Проблема собственно в следующем:
пришел телефон w200i CID52 на разлок+языки.
стояла прошивка R4GB001, скачал новую R4JA011 с языковым пакетом BALTIC.
Пользуюсь SETool боксом: вставил файл более свежей прошивки и языковой файл в поле для файлов, галки на:
- complete phone after flash
- unlock after flash
- signed mode
- perform full unlock instead of usercode reset
Отправил на калькуляцию сигнатур:
Код:
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
Flash ID check:897E
Flash props sent ok
LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
Executing CSCA-based unlock.
Asking for EROM signature...
Waiting for calculation process...
RESPONSE: "359707ХХХХХХХХ ADDED TO QUEUE,CHECK BACK LATER" (1)
SIGNATURE QUEUED FOR CALCULATION, CHECK BACK LATER
signature calculation not done,err: 26
Elapsed: 9 secs.
6 кредитов ушло..
заходил позжже на проверку:
Код:
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХCERT:RED
LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
Flash ID check:897E
Flash props sent ok
LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
Executing CSCA-based unlock.
Asking for EROM signature...
Waiting for calculation process...
RESPONSE: "359707ХХХХХХХХ ALREADY IN QUEUE" (15)
MSG: "359707ХХХХХХХХ"
signature calculation not done,err: 26
Elapsed: 9 secs.
через день когда скалькулировалась сигнатура, не хватило кредитов на завершение операции отлочки:
Код:
v0.914028/UNI
CARD SERIAL: 00069162
Loaded 51 flash descriptors
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
Flash ID check:897E
Flash props sent ok
LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
Executing CSCA-based unlock.
Asking for EROM signature...
Waiting for calculation process...
RESPONSE: "SUCCESS" (1038)
Backup security data...
loader startup: executed
loader GDFS startup: executed
loader unlock: executed
Erasing locks...
DISCONNECT PHONE, FULLY TURN IT ON AND ATTACH AGAIN.
BE SURE THAT YOU SET PHONE IN "PHONE MODE"
IF ASKED, INSTALL PHONE DRIVERS
SEARCHING FOR PHONE, "STOP" TO ABORT
PHONE FOUND AT COM23
PHONE READY TO PROCEED.
Connecting to server
No credits left.
Пока ждал перевода кредитов, профлешил новой прошивкой R4JA011 (ибо подумал, что осталась только отлочка за 4 кредита, а процесса флеширования новой версией флешфайла и языкового файла не было, и чтобы не получить отлоченный телефон со старым языковым пакетом, я собственно и профлешил ДО второго этапа - начала процесса разблокировки через сервер):
Код:
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
Flash ID check:897E
Flash props sent ok
writing D:\-=SonyEricsson=-\SETool2G\flash\w200 cid52 red\R4JA011_1250719_GENERIC_ME.ssw
CURRENT FLASH FILE CID:52
SSW uses complete hash, hash len is:6360
Will flash 318 blocks...
SSW loading returns:0
writing D:\-=SonyEricsson=-\SETool2G\flash\w200 cid52 red\R4JA011_FS_BALTIC_ME_RED_CID52.ssw
CURRENT FLASH FILE CID:52
SSW uses complete hash, hash len is:2420
Will flash 121 blocks...
SSW loading returns:0
LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
loader startup: executed
loader GDFS startup: executed
loader filesystem startup: executed
loader unlock: executed
Flashing upgrade archive:D:\-=SonyEricsson=-\SETool2G\flash\w200 cid52 red\R1A_CDA102738_114__FS__Bite_Lithuania.zip
bad file, will not flash it.
Elapsed: 318 secs.
После получения кредитов закончил второй этап:
Код:
v0.914028/UNI
CARD SERIAL: 00069162
Loaded 51 flash descriptors
SERVER CREDITS LEFT/USED: 12/8
CARD COUNTERS: FLASH 2, UNLOCK 0
Elapsed: 2 secs.
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
Flash ID check:897E
Flash props sent ok
LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
Executing CSCA-based unlock.
Asking for EROM signature...
signature found, skipping calculation
Backup security data...
loader startup: executed
loader GDFS startup: executed
loader unlock: executed
Erasing locks...
DISCONNECT PHONE, FULLY TURN IT ON AND ATTACH AGAIN.
BE SURE THAT YOU SET PHONE IN "PHONE MODE"
IF ASKED, INSTALL PHONE DRIVERS
SEARCHING FOR PHONE, "STOP" TO ABORT
PHONE FOUND AT COM23
PHONE READY TO PROCEED.
Connecting to server
seed is:001F2B1E
Phone succefully unlocked. USERCODE RESET TO "0000"
Elapsed: 61 secs.
В итоге при включении получил а телефоне Configuration error. Contact your service provider. Прошил по новой с разблокировкой через сервер:
Код:
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
Flash ID check:897E
Flash props sent ok
writing D:\-=SonyEricsson=-\SETool2G\flash\w200 cid52 red\R4JA011_1250719_GENERIC_ME.ssw
CURRENT FLASH FILE CID:52
SSW uses complete hash, hash len is:6360
Will flash 318 blocks...
SSW loading returns:0
writing D:\-=SonyEricsson=-\SETool2G\flash\w200 cid52 red\R4JA011_FS_BALTIC_ME_RED_CID52.ssw
CURRENT FLASH FILE CID:52
SSW uses complete hash, hash len is:2420
Will flash 121 blocks...
SSW loading returns:0
LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
loader startup: executed
loader GDFS startup: executed
loader filesystem startup: executed
loader unlock: executed
writing tpa/preset/custom/C3_PCA_G3v2.cer
writing tpa/preset/custom/CONTENT_DOWNLOAD_HOOK_2.itm
writing tpa/preset/custom/customize.xml
writing tpa/preset/custom/DESKTOP_HOOK_2.itm
writing tpa/preset/custom/Entrust.net Root Certificate.cer
writing tpa/preset/custom/Entrust.net_WTLS_Root_Certificate.wcrt
writing tpa/preset/custom/FM_PICTURES_HOOK_3.itm
writing tpa/preset/custom/FM_SOUNDS_HOOK_3.itm
writing tpa/preset/custom/FM_THEMES_HOOK_3.itm
writing tpa/preset/custom/FM_VIDEOS_HOOK_3.itm
writing tpa/preset/custom/GAMES_HOOK_3.itm
writing tpa/preset/custom/GTE_CyberTrust_Root.cer
writing tpa/preset/custom/GTE_Cybe_Trust_Root_WTLS.wcrt
writing tpa/preset/custom/Root.cer
writing tpa/preset/custom/SEMC_E2E_Root_CA.crt
writing tpa/preset/custom/SETT_RINGTONE_HOOK_3.itm
writing tpa/preset/custom/ThawtePremium.der
writing tpa/preset/custom/ThawteServerCA.cer
writing tpa/preset/custom/Utiroot.cer
writing tpa/preset/custom/VeriSignClass3Root.cer
writing tpa/preset/custom/Verisign_Class_3_CA_WTLS.wcrt
Phone detached
Elapsed: 282 secs.
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
Flash ID check:897E
Flash props sent ok
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
FLASH CID:52 COLOR:RED
Model:W200i
MAPP CXC article: R4JA011 prgCXC1250719_GENERIC_ME
MAPP CXC version: R4JA011
Language Package:BALTIC
CDA article: CDA102738/80
CDA version: R6A
Default article: cxc1250728
Default version: R4JA011
PROVIDER: 000-00
SIMLOCKS NOT DETECTED
USERCODE:0000
RESTORATION FILE PRESENT FOR DETECTED FIRMWARE
SECURITY UNITS BACKUP CREATED.
Elapsed: 5 secs.
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
LDR:061205 1354 HAN_DB2012_FLASHLOADER_R2B012_CXC1326738
Flash ID check:897E
Flash props sent ok
LDR:070410 1405 HANCXC1327364_COMPACT_SEMC_CS_LOADER_1_R3B009
Executing CSCA-based unlock.
Asking for EROM signature...
signature found, skipping calculation
Backup security data...
loader startup: executed
loader GDFS startup: executed
loader unlock: executed
Erasing locks...
DISCONNECT PHONE, FULLY TURN IT ON AND ATTACH AGAIN.
BE SURE THAT YOU SET PHONE IN "PHONE MODE"
IF ASKED, INSTALL PHONE DRIVERS
SEARCHING FOR PHONE, "STOP" TO ABORT
PHONE FOUND AT COM23
PHONE READY TO PROCEED.
Connecting to server
seed is:00605DCB
Phone succefully unlocked. USERCODE RESET TO "0000"
Elapsed: 204 secs.
SIGNED MODE (USING SERVER).
ChipID:8040,EMP protocol:0301
NEW SECURITY MODEL DETECTED
PHONE IS RED RETAIL PRODUCT
FLASH CID detected:52
Speed:921600
Flash ID check:897E
Flash props sent ok
OTP LOCKED:1 CID:51 PAF:1 IMEI:359707ХХХХХХХХ CERT:RED
FLASH CID:52 COLOR:RED
Опять -4 кредита, а OTP LOCKED:1. Чувствую что где-то я наглупил, но как выйти из ситуации не представляю, кредиты терять не охота, итак телефон стал золотым уже...
Пробывал прошиться старой версией прошивки той что стояла (предположив, что калькуляция сигнатур была сделана для нее), однако после прошивки и после идентификации версия прошивки осталась новая..
Кредиты были с одного аккаунта.