PDA

View Full Version : HELP with G4 Unlocking project!!!!


blazoner
26th November 2006, 06:33 AM
It was suggested in this thread (http://forum.xda-developers.com/showthread.php?t=283147) that those unlocking their Wizard devices through IMEI Check (http://www.imei-check.co.uk/), download USB-Monitor (http://www.hhdsoftware.com/Products/home/usb-monitor.html) (available HERE (http://hhdsoftware.com/Download/usb-monitor.exe) free for 30 days as shareware) and run it BEFORE RUNNING THE IMEI CHECK SOFTWARE ON THEIR DEVICE!
Then post the results to the FORUM.

I propose that we use this thread to do that, so a SIMPLE AND FREE unlock method can be found!

Before you start in on me about taking one for the team, I PAID TO UNLOCK MY G3 WITH IMEI CHECK TOO! :rolleyes: (And if I'd have known I could have helped by doing this, I would have!)

I feel it would be an excellent way to repay the entire wizard community for their wonderful time and effort!

And NO, this is NOT something I'm doing myself, I'm just trying to get the ball rolling!

__s
27th November 2006, 09:40 AM
i will gladly post dumped info after imei check unlocking procedure. cuz i think its too expensive :). im planing to do this in abt two weeks.

faria
27th November 2006, 10:27 AM
It was suggested in this thread (http://forum.xda-developers.com/showthread.php?t=283147) that those unlocking their Wizard devices through IMEI Check (http://www.imei-check.co.uk/), download USB-Monitor (http://www.hhdsoftware.com/Products/home/usb-monitor.html) (available HERE (http://hhdsoftware.com/Download/usb-monitor.exe) free for 30 days as shareware) and run it BEFORE RUNNING THE IMEI CHECK SOFTWARE ON THEIR DEVICE!
Then post the results to the FORUM.

I propose that we use this thread to do that, so a SIMPLE AND FREE unlock method can be found!

Before you start in on me about taking one for the team, I PAID TO UNLOCK MY G3 WITH IMEI CHECK TOO! :rolleyes: (And if I'd have known I could have helped by doing this, I would have!)

I feel it would be an excellent way to repay the entire wizard community for their wonderful time and effort!

And NO, this is NOT something I'm doing myself, I'm just trying to get the ball rolling!i have been working on this with another member,i will post my findings later,i also plan to ask for help from 2 members that undestand more that me about rom unlocking logs.

blazoner
27th November 2006, 01:26 PM
Thanks for taking notice, Faria!

It's some of the discussion about your 3.0.0.0 ROM's that has inspired me to get this started.
I figure the more objective (system provided) information we have, the closer we are to a simple solution.

Looking forward to any findings! :D

DANEMAN
27th November 2006, 01:27 PM
i have been working on this with another member,i will post my findings later,i also plan to ask for help from 2 members that undestand more that me about rom unlocking logs.
hello mine is cid unlocked but if you need me to try anything give me a bell
iam on g4
spl/ipl 2.21
faria rc1 12mb
ext v3
rom 3.0
radio02.47.11

AirwolfUK
27th November 2006, 05:38 PM
Mine is CID unlocked using the IMEI site:

G4 - i-mate k-jam
IPL/SPL 2.16.0001
ROM Faria RC1 8mb
ExtROM v3
Radio 2.47.11

Happy to help if i can

cptcafne
28th November 2006, 06:20 AM
I just tried to run the IMEI software again while run USB monitor, but the IMEI software can not connect to the phon with the monitor program running. I tried 5 times

Thunder_PC
28th November 2006, 02:29 PM
still cid locked here. I plan to unlock as soon as I get done getting all the crumb-snatcher's xmas shopping done ;). I will be sure to to what I can to help with logs/etc.

fla242
29th November 2006, 10:22 AM
I just tried to run the IMEI software again while run USB monitor, but the IMEI software can not connect to the phon with the monitor program running. I tried 5 times


Bad news :(

Somebody else ?

fla242
29th November 2006, 01:01 PM
hello,

i've just unlocking my Wizard devices through IMEI Check...And i've log file from usb-monitor !!

But file size is over 2mb !

blazoner
29th November 2006, 01:26 PM
hello,

i've just unlocking my Wizard devices through IMEI Check...And i've log file from usb-monitor !!

But file size is over 2mb !

Cool! I was just about to assume that the IMEI Check software checked for usb monitor, etc. and disallowed running the two together.
Can you zip the file and upload it?
If you don't have a zip program, google winzip, or winrar.
If the file is text based, it shoul zip nice!
Forgive the spelling, I'm sitting on the side of the road waiting on a tow-truck.... :o

blazoner
29th November 2006, 01:32 PM
NIX THAT! DON'T POST YOUR IMEI INFO!!
We'll get in touch and make arrangements!

fla242
29th November 2006, 01:46 PM
NIX THAT! DON'T POST YOUR IMEI INFO!!
We'll get in touch and make arrangements!

That's what i'm tell me ;)

dodadent
3rd December 2006, 11:07 PM
Mine is Locked

pof
6th December 2006, 04:10 AM
Have a look at this thread in order to understand how this was done in the Hermes:

Reverse engineering the HERMES imei-check unlocker (http://forum.xda-developers.com/showthread.php?t=280819)

The bootloader commands for the Hermes are explained in these wiki pages, you _really_ need to do something similar for the wizard:


Hermes Bootloader Information (http://wiki.xda-developers.com/index.php?pagename=Hermes_BootLoader)
Hermes Radio Bootloader and AT command interpreter (http://wiki.xda-developers.com/index.php?pagename=Hermes_RadioBootLoader)


Some hints that may help you:

1. You can run the unlocker as many times as you want, it doesn't matter if you've already cid unlocked your device, the imei-check unlocker will behave the same.

2. In order for the USB monitor capture to be useful, you need to click on the "COMPLETE" tab and when you have captured it, export it as ANSI TEXT.

3. If the app fails (communication error) you need to create 2 admin users, 1 for running usb monitor and the other for running the unlocker. Use right click, "run as..." and then select the other admin user. You need to repeat this process several times until you can successfully get the log.

4. be careful on what you post here, as imei-check has intelectual property rights on their work. Do not "copy" their solution, but reimplement it in another way.

docdoc8
7th December 2006, 02:21 AM
look its not intellectual property simply because its a solution around a software lock put on by the manufacturer ...this voids the warrantee anyway. post it simply because you can don't worry about intellectual property

lasc
7th December 2006, 03:53 AM
and what about goldcard(http://forum.xda-developers.com/showthread.php?t=270952)? is it way to flash whithout unlockCID?

blazoner
7th December 2006, 06:41 AM
look its not intellectual property simply because its a solution around a software lock put on by the manufacturer ...this voids the warrantee anyway. post it simply because you can don't worry about intellectual property

It's intellectual property simply because it's their solution. DON'T post it, unless you want to be named in their lawsuit! Furthermore, DON'T post it because none of us can afford having xda-developers closed down because they are getting sued!

The trick is that the ultimate solution was designed by HTC. IME Check just exploits it.
Therefore, if we can see what IMEI Check is doing, we can find a different way of doing the same thing!

As an example:
IMEI Check rolls a ball by pushing it with a stick, so we blow on it to make it move, or we dig under it to make it roll downhill.

Either way, we can't be accused of doing it the same way they are, but we're still rolling the ball. ;)

docdoc8
12th December 2006, 12:52 PM
if anyone will sue xda developers it will not be IMEI Check it will be the HTC or the companies involved in making the phones/MDA's. Remember its the company who made the phone G4 so people couldn't mod it.
i doubt IMEI check has the money for lenghy court costs.


plus if you reverse engineer IMEI's way of Unlocking but change the order of doing it your essentially copying them anyway.

Just my opinion.

anyway this site is great, keep up the good work fellas.

SanderZ
13th December 2006, 02:28 PM
Is there a way of checking if you're PDA is locked o not?

dipulmiah
13th December 2006, 03:21 PM
Is there a way of checking if you're PDA is locked o not?

Yeah, you can always insert another network sim card in & see if it accepts it!!!!

SanderZ
13th December 2006, 07:12 PM
I don't have a second sim-card.
But i got mine from my boss and used my own sim-card with it.
So i Guess it's not locked. but just to make shure

tachero
13th December 2006, 08:53 PM
hi, i tried unlocking a g4 with the lokiwiz, it threw a few errors, now i want to use the imei-check.co.uk. how do i know if it will work or if the wizard its a brick now?
it seems to be functional.
thanks
any help is appreciated,!

its a cingular 8125

_Nomad_
13th December 2006, 09:13 PM
The term brick refers to it actually being a brick as in it wont start! If it's working it's working...

fla242
13th December 2006, 11:46 PM
hi, i tried unlocking a g4 with the lokiwiz, it threw a few errors, now i want to use the imei-check.co.uk. how do i know if it will work or if the wizard its a brick now?
it seems to be functional.
thanks
any help is appreciated,!

its a cingular 8125


If it seems to be functional then it work !!
imei-check.co.uk work great i comfirm.

hoang0501
14th December 2006, 12:04 AM
what is different between CID lock and sim lock ?

fla242
14th December 2006, 12:25 AM
what is different between CID lock and sim lock ?

Sim lock is creating by operator to prevent use of phone on other network

Cid lock is creating by manufacturer to prevent installation of Rom not release by it

tachero
14th December 2006, 12:25 AM
I did the imei and it worked. Had some problems but was able to get around it. 40 dollars its a tad expensive

simplekanc
18th December 2006, 11:18 AM
I will post dumped info after unlocking, but I can't get verified account on paypal and I can't pay for it :(

IPL 2.16.001
SPL 2.16.001

happytomato
19th December 2006, 12:05 PM
hi,
please PM me the usb log dump, as i will start work, i can code, so lets see if we can make this happen !

PiGG
20th December 2006, 10:58 PM
I have succesfully run IMEIcheck while USB logger was running
( my phone WAS SIM unlocked, but it's a G4, so not yet CID unlocked.. hopefully now it is )

File is attached!

Removed the attachment, but have it here saved on my pc.
email me at my hotmail if anyone needs it for research. my account on hotmail is bhofland

fla242
21st December 2006, 09:01 AM
I have succesfully run IMEIcheck while USB logger was running
( my phone WAS SIM unlocked, but it's a G4, so not yet CID unlocked.. hopefully now it is )

File is attached!

Hello you shouldn't post this file on the web because the file contain certainly imei info of your phone.

Do what you want but i'm not sure that's a good idea

simplekanc
21st December 2006, 09:43 AM
I have succesfully run IMEIcheck while USB logger was running
( my phone WAS SIM unlocked, but it's a G4, so not yet CID unlocked.. hopefully now it is )

Try to run aWizard with CID unlock. If write operation success - CID was unlocked by IMEIcheck. Or I'm wrong?

machinagod
21st December 2006, 06:45 PM
CID unlock and DOC protection are 2 very different things. Unlocking the CID shouldn't enable write-access to the DOC.

Just my 2 cents,
Ricardo

simplekanc
21st December 2006, 09:11 PM
CID unlock and DOC protection are 2 very different things. Unlocking the CID shouldn't enable write-access to the DOC.
Just my 2 cents,
Ricardo
Ok. r2sd spl command :)


wdata 92000000- it's checker splash.

wdata 91000000-910BFFFF - SPL,
on first and second stages differs (some bytes)

We need at least one more log from another device to compare
See post below.

pof
21st December 2006, 09:14 PM
@PiGG: nice, here is what it does:

(bold for commands sent by unlock utility to the bootloader, indented is output returned by the bootloader)

set 1 0
Type (0x1)(Operation mode flag): cOpModeFlag=(0x0)
set 5 ffffffff
Type (0x5)(Background color value): g-wBColor=(0xFFFFFFFF)
set 2 0
Type (0x2)(Back color flag): cBackColorShowFlag=(0x0)
set 6 000000
set 4 000000
Type (0x4)(Front color value): g-wFColor=(0x0) (0x0)
progressbar 0 239 0 255 ffffff 100 0
shmsg 0 0 " . : | Wizard Unlock | : ."
info 1
shmsg 3 0 " ..detecting device.."
set 32 2
info 0
shmsg 4 0 " >>>Wizard found"
kadc
GSM-Modem-Init: Include DAGON
Copying GSM Data image to SDRAM: 00004000
GSM -dwSize = 345B1
GSM Page0
**GSM Page dwOffsetGSMcodShift:65536
**GSM Page dwOffsetBlock: 1
GSM -dwSize = 45627
GSM Page1
***GSM Page dwOffsetGSMcodShift:131072
***GSM Page dwOffsetBlock: 2
GSM --dwSize = 4B75E
GSM Page2
***GSM Page dwOffsetGSMcodShift:196608
***GSM Page dwOffsetBlock: 3
GSM --dwSize = 4E15B
GSM Page3
***GSM Page dwOffsetGSMcodShift: 0
***GSM Page dwOffsetBlock: 5
GSM --dwSize = 4B3B0
GSM Page4
***GSM Page dwOffsetGSMcodShift: 65536
***GSM Page dwOffsetBlock: 6
GSM --dwSize = 4CA79
GSM Page5
***GSM Page dwOffsetGSMcodShift: 131072
***GSM Page dwOffsetBlock: 7
GSM --dwSize = 28B59
GSM Page6
***GSM Page dwOffsetGSMcodShift: 196608
***GSM Page dwOffsetBlock: 8
GSM --dwSize = C490
GSM Page7
Copying GSM CODE image to SDRAM: 00000000
ARMBOOT = 1 --> boot from CS3
Reset RAM 7
ok
AT-Command Interpreter ready
AT+GSN
356XXXXXXXXXXXX
set
shmsg 5 0 " >>> unlock stage 1"
password XTC
ruustart
wdata 8FA00398 4
shmsg 6 0 " preparing."
progressbar 10 229 300 316 ffff 0 0
wdata 91000000 10000
progressbar 10 229 300 316 ffff 8 0
wdata 91010000 10000
progressbar 10 229 300 316 ffff 16 0
wdata 91020000 10000
progressbar 10 229 300 316 ffff 25 0
wdata 91030000 10000
progressbar 10 229 300 316 ffff 33 0
wdata 91040000 10000
progressbar 10 229 300 316 ffff 41 0
wdata 91050000 10000
progressbar 10 229 300 316 ffff 50 0
wdata 91060000 10000
progressbar 10 229 300 316 ffff 58 0
wdata 91070000 10000
progressbar 10 229 300 316 ffff 66 0
wdata 91080000 10000
progressbar 10 229 300 316 ffff 75 0
wdata 91090000 10000
progressbar 10 229 300 316 ffff 83 0
wdata 910A0000 10000
progressbar 10 229 300 316 ffff 91 0
wdata 910B0000 10000
progressbar 10 229 300 316 ffff 100 0
ruuflashdoc 91000000 c0000 71216fd4
shmsg 6 0 " preparing..."
ruurun 12345678
shmsg b 5 "rebooting..."
ruurun 12345678
ResetDevice

--- device resets here ---

set 1 0
Type (0x1)(Operation mode flag): cOpModeFlag=(0x0)
set 5 ffffffff
Type (0x5)(Background color value): g-wBColor=(0xFFFFFFFF)
set 2 0
Type (0x2)(Back color flag): cBackColorShowFlag=(0x0)
set 6 000000
set 4 000000
Type (0x4)(Front color value): g-wFColor=(0x0) (0x0)
progressbar 0 239 0 255 ffffff 100 0
shmsg 0 0 " . : | Wizard Unlock | : ."
password XTC
set 32 2
+ SD Controller init
- SD Controller init
+StorageInit
***** user area size = 0x3C8C0000 Bytes
g_cKeyCardSecurityLevel = FF
set
shmsg 5 0 " >>> unlock stage 2"
ruustart
wdata 8FA00398 4
shmsg 6 0 " unlocking."
progressbar 10 229 300 316 ffff 0 0
wdata 92000000 10000
progressbar 10 229 300 316 ffff 33 0
wdata 92010000 10000
progressbar 10 229 300 316 ffff 66 0
wdata 92020000 10000
progressbar 10 229 300 316 ffff 100 0
ruuflashdoc 92000000 30000 7fb33184
shmsg 6 0 " unlocking..."
wdata 8FA00398 4
progressbar 10 229 300 316 ffff 0 0
wdata 91000000 10000
progressbar 10 229 300 316 ffff 8 0
wdata 91010000 10000
progressbar 10 229 300 316 ffff 16 0
wdata 91020000 10000
progressbar 10 229 300 316 ffff 25 0
wdata 91030000 10000
progressbar 10 229 300 316 ffff 33 0
wdata 91040000 10000
progressbar 10 229 300 316 ffff 41 0
wdata 91050000 10000
progressbar 10 229 300 316 ffff 50 0
wdata 91060000 10000
progressbar 10 229 300 316 ffff 58 0
wdata 91070000 10000
progressbar 10 229 300 316 ffff 66 0
wdata 91080000 10000
progressbar 10 229 300 316 ffff 75 0
wdata 91090000 10000
progressbar 10 229 300 316 ffff 83 0
wdata 910A0000 10000
progressbar 10 229 300 316 ffff 91 0
wdata 910B0000 10000
progressbar 10 229 300 316 ffff 100 0
ruuflashdoc 91000000 c0000 86221939
shmsg 6 0 " unlocking....."
shmsg 8 0 " unlocking done"
ruurun 0
shmsg b 5 "rebooting..."

You can extract what is sent encapsulated in HTCS / HTCE blocks in every wdata command by exporting the .lgs file to ANSI Text, and then using a hex editor.

pof
21st December 2006, 09:36 PM
For those afraid of attaching because of imei info, do not attach the .lgs file but convert it to text (using the export function of USB monitor) and then remove your imei in the text file, it is shown after AT+GSN.

fla242
22nd December 2006, 09:58 AM
We need at least one more log from another device to compare



Hi,

Here is Mine ;)

http://www.fla242.net/Fla242-unlock-log.zip

pof
22nd December 2006, 10:28 AM
I guess this is more or less what they do:

1. At stage 1 they flash a patched the SPL (bootloader), so that instead of reflashing the splash screen it writes to the security area where the CID is stored
2. At stage 2 they send the wdata commands to reflash "splash screen" to the modified bootloader, this changes the CID
3. they flash a normal SPL back again

mun_rus
22nd December 2006, 10:41 AM
so, can we say that the free way to cid unlock on g4 exists?
wht about tool that was atached in previous post? does it cid unlock g4 device?

simplekanc
23rd December 2006, 12:58 PM
so, can we say that the free way to cid unlock on g4 exists?


No, we can't.

I have some questions:

1. Who knows how to convert SPL from our log (wdata 91010000-910BFFFF) to .nb file?

2. What is located at addr 8FA00398? (from log: wdata 8FA00398 4, bytes:01 00 00 00)

mestrini
24th December 2006, 02:36 AM
1- Maybe joining up those log chunks and seeing if they make up 64k. If so then try to use typhooncidedit.pl or lokiwiz to decrypt it (just some thoughts)

2-Those 4 bytes exists at the very start of an encrypted CID block (at least extracted from my G3 wizard, may differ from others) but dunno what they're for


I know that this is a but off-topic but does anyone know how to get out of a kadc command in mtty.exe?

pof
24th December 2006, 06:39 PM
1. Who knows how to convert SPL from our log (wdata 91010000-910BFFFF) to .nb file?

Use any hex editor, copy paste the HEX values (without the ascii right column) and save as binary.

the-equinoxe
24th December 2006, 07:02 PM
Use any hex editor, copy paste the HEX values (without the ascii right column) and save as binary.

also you can have good help from excel:
Cut and paste the parts from the log to a txt,
import it to excel, removing ascii and saving it again as a txt (replce all [tabs by [space], takes a while!!), then opening the new txt, opening winhex and paste the hex..
Works like a charm ;)

neonkoala
24th December 2006, 09:23 PM
Do we not need wdata 91000000 10000 as well to make the complete SPL?

mestrini
25th December 2006, 01:38 AM
Do we not need wdata 91000000 10000 as well to make the complete SPL?



You need all the chunks as they are 12*0x10000 which makes 0xc0000, the size of SPL ;)

mestrini
27th December 2006, 10:25 PM
It's common that G3 SPL can't be used in G4 and vice-versa so how come this unlock software's SPL makes no distinction between both types of SPL?

Anyone has any thoughts on that?

pof
27th December 2006, 10:44 PM
Probably "set 32 2" or "info 0" commands return different output depending if device is run on G3 or G4 wizard.

mestrini
27th December 2006, 11:33 PM
Info 1 returns the device SPL with all the digits so that should mean that the sw must have two kinds of SPL packed inside itself...

Once again, a bit off-topic, but do you have any clue how mtty communicates with the devices? Normal USB drivers/commands? Do you know any amateur work on that area? tx

skygear
29th December 2006, 05:02 AM
a few questions ...
1. does the imei proggie connect to the internet during the process?
a.if not cant you use IDA to disassemble it?
b. if so could you use wireshark to intercept the packets of data transfered over the net...

pof
29th December 2006, 06:29 PM
1. does the imei proggie connect to the internet during the process?
No.

a.if not cant you use IDA to disassemble it?
The binary it's packed with themida... debugging doesn't help much.

b. if so could you use wireshark to intercept the packets of data transfered over the net...
nothing over the net... only usb sniffing is useful here.

cecoutinho
3rd January 2007, 11:45 AM
Newbie here, I have a QTEK 9100 and I'm SIM unlocked. Two questions:
1) How do I know if I'm a G3 or G4?
2) How do I know if I am CID locked?

Thx

fla242
3rd January 2007, 11:56 AM
hello,

This is not good topic here, please take a look in other thread in G4 section.

Thanks

libertysyclone
4th January 2007, 03:46 PM
Question #1 DOES the project still need more logging info from this? and do you still want me to use USB monitor or some other program? Who do i need to send it to?

Question #2 does a unlocked CID allow me to use any ROM or do I still have to stick with the G4 friendly ones? and does it reamin unlocked after everyreflash?

neonkoala
4th January 2007, 06:50 PM
1. I'm not sure but any logging info is good so if you are paying to unlock then any results would be great! Stick with USB monitor I would think is best as some people have licenses for it to replay the log.

2. You still need G4 friendly ones as this is due to the chip inside being different to the G3, and yes it does stay unlocked after every reflash.

PiGG
4th January 2007, 10:56 PM
I saw there was some confusion about my attempt.

It did succeed. I unlocked the CID ( The SIMlock was already removed via lokiwiz ) and upgraded my Vario to 3.0.0.0 from molski.biz

That version is running fine and stable now with numerous benefits, which would be offtopic here.

d0ug
6th January 2007, 06:56 PM
I'm curious what the status is on this unlocking project. I've seen a couple people have posted USB logs. Do we have enough information now to make an unlock utility now? If we do have enough information now, is anyone actually doing any coding, or do we need a coder to go any farther?

pof
9th January 2007, 10:34 AM
The data written to the phone is actually different in each unlocking, most probably this is dependant on the DOC unique ID of each phone, so it would be good to have this dumped (pdocread) before and after the unlocking process is done.

