chabrus
29.11.2011, 22:30
Предыстория такова: Телефон стал глючить и подтормаживать, почле чего хозяин удалил несколько установленных приложений, и телефон перестал включаться, просто бзикал.
Клиент решил что села АКБ, и подключил ТА к ЗУ, которое в свою очередь он подключил к китайскому преобразователю 12-220в.
Через некоторое время он снял ТА с зарядки, и после попытки включить он просто завис на белом дисплее.
До меня тело прошивали версией 022.003.
Прошил телефон той же версикй Best в реж ме dead usb. Ситуация не изменилась, нет локала и не прошли сбросы.
Затем узнал что это не последняя версия на сегодня, скачал и пролил тем же способом версию 025.007. На дисплее появился локал, и прошли все сбросы. Результат не изменился. ТА все так же висит на белом дисплее.
Заменил Gazoo на 100% рабочую, дальше копать не стал, решив сначала исключить софтовую проблемму на 100%.
Подцепил тело к Cyclone через Fbus и проверка сертификатов показало знакомое Sim Lock damaged:poz:
RPL пока заказывать не решился, поскольку телефон все таки не включается.
Затер тело при помощи Best и прошил последней версией, ничего не изменилось.
К сожалению большинство логов не сохранил, поскольку не думал что придется создавать тему на форуме.
Затер тело через Fbus интерфейс.
Лог cyclone:
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
Erasing flash chip...
Started group flash erase
EraseArea[0,CMT]: 0x00000000-0x3FFFFFFF, ONENAND
Waiting 640s for erasure finish...
Erase taken 4.157s
Restarting MCU...
BB5 Full Erase Finished!
Лог прошивки тем же продуктом:
Scanning avaiable products...
Processing C:\Program Files\Nokia\Phoenix\Products\...
Found 17 products, Filtering BB5 Products - wait...
5 Products left after filtering. Ready.
Retrieving Variants for Product RM-675 - wait...
2 Variants Retrieved
Processing pre flash tasks...
Pre flash tasks finished, continuing...
Processing RM-675_025.007_79.92_prd.core.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_79.92_prd.core.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0xFFFFFFFF00000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
Warning: PAPUBKEYS Hash Missing!
Flashbus Write baud set to 5.0Mbits
Sending Certificates...
Certificates OK
Partitioning...
Partitioning OK
Started group flash erase
EraseArea[0,CMT]: 0x00040000-0x0007FFFF, ONENAND
EraseArea[0,CMT]: 0x000C0000-0x008BFFFF, ONENAND
EraseArea[0,CMT]: 0x00DC0000-0x0E97FFFF, ONENAND
EraseArea[0,CMT]: 0x2E100000-0x3E5FFFFF, ONENAND
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 2.94s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT ADA Certificate...
Writing CMT KEYS Certificate...
Writing CMT PRIMAPP Certificate...
Writing CMT RAP3NAND Certificate...
Writing CMT SOS+PMML Certificate...
Writing CMT PASUBTOC Certificate...
WARNING: CMT PAPUBKEYS Hash is Empty, writing first found PAPUBKEYS
Writing CMT PAPUBKEYS Certificate...
Writing CMT GENIO_INIT Certificate...
Writing CMT SOS*UPDAPP Certificate...
Writing CMT SOS*DSP0 Certificate...
Writing CMT LDSP Certificate...
Writing CMT SOS*ISASW Certificate...
Writing CMT SOS+CORE Certificate...
Writing CMT SOS+ROFS1 Certificate...
Programming Status OK!
All blocks written OK! Time taken 139.250s
Flashing Speed: 7413,60 kBit/S
Restarting MCU...
Processing RM-675_025.007_79.92_prd.core.fpsx (APE)...
Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x09F40000-0x0DA7FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.266s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS2 Certificate...
Programming Status OK!
All blocks written OK! Time taken 52.735s
Flashing Speed: 7593,13 kBit/S
Restarting MCU...
Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx (APE)...
Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_00.01_79.92_prd.rofs3.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x0DA80000-0x0E97FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.94s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS3 Certificate...
Programming Status OK!
All blocks written OK! Time taken 0.281s
Flashing Speed: 139,93 kBit/S
Restarting MCU...
Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx (APE)...
Processing RM-675_025.007_U01.01_79.92.uda.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_U01.01_79.92.uda.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x0E980000-0x2E0FFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 2.93s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Programming Status OK!
All blocks written OK! Time taken 172.109s
Flashing Speed: 7258,60 kBit/S
Restarting MCU...
Processing RM-675_025.007_U01.01_79.92.uda.fpsx (APE)...
Processing rm675_ENO_v_0.0491_APEONLY.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
rm675_ENO_v_0.0491_APEONLY.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Sending Certificates...
Certificates OK
Started group flash erase
EraseArea[0,CMT]: 0x008C0000-0x00DBFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.47s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS*ENO Certificate...
Programming Status OK!
All blocks written OK! Time taken 5.125s
Flashing Speed: 7095,77 kBit/S
Restarting MCU...
Processing rm675_ENO_v_0.0491_APEONLY.fpsx (APE)...
All images processed OK! Processing post flash tasks...
Setting Factory Defaults...
Factory defaults OK
Reading info...
MCU Version V 92_11w37
MCU Date 14-09-11
Product RM-675 (Nokia C7-00)
Manufacturer (c) Nokia
IMEI 12345610654321?
IMEI Spare 1A32541660452301
IMEI SV 1332541660452321F1000000
PSN 0
PSD 0000000000000000
LPSN 0
APE SW 025.007
APE Variant 025.007025.007.04.01025.007.00.01
APE Test rm675_ENO_v_0.0491
APE HW 256
APE ADSP 256
APE BT HCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.
RETU 35
TAHVO 00
AHNE 11
PCI o256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
UEM 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
RFIC |Alli_4.3.4
DSP 92_11w36
LCD 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91Ґ025.007.U01.01
ADSP DevID 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
ADSP RevID 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
Failed to read info -> Failed to read SP info
Read info thread finished, continuing...
Post flash tasks finished!
Flashing successfully finished!
По идее телефон после этого должен включиться и запуститься, только с дефолтным имей, но он по прежнему висит на белом дисплее и не запускается.
Пролил Бестом сертификаты которые он автоматом сливает перед прошивкой,
Результат:
Checking StartUp data ...
-----------------------
SDD Key status : SDData is Ok
SimLock status : SimLock Damaged!!!!! :(
- > Do REPAIR SL if it SL2/SL phone, if SL3 - Help Only Backup Or RPL
Security status : Security is Ok
-----------------------
PA_SimLock Version :
PA_SL phone detected
Done!
Прошил тело бестом еще раз:
Core version : 1.30 Rev : 1.1
Selected FlashSettings :
Check FlashFiles, Please, wait...
Files Set for Flashing :
MCU : RM-675_025.007_79.92_prd.core.fpsx
PPM : RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx
PPM2 : RM-675_025.007_00.01_79.92_prd.rofs3.fpsx
CNT : RM-675_025.007_U01.01_79.92.uda.fpsx
APE : rm675_ENO_v_0.0491_APEONLY.fpsx
Flashing phone now...
Check files done...
-> SWversion check skipped : Dead mode selected
Dead Mode is Selected
Waiting for USB device...
--- Insert cable and charger or press phone's power button! ---
Connection opened successfully
Waiting for communication response...
[BB5 FLASH]: Bootrom Ok!
ASIC ID: 000000030000022600010007600C192102031104
CPU ID : RAPU v11 , Features : Dead-Test , USBRPL , FullUSB
EM0 ID: 00000C35
EM1 ID: 00000C30
PUBLIC ID: 27D00005BFA80344F6035905AAA941F74938BCA8
ASIC MODE ID: 00
ROOT KEY HASH: 916F75217F32081248B15C38DFC8E81B
ROM ID: E693EF0DAC22615B
Use RAPUv11_2nd.fg , Rev : 3.0 Ver : 11.34.0
Processing RAWLOADER...
FLIC : 006800EC
Req : XSR 1.6
Use RAPUv11_XSR17_alg.fg , Rev : 3.0 Ver : 11.34.0
Processing PASUBTOC ...
Processing ALG ...
Boot Done! :)
TIME : Boot time : 00:00:03
Reopening the connection...
Waiting for response: 30
Waiting for response: 29
ADL: Check mode
Select ASIC [C900]
PAPUBkeys : 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
ADL: phone is in flash mode
Backup enabled, will read all certificates...
Reading NPC certificate...
IMEI : 355379043622892
Reading CCC certificate...
Reading HWC certificate...
Reading R&D certificate...
Reading VARIANT certificate...
Reading PARTNERC certificate...
Reading MDM_KEYS certificate...
Cert Read done!
NPC Certificate saved...
CCC Certificate saved...
HWC Certificate saved...
RPL saved : c:\InfinityBox\BEST\Backup\Cert\355379043622892_CR T_2nd.rpl
===Flashing [MCU]===
Erase : Processing RM-675_025.007_79.92_prd.core.fpsx
Partitioning....
Partitioning Ok...
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:02
Write : Processing RM-675_025.007_79.92_prd.core.fpsx
CMT: Writing Hash CERT [ADA]
CMT: Writing Hash CERT [KEYS]
CMT: Writing Hash CERT [PRIMAPP]
CMT: Writing Hash CERT [RAP3NAND]
CMT: Writing Hash CERT [SOS+PMML]
CMT: Writing Hash CERT [PASUBTOC]
CMT: Writing Hash CERT [PAPUBKEYS]
CMT: Writing Hash CERT [GENIO_INIT]
CMT: Writing Hash CERT [SOS*UPDAPP]
CMT: Writing Hash CERT [SOS*DSP0]
CMT: Writing Hash CERT [LDSP]
CMT: Writing Hash CERT [SOS*ISASW]
CMT: Writing Hash CERT [SOS+CORE]
CMT: Writing Hash CERT [SOS+ROFS1]
Total writen 516 blocks
TIME : Write time : 00:00:14
MCU Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [PPM]===
Erase : Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:00
Write : Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx
CMT: Writing Hash CERT [SOS+ROFS2]
Total writen 192 blocks
TIME : Write time : 00:00:05
PPM Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [PPM2]===
Erase : Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:00
Write : Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx
CMT: Writing Hash CERT [SOS+ROFS3]
Total writen 2 blocks
TIME : Write time : 00:00:00
PPM Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [CNT]===
Erase : Processing RM-675_025.007_U01.01_79.92.uda.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:02
Write : Processing RM-675_025.007_U01.01_79.92.uda.fpsx
Total writen 596 blocks
TIME : Write time : 00:00:20
CNT Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [APE]===
Erase : Processing rm675_ENO_v_0.0491_APEONLY.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:00
Write : Processing rm675_ENO_v_0.0491_APEONLY.fpsx
CMT: Writing Hash CERT [SOS*ENO]
Total writen 19 blocks
TIME : Write time : 00:00:00
APE Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
ADL: Close_Session
Content: 000300000000020000000200000000
ADL: Reboot
Flashing done!
Total flash time : 00:00:46
Reboot phone now...
Reading Phone Info....
Connected phone - Nokia C7-00
Software Info: V 92_11w37 14-09-11 RM-675 (c) Nokia
IMEI: 355379043622892
Ape Version: 025.007
Product code: 059D9Z9
Checking...
SimLock status : SimLock Damaged!!!!! :(
Security status : Security is Ok
Read Info Done!
Settings After Flash Defaults...
Error When resetting FullFactory :( ...
Error When resetting Product Tune :( ...
Error When resetting SW upgrade Default :( ...
AfterFlash operations done ;D
Done!
Elapsed: 00:01:22
Connect phone on selected interface...
Локал на дисплее появился, но сбросы не прошли. Ситуация с работоспособностью телефона не изменилась.
Если его затереть, то сбросы проходят.
И не понять, то ли тело так софтово убито, то ли из за перепада напряжения в СЗУ его так торкнуло.
Собственно мне непонятно вот что:
Если скажем в 6300 сбит SD то телефон не будет запускаться.
Должен ли запускаться С7-00 без Sim Lock?
Потому что по идее он должен при включении падать в contact servise, а я где то слышал что в этой модели телефона, contact servise не отображаетсяна дисплее.
И должен ли он включаться после стирания и прошивки, без сертификатов, как остальные телефоны?
И исходя из высшеописанного, есть ли смысл заказывать RPL в данный момент.
ЗЫ: прошу ногами сильно не пинать, просто эта модель только недавно вошла широкое распостранение в моем регионе, и потому достаточного опыта по ее ремонту еще не имею.
С уважением: Руслан.
Клиент решил что села АКБ, и подключил ТА к ЗУ, которое в свою очередь он подключил к китайскому преобразователю 12-220в.
Через некоторое время он снял ТА с зарядки, и после попытки включить он просто завис на белом дисплее.
До меня тело прошивали версией 022.003.
Прошил телефон той же версикй Best в реж ме dead usb. Ситуация не изменилась, нет локала и не прошли сбросы.
Затем узнал что это не последняя версия на сегодня, скачал и пролил тем же способом версию 025.007. На дисплее появился локал, и прошли все сбросы. Результат не изменился. ТА все так же висит на белом дисплее.
Заменил Gazoo на 100% рабочую, дальше копать не стал, решив сначала исключить софтовую проблемму на 100%.
Подцепил тело к Cyclone через Fbus и проверка сертификатов показало знакомое Sim Lock damaged:poz:
RPL пока заказывать не решился, поскольку телефон все таки не включается.
Затер тело при помощи Best и прошил последней версией, ничего не изменилось.
К сожалению большинство логов не сохранил, поскольку не думал что придется создавать тему на форуме.
Затер тело через Fbus интерфейс.
Лог cyclone:
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
Erasing flash chip...
Started group flash erase
EraseArea[0,CMT]: 0x00000000-0x3FFFFFFF, ONENAND
Waiting 640s for erasure finish...
Erase taken 4.157s
Restarting MCU...
BB5 Full Erase Finished!
Лог прошивки тем же продуктом:
Scanning avaiable products...
Processing C:\Program Files\Nokia\Phoenix\Products\...
Found 17 products, Filtering BB5 Products - wait...
5 Products left after filtering. Ready.
Retrieving Variants for Product RM-675 - wait...
2 Variants Retrieved
Processing pre flash tasks...
Pre flash tasks finished, continuing...
Processing RM-675_025.007_79.92_prd.core.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_79.92_prd.core.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0xFFFFFFFF00000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
Warning: PAPUBKEYS Hash Missing!
Flashbus Write baud set to 5.0Mbits
Sending Certificates...
Certificates OK
Partitioning...
Partitioning OK
Started group flash erase
EraseArea[0,CMT]: 0x00040000-0x0007FFFF, ONENAND
EraseArea[0,CMT]: 0x000C0000-0x008BFFFF, ONENAND
EraseArea[0,CMT]: 0x00DC0000-0x0E97FFFF, ONENAND
EraseArea[0,CMT]: 0x2E100000-0x3E5FFFFF, ONENAND
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 2.94s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT ADA Certificate...
Writing CMT KEYS Certificate...
Writing CMT PRIMAPP Certificate...
Writing CMT RAP3NAND Certificate...
Writing CMT SOS+PMML Certificate...
Writing CMT PASUBTOC Certificate...
WARNING: CMT PAPUBKEYS Hash is Empty, writing first found PAPUBKEYS
Writing CMT PAPUBKEYS Certificate...
Writing CMT GENIO_INIT Certificate...
Writing CMT SOS*UPDAPP Certificate...
Writing CMT SOS*DSP0 Certificate...
Writing CMT LDSP Certificate...
Writing CMT SOS*ISASW Certificate...
Writing CMT SOS+CORE Certificate...
Writing CMT SOS+ROFS1 Certificate...
Programming Status OK!
All blocks written OK! Time taken 139.250s
Flashing Speed: 7413,60 kBit/S
Restarting MCU...
Processing RM-675_025.007_79.92_prd.core.fpsx (APE)...
Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x09F40000-0x0DA7FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.266s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS2 Certificate...
Programming Status OK!
All blocks written OK! Time taken 52.735s
Flashing Speed: 7593,13 kBit/S
Restarting MCU...
Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx (APE)...
Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_00.01_79.92_prd.rofs3.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x0DA80000-0x0E97FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.94s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS3 Certificate...
Programming Status OK!
All blocks written OK! Time taken 0.281s
Flashing Speed: 139,93 kBit/S
Restarting MCU...
Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx (APE)...
Processing RM-675_025.007_U01.01_79.92.uda.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-675_025.007_U01.01_79.92.uda.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x0E980000-0x2E0FFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 2.93s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Programming Status OK!
All blocks written OK! Time taken 172.109s
Flashing Speed: 7258,60 kBit/S
Restarting MCU...
Processing RM-675_025.007_U01.01_79.92.uda.fpsx (APE)...
Processing rm675_ENO_v_0.0491_APEONLY.fpsx (CMT)...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 27D00005BFA80344F6035905AAA941F74938BCA8
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
rm675_ENO_v_0.0491_APEONLY.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
Flashbus Write baud set to 5.0Mbits
Sending Certificates...
Certificates OK
Started group flash erase
EraseArea[0,CMT]: 0x008C0000-0x00DBFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.47s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS*ENO Certificate...
Programming Status OK!
All blocks written OK! Time taken 5.125s
Flashing Speed: 7095,77 kBit/S
Restarting MCU...
Processing rm675_ENO_v_0.0491_APEONLY.fpsx (APE)...
All images processed OK! Processing post flash tasks...
Setting Factory Defaults...
Factory defaults OK
Reading info...
MCU Version V 92_11w37
MCU Date 14-09-11
Product RM-675 (Nokia C7-00)
Manufacturer (c) Nokia
IMEI 12345610654321?
IMEI Spare 1A32541660452301
IMEI SV 1332541660452321F1000000
PSN 0
PSD 0000000000000000
LPSN 0
APE SW 025.007
APE Variant 025.007025.007.04.01025.007.00.01
APE Test rm675_ENO_v_0.0491
APE HW 256
APE ADSP 256
APE BT HCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.
RETU 35
TAHVO 00
AHNE 11
PCI o256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
UEM 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
RFIC |Alli_4.3.4
DSP 92_11w36
LCD 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91Ґ025.007.U01.01
ADSP DevID 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
ADSP RevID 256qHDHCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.n256i025.007j("025.007025.007.04.01025.007.00.01krm675_ENO_v_0.04 91
Failed to read info -> Failed to read SP info
Read info thread finished, continuing...
Post flash tasks finished!
Flashing successfully finished!
По идее телефон после этого должен включиться и запуститься, только с дефолтным имей, но он по прежнему висит на белом дисплее и не запускается.
Пролил Бестом сертификаты которые он автоматом сливает перед прошивкой,
Результат:
Checking StartUp data ...
-----------------------
SDD Key status : SDData is Ok
SimLock status : SimLock Damaged!!!!! :(
- > Do REPAIR SL if it SL2/SL phone, if SL3 - Help Only Backup Or RPL
Security status : Security is Ok
-----------------------
PA_SimLock Version :
PA_SL phone detected
Done!
Прошил тело бестом еще раз:
Core version : 1.30 Rev : 1.1
Selected FlashSettings :
Check FlashFiles, Please, wait...
Files Set for Flashing :
MCU : RM-675_025.007_79.92_prd.core.fpsx
PPM : RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx
PPM2 : RM-675_025.007_00.01_79.92_prd.rofs3.fpsx
CNT : RM-675_025.007_U01.01_79.92.uda.fpsx
APE : rm675_ENO_v_0.0491_APEONLY.fpsx
Flashing phone now...
Check files done...
-> SWversion check skipped : Dead mode selected
Dead Mode is Selected
Waiting for USB device...
--- Insert cable and charger or press phone's power button! ---
Connection opened successfully
Waiting for communication response...
[BB5 FLASH]: Bootrom Ok!
ASIC ID: 000000030000022600010007600C192102031104
CPU ID : RAPU v11 , Features : Dead-Test , USBRPL , FullUSB
EM0 ID: 00000C35
EM1 ID: 00000C30
PUBLIC ID: 27D00005BFA80344F6035905AAA941F74938BCA8
ASIC MODE ID: 00
ROOT KEY HASH: 916F75217F32081248B15C38DFC8E81B
ROM ID: E693EF0DAC22615B
Use RAPUv11_2nd.fg , Rev : 3.0 Ver : 11.34.0
Processing RAWLOADER...
FLIC : 006800EC
Req : XSR 1.6
Use RAPUv11_XSR17_alg.fg , Rev : 3.0 Ver : 11.34.0
Processing PASUBTOC ...
Processing ALG ...
Boot Done! :)
TIME : Boot time : 00:00:03
Reopening the connection...
Waiting for response: 30
Waiting for response: 29
ADL: Check mode
Select ASIC [C900]
PAPUBkeys : 95A68E9FA27B2BFA89EA204FC846EB73DEF1D93F
ADL: phone is in flash mode
Backup enabled, will read all certificates...
Reading NPC certificate...
IMEI : 355379043622892
Reading CCC certificate...
Reading HWC certificate...
Reading R&D certificate...
Reading VARIANT certificate...
Reading PARTNERC certificate...
Reading MDM_KEYS certificate...
Cert Read done!
NPC Certificate saved...
CCC Certificate saved...
HWC Certificate saved...
RPL saved : c:\InfinityBox\BEST\Backup\Cert\355379043622892_CR T_2nd.rpl
===Flashing [MCU]===
Erase : Processing RM-675_025.007_79.92_prd.core.fpsx
Partitioning....
Partitioning Ok...
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:02
Write : Processing RM-675_025.007_79.92_prd.core.fpsx
CMT: Writing Hash CERT [ADA]
CMT: Writing Hash CERT [KEYS]
CMT: Writing Hash CERT [PRIMAPP]
CMT: Writing Hash CERT [RAP3NAND]
CMT: Writing Hash CERT [SOS+PMML]
CMT: Writing Hash CERT [PASUBTOC]
CMT: Writing Hash CERT [PAPUBKEYS]
CMT: Writing Hash CERT [GENIO_INIT]
CMT: Writing Hash CERT [SOS*UPDAPP]
CMT: Writing Hash CERT [SOS*DSP0]
CMT: Writing Hash CERT [LDSP]
CMT: Writing Hash CERT [SOS*ISASW]
CMT: Writing Hash CERT [SOS+CORE]
CMT: Writing Hash CERT [SOS+ROFS1]
Total writen 516 blocks
TIME : Write time : 00:00:14
MCU Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [PPM]===
Erase : Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:00
Write : Processing RM-675_025.007_04.01_Russian_79.92_prd.rofs2.fpsx
CMT: Writing Hash CERT [SOS+ROFS2]
Total writen 192 blocks
TIME : Write time : 00:00:05
PPM Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [PPM2]===
Erase : Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:00
Write : Processing RM-675_025.007_00.01_79.92_prd.rofs3.fpsx
CMT: Writing Hash CERT [SOS+ROFS3]
Total writen 2 blocks
TIME : Write time : 00:00:00
PPM Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [CNT]===
Erase : Processing RM-675_025.007_U01.01_79.92.uda.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:02
Write : Processing RM-675_025.007_U01.01_79.92.uda.fpsx
Total writen 596 blocks
TIME : Write time : 00:00:20
CNT Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
===Flashing [APE]===
Erase : Processing rm675_ENO_v_0.0491_APEONLY.fpsx
Erasing....
Erasing Ok...
TIME : Erase time : 00:00:00
Write : Processing rm675_ENO_v_0.0491_APEONLY.fpsx
CMT: Writing Hash CERT [SOS*ENO]
Total writen 19 blocks
TIME : Write time : 00:00:00
APE Write done
ADL: Request programm status
NAND status : 00000002 / 00000002 / 00000000
ADL: Close_Session
Content: 000300000000020000000200000000
ADL: Reboot
Flashing done!
Total flash time : 00:00:46
Reboot phone now...
Reading Phone Info....
Connected phone - Nokia C7-00
Software Info: V 92_11w37 14-09-11 RM-675 (c) Nokia
IMEI: 355379043622892
Ape Version: 025.007
Product code: 059D9Z9
Checking...
SimLock status : SimLock Damaged!!!!! :(
Security status : Security is Ok
Read Info Done!
Settings After Flash Defaults...
Error When resetting FullFactory :( ...
Error When resetting Product Tune :( ...
Error When resetting SW upgrade Default :( ...
AfterFlash operations done ;D
Done!
Elapsed: 00:01:22
Connect phone on selected interface...
Локал на дисплее появился, но сбросы не прошли. Ситуация с работоспособностью телефона не изменилась.
Если его затереть, то сбросы проходят.
И не понять, то ли тело так софтово убито, то ли из за перепада напряжения в СЗУ его так торкнуло.
Собственно мне непонятно вот что:
Если скажем в 6300 сбит SD то телефон не будет запускаться.
Должен ли запускаться С7-00 без Sim Lock?
Потому что по идее он должен при включении падать в contact servise, а я где то слышал что в этой модели телефона, contact servise не отображаетсяна дисплее.
И должен ли он включаться после стирания и прошивки, без сертификатов, как остальные телефоны?
И исходя из высшеописанного, есть ли смысл заказывать RPL в данный момент.
ЗЫ: прошу ногами сильно не пинать, просто эта модель только недавно вошла широкое распостранение в моем регионе, и потому достаточного опыта по ее ремонту еще не имею.
С уважением: Руслан.