Re: Nokia 6730 RM-547, повредил Sim-Lock зону, помогите восстановить.
#24
Возьму истофету на себя, так как камрад Алексей ака
TATARIN на гастролях в Одессе. Делаем все пошагово.
Код:
BUS Check
Using device: AdvanceBox Turbo Flasher
Library version: 1.0.0.8955(29-09-2010), 1.0.0.14639(29-09-2010)
RAP Data :
SYSTEM ASIC ID: 000000030000022600010007600C192102011104 [RAPU ver: 1.1]
EM0 ID: 00000C34
EM1 ID: 00000C30
PUBLIC ID: 1CD000178D6003446267C35FE634B936AF308B0B
ASIC MODE ID: 00
ROOT KEY HASH: 25B977A055BE9B5DEC0C38A2A279C695
ROM ID: 3E273BF637BE26FA
SecondaryBoot: RAPUv11_2nd.fg [BB5] version: 9.50.0 revision: 3.0 size: 0x3A40
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
FlashID0: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: NOR,RAP
FlashID1: 0000 0001 - 0000 0000 [unused/removed] type: NOR,RAP
FlashID2: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: MuxOneNAND,RAP
Algorithm: RAPUv11_XSR17_alg.fg [XSR 1.6] version: 9.50.0 revision: 3.0 size: 0x7F29B
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
RAP PAPUBKEYS HASH: DA2DB2D32C1B2D9886A55B5D8A14F19ADDC53128
Original Imei: 3542170хххххххх
Original Product code: 0583156
Bluetooth ID: 1886AC911C90
Phone not responding !
Далее
Код:
Reset NPC
RAP Data :
SYSTEM ASIC ID: 000000030000022600010007600C192102011104 [RAPU ver: 1.1]
EM0 ID: 00000C34
EM1 ID: 00000C30
PUBLIC ID: 1CD000178D6003446267C35FE634B936AF308B0B
ASIC MODE ID: 00
ROOT KEY HASH: 25B977A055BE9B5DEC0C38A2A279C695
ROM ID: 3E273BF637BE26FA
SecondaryBoot: RAPUv11_2nd.fg [BB5] version: 9.50.0 revision: 3.0 size: 0x3A40
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
FlashID0: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: NOR,RAP
FlashID1: 0000 0001 - 0000 0000 [unused/removed] type: NOR,RAP
FlashID2: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: MuxOneNAND,RAP
Algorithm: RAPUv11_XSR17_alg.fg [XSR 1.6] version: 9.50.0 revision: 3.0 size: 0x7F29B
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
RAP PAPUBKEYS HASH: DA2DB2D32C1B2D9886A55B5D8A14F19ADDC53128
Erasing CMT NPC ... OK
Read info
Phone Type: RM-547 (Nokia 6730c-1)
SW Version: V ICPR82_09w21.1 28-05-09 RM-547 (c) Nokia
Imei plain: 12345610654321-?
Product Code: 0583156
ApeCoreSw: 021.009
Language Pack:
- not available.
SIMLOCK invalid!
SUPERDONGLE_KEY seems to be valid
CMLA_KEY seems to be valid
WMDRM_PD seems to be valid
SIMLOCK_TEST passed
SECURITY_TEST passed
TimeStamp: 2010-07-09T05:21:43+00:00
SW Version: 031.022
Variant Version: 005
ProductProfile: RM547_0583156_031.022_005.spr
Simlock: simlock_3gstandard_bb5.bin
Imei plain is invalid !!!
SIMLOCK_DATA corrupted!
Запись файла
Erase_256_rapu_uni.fpsx
Код:
Using device: AdvanceBox Turbo Flasher
Library version: 1.0.0.8955(29-09-2010), 1.0.0.14639(29-09-2010)
Processing file: Erase_256_rapu_uni.fpsx as CNT
[BB5 ,XSR 1.6] size: 148 Bytes
RAP Data :
SYSTEM ASIC ID: 000000030000022600010007600C192102011104 [RAPU ver: 1.1]
EM0 ID: 00000C34
EM1 ID: 00000C30
PUBLIC ID: 1CD000178D6003446267C35FE634B936AF308B0B
ASIC MODE ID: 00
ROOT KEY HASH: 25B977A055BE9B5DEC0C38A2A279C695
ROM ID: 3E273BF637BE26FA
Sorry, Unable to find bootloader for this RAP ID !
Flashing terminated with error(s) in 27.750 s
RX Buffer: 01
Как и предупреждалось что файл рассчитан под Best. Не хитрые манипуляции с ENO файлом и мы получили Erase файл который прикрепил. Адресация стирания подбиралась опытным путем, удаляет только 250 Мб, 251 и больше не хочет стирать выкидывает ошибки о не правильной адресации.
Код:
Using device: AdvanceBox Turbo Flasher
Library version: 1.0.0.8955(29-09-2010), 1.0.0.14639(29-09-2010)
Processing file: Erase_250Mb_rapu_6730 RM-547.fpsx as CNT
[BB5,XSR 1.6] size: 264 Bytes
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104
RAP Data :
SYSTEM ASIC ID: 000000030000022600010007600C192102011104 [RAPU ver: 1.1]
EM0 ID: 00000C34
EM1 ID: 00000C30
PUBLIC ID: 1CD000178D6003446267C35FE634B936AF308B0B
ASIC MODE ID: 00
ROOT KEY HASH: 25B977A055BE9B5DEC0C38A2A279C695
ROM ID: 3E273BF637BE26FA
SecondaryBoot: RAPUv11_2nd.fg [BB5] version: 9.50.0 revision: 3.0 size: 0x3A40
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
FlashID0: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: NOR,RAP
FlashID1: 0000 0001 - 0000 0000 [unused/removed] type: NOR,RAP
FlashID2: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: MuxOneNAND,RAP
Algorithm: RAPUv11_XSR17_alg.fg [XSR 1.6] version: 9.50.0 revision: 3.0 size: 0x7F29B
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
RAP PAPUBKEYS is blank/erased.
Storing certificate [NPC, CCC, HWC, R&D] ...OK
Erase size: 250.00 MB
CMT MuxOneNAND area [00000000-0F9FFFFF]
Flashing completed in 31.359 s
Phone not responding !
Total time to process is 1 min 13.078 s
Как видим LOCAL у нас пропал. Приступим к восстановлению.
Цитата:
После стирания нужно пролить MCU+PPM+ENO+CNT - телефон долже входить в локал, включаться.
|
Код:
Using device: AdvanceBox Turbo Flasher
Library version: 1.0.0.8955(29-09-2010), 1.0.0.14639(29-09-2010)
RAP Data :
SYSTEM ASIC ID: 000000030000022600010007600C192102011104 [RAPU ver: 1.1]
EM0 ID: 00000C34
EM1 ID: 00000C30
PUBLIC ID: 1CD000178D6003446267C35FE634B936AF308B0B
ASIC MODE ID: 00
ROOT KEY HASH: 25B977A055BE9B5DEC0C38A2A279C695
ROM ID: 3E273BF637BE26FA
SecondaryBoot: RAPUv11_2nd.fg [BB5] version: 9.50.0 revision: 3.0 size: 0x3A40
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
FlashID0: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: NOR,RAP
FlashID1: 0000 0001 - 0000 0000 [unused/removed] type: NOR,RAP
FlashID2: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: MuxOneNAND,RAP
Algorithm: RAPUv11_XSR17_alg.fg [XSR 1.6] version: 9.50.0 revision: 3.0 size: 0x7F29B
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
RAP PAPUBKEYS is blank/erased.
Processing file: rm547_031.022_prd.core.fpsx as MCU
[BB5,XSR 1.6] size: 91.10 MB
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 600C192102031104
Storing certificate [NPC, CCC, HWC, R&D] ...OK
Partitioning ...OK
Erase size: 181.06 MB
CMT MuxOneNAND area [00020000-0003FFFF]
CMT MuxOneNAND area [00060000-004DFFFF]
CMT MuxOneNAND area [008E0000-0B93FFFF]
Format Partition ...
Flash programming ...
CMT PAPUBKEYS: DA2DB2D32C1B2D9886A55B5D8A14F19ADDC53128 (RAP Certificate 185 v.1) written.
Programming completed in 49.859 s
Processing file: rm547_031.022_01.01_Euro1_prd.rofs2.fpsx as PPM
[BB5,XSR 1.6] size: 40.62 MB
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 600C192102031104
Erase size: 51.00 MB
CMT MuxOneNAND area [06D40000-0A03FFFF]
Flash programming ...
Programming completed in 22.250 s
Processing file: rm547_031.022_202.07_VF_IT_prd.rofs3.fpsx as PPM
[BB5,XSR 1.6] size: 18.36 MB
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 600C192102031104
Erase size: 25.00 MB
CMT MuxOneNAND area [0A040000-0B93FFFF]
Flash programming ...
Programming completed in 10.125 s
Processing file: rm547_031.022_202.07_UDA_VF_IT_prd.uda.fpsx as CNT
[BB5,XSR 1.6] size: 6.73 MB
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 600C192102031104
Erase size: 61.00 MB
CMT MuxOneNAND area [0B940000-0F63FFFF]
Flash programming ...
Programming completed in 3.859 s
Processing file: RM547_APE_ONLY_ENO_09w26_v0.024.fpsx as CNT
[BB5,XSR 1.6] size: 2.28 MB
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104
Storing certificate [NPC, CCC, HWC, R&D] ...OK
Erase size: 4.00 MB
CMT MuxOneNAND area [004E0000-008DFFFF]
Flash programming ...
Programming completed in 1.407 s
Flashing completed in 1 min 36.609 s
Phone Type: RM-547 (Nokia 6730c-1)
SW Version: V ICPR82_10w08 26-02-10 RM-547 (c) Nokia
Imei plain: 12345610654321-?
ApeCoreSw: 031.022
Language Pack:
- not available.
SIMLOCK invalid!
SUPERDONGLE_KEY invalid!