CAnnabYS
14th January 2007, 02:14 PM
wouldn't it be a bit easier to figure out how the key files for the imei check program are generated? :confused:

internetadam4657
20th January 2007, 07:35 PM
so do we have any updates on the progress?

i've been a long time lurker here but i just got a g4 wizard and i'm not too keen on forking over $40 USD for unlocking my 8125.

madjokeer
20th January 2007, 10:59 PM
i tried just unlocking the sim with lokiwiz but i didnt work for the G4, i see posts in there stating its working.. what version you guys using for lokiwiz?

neonkoala
20th January 2007, 11:42 PM
Going off topic ^ but try using Lokiwiz 3.0 rather than v2.

-----

I think progress is reliant on rebuilding some of the ROMs snatched from USB into workable files from the hex.

uberdeity
22nd January 2007, 11:20 PM
Hey there, I'm just a mere newbie, but has anyone tried just renaming the key file? I just paid to unlock mine and I recieved a 32.3kb .unl file with the name in the format "<first 15 digits of IMEI returned from *#06#>.unl"

Does this seem like it would work? Also, would this be legal?

d0ug
23rd January 2007, 12:36 AM
Hey there, I'm just a mere newbie, but has anyone tried just renaming the key file? I just paid to unlock mine and I recieved a 32.3kb .unl file with the name in the format "<first 15 digits of IMEI returned from *#06#>.unl"

Does this seem like it would work? Also, would this be legal?



I highly doubt that would work. That would just be too easy. Most likely the file contains an encryption key based on your IMEI, and maybe the actual encrypted binary files that are used to unlock the phone. Seeing as the file is 32k, that’s a lot of data. Even the strongest of encryption keys can fit in under 1-2k of space. The rest of that file is either parts of the unlocking program encrypted to keep people from cracking their unlocker, and probably even the chunks of data that they write into the flash of the phone to unlock it.

I actually paid to unlock mine last night. I’ve already had the phone 2 months. My luck if i keep waiting it will be another 6-9 months if ever until a free unlocker comes out. By then ill probably be moving on to a new device.

simplekanc
2nd February 2007, 02:39 PM
Who can donate my CID-unlock procedure? I'll send all log files and unl file.
I have not a credit card - that's why I can't paid to imei-check.

vippie
4th February 2007, 01:14 PM
Who can donate my CID-unlock procedure?

Nice try :D! Anybody that stupid? :)

simplekanc
5th February 2007, 08:46 AM
See this thread http://forum.xda-developers.com/showthread.php?t=271043
I think no need to CID unlock now. I just reflash my device with arabic :)

chriskaragiannis
7th February 2007, 08:55 AM
i just had a look at this thread, http://forum.xda-developers.com/showthread.php?t=293080
Check out the pictures on the thread. Could this be the CID unlocking program that we have all been waiting for? I was just about to pay to get mine unlocked and i thought i check the G4 Forums and i cant belive that its soon going to be possible!!!!
Check it out!

tkteun
4th April 2007, 03:04 PM
Just tried USB capturing the unlock attempt by "M3000v4Unlock.exe"

And found out it automaticly shuts down your PC when HHD USB Monitor is even installed :)

stoof
4th April 2007, 05:15 PM
i was wondering if any new findings were done on this... i've been looking forward for a cid unlocking way of my G4 , 28 euros is not really cheap

Sincere
6th April 2007, 11:23 PM
anybody know if these guys do sim or cid unlock it is only $25 skystartrade .com

mam-rez
15th April 2007, 12:31 PM
hi...

in one of the sites there was an article on win6 for cellphone g3 or g4
my cellphone is imate k-jam
ipl: 1.00
spl: 1.00

according to article my cellphone is g3
after installing process the windows wich i installed didn't work properly and changed from wizard to prophet
my new ipl: 1.00 spl: 2.20

i can't install my cellphone's windows anymore
i can't unlock prophet and change it to wizard

how can i do the things above...

plz help me A.S.A.P

i'm really mixed up

:confused: :confused: :confused: :confused:

starkwong
18th April 2007, 04:10 AM
1. You are obviously posted in the wrong place, it's a G3
2. You certainly did not unlock your CID before flashing
3. Wizard is NOT Prophet, you cannot flash a Prophet ROM to Wizard device

Try this:
1. Go to http://forum.xda-developers.com/showthread.php?t=285435 and read through the whole guide
2. Download the button's 1.05 ROM (Don't ask where is it, you didn't read the post carefully)
3. Follow the instruction to recover and unlock CID.
4. Upgrade your IPL/SPL to 2.xx
5. Pick a WM6 rom FOR WIZARD and flash it.

xvemokidvx
6th June 2007, 04:08 AM
no news on a free unlocker or do we still have to pay for it?

mestrini
6th June 2007, 11:05 PM
no news on a free unlocker or do we still have to pay for it?

I'm sure that if there was a free wizard unlocker it would have a sticky thread on its own ;)

ONYX.PT
10th June 2007, 02:59 AM
:( so there is no g4 cid unlock for free, if anyone find some kind of solution please do post, at the moment i use ShellTool to do ROM change but.... not any more since the last time because of an error the almost brick my 9100, SO! STILL LOOKING FOR A FREE SOLUTION :D

CrArc
14th June 2007, 04:56 PM
I am going to squat on this thread.... I just bricked my last G4 flashing a naughty ROM with Shelltool. Because it was CID locked, i couldn't flash a working ROM back onto it as I couldn't boot into Windows! :-D mind you I can't afford £40 for unlocking my new one...

*patience* though what I'm really after is the wizzy new GUI on the HTC Touch..

mestrini
16th June 2007, 09:35 AM
I am going to squat on this thread.... I just bricked my last G4 flashing a naughty ROM with Shelltool. Because it was CID locked, i couldn't flash a working ROM back onto it as I couldn't boot into Windows! :-D mind you I can't afford £40 for unlocking my new one...

*patience* though what I'm really after is the wizzy new GUI on the HTC Touch..

You can't brick a phone by using a RAPI tool. what you can do is mess up IPL/SPL and OS and make it a very strange software salad for the phone to accept. But, as long as you can go into bootloader mode you might have a way to get your phone back.

CrArc
16th June 2007, 07:27 PM
Yeah you'd think! I was convinced I could revive it too, since it could boot into the bootloader. I had to mix and match RUU utilities because half of them threw up errors until I found one that worked, and then it was a case of trying several different WM6/WM5 images to find one that it booted with.

I couldn't try the mtty app to try the copy-to-miniSD-then-copy-back method as it was CID locked. But it solved the problem for me anyway, because after about the twelfth flash, it died completely - wouldn't charge, turn on, nothing. So... bricked. *sigh*

mestrini
17th June 2007, 02:30 AM
Yeah you'd think! I was convinced I could revive it too, since it could boot into the bootloader. I had to mix and match RUU utilities because half of them threw up errors until I found one that worked, and then it was a case of trying several different WM6/WM5 images to find one that it booted with.

I couldn't try the mtty app to try the copy-to-miniSD-then-copy-back method as it was CID locked. But it solved the problem for me anyway, because after about the twelfth flash, it died completely - wouldn't charge, turn on, nothing. So... bricked. *sigh*

That's not bricked!! It's flat battery :p

ChristoA1
18th June 2007, 07:47 PM
Hey guys, I don't know if this is a little off topic or not...

I just bought the IMEI-Check software, and got the unl file from them. When I try to run the program, it's shutting down my computer. I don't have the USB Monitor or anything installed, and I'm running Vista Ultimate as Administrator. I'm emailing back and forth with them (to their credit, they're pretty fast on responses, less than 10 min at this time of day), but I'm worried about them saying "Sorry, it's just not working" and then me being out $40. If worse comes to worst, and I have to do a PayPal dispute, is there anything they can do since they have my IMEI? Is it legal for them to do? I don't want them to deactivate my phone or anything just because the software isn't working...

Advice? Hopefully it won't get that far and either 1) we'll get it working, or 2) they'll refund me.

AdamG
18th June 2007, 08:01 PM
Hey guys, I don't know if this is a little off topic or not...

I just bought the IMEI-Check software, and got the unl file from them. When I try to run the program, it's shutting down my computer. I don't have the USB Monitor or anything installed, and I'm running Vista Ultimate as Administrator. I'm emailing back and forth with them (to their credit, they're pretty fast on responses, less than 10 min at this time of day), but I'm worried about them saying "Sorry, it's just not working" and then me being out $40. If worse comes to worst, and I have to do a PayPal dispute, is there anything they can do since they have my IMEI? Is it legal for them to do? I don't want them to deactivate my phone or anything just because the software isn't working...

Advice? Hopefully it won't get that far and either 1) we'll get it working, or 2) they'll refund me.

I myself bought a unlocking key from imei check as well a few days ago, it worked fine but I'm on XP, they can't lock/deactivate your phone no matter what theyre website says because the service they offer isn't fully legit anyway, the CID lock is put there for a reason and they are offering a service to unlock it and its leaving O2 and other companies out of pocket effectively in a way, so they're not going to report fraud to anybody. Can't you put one of these Windows XP Mini USB Distros on your a USB flash disk and just use that so you can use your unlocking key?

Also in response to this topic, I think we could just use they're tool to unlock our XDAs if we could create the unl files they give, the algorithm can't be that hard to crack as they instantly generate files using they're php script the PayPal IPN is processing to. I'm willing to donate my unl file to help with this if anybody is wishing to try and take this path, just send me a pm.

ChristoA1
18th June 2007, 08:38 PM
I myself bought a unlocking key from imei check as well a few days ago, it worked fine but I'm on XP, they can't lock/deactivate your phone no matter what theyre website says because the service they offer isn't fully legit anyway, the CID lock is put there for a reason and they are offering a service to unlock it and its leaving O2 and other companies out of pocket effectively in a way, so they're not going to report fraud to anybody. Can't you put one of these Windows XP Mini USB Distros on your a USB flash disk and just use that so you can use your unlocking key?

Also in response to this topic, I think we could just use they're tool to unlock our XDAs if we could create the unl files they give, the algorithm can't be that hard to crack as they instantly generate files using they're php script the PayPal IPN is processing to. I'm willing to donate my unl file to help with this if anybody is wishing to try and take this path, just send me a pm.

Thanks for the response! I figured about as much, but just wanted to be sure... This is going to sound dumb, but what would you suggest for said "Windows XP Mini USB Distro"? Also, if things don't go well, I could donate my unl file, as it means nothing to me, and I'm the only one with this IMEI :-)

AdamG
21st June 2007, 11:28 PM
The unl isnt useless you will need it, cant seem to find the premade installs of xp for usb disks but they are out there heres a guide for making your own though, http://www.ngine.de/index.jsp?pageid=4176

djohno1973
24th June 2007, 12:23 AM
Try mojopack (dont know url, try google) its xp on a memory stick of youre choice.

sactownsoldier23
5th August 2007, 04:19 AM
Correct me if I'm wrong, but according to my understanding does the website imei-check.co.uk only provide a SIM-unlock and NOT the CID-unlock??? If so, with the SIM unlocked can you use lokiwiz to CID-unlock or is CID-unlock an ongoing issue for G4 phones?

Thanks

mestrini
5th August 2007, 12:12 PM
Correct me if I'm wrong, but according to my understanding does the website imei-check.co.uk only provide a SIM-unlock and NOT the CID-unlock??? If so, with the SIM unlocked can you use lokiwiz to CID-unlock or is CID-unlock an ongoing issue for G4 phones?

Thanks

imei-check's tool does it all (SIM and CID) and for all models. There's no FREE G4 CID unlocking

DelGreco
6th August 2007, 05:17 PM
imei-check's tool does it all (SIM and CID) and for all models. There's no FREE G4 CID unlocking

If I CID unlock my G4 Qtek S200 with imei-check's tool your Wizard Service Tool work on my S200 ?

mestrini
6th August 2007, 10:44 PM
If I CID unlock my G4 Qtek S200 with imei-check's tool your Wizard Service Tool work on my S200 ?

Yes it will work on ROM areas that have same size as Wizard like CID block but may fail on others.

As long as you're not trying to write to ROM i believe it's safe to use. I might even make use of your experience in order to make it more compatible with S200 ;)

cheers

GateArray
7th August 2007, 02:54 AM
There's no FREE G4 CID unlocking

Someone knows which is the REAL difference between the G3 and G4 devices?

HW?
SW?
A combination of?

I bought a WIZA200 for my wife but I got it is G4 device.... :-((((

bjeli
18th October 2007, 05:56 PM
So if I understand it correct, there is NO other possible way to unlock your cid unless you pay for it?

I just bought a MDA Vario with T-mobile (Holland) and noticed following the tutorials etc that I have a G4.

the-equinoxe
18th October 2007, 09:08 PM
So if I understand it correct, there is NO other possible way to unlock your cid unless you pay for it?

I just bought a MDA Vario with T-mobile (Holland) and noticed following the tutorials etc that I have a G4.

You can use soft or hard SPL for unlocking the SPL.
Be shure to read the stickies though.

Veel plezier (have fun),

EquinoXe

josmeijer
10th May 2008, 07:52 AM
hello,

i've just unlocking my Wizard devices through IMEI Check...And i've log file from usb-monitor !!

But file size is over 2mb !

You might consider to upload it to the webspace that you doubtlessly have somewhere and give the link to the forum?

supernerd1991
2nd June 2009, 12:58 AM
I got it unlocked but still having problems. Waste of money, maybe. We'll see.

tigrisimo
2nd June 2009, 04:21 PM
I got it unlocked but still having problems. Waste of money, maybe. We'll see.

Great price!
hi!
how do you know is unlocked? is a G3 or G4 device?
always chek it first (IPL/SPL) and then you will realize if is G3 or G4
Now you have 2 dowoload the rom you want and then (if device is unlocked) you will be able 2 flash with no other procedures
Good Luck!!