S-off is Official!!! With Instructions...

Search This thread

redbean25

Senior Member
Jan 4, 2012
372
99
Seattle
It worked like a charm the first try: I was on rez rom 3.4. My hboot now is 2.21.2121
radio 1.22.10.0310r/1.22.10.0308r

Is this correct? If so do i need to just flash the rom of my choice from this point on?

Those are the same hboot and radio versions I have and are correct it you installed the JuopunutBear hboot from the ICS version and were running the ICS leak prior to performing S-OFF.

Now just re-install the boot.img from rez rom 3.4 if it doesn't boot into the rom. Although from what I am told, if the ControlBear finishes without error, it will restore the boot.img and recovery.img after it is done. I on the other hand had to reload both.
 

chaos254

Senior Member
Mar 4, 2011
188
25
Just tried doing this and failed. I followed the instructions and everything seemed fine but it never asked me for the wire trick. When it said rebooting to fastboot it said quit and that was it. Here is what it says now. Im confused to why it won't prompt me to do the wire trick. thanks

======== ControlBear version 0.2.2 for JuopunutBear S-OFF ==========
Starting up......
Connecting to device...
Found backups!
Making room for beer......
Loading sixpacks on sdcard......
Loaded......
Board vigor detected
5
Rebooting into fastboot!!Quit....
Press ENTER to exit.....
 

DroidTemplar

Member
Mar 27, 2012
22
5
Houston
S-Off Success

Thanks to the developers, forum moderators, forum members for the gift of S-Off.

If my experience can help;

As recommended, I read and learned for several days from others and collected what I considered important info into a cheat sheet. I went from noob with a stock off the shelf Rezound to noob with S-Off in 4 hours. The first 2 hours were spent getting a Win7x32 setup with Android SDK r19, killing PDANet and killing HTC sync, preparing the Rezound by a factory reset, getting unlock bin from HTC, fastbooting unlock bin, fastbooting Amon Ra 3.15, and using Amon Ra to set SU for root. Used a spare 16GB microSD Class 4 for the nand backup.

I choose the paper clip method. I reshaped the paper clip into a U shape, and sanded the ends of the clip to get clean conductive metal surface and a flat surface for better chance of contact. I had to adjust the U shape so that the pin 1 clip end was a straight right angle to the phone and the ground clip end was positioned over the ground pin. I tried both the ground pin and USB ground shield tricks but my luck happened when using the ground pin.

I got all of the needed files in c:\android, started cmd in Win+R, and did a “fastboot devices” to verify the phone was connected and listed under the “fastboot devices” command. Set properties on ControlBear to Run As Administrator. Took a deep breath then made the leap. I had to rerun ControlBear almost a dozen times before it worked its way to displaying the wire trick prompt. When peeking at the display, I was seeing the black screen and green arrow. With one exception for a battery pull to clean up the Rezound, I did not do anything else other than doubleclick ControlBear to rerun ControlBear. Each time I ran ControlBear, ControlBear made it a little further along into the expected prompts. In the middle of the series of ControlBear reruns, ControlBear did say it could not recognize the device. I did a battery pull on the Rezound and the Rezound booted into FastBoot. ControlBear picked up where it left off. With each rerun of ControlBear I would see more of the reported prompts.

When you see the error code 667377, you are almost there if you can get past the wire trick. I think like others that there are several factors at work in the timing. The developers say that the exploit is based on the stock ROM. That means that the 1.75 seconds occurs in a specific place in the running code. Anything that changes when the 1.75 second code executes will change the 1.75 second timing. Custom ROMs, apps running, cpu throttle apps or anything else affecting when the processor gets to the special code, maybe affecting the variations in timing results. My stock Rezound already had the stock ROM, but I did a factory reset to set my Rezound as close a possible to what this trick was developed for. Noticed that some successes did occur after the stock RUU, maybe coincidence, not always necessary since others have had success without being stock. But it may improve the odds if you are looking for it being easier.

