY NICE OF YOU.
And just so you know - I spent $100 on ebay and bought a replacement! So, now I can totally devote myself to learning what (if anything) can be done to unbrick my old one.
Click to expand...
Click to collapse
Thanks for the comments!
$100... wow, I hate to say what I paid for my 501 new here in Moscow But now, I use my a701.
Typically, the a50x tablets have a reputation of being "bullet-proof", although lately, seems a rash of bricked tabs. Perhaps just due to old age.
You're correct about the motherboard, more specifically the emmc memory on it, is the likely culprit due to what you've stated. Or.... it could just be a corrupted file. Who knows until we investigate a little.
For starters, lets do some simple stuff first. Following is a link to some ICS update files. There are 4 of them. I have already de-crypted them. Now, download each to a individual folder on your PC. You will see they are numbered. This is to keep them separate so you know which is which.
Now, choose one of them (really doesn't matter which one, but maybe start with the highest number first). Rename it to "update.zip" (make sure it is not "update.zip.zip" as this is a common mistake. If your PC doesn't show the .zip extension, just rename it to update)
Now, copy it to your external SD card. Power on your tablet holding Vol+ (or minus) and PWR. Continue pressing until you see text about installing the update in the upper left corner, then release. We'll see if it installs all the way. If after 15 minutes it doesn't (it may stop at about 25%), then PWR off, and rename and copy the next update file, and try that one. Might have to try all 4, so make sure your tab is fully charged.
If none of these install all the way, then life becomes a little more difficult......
Links to my server (large files 300+mb)
http://d-h.st/Zf8
http://d-h.st/2cm
http://d-h.st/gw8
http://d-h.st/KXl
the JTiind
Moscow Desire said:
If you do not have your UID number, all is not lost. Rumor has it that after ICS, the UID sometimes is the serial number you'll find on your Ext SD cover. Now some people confirmed this, and some say no. But it's worth a shot to use that number when trying to run an EUU file. If not, you will have to install Ubuntu on your PC and use the Linux method of getting it. More later.
Click to expand...
Click to collapse
Can I get in on this conversation? For three days, I've been trying to revive my brother's A500. It seems like every option I come across requires the sbk, or the cpuid. I don't have the cpuid and can't figure out how to retrieve it since the tablet appears to be stuck in apx mode. The power button is illuminated and nothing comes on the screen. Windows device manager displays Acer USB Boot-recovery driver.
I've tried using AfterOTA v1.09 to flash recovery and bootloader files, but not sure if I've chosen the correct files to flash. I found a zip file here on the forums that contained ics_boot_unlk_v6_500.bin and recovery_thor17_403.img that I've attempted to use. AfterOTA just hangs on [2/3] flashing recovery...
Not knowing this all important UID, where do I go from here? Can I hear more about this Ubuntu method? Will that help in this case?
Thank you!
holtsclaw said:
Can I get in on this conversation? For three days, I've been trying to revive my brother's A500. It seems like every option I come across requires the sbk, or the cpuid. I don't have the cpuid and can't figure out how to retrieve it since the tablet appears to be stuck in apx mode. The power button is illuminated and nothing comes on the screen. Windows device manager displays Acer USB Boot-recovery driver.
I've tried using AfterOTA v1.09 to flash recovery and bootloader files, but not sure if I've chosen the correct files to flash. I found a zip file here on the forums that contained ics_boot_unlk_v6_500.bin and recovery_thor17_403.img that I've attempted to use. AfterOTA just hangs on [2/3] flashing recovery...
Not knowing this all important UID, where do I go from here? Can I hear more about this Ubuntu method? Will that help in this case?
Thank you!
Click to expand...
Click to collapse
Yep.... UID is all important. Uses what we call "NVFlash" to install bootloader and recoveries when all else fails. You UID is specific to each tab. No 2 are alike (as far as we know). With it, we can convert it to an SBK (Secure Bootloader Key). The stuff acer don't really wanna give us. This allows the use of NVFlash via APX mode (which you have already discovered.
Here is a link to getting your UID via various methods. The ones you want to pay attention to, are the links using Ubuntu (halfway thru the guide) Note that you may have to look at links within links to get all the methods people have tried, as some change a bit of the scripts here and there, but you should be able to figure it out.
http://forum.xda-developers.com/showthread.php?p=25429111#post25429111
http://forum.xda-developers.com/showthread.php?t=1751978
also of use, is a tool called "babsector". This tries to repair/workaround physical sectors on some tabs. But you shouldn't need that yet. So read that guide and check the links in it for using Ubuntu.Never had to use it myself, so not a lot of further advice on the technical aspect.
MD
rainbow4 said:
First - thanks for the reply - it was VERY NICE OF YOU.
And just so you know - I spent $100 on ebay and bought a replacement! So, now I can totally devote myself to learning what (if anything) can be done to unbrick my old one.
1. There is no external markings on this tablet AT ALL. No stickers, no nothing.
2. When I open up the SD card slot - I do get a SNID of 13001360415
3. When I do Power Volume+ slide - I get "erasing user data" and immediately below it "erasing cache"
4. It then goes to ACER logo screen and stops.
Logic tells me that A) the motherboard (or whatever passes for a motherboard on this tablet) might be bad. It's trying to go through its boot sequence and there's a physical fault or B) the motherboard could be good, but the inherent "boot disk" software is now corrupted - its locking up - and never getting to the OS software.
Or I could be wrong.
In either case - I feel like I have insufficient knowledge to properly diagnose AND determine if this is repairable at all. And that being said, IF someone has experienced this before, gone through the trial and error, and can say.... "Hey, I've fixed twenty of these, no problems" - I will happily defer to their experience.
Anyway - based on symptoms - if you think I have a fighting chance of salvaging this - I am game!
Click to expand...
Click to collapse
OH MY GOSH - IT WORKED! YOU ARE THE HERO OF ALL MANKIND!!
It took me a bit of minor tweeking - in that I had to rename the file BEFORE copying it to the SD Card - because I was getting some copying errors.
The version that took was #3 - what I mean by that is.... it was the third one in the Windows Explorer naming sequence. I don't know what the name of it is now, because I obviously updated the name to be "update.zip"
So..... it "took" and started giving me a working Android Robot - whereas the others had given me a Dead Android with the Information icon.
I waited through the process - it loaded the operating system and prompted me to select language, country, wifi, log in with google, AND I WAS UP AND RUNNING!
I am going to post these results as a specific FIX and encourage everyone to try it who has a bricked tablet!
:victory::victory::victory::laugh::laugh::victory::victory:

[GUIDE] SUCCESS!!! SIM-Unlock Sprint XT1056 (SIM-CRACK) Moto X GSM **NOW U.S. TOO!**

Greetings fellow XDAers,
It's finally happened: SIM-Unlock for the Sprint Moto X (XT1056)
(International-use Only. Anyone in the U.S. - Don't bother at the moment. Myself and some others are looking into the possibility of extending the SIM-CRACK to U.S. users, but RIGHT NOW, not possible. Sorry.) NOW EXTENDED TO DOMESTIC U.S. USERS AS WELL! - I have discovered the domestic-unlock solution!!!!
First, a little background:
Since its debut in August, 2013 many people have been trying to crack the SIM-LOCK on the XT1056. Many have tried and long since given up. I officially became involved in the project in May, 2014, and since then, had taken over the project. After much research, I determined that a Chinese hacker had found the solution and was offering a SIM-Unlock service on Taobao.com. This individual was extremely secretive about his methods - and told no one the solution. In order to use the service, you had to SEND your XT1056 to China to be unlocked (for fear of someone discovering his method). Then, a short time afterwards, the listing completely disappeared from Taobao, never to be seen again. Afterwards, sellers only offered PRE-SIM-CRACKED XT1056's on Taobao. Fortunately, I had already discovered (by reading his prior listing), that the SIM-Unlock required that you NEVER erase the modemst1 and/or modemst2 partitions (the equivalent of EFS/baseband cache on the Moto X).
At this point, I knew without a doubt that the key was in the modemst partitions. The breakthrough, however, didn't come until Mid-July, when another XDA Member: @yefonme posted to the thread that they had obtained a China-SIM-Cracked XT1056. This user confirmed the information I already knew by telling me that the seller advised that they must never erase the modemst partitions or the SIM-Unlock would be lost. This user generously offered to assist in helping find the solution, just for sheer curiosity - they wanted to know HOW the SIM-Unlock was achieved.
At this point, I thought we had everything we needed. Knowing that the key lies in the baseband cache, I requested various users to use a tool to backup their modemst1/modemst2 partitions, and send them to me for comparison with a HEX-Editor. Several users obliged, but unfortunately, we hit another roadblock -- the EFS partitions turned out to be ENCRYPTED TO HELL! That method was going nowhere. Then I realized that upon erasing the baseband cache (modemst1/modemst2 partitions), that all NV-ITEMS were reset to their factory defaults. BINGO! This means that the baseband cache partitions MUST store the encrypted contents of NVRAM!
This meant we had another option! Using standard CDMA tools, we could do a "DUMP" of the values stored in NVRAM. Another user, @ezeuba, suggested a simple tool, and provided instructions for the other's involved to DUMP the contents of their NVRAM, for comparison. Another big issue: Since many NVITEMS are inactive / restricted, even between 2 Sprint SIM-Locked devices, it made it completely impossible to use a utility to run a differential comparison between these NV-DUMPS. This meant that the NV-ITEMS had to be compared manually, by-hand.
I spent countless hours scouring through the data, comparing the THOUSANDS of NV-ITEMS from the China-Cracked XT1056 with the dumps provided by the Sprint SIM-Locked users. It was taking forever! I knew that the key to comparing the NVITEMS was finding values that were the SAME on all the Locked XT1056s, but DIFFERENT, only on the SIM-CRACKED XT1056. If a particular NVITEM differs between 2 or more LOCKED XT1056s, it is likely not the value we are looking for.
Then, finally, I came across an NVITEM that struck me as unique. It was the SAME on all the LOCKED XT1056's I analyzed, but different ONLY on the CRACKED XT1056. I was hesitantly optimistic, and posted about it here: http://forum.xda-developers.com/showpost.php?p=54334931&postcount=250
Well, my intuition was Spot-On, and this DID turn out to be the proverbial "smoking gun". Another user (ignoring my suggestions to WAIT and let another user who had offered to donate an XT1056 mainboard try it first) went ahead and wrote the new value as I had suggested. BAM!!! And the rest is HISTORY.
OK, so enough about the history, and on to the solution!!!!!
So the key lies in NVITEM # 8378
On the China-Cracked XT1056, the value was "01"
On all the SIM-LOCKED XT1056's, the value was "00"
That's all there is to it. You can use the CDMA Tool of your choice to write "01" to NVITEM 8378 to achieve SIM-Unlock!
You will also need to change the RUIM config to "RUIM-Only" in order to prevent the phone from reverting to CDMA-mode upon reboot. This is controlled by NVITEM 855 (see instructions in post # 2)
This method is KNOWN to unlock for all international GSM carriers, but DOES NOT unlock for Domestic U.S. carriers. Something else is in place, it appears, that BLOCKS the United States MCCs. NOW EXTENDED TO U.S. USERS AS WELL!!!
POST # 2 in this thread will be reserved for complete instructions for those of you who aren't familiar with how to write NV-ITEMS. These instructions are courtesy of @ezeuba.
POST # 3 will be reserved for detailed instructions on how to install the necessary DIAG Drivers, and how to manually FORCE driver installation, if necessary.
I believe in giving credit where it is due, so I want to personally thank:
* @hsngt and @jaaa1976 - who provided me with the NVDUMPS I used to find the SIM-Unlock method. @jaaa1976 was the FIRST person to be unlocked by my method
* @ezeuba for providing these users with step-by-step instructions on how to READ and SAVE said NVITEM dumps.
* @Vivjen for support and generous offer to donate a XT1056 mainboard (which turned out to be unnecessary)
* @crabbyone for encouraging me to take a 2nd look at NVITEM # 8322 (which turned out to be the Domestic Unlock solution)
* @Arnold Snarb for originally discovering the property of NVITEM # 8322 (which unlocked the Razr M for domestic use)
* All the others who submitted EFS and/or NVDUMPS (even though I didn't use them to find the solution)
* Everyone who believed in me and provided encouragement and moral support ( that includes YOU, @KJ )
* Everyone who makes good on their bounty pledges and everyone who DONATES (paypal: [email protected] )
* Everyone who is appreciative and gracious for the ENORMOUS amount of time I've spent making this SIM-Unlock possible for everyone
* The China-man who found the solution FIRST, even though he didn't share it with anyone and intended to only use it for Profit (I bet he is PISSED at me -- he was charging $80 U.S. for EACH unlock )
*** and ESPECIALLY @yefonme --- without YOU, NONE of this would be possible.
[Q]: How much should I donate to you for all the time (weeks) you spent working on this?
[A]: Please donate what you feel it is worth to you. The XT1056 can be found far cheaper than any other Moto X Variant, and now that we can SIM-UNLOCK it, it will become much more popular. If I have saved you money, or added value to the phone you already own, I would appreciate being compensated accordingly. I realize that some are not able to donate, and I understand. Do what you can / what you feel is fair. I spent countless hours on this, and would appreciate being somewhat-compensated for my efforts. This, of course, is not a requirement, since I have posted the solution and made it freely available to everyone. Keep in mind that the China Taobao-seller was charging $80 for EACH unlock...and HIS sim-crack didn't even unlock for Domestic U.S users!!!
PayPal Donation address: [email protected]
DO NOT email me asking for help with this. I won't answer you. *Post in the Thread* - this is the only way you will get support. I'm sure that you understand...
Additional info:
This works for all Republic Wireless XT1049's also, but ONLY if you can unlock the bootloader (only possible through the "China Middleman" - use search). You MUST flash the Sprint XT1056 ROM to your RW XT1049 device for this to work for you.
DISCLAIMER:
If you use my SIM-CRACK, I'm not responsible for ANYTHING that goes wrong. USE CAUTION! If you hit the wrong button, or write the wrong NVITEM, you could end up in BIG TROUBLE (possible BRICK). You have been warned.
And lastly, YOU MAY ---NOT--- COPY ANY PART OF MY SIM-UNLOCK METHODS. YOU MAY NOT SHARE/RE-DISTRIBUTE MY FILES, OR POST THEM TO OTHER SITES. THE ONLY ACCEPTABLE THING IS TO ---LINK--- THIS THREAD TO OTHER SITES. IT IS UNACCEPTABLE TO STEAL MY (OR ANYONE ELSE'S) WORK!!!!! I will be extremely offended if I find that someone stole my work and posted it elsewhere. ONLY Link this thread. Don't copy any or all of its contents elsewhere. PERIOD.
^This is NOT an unreasonable request....
FULL INSTRUCTIONS ​
!!!!! A WORD OF WARNING:
Once you complete this method, it is possible that you will NEVER be able to use your phone on Sprint / CDMA again! I -stupidly- flashed my Republic Wireless XT1049 (I should have known better -- I am using their service, and had no intentions of switching to GSM) in attempt to get better results / instructions for you guys. Now my phone is STUCK in GSM mode, the roaming indicator will not go away, I can't make calls on CELL, and no matter what I've tried, I cannot revert back. Not flashing my EFS backup, nor flashing back to stock, nor erasing the modemst partitions has been able to get me back on CDMA. PRL is STUCK on "1", and no matter how many times I write a new PRL, it won't stick. I'll be lucky if I can get my phone back in working order.....
^EDIT to above: This turned out to be EASILY fixed by flashing the entire SPRINT SBF to my Republic Wireless device, then, subsequently flashing back the Republic Wireless ROM (I WANT to STAY on Republic Wireless). DO NOT ATTEMPT THIS SIM-Unlock on the Republic Wireless ROM. Something about the RW ROM prevents you from going back to CDMA once on GSM. Flash the SPRINT ROM, FIRST, if you want to GSM-Unlock your Republic Wireless XT1049. The SPRINT ROM does not seem to have this issue, so you are probably OK, but take caution, nonetheless. I'm finally back on Republic Wireless (CDMA) after hours of frustration and fear that I was permanently stuck on GSM.
I don't recommend this if you plan to ever go back to CDMA / Sprint Probably fine - But once again, use caution.
Still want to continue? ------> Don't blame me if you end up STUCK on GSM
If you want my support, you must be on the Stock XT1056 Sprint ROM. I will not support any other ROMS from any other variants, or any custom roms. If you change roms, good luck, but no support will be provided. Additionally, support will ONLY be provided by posting to this thread. Do not email me or PM me with questions. I'm sure you understand...
AND Don't forget: This DOES NOT unlock for Domestic use, in the United States. Blame Motorola/Sprint. Something else is in place, it seems, that BLOCKS the U.S. MCCs. If you live in the U.S., DON'T BOTHER, unless you plan to sell your device to someone overseas. Myself and others are looking into the possibility of extending the SIM-Unlock to those in the U.S., but hasn't happened YET. I've also discovered the DOMESTIC UNLOCK solution now, as well!!!
FIRST, you must be in DIAGNOSTIC MODE:
You MUST have "USB Debugging" DISABLED, or the DIAG Port will NOT activate!!!
ezeuba said:
There are 2 ways to get to DIAG mode on this device. If ##3424# doesn't work, you can try the default for most Motorola devices: Power off phone. Hold down BOTH Volume Buttons and press the Power Button (It's called the 3-finger salute). When the phone boots, it will display a diagnostic screen called Fastboot Mode with options to scroll to and select. Use the Volume Down Button to scroll and the Volume Up Button to select. Scroll to the bottom of that list and when BP TOOLS is highlighted, press the Volume Up Button. The phone will restart and if you have Motorola device drivers on your computer, it will install the correct port (something like BP DIAG port Motorola QC Diag Port - look for it in your computer's Device Manager to get the port number).[/B]
Click to expand...
Click to collapse
****If you are having driver issues, and you have an entry for "Motorola QC Diag Interface" (not "Port") under "Other Devices" (and not "Ports (COM & LPT)"), SEE POST # 3 for detailed instructions (WITH PICTURES) on how to FORCE the driver installation.
Next, download and install the attached "SPCUtility.apk" app on your phone. Run it -- it will give you YOUR SPC Code. Write it down / take note of it.
IF ANYONE CAN TELL ME WHO DEVELOPED THIS APP, I WILL GIVE THEM THE APPROPRIATE CREDIT. I have tried (without success) to find out who the author is.
Then, flash the attached nv-unlock.txt, nv-unlock2.txt, unlock-domestic.txt AND nv-ruim-only.txt files as per these instructions:
1. Open the attached "NV-Items Reader-Writer"
2. Enter YOUR COM PORT # as shown in DEVICE Manager
3. Enter YOUR SPC Code into the box, as shown.
4. Check the box immediately next to where you entered the SPC Code.
5. Click "Connect"!
Now, follow these instructions:
1. Click "READ" --AT THE TOP--
2. Make sure it says: "SPC is Correct. Phone Unlocked."
3. Click the "Write" button, and find the "nv-unlock.txt" file - make sure it confirms success
4. Click the "Write" button, and find the "nv-unlock2.txt" file - make sure this confirms success
5. Click the "Write" button, and find the "unlock-domestic.txt" file - make sure this also confirms success
6. Click the "Write" button, and find the "nv-ruim-only.txt" fine - and make sure it confirms success as well
7. Last, click MODE, then RESET
And lastly, once the phone reboots, go to Settings, More, Mobile Networks and select GSM/UMTS.
DONE! You are SIM-Unlocked!
KNOWN ISSUES: On domestic carriers, users are reporting that although it DOES work, the signal bars may show no service. (I am looking into this.) Additionally, if data isn't working, YOU NEED TO INPUT THE PROPER APN FOR YOUR CARRIER (as with all GSM phones).
^^^***THIS MAY BE SOLVED*** Apparently, it involves simply using fastboot to set your carrier! (THANKS, @ejlmd , and @leonardoafa !!!) You can see this post for more details: http://forum.xda-developers.com/showpost.php?p=54468353&postcount=126 (And hit the "THANKS" to @ejlmd, and @leonardoafa in the linked post). This **should** fix your signal bar issues, AND roaming indicator, and allow SMS without issue.
ALSO, you will NOT get LTE data...on any carrier except Sprint because the radio inside doesn't support any LTE bands except 25 (used by Sprint). You also won't get HSPA/HSPA+ (3G/4G) data for any carrier using frequencies not supported by the Sprint Moto X. For instance: If you are using T-Mobile, unless you are in an area that has been re-farmed to 1900mhz HSPA/HSPA+, you will only get EDGE data. This is because T-Mobile extensively uses HSPA/HSPA+ on the 1700mhz AWS band which is not supported by the Sprint Moto X. See the link below for a complete list of frequencies supported by the XT1056.
http://en.wikipedia.org/wiki/Moto_X
Keep in mind that once you write the "nv-ruim-only.txt" file, you will no longer be able to use CDMA without flashing the "revert" file listed below (puts you back on the default RUIM-CONFIG). The "revert" file is ONLY to be used if you want (for some reason) to switch back to CDMA. You do not need it if you intend to only use GSM. Also, the purpose of "nv-unlock2" is to unlock the MIP settings, and prevent the phone from reverting BACK to NV-Only upon reboot.
Additionally, keep in mind that if you ever "SBF" back to stock, using RSD Lite (or fastboot method), it will un-do the SIM-CRACK, and you will need to repeat these steps.
You ***SHOULD*** be able to accept Updates (OTAs) without losing the SIM-CRACK.
*****If you click any of the attached TXT files, and it OPENS in your browser, instead of downloading, RIGHT-CLICK on it, and click "Save Link As" -- it should download without issue.
[Q]: How much should I donate to you for all the time (weeks) you spent working on this?
[A]: Please donate what you feel it is worth to you. The XT1056 can be found far cheaper than any other Moto X Variant, and now that we can SIM-UNLOCK it, it will become much more popular. If I have saved you money, or added value to the phone you already own, I would appreciate being compensated accordingly. I realize that some are not able to donate, and I understand. Do what you can / what you feel is fair. I spent countless hours on this, and would appreciate being somewhat-compensated for my efforts. This, of course, is not a requirement, since I have posted the solution and made it freely available to everyone. Keep in mind that the China Taobao-seller was charging $80 for EACH unlock...and HIS sim-crack didn't even unlock for Domestic U.S users!!!
PayPal Donation address: [email protected]
Driver Issues?​
This post is for you.
In order to use the DIAG interface, you must first install the Motorola Drivers from here: https://motorola-global-portal.custhelp.com/app/answers/detail/a_id/88481
REMEMBER: As stated in POST # 2, you MUST have "USB Debugging" DISABLED, or the DIAG port will NOT activate.
If you installed these drivers, and you still can't get it to work, and you have an entry under "Other Devices" (In Device Manager) called "Motorola QC Diag Interface" (SEE PIC1, attached below) follow the instructions in the attached pictures STEP-BY-STEP, IN ORDER, to FORCE driver installation.
We are ONLY concerned with the QC Diag Interface - don't worry about the rest of the entries under "Unknown Devices" -- these are not important.
Once you have successfully FORCED the driver installation, you should have an entry under Ports (COM & LPT), called "Motorola QC Diag Port (COMX)" (SEE PIC8, attached below). NOTE the value of "X" - this is the COM port you will use for our purposes. When you successfully have this entry, you can continue with the "FULL INSTRUCTIONS" in POST # 2.
[Q]: How much should I donate to you for all the time (weeks) you spent working on this?
[A]: Please donate what you feel it is worth to you. The XT1056 can be found far cheaper than any other Moto X Variant, and now that we can SIM-UNLOCK it, it will become much more popular. If I have saved you money, or added value to the phone you already own, I would appreciate being compensated accordingly. I realize that some are not able to donate, and I understand. Do what you can / what you feel is fair. I spent countless hours on this, and would appreciate being somewhat-compensated for my efforts. This, of course, is not a requirement, since I have posted the solution and made it freely available to everyone. Keep in mind that the China Taobao-seller was charging $80 for EACH unlock...and HIS sim-crack didn't even unlock for Domestic U.S users!!!
PayPal Donation address: [email protected]
You're the man!!! I doff my hat for you, sir. I think the best option will be to create an nv-item txt file for that particular nv-item (8378). I will get to it now and see what gives. Cheers man...
ezeuba said:
You're the man!!! I doff my hat for you, sir. I think the best option will be to create an nv-item txt file for that particular nv-item (8378). I will get to it now and see what gives. Cheers man...
Click to expand...
Click to collapse
Excellent! Please get me the instructions & necessary tools to use ASAP so I can post it in Post # 2 for the users who need step-by-step instructions. Thanks for all your help as well - I have given you credit accordingly.
Excellent work,buddy!!!
Thanks to your efforts, I can imagine how difficult it is.
And I was very pleased to be able to help.:victory:
Done!!!
Just flash this attached file. Connect as usual to the NV-ITEMS Reader/Writer. Click Write and select the attached file which you must have downloaded. After writing, go to Mode and click reset. Phone will restart. Go to Settings, More, Mobile Networks and select GSM/UMTS. Phone unlocked. Special thanks again to @samwathegreat without whom this will not be possible.
I'm on GSM right now...
NB If you've been using this phone on CDMA, you need to change RUIM Config to RUIM Only, else whenever you restart it will revert back to CDMA mode.
ezeuba said:
Just flash this attached file. Connect as usual to the NV-ITEMS Reader/Writer. Click Write and select the attached file which you must have downloaded. After writing, go to Mode and click reset. Phone will restart. Go to Settings, More, Mobile Networks and select GSM/UMTS. Phone unlocked. Special thanks again to @samwathegreat without whom this will not be possible.
I'm on GSM right now...
Click to expand...
Click to collapse
POST # 2 Updated. Thanks!!!!!
hey man, amazing job on this! so many people will happy to see this!
You're the man!!!
Thanks again everyone.
I REALLY need someone in the United States to test this and advise whether or not it unlocks for Domestic (U.S.) GSM Carriers.
We know that the "official" Sprint OTA-Sim-Unlock (only offered if you are a current sprint customer, have had an account for a specified amount of time, and meet other criteria) does NOT unlock for domestic use (international only).
I'm anxious to find out if my SIM-CRACK unlocks for those of us in the U.S. -- I need to know ASAP so I can update my OP accordingly.
@samwathegreat
If it is possible that you could make a video or how to flash this to your phone I think it would be beneficial to some. Even if your phone is already unlocked if you can flash this way then I feel that it's going to stop the millions of questions that are going to come from the thread. Just my two cents, thanks again :good: :victory: :highfive:
Vekhez said:
@samwathegreat
If it is possible that you could make a video or how to flash this to your phone I think it would be beneficial to some. Even if your phone is already unlocked if you can flash this way then I feel that it's going to stop the millions of questions that are going to come from the thread. Just my two cents, thanks again :good: :victory: :highfive:
Click to expand...
Click to collapse
Good suggestion. Full, detailed, instructions are listed in POST # 2 already, but this could help some, and I could put it in POST # 3. I'll see if I can get another user to make a video.
Remember: I don't own an XT1056: I did all of this for YOU GUYS, and all without even owning a Sprint XT1056
You are welcome to create a video yourself! I think the instructions are concise enough that you should be able to manage making a video. If you do, I'll post it in #3 and give you appropriate credit for it.
samwathegreat said:
Good suggestion. Full, detailed, instructions are listed in POST # 2 already, but this could help some, and I could put it in POST # 3. I'll see if I can get another user to make a video.
Remember: I don't own an XT1056: I did all of this for YOU GUYS, and all without even owning a Sprint XT1056
You are welcome to create a video yourself! I think the instructions are concise enough that you should be able to manage making a video. If you do, I'll post it in #3 and give you appropriate credit for it.
Click to expand...
Click to collapse
I don't have the appropriate equipment or environment (living in a 'college dorm' (kinda like that) with 24 people, it's never quiet) otherwise I would make one ASAP.
You don't even have one?! OH MY GOD. Your amazing doing all of this without the device...
Also a few things, I can't download the .txt file... I can only view what it says... So how do I download that, and then from that where do I put it to flash, just in the text box?
Vekhez said:
I don't have the appropriate equipment or environment (living in a 'college dorm' (kinda like that) with 24 people, it's never quiet) otherwise I would make one ASAP.
You don't even have one?! OH MY GOD. Your amazing doing all of this without the device...
Also a few things, I can't download the .txt file... I can only view what it says... So how do I download that, and then from that where do I put it to flash, just in the text box?
Click to expand...
Click to collapse
Right-click the txt file. Then click "save link as". It will download perfectly. I will add this info to Post#2
XT1052
Nice job ! I followed the old thread.. I know how much work it was.
Just a question. This method will work on moto XT1052 version ?
Green78 said:
Nice job ! I followed the old thread.. I know how much work it was.
Just a question. This method will work on moto XT1052 version ?
Click to expand...
Click to collapse
No idea? Use the NV-ITEM reader/writer attached in POST # 2 to read NVITEM 8378
Under Range (Dec), type 8378 into both fields (type nothing into the HEX boxes) and click READ. If NV8378 is "00", there is a good chance it will. Try and let me know!!!! If it already reads "01", it won't work.
...can't you get a SIM-Unlock code from a regular GSM Sim-Unlock-Code seller for the XT1052?
actually I don't need sim unlock....but, some of french moto X owner bought their phone on US (XT1053 sorry, not XT1052).
But my question is the same: does it work on other moto X model ?
I'm gonna try you method to see what happen.
Green78 said:
actually I don't need sim unlock....but, some of french moto X owner bought their phone on US (XT1053 sorry, not XT1052).
But my question is the same: does it work on other moto X model ?
I'm gonna try you method to see what happen.
Click to expand...
Click to collapse
ALL XT1053s should already be sim-unlocked. In fact, all variants except the XT1056 and XT1049 (that aren't -already- unlocked) can be SIM-Unlocked using the normal methods...(online code-sellers, etc.)
My method definitely works on all XT1056s.
It *SHOULD* work on all XT1049s (Republic Wireless), but ONLY if you unlock the BL and flash the XT1056 ROM to it.
ezeuba said:
Just flash this attached file. Connect as usual to the NV-ITEMS Reader/Writer. Click Write and select the attached file which you must have downloaded. After writing, go to Mode and click reset. Phone will restart. Go to Settings, More, Mobile Networks and select GSM/UMTS. Phone unlocked. Special thanks again to @samwathegreat without whom this will not be possible.
I'm on GSM right now...
NB If you've been using this phone on CDMA, you need to change RUIM Config to RUIM Only, else whenever you restart it will revert back to CDMA mode.
Click to expand...
Click to collapse
Thanks for the update. Can you provide more detailed instructions on how to change to RUIM only? I know how to do this....with DFS anyways....but many won't. Which tool do you suggest?
Actually, I believe that RUIM config is also stored in a NV item!
I *believe* that it is NVITEM 855 --- can you check for me? If I'm right, "00" = RUIM only, and "01" = default setting. Can you confirm?!?!
We could just update the txt file with this one additional NV-Value, and the users would only have to flash the ONE file, and it will crack AND set the RUIM config to RUIM only.
What do you think?

Unbricking and QPST - All Snapdragon / Qualcomm devices

Hello All,
First let me say thanks to all XDA Developers, and without this forum I would still be a pleb when it comes to unbricking. :highfive:
The link to QPST: androidbrick.com/download/latest-qpst-2-7-build-422-425-430-437-qfil-qualcomm-flasher/
(Sorry, I haven't passed 10 posts yet, so you have to manually enter into the address bar)
I came to this forum seeking answers to unbrick my hardbricked Note 4, and after many hours of heartbreak and headache, I have come across a tool called QPST.
This tool is used by Qualcomm, and if you read carefully through the accompanying documentation, you will find some interesting stamps - such as "Confidential" etc.
While I am no expert in the use of QPST, from my own incomplete research I am convinced this tool can be used on any device which sports a Qualcomm chipset (Snapdragon etc.) to unbrick it from certain death.
I have not yet succeeded with my attempts at unbricking, but it is now only a matter of time and kind people pointing me in the right directions. :fingers-crossed:
I am looking for the right files to go in the "phone image" and "boot image" lines in the QPST Software Download program.
I hope we can all see the opportunity this tool represents and spread the word among the greater community, not just developers.
Edit:
Using Software Download:
Phone image files will have a .hex extension and I do not believe they can be found on sammobile. I still haven't found the right one.
Boot image files: I still don't know what they will look like. Likely a .hex file.
Using QFIL:
I suspect all these files can be acquired from a service ROM (whatever a service ROM is - I don't think it is a ROM for android as I know them). I am not completely sure of this however.
Using the flat build option will let you select the programmer. It will have a file name like:
prog_emmc_firehoseXXXX.mbn
(Replace XXXX with the correct numbers for your snapdragon. I don't know what the right ones for the Snapdragon 805 are, but I strongly suspect 8084, with a remote possibility of 8064. Edit: I don't know, don't take my word.
There are posts for other phones on XDA, I don't know if they use the 805 chipset or if the files are compatible.) <--- If anyone wants to research, feel free. Team efforts make a big job seem easy! Please post your results!
Accompanying your firehose file will be a bunch of other files in the same folder.
You will need two .xml files to go with the above (usually in the same folder), which will look like as follows:
rawprogram0XXXX.xml (here XXXX denotes some numbering system which will be determined by the internal memory of the device eg 16GB, 32GB, 64GB. I saw an example for a OnePlus One which had rawprogram0_64G.xml.
I'm NOT 100% SURE on this numbering system, as elsewhere on XDA I have come across different file names!
Here's the truncated link: androidbrick.com/ultimate-qualcomm-snapdragon-unbrick-guide-snapdragons-are-unbrickable-qhsusb_dload_qpst_qfil/)
patch0.xml
When I find the above, I will post or hassle an admin to post, as these will likely unbrick any Snapdragon 805. Happy hunting!
Here's a truncated link to XproZayd's thread, where a different avenue is explored (and where I got my idea about the 8084 number for firehose -- Remember, I could be wrong!)
forum.xda-developers.com/note-4/help/unbrick-samsung-galaxy-note-4-sm-n910w8-t3249970
This thread is for discussing QPST and how to use it - if you have a hard bricked phone I am not able to help at this stage. However, should anybody find / 'acquire' the right files to use with QPST, we will all benefit.
What made your device hard brick
Sent from my SM-N910G using Tapatalk
Mistake 1: I bought the phone with the known problem of a USB port not working.
Mistake 2: I bought a replacement USB board and replaced it myself, after which the fun and games began. The one time the screen did light up I got an error message about mmc read fail and could not boot.
Mistake 3: Like a fool, I pulled the battery. Now I have a hard bricked / useless Note 4.
Unless the mmc is physically damaged (which I refuse to believe) the phone should be salvageable from its hard brick state. Provided I can find the right files to go with QPST.
Edit:
I have tried contacting Qualcomm to get the files, who have pointed out that they are proprietary to the licensee, ie Samsung. Here's the e-mail below.
Any information other than what is listed on our website (URL listed below for your reference) is Proprietary to Licensees.
However, the following link should help you with the information you're looking for:
http://www.mydragonboard.org
Alternatively, we recommend you follow-up with a vendor that carries this product and seek their feedback on your technical questions.
Please note, Qualcomm is the technology provider, not a manufacturer of consumer products and therefore we are unable to answer your product specific question. We hope this direction helps.
Thank you for your inquiry,
Qualcomm Technologies Inc.
can you explain to me everything that is happening?
i got my note 4 hardbricked from......
i really dont know
i was modifying my phone but then it would not boot
AlexanderDAB said:
can you explain to me everything that is happening?
i got my note 4 hardbricked from......
i really dont know
i was modifying my phone but then it would not boot
Click to expand...
Click to collapse
Is it going in download mode or recovery ?
What were you exactly flashing ?
Is it detected in pc as qhsb loader ?
Is the splash screen GALAXY NOTE 4 showing up ?
Sent from my SM-N910G
Update:
So far I have contacted Qualcomm, Intrinsyc (they sell Snapdragon development boards), and a Samsung retail outlet.
All have come back as a negative - the closest I could get was the Samsung retail outlet where a dude used to work in the repair centre and had access to the files then.
Unfortunately, Samsung revoked his permissions now that he only works in a retail outlet.
He knew what I was talking about, but due to Samsung and their encryption etc, he couldn't provide me with the files.
C_dog_1 said:
Mistake 1: I bought the phone with the known problem of a USB port not working.
Mistake 2: I bought a replacement USB board and replaced it myself, after which the fun and games began. The one time the screen did light up I got an error message about mmc read fail and could not boot.
Mistake 3: Like a fool, I pulled the battery. Now I have a hard bricked / useless Note 4.
Unless the mmc is physically damaged (which I refuse to believe) the phone should be salvageable from its hard brick state. Provided I can find the right files to go with QPST.
Edit:
I have tried contacting Qualcomm to get the files, who have pointed out that they are proprietary to the licensee, ie Samsung. Here's the e-mail below.
Any information other than what is listed on our website (URL listed below for your reference) is Proprietary to Licensees.
However, the following link should help you with the information you're looking for:
http://www.mydragonboard.org
Alternatively, we recommend you follow-up with a vendor that carries this product and seek their feedback on your technical questions.
Please note, Qualcomm is the technology provider, not a manufacturer of consumer products and therefore we are unable to answer your product specific question. We hope this direction helps.
Thank you for your inquiry,
Qualcomm Technologies Inc.
Click to expand...
Click to collapse
I have the same problem and also looking for a solution. I will contribute to this post as I find something.
There is a similar post here:
http://forum.xda-developers.com/note-4/help/unbrick-samsung-galaxy-note-4-sm-n910w8-t3249970
---------- Post added at 07:10 PM ---------- Previous post was at 06:30 PM ----------
Try this manual.
http://dl-1.va.us.xda-developers.co....rar?key=yrJPiZgu63c6RxNIbU_xVA&ts=1474829412
I've found it earlier today but haven't had a chance to try it yet.
Says the file is gone
Sent from my SM-N930W8 using XDA Labs
It's just the pdf and .pit that i used here: http://forum.xda-developers.com/note-4/help/hard-brick-phone-off-long-help-fellow-t3468792
yashthemw said:
Is it going in download mode or recovery ?
What were you exactly flashing ?
Is it detected in pc as qhsb loader ?
Is the splash screen GALAXY NOTE 4 showing up ?
Sent from my SM-N910G
Click to expand...
Click to collapse
it won't boot at all
i was messing around with the system on the factory binary firmware
yes, it is
nope, it will not boot
i have same problem does any one sucess with this process ?
Hey guys, i successfully created a Debrick.img for note 4 , used my own functional note 4 to create one .
http://forum.xda-developers.com/showthread.php?t=3488114
Don't forget to Press thanks .
Reporting Via N910G.
yashthemw said:
Hey guys, i successfully created a Debrick.img for note 4 , used my own functional note 4 to create one .
http://forum.xda-developers.com/showthread.php?t=3488114
Don't forget to Press thanks .
Reporting Via N910G.
Click to expand...
Click to collapse
can you get me a dude with an AT&T note 4?
same boat with my N910F
C_dog_1 said:
Hello All,
First let me say thanks to all XDA Developers, and without this forum I would still be a pleb when it comes to unbricking. :highfive:
The link to QPST: androidbrick.com/download/latest-qpst-2-7-build-422-425-430-437-qfil-qualcomm-flasher/
(Sorry, I haven't passed 10 posts yet, so you have to manually enter into the address bar)
I came to this forum seeking answers to unbrick my hardbricked Note 4, and after many hours of heartbreak and headache, I have come across a tool called QPST.
This tool is used by Qualcomm, and if you read carefully through the accompanying documentation, you will find some interesting stamps - such as "Confidential" etc.
While I am no expert in the use of QPST, from my own incomplete research I am convinced this tool can be used on any device which sports a Qualcomm chipset (Snapdragon etc.) to unbrick it from certain death.
I have not yet succeeded with my attempts at unbricking, but it is now only a matter of time and kind people pointing me in the right directions. :fingers-crossed:
I am looking for the right files to go in the "phone image" and "boot image" lines in the QPST Software Download program.
I hope we can all see the opportunity this tool represents and spread the word among the greater community, not just developers.
Edit:
Using Software Download:
Phone image files will have a .hex extension and I do not believe they can be found on sammobile. I still haven't found the right one.
Boot image files: I still don't know what they will look like. Likely a .hex file.
Using QFIL:
I suspect all these files can be acquired from a service ROM (whatever a service ROM is - I don't think it is a ROM for android as I know them). I am not completely sure of this however.
Using the flat build option will let you select the programmer. It will have a file name like:
prog_emmc_firehoseXXXX.mbn
(Replace XXXX with the correct numbers for your snapdragon. I don't know what the right ones for the Snapdragon 805 are, but I strongly suspect 8084, with a remote possibility of 8064. Edit: I don't know, don't take my word.
There are posts for other phones on XDA, I don't know if they use the 805 chipset or if the files are compatible.) <--- If anyone wants to research, feel free. Team efforts make a big job seem easy! Please post your results!
Accompanying your firehose file will be a bunch of other files in the same folder.
You will need two .xml files to go with the above (usually in the same folder), which will look like as follows:
rawprogram0XXXX.xml (here XXXX denotes some numbering system which will be determined by the internal memory of the device eg 16GB, 32GB, 64GB. I saw an example for a OnePlus One which had rawprogram0_64G.xml.
I'm NOT 100% SURE on this numbering system, as elsewhere on XDA I have come across different file names!
Here's the truncated link: androidbrick.com/ultimate-qualcomm-snapdragon-unbrick-guide-snapdragons-are-unbrickable-qhsusb_dload_qpst_qfil/)
patch0.xml
When I find the above, I will post or hassle an admin to post, as these will likely unbrick any Snapdragon 805. Happy hunting!
Here's a truncated link to XproZayd's thread, where a different avenue is explored (and where I got my idea about the 8084 number for firehose -- Remember, I could be wrong!)
forum.xda-developers.com/note-4/help/unbrick-samsung-galaxy-note-4-sm-n910w8-t3249970
This thread is for discussing QPST and how to use it - if you have a hard bricked phone I am not able to help at this stage. However, should anybody find / 'acquire' the right files to use with QPST, we will all benefit.
Click to expand...
Click to collapse
Im in the same boat with my NOTE 4 N910F. Totally blacked out but still picking it up on the PC with QFIL files have found some files but there not the right phone I think.
so fails to load with SAHARA.
cannot find firehose for 910F. Wish someone could solve this one and then publish it all. someone will eventually but QFIL will unbrick all Qualcomm provided you can make the files.
Let me know if you or anyone does. cheers
Lofhario said:
Im in the same boat with my NOTE 4 N910F. Totally blacked out but still picking it up on the PC with QFIL files have found some files but there not the right phone I think.
so fails to load with SAHARA.
cannot find firehose for 910F. Wish someone could solve this one and then publish it all. someone will eventually but QFIL will unbrick all Qualcomm provided you can make the files.
Let me know if you or anyone does. cheers
Click to expand...
Click to collapse
https://forum.xda-developers.com/showthread.php?t=3488114
Tried this?
Reporting Via N910G.
Hi, got a Phicomm Energy M+ (E551). It turned off as the battery was empty, so I charged it overnight.
But:
-Switching it on only shows the phicomm logo
-Trying to enter recovery, shows phicomm logo for a second and then the screen stays lit. Nothing else happens.
-On Windows 7 device manager shows it as "RELINK HS-USB QDLoader 9008 (Com3)" (VOL Up+VOL Down + Power)
-fastboot/adb wont find it
-I tried this http://www.droidsavvy.com/unbrick-qualcomm-mobiles/
I dont have a emmc backup but an unzipped Stock ROM of the E551L which support told me to use. (put on SD card and reboot into recovery, but I cant get into recovery)
Hence I use the unzipped ROM with the Qualcomm FLasher :S (http://na.phicomm.info/release/E551L...TA package.zip)
-It starts the process but then says "Failed to enter EDL" (Emergency) mode
Another thing I stumbled across is :
E551L has Qualcomm MSM8916 and Android 4.4.2
E551M has Qualcomm MSM8915 and Android 4.4.4
Will I have to quire a deepflash cable or am I missing something here ?
yashthemw said:
Hey guys, i successfully created a Debrick.img for note 4 , used my own functional note 4 to create one .
http://forum.xda-developers.com/showthread.php?t=3488114
Don't forget to Press thanks .
Click to expand...
Click to collapse
tried but not working
waiting for other solution

Wanted Firmware for Chinese 7" Head Unit with AC8227 YT9216B_00002_V004_20190530

Hello I need help, by mistake I flashed SP_Flash_Tool a version that in the end was incompatible with my AC8227 YT9216B with what remained brick.
I am trying to recover it with versions that download YT9217 and YT9218 but it is known that they are very different from the version that I had the YT9216B_00002_v004_20190530 and by means of USB bridging the test point close to negative but even though the program SP_Flash_Tool- 5.1916 always ends with failure 4032 or 5054 both related to the DMRAM.
There would be someone in the forum that could help me indicating where to find the link to download my ROM? I have already reviewed the month of 400 pages of the 4PDA forum and I did not find it.
I believe this (Link) is the version you are looking for. Its a memory dump. If you need help flashing it, follow the instruction here. Error 4032 means you are not using correct scatter file. and 5054 means there is not correct preloader file to go with the scatter. You can try the one I have shared, or copy the 2 files from other similar firmwares offered at 4pda
I hope it helps.
lmmerono said:
Hello I need help, by mistake I flashed SP_Flash_Tool a version that in the end was incompatible with my AC8227 YT9216B with what remained brick.
I am trying to recover it with versions that download YT9217 and YT9218 but it is known that they are very different from the version that I had the YT9216B_00002_v004_20190530 and by means of USB bridging the test point close to negative but even though the program SP_Flash_Tool- 5.1916 always ends with failure 4032 or 5054 both related to the DMRAM.
There would be someone in the forum that could help me indicating where to find the link to download my ROM? I have already reviewed the month of 400 pages of the 4PDA forum and I did not find it.
Click to expand...
Click to collapse
viktorsaari said:
I believe this (Link) is the version you are looking for. Its a memory dump. If you need help flashing it, follow the instruction here. Error 4032 means you are not using correct scatter file. and 5054 means there is not correct preloader file to go with the scatter. You can try the one I have shared, or copy the 2 files from other similar firmwares offered at 4pda
I hope it helps.
Click to expand...
Click to collapse
Thank you very much for your help, I will try it immediately to see if with a little luck and your copy of the firmware convinces my computer and starts once and for all, although I do not have too much hope, but anyway, we will try achieve.:good
Nothing, still the same, error 4032 put it as you put it.
Connected to a 12V source the screen starts in a blue color and there is no change unless the reset button is pressed, I don't know if that can indicate any other fault such as that the MCU memory had been erased or corrupted and that is why he does not stop doing anything but the question is that following the procedure for the use of the "test point" step by step always cindependently of using a flash tool or another, of using different scatter files or firm YT9216 / 17/18, B, Whatever the question is, always, always the blissful error 4032 above all.
I don't know what to do, any suggestion is accepted even if it is to use a hammer as a tool.
did you try the scatter and preloader from my post?
viktorsaari said:
did you try the scatter and preloader from my post?
Click to expand...
Click to collapse
yes both and in different ports of the PC (windows10)
the error you have described is only the wrong scatter and preloader file. its only a matter of finding the correct one. I also found the scatter that worked from a different firmware(the firmware didnt work but only the scatter did) , and installed different firmware. It might be possible for you to extract original scatter from the device using MTK droid tools.
lmmerono said:
yes both and in different ports of the PC (windows10)
Click to expand...
Click to collapse
viktorsaari said:
the error you have described is only the wrong scatter and preloader file. its only a matter of finding the correct one. I also found the scatter that worked from a different firmware(the firmware didnt work but only the scatter did) , and installed different firmware. It might be possible for you to extract original scatter from the device using MTK droid tools.
Click to expand...
Click to collapse
Thanks, I found about 20 scatter files between AC8227_Android_scatter and MT3367_Android_scatter, I have about 10 preloader_8227l_demo_ (Preloader) and another 15 different SP_Flash_Too.
I will have to arm myself with patience and try different combinations (so far I have tried more than 50 with the same result, the always present ERROR (4032).
We'll see if I get it or give up before, the ideal is that somewhere the files were found together and that they were already successfully tested but that would be daydreaming.:crying:
Another possible solution would be to enter the way that I would recognize a USB Flash drive with an XYAUTOUPG file or whatever I had tried with it but since this brick after pressing the reset it still does not know.
wow, I'm impressed by your patience
I also downloaded many files from the Russian forum. One of the problems I faced is if the folder name contains some Russian characters, the flashtool gives similar errors. Also some suggested, removing first 4 lines from the scatter file helps in some cases.
I remember I also had disappointments first. Many times I packed everything up and put in storage, but then brought it back for further testing. and one day I got lucky. Hopefully you too will fix it soon.
lmmerono said:
Thanks, I found about 20 scatter files between AC8227_Android_scatter and MT3367_Android_scatter, I have about 10 preloader_8227l_demo_ (Preloader) and another 15 different SP_Flash_Too.
I will have to arm myself with patience and try different combinations (so far I have tried more than 50 with the same result, the always present ERROR (4032).
We'll see if I get it or give up before, the ideal is that somewhere the files were found together and that they were already successfully tested but that would be daydreaming.:crying:
Another possible solution would be to enter the way that I would recognize a USB Flash drive with an XYAUTOUPG file or whatever I had tried with it but since this brick after pressing the reset it still does not know.
Click to expand...
Click to collapse
viktorsaari said:
wow, I'm impressed by your patience
I also downloaded many files from the Russian forum. One of the problems I faced is if the folder name contains some Russian characters, the flashtool gives similar errors. Also some suggested, removing first 4 lines from the scatter file helps in some cases.
I remember I also had disappointments first. Many times I packed everything up and put in storage, but then brought it back for further testing. and one day I got lucky. Hopefully you too will fix it soon.
Click to expand...
Click to collapse
Thanks for your help but I don't get results on the other hand, the test point disappeared from using it so much, it was deleted and since the processor does not have the pins in the air it can no longer even be tried.
I do not know if there is another test point or one that could help for the purpose that is sought and is: to start this brick.
On the main board, from where there would be a SIM socket, there is a connector that could appear to be a USB socket to be used by the Technical Service in the commissioning of the newly assembled ones.
Anyway, I just want to be able to recover my radio.
Thanks for your help.
Hello my friend I hope you upload the file again, YT9216B_00002_v004_20190530 * Thank
viktorsaari said:
I believe this (Link) is the version you are looking for. Its a memory dump. If you need help flashing it, follow the instruction here. Error 4032 means you are not using correct scatter file. and 5054 means there is not correct preloader file to go with the scatter. You can try the one I have shared, or copy the 2 files from other similar firmwares offered at 4pda
I hope it helps.
Click to expand...
Click to collapse
Hello my friend
I hope you upload the file again,
YT9216B_00002_v004_20190530
* Thank you
imr088888 said:
Hello my friend
I hope you upload the file again,
YT9216B_00002_v004_20190530
* Thank you
Click to expand...
Click to collapse
Not exactly the same date but this will work. Just a newer update with root and TWRP
Firmware YT9216B_00002_V004_20190826 (UI1) ROOT, TWRP, translation. (1/16)
https://drive.google.com/file/d/132kkj5neExIr9UufZIgAqeEu67JSVtu3/view
Hi my friend, I could not update, I put the update in usb and the update did not show me, is there a certain way to install?
Hi there I exausted the whole xda and russian forum for something that can work..
exausted different forums.... and tryd a lot of firmware and methods...
I did about the same I am afraid.... no backup and now black screen on startup and no connection to usb no more......
yesterday it still connected to my laptop....you could hear it connect in windows but i couldnt get anything to load on it... all sorts of errors in Flash tool....
eventually i I Did manage to download the preloader onto ny headunit from firmware I found in this post....
I found out that I had to use this order: I would connect my usb... click download in Flashtool then it starts... and I switch on the power of my head unit.... and it completed the upload of the preloader..... So i finally thought Yessssss now install the rest of the firmware.... but after this I had no connection with my head unit... it doesnt find it anymore trough USB.....
but after that I installed that preloader file... I can no longer get any connection no more to my hu....
please help me out.... I also did read some stuff that you need to connect or push 3 spots togheter on youre pcb...?? does anyone got more information or a clear foto of wich and how I connect these 3 spots?
Or maybe now a way I can unbrick my device or have correct software for me??
Ive been trying to fix it 4 3 days in a row now... but I am about to go insane
System information I found in factory settings when the unit was still stock and untouched:
YT9216B_00002_V004_20190708
kenel: 3.18.22
Flash:16G
CPU:A7 1.3 GHz x 4
Display 1024 * 600
MCU1: HW8227L-3.3-SW0-3.1
Inide when i open it op the sticker on the connectors on the pcb tells me:
YT9216B Vo.1 16C
A.005-YT9216B004
20200214
And here is the information of the store i bought it from in the original advertisement:
Specifications on website:
● System:Andriod 8.1
● Model:SU 9701
● Radio Chip:QN8035
● Software:8227L
● Type:Android navigation MP5
● Size:7 Inch
● Bluetooth:Bluetooth 4.0
● Resolution:1024*600
● Audio Amplifier:TDA7388
● Voltage:12V
● Power Output:60W
● Memory:1G+16G
● Audio format:MP3/WMA/WA/OGG/FLAC/APE
● Video format:RM/RMVB/MP4/FLV/MKV/3GP/AVIASF/SWFMP1
● Image foramt:JPG
● FM Range:FM 87.5~108MHz
● Operating temperature:-10℃ ~ +60℃
● USB Interface:USB 2.0
● Product Size:188mm*58mm*165mm
● Weight:1922g
● Button: Physical button/Reset button
● Factory password:1111
My apologies for my bad English (not my native language).
Hope you guys can help me unroot it...
martinique78 said:
Not exactly the same date but this will work. Just a newer update with root and TWRP
Firmware YT9216B_00002_V004_20190826 (UI1) ROOT, TWRP, translation. (1/16)
https://drive.google.com/file/d/132kkj5neExIr9UufZIgAqeEu67JSVtu3/view
Click to expand...
Click to collapse
I have this radio version and I can't update it. I tried USB update with a flash pen USB and gave me an error. I tried with SP flash and gave me error 4032 with the test points method... I don't know what can I do more.
DFC said:
I have this radio version and I can't update it. I tried USB update with a flash pen USB and gave me an error. I tried with SP flash and gave me error 4032 with the test points method... I don't know what can I do more.
Click to expand...
Click to collapse
I gave up on this junk radio a while ago...worked for a few days then it just went blank and got really hot so i pulled it out. Now it sits in a box in pieces.
My radio looks like a PODOFO, It's a YT9216B_00002_v004_20190826 firmware but aida64 show yt9218B.
I tried some methods, nothing worked. I tried to update via Android update, flash with USB with SP flash, flash with USB pen and sd card, without success .I decided to try again. Can someone help me, and on first place tell me what is the correct firmware for this device? And a full tutorial step by step (without shortcuts)? or some tip that can help me?
yt9216b
hello can you help me please me send new rom
thank you
YT9216B?
morio005 said:
hello can you help me please me send new rom
thank you
Click to expand...
Click to collapse
Hi, I wanted to know if this version of the radio was updated? Thank you
Renstaman said:
Hi there I exausted the whole xda and russian forum for something that can work..
exausted different forums.... and tryd a lot of firmware and methods...
I did about the same I am afraid.... no backup and now black screen on startup and no connection to usb no more......
yesterday it still connected to my laptop....you could hear it connect in windows but i couldnt get anything to load on it... all sorts of errors in Flash tool....
eventually i I Did manage to download the preloader onto ny headunit from firmware I found in this post....
I found out that I had to use this order: I would connect my usb... click download in Flashtool then it starts... and I switch on the power of my head unit.... and it completed the upload of the preloader..... So i finally thought Yessssss now install the rest of the firmware.... but after this I had no connection with my head unit... it doesnt find it anymore trough USB.....
but after that I installed that preloader file... I can no longer get any connection no more to my hu....
please help me out.... I also did read some stuff that you need to connect or push 3 spots togheter on youre pcb...?? does anyone got more information or a clear foto of wich and how I connect these 3 spots?
Or maybe now a way I can unbrick my device or have correct software for me??
Ive been trying to fix it 4 3 days in a row now... but I am about to go insane
System information I found in factory settings when the unit was still stock and untouched:
YT9216B_00002_V004_20190708
kenel: 3.18.22
Flash:16G
CPU:A7 1.3 GHz x 4
Display 1024 * 600
MCU1: HW8227L-3.3-SW0-3.1
Inide when i open it op the sticker on the connectors on the pcb tells me:
YT9216B Vo.1 16C
A.005-YT9216B004
20200214
And here is the information of the store i bought it from in the original advertisement:
Specifications on website:
● System:Andriod 8.1
● Model:SU 9701
● Radio Chip:QN8035
● Software:8227L
● Type:Android navigation MP5
● Size:7 Inch
● Bluetooth:Bluetooth 4.0
● Resolution:1024*600
● Audio Amplifier:TDA7388
● Voltage:12V
● Power Output:60W
● Memory:1G+16G
● Audio format:MP3/WMA/WA/OGG/FLAC/APE
● Video format:RM/RMVB/MP4/FLV/MKV/3GP/AVIASF/SWFMP1
● Image foramt:JPG
● FM Range:FM 87.5~108MHz
● Operating temperature:-10℃ ~ +60℃
● USB Interface:USB 2.0
● Product Size:188mm*58mm*165mm
● Weight:1922g
● Button: Physical button/Reset button
● Factory password:1111
My apologies for my bad English (not my native language).
Hope you guys can help me unroot it...
Click to expand...
Click to collapse
Hello, Did you solve issue?
I'm facing same issue. My android radio is the same of yours.

YT9213AJ 2gb/16gb rooting/recovery

Do not blindly flash this device without knowing what you are doing. While the device is hard to brick in general, it is very easy for someone new to brick it by flashing the wrong partitions.
I will write a generalized tutorial that will cover the basics and hopefully make everyone feel better about flashing the device. At first I was skeptical but after understanding everything, I have to say it really isn't that bad, and I am here doing all the leg work for these fake 2gb (its really 1gb ram) and 16gb hdd
OK I am goin gto try and put all of this information in one place because these units say android 10 or 10.1 but in reality cpu-z they are android 9 with api of 27 (will double check to be sure. This unit says it is 2gb ram but it is indeed 1024 MB (q GB). I am not sure if the other custom firmwares dumps from 1gb yt9213aj models will work without problems on these yt9213aj units that say 2gb.
In order to try anything you need to first make a scatter file for your unit. I messaged the manufacture of my unit for a firmware and they sent it. I unzipped it and looked at the scatter file and it is of a different formatting than one that comes from mtk droid tool.
So, mtk droid tool doesn't work with OS versions 9 or higher. It is the problem of adb. But we can follow this guide https://forum.xda-developers.com/t/...not-revealed-error-in-mtkdroid-tools.3582571/ and get it to work.
Once you have your device connected and recognized in droid tools you should first create the scatter file, as this is the most important step to do a full readback in SP flash tools.
Once you have a backup, you are in the clear for the most part. I am still trying to figure out how to backup preloader and etc if possible.
Now you will also need to connect some kind of wire or some small buttons taken from something disassembled. Just something that you can use as a mock button because there is no hardware button on the device for up/down and OK and you cannot use the touch buttons. So you need to short these traces while in recovery in order to get further/
The main point of this thread is to update the existing ones and to add tools and stuff nmeeded in one location because it has taken me over 5 days to search for all fo this, and I am still not done, so lets make it a little easier on the new comers because the last thing we want to do is brick each others devices by using old outdated guides that don't fully work.
Flow chart of process: install mtk droid tools and sp flash tools ->enable oem debugging and oem unlock on device -> follow guide to get mtk droid tools to work -> get scatter file using mtk droid tools -> make a full readback in sp flash tools -> solder wires/buttons onto test points -> boot to fastboot and unlock bootloader -> fastboot flash recovery <image name> -> boot into recovery and install root and/or custom firmware.
Anyone more skilled knows any better?
This post is a WIP and will be updated periodically as I source information. The main idea behind this post is to bring all resources for yt9213aj in one spot. There is plenty of information, its just very hard to navigate especially for someone new to flashing these devices, and even worse to someone who has never flashed any device
OK after trying what seems like 300 twrp's I finally found one that does work with this device. I thin kthe main difference here is that the board is a new revision and some arch changes caused older version that were ported to not work. This one booted right into it but was in russian, which is easily fixable within the twrp gui.
I will add all of these files to the op when I have collected everything.
I do not think that this version board I have has hifi? Maybe I am mistaken? I have an audio glitch at 19-20 when playing music, the sound will get louder and sound good for a fraction of a second then return to sounding ****ty. So I will look into this more. What sucks is that there are so many of the same **** that doesn't work for this model so its like... I would rather garggle gasoline than have to sift through forums that were translated on the fly
Anyway here is the twrp for this particular device - https://www.dropbox.com/s/vogg7854a7ln2zu/twrp-9213aj.img?dl=0
EDIT: also you can boot to fastboot (adb reboot bootloader) and use fastboot getvar all to get factory partition sizes that's needed to create scatter file (you will need to use a hex calculator to create it, or wait for me to upload my scatter file once I have it done). You need to be making dumps in sp flash tool way before you are ever writing anything. Make plenty of readbacks and get to know how to read it before you write anything. Blindly flashing is not what you really want to do lol
Mtk drivers for pc
to install, you will need to disable signature verification and I had to turn on test signing as well
I have successfully rooted this thing. I did encounter something kind of strange though. When I patched the boot.img I had from the device and the one I got in ota update and patched with magisk. When I booted and checked the root with magisk it said there was an unsupported root using su already. It did this for both boot.imgs.
Anyone ever heard of this on stock firmwares? I am able to grant root permissions to busybox and etc so it seems to be working OK. Maybe the root that is there is the chinese root for backdoor tracking and surveillance xD
Wonder how to see what unsupported su commands are being sent?
EDIT: i also took a lot of pictures of the board. It is yt9213aj v1.2 board. I will update the original post in the few days with everything needed for this model including testpoints etc. The test points are a little different but its pretty much the same. The only two you need in the end are the two bigger ones (for unlocking bootloader) then your set. You could drill some holes and run wire down to the trace and put some hardware buttons for the mcu to use to select things in fastboot and official recovery.
There is also another port/connector on this thing above the touch sensor board. I think we could buy a ribbon cable to connect here and run it to another board with hardware button. Actually I think the connector is for hardware buttons specifically but I don't know for sure. Must do more research
These things have are rooted from the factory. When I try to use magisk it says there is another unsupported su. The Unsu.zip floating around cures that. Then you can install magisk.
Also another thing about these things being prerooted... I think you can dump and flash without any extra sp flash tools or mtkdroid. I was dumping the partitions using adb pull function. Adb pull /dev/block/platform/soc/11230000.mmc/by-name/<insert partition name here>"
And
"/dev/block/mmcblk0pxx" where xx is the specific partition to read/write to.
I had got a scatter.txt in the ota update I obtained from the manufacturer which had all the partition layouts. I used this and a log from a failed supersu.zip install to create a scatter.txt for this particular device. The supersu log can be obtained by trying to flash the supersu zip in recovery, then in adg just pull the log file adb shell cat /tmp/recovery.log. Once you have this, you will have to use brain.exe to make your own scatter for sp flash tools.
All in all its pretty easy to actually root the device, and they are actually rooted from the factory, most likely for some functions within the os to work (like surveillance and spying xD) but that can easily be removed with the unsu.zip then install magisk.
I will be writing up a guide for this specific model in a few more days. If you read this thanks for listening to the rumbling of a mad man
Just discovered another problem. When I try to edit anything in /system it says its read only. Mounting is or remounting it shows as successful with no errors, but something is blocking it from mounting as system. I am trying to rename this audio_effects.conf and it willnt let me. I think it might be some proprietary code in the kernel designed to block mounting or remounting of certain or all partitions.
I think that a lot of them are software locked, like the fader and balance and volume level. Notice how some of these have glitches when turning the volume up and down. I think that there is some code that disables some functions of higher end units, depending on the model. If you buy a cheaper 100 dollar head unit, maybe it is indeed just software locked down.
I know for fact the amp chip in my head unit, YD7388, sec sheet says 4 channel. But my device is only 2 channel, no fader. Also the spec sheet says it needs no output capacitor but mine has one I think (there is a huge capacitor soldered next to the chip. I have some pics of the board and test points and chip markers etc. Once I have everythign ready I will make a nice guide
Wow I think I found the reason this thing outputs as 2 channel on 4 speakers. I need someone with a real 4 channel version to message me so I can get a few files for comparison. If this is the case, a simple magisk module would fix the fixed 2 channel problem we have. In the audio_policy_configuration.xml they have all output set as
XML:
<devicePort tagName="FM Tuner Out" type="AUDIO_DEVICE_OUT_FM" role="sink">
<profile name="" format="AUDIO_FORMAT_PCM_16_BIT"
samplingRates="44100" channelMasks="AUDIO_CHANNEL_OUT_STEREO"/>
</devicePort>
I wonder if you set AUDIO_CHANNEL_OUT_STEREO to multichannel or maybe like "AUDIO_CHANNEL_OUT_QUAD " as described in the official android docs say, I wonder if that would enable true 4 channel (or 5.1)?
If someone who has a 4 real 4 channel stereo and it is around the model of yt9213aj, then send me a message so we can collaborate. If you are not rooted do not worry I will help you

Categories

Resources