- WD timer enabled, phone will reboot itself after 3 min.
SIMLOCK_TEST passed
SECURITY_TEST passed
Imei plain is invalid !!!
SIMLOCK_DATA corrupted!
Total time to process is 1 min 53.828 s
Цитата:
После восстанавливаем только NPC/CCC/HWC - получаем рабочую тушку ( относительно ) с CS и локалом.
|
Код:
Imei: 3542170хххххххх
Restoring RF/BB DATA from backup ...
Up****** RF ...OK
Up****** BB ...OK
Up****** WARRANTY ...OK
Up****** PROD ...OK
Up****** BT ...OK
RAP Data :
SYSTEM ASIC ID: 000000030000022600010007600C192102011104 [RAPU ver: 1.1]
EM0 ID: 00000C34
EM1 ID: 00000C30
PUBLIC ID: 1CD000178D6003446267C35FE634B936AF308B0B
ASIC MODE ID: 00
ROOT KEY HASH: 25B977A055BE9B5DEC0C38A2A279C695
ROM ID: 3E273BF637BE26FA
SecondaryBoot: RAPUv11_2nd.fg [BB5] version: 9.50.0 revision: 3.0 size: 0x3A40
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
FlashID0: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: NOR,RAP
FlashID1: 0000 0001 - 0000 0000 [unused/removed] type: NOR,RAP
FlashID2: 0020 0040 - 0000 0031 [ST NAND KAT00F00RA] type: MuxOneNAND,RAP
Algorithm: RAPUv11_XSR17_alg.fg [XSR 1.6] version: 9.50.0 revision: 3.0 size: 0x7F29B
Supported RAP Ids: 4003192102001104, 400C192102001104, 6003192102001104, 600C192102001104, 6003192102011104, 600C192102011104, 6003192102021104, 600C192102021104, 6003192102031104, 600C192102031104
TransmissionMode: DDR&TX2
RAP PAPUBKEYS HASH: DA2DB2D32C1B2D9886A55B5D8A14F19ADDC53128
NPC verified Ok.
Up****** CMT NPC ...OK
Up****** CMT CCC ...OK
Up****** CMT HWC ...OK
Up****** PRODUCTCODE (0583156)... OK
Up****** PSN (CLF791851)... OK
Up****** HWID (0500)... OK
Up****** SIMLOCK...OK
Trying to update SUPERDONGLE_KEY(from PM308 backup)...error 0x0
PM308 is readonly?
Up****** WMDRM_PD...OK
Certificate programmed successfully !
Phone Type: RM-547 (Nokia 6730c-1)
SW Version: V ICPR82_10w08 26-02-10 RM-547 (c) Nokia
Imei plain: 3542170ххххххх-х
Product Code: 0583156
ApeCoreSw: 031.022
Language Pack:
- not available.
This is SL3 phone(Simlock2 format).
- Avoid SW Downgrade & manual erase to this phone !
SIMLOCK seems to be valid
SUPERDONGLE_KEY invalid!
- WD timer enabled, phone will reboot itself after 3 min.
SIMLOCK_TEST passed
SECURITY_TEST passed
Imei net: 3542170хххххххх
Version: SIMLOCK SERVER
Provider: Nokia Test, Country: Finland
Counter: 0/3, 0/10
CONFIG_DATA: 2440700000000000
PROFILE_BITS: 0000000000000000
BLOCK 1: 1=OPEN 2=OPEN 3=OPEN 4=OPEN 5=OPEN, DATA=FFFFFF
BLOCK 2: 1=OPEN 2=OPEN 3=OPEN 4=OPEN 5=OPEN, DATA=FFFFFF
BLOCK 3: 1=OPEN 2=OPEN 3=OPEN 4=OPEN 5=OPEN, DATA=FFFFFF
BLOCK 4: 1=OPEN 2=OPEN 3=OPEN 4=OPEN 5=OPEN, DATA=FFFFFF
BLOCK 5: 1=OPEN 2=OPEN 3=OPEN 4=OPEN 5=OPEN, DATA=FFFFFF
BLOCK 6: 1=OPEN 2=OPEN 3=OPEN 4=OPEN 5=OPEN, DATA=FFFFFF
BLOCK 7: 1=OPEN 2=OPEN 3=OPEN 4=OPEN 5=OPEN, DATA=FFFFFF
Как видем телефон полностью восстановлен, и готов к заказу RPL. Как ни странно но телефон полностью включается звонит. За пол часа теста ни разу не перегрузился. До приезда Алексея с Одессы похожу с телефоном, протестирую.
P.S. Огромная благодарность всем принявшим участие в этой теме. Тема получилась весьма информативна и раскрыта суть проблемы. Ответ оказался прост, отсутствие правильного стирания или отсутствие стирания как такового вообще, любым доступным на данное время продуктом. Про BEST не скажу не знаю.
Здесь был вложен файл: Erase_250Mb_rapu_6730 RM-547.rar (305 байт), но к сожалению был утерян. Если он у Вас есть, свяжитесь с администрацией для его восстановления. Спасибо.