After a dozen reruns of ControlBear, the process had progressed where I started seeing the do the wire trick prompt. ControlBear prompts many times but will eventual give up and check the phone. This is when you will see the error code and no success. After two failed attempts, I decided to remove the SIM card so it would not interfere (maybe just coincidence). The third attempt succeeded. I hit it on the second ‘do wire trick’ prompt. Unlike the other times, ControlBear begin checking the phone only after two wire trick prompts. ControlBear finished the process, asked about permission for the hboot update, I said yes, and the phone booted normally with no missing data. During the successful attempt, I did change from a double tap to a double brush stroke on the ground pin while holding pin 1 wire steady and straight.

The now S-Off phone is locked with Amon Ra 3.15 still loaded.

Suggestions,
If using Windows and x64 not working for you, try to use an x32 version,
After installing SDK r18, still need to run SDK Manager to update to r19 and load all files,
Use fastboot devices to make sure your phone is connected,
Use a paper clip reshaped and ends sanded,
Use stock ROM cleaned by factory reset,
Pull SIM card,
Make sure you are using the correct ControlBear release for your GB or ICS.
Set ControlBear properties Compatibility to ‘Run this program as an administrator’,
Only need to rerun ControlBear to continue pushing the progress a little further along,
When getting the wire trick prompt, use brushstroke if tap is not working for you,
Had PDANet installed but killed (some people have said the PDANet drivers were helpful, maybe coincidence)


Thoughts,
Like others have said, can be unsettling during the process, but very satisfying when successful.
Noticed that my 4G reception is much better with whatever new software was loaded during the process. Noticed hboot changed from 2.10 to 2.11.
Exploit may be fixed with May 9th RUU, so I plan to repeat the success with the remaining Rezounds before the next RUU.
As reported by others, success can be had without parts of this, but if a different way is not working, maybe these suggestions may help.

---------- Post added at 11:49 AM ---------- Previous post was at 11:42 AM ----------

Just tried doing this and failed. I followed the instructions and everything seemed fine but it never asked me for the wire trick. When it said rebooting to fastboot it said quit and that was it. Here is what it says now. Im confused to why it won't prompt me to do the wire trick. thanks

======== ControlBear version 0.2.2 for JuopunutBear S-OFF ==========
Starting up......
Connecting to device...
Found backups!
Making room for beer......
Loading sixpacks on sdcard......
Loaded......
Board vigor detected
5
Rebooting into fastboot!!Quit....
Press ENTER to exit.....


Normal. You are part way down the path. Keep rerunning ControlBear to finish the journey.
 
Last edited:
  • Like
Reactions: taptaptouch

chaos254

Senior Member
Mar 4, 2011
188
25
I re ran it like 10 times and it kept saying the same thing. Never once did I get to the screen to try the wire trick. I ended up flashing the backup recovery and boot.img. Going to give it another go by starting fresh in the rom... I just wish I knew why it wasn't prompting me for the wire trick

UPDATE: Started over and it is still doing the same thing. Says rebooting to fastboot....QUIT hit enter to exit. I pulled the battery and it went to fastboot so I re ran the program hoping it would continue from where it left out but it instead it rebooted from bootloader back to the black screen with the JuopunutBear image. For some reason it will NOT boot into fastboot on its own. I just need to figure out why. I know adb and fastboot are working since I just checked adb devices and just used fastboot to flash the recovery and boot imgs. Any help would be great. Thanks
 
Last edited:

DroidTemplar

Member
Mar 27, 2012
22
5
Houston
I re ran it like 10 times and it kept saying the same thing. Never once did I get to the screen to try the wire trick. I ended up flashing the backup recovery and boot.img. Going to give it another go by starting fresh in the rom... I just wish I knew why it wasn't prompting me for the wire trick

Your phone was trying to boot into fastboot. If fastboot had been 'detected', the 'do not remove sd card do wire trick' would have been the next prompt. You were almost there. Keep trying.

When I got stuck, the battery pull and reboot helped me keep going. Dont know if that would have been right for you.

Good luck,

---------- Post added at 12:42 PM ---------- Previous post was at 12:20 PM ----------

I re ran it like 10 times and it kept saying the same thing. Never once did I get to the screen to try the wire trick. I ended up flashing the backup recovery and boot.img. Going to give it another go by starting fresh in the rom... I just wish I knew why it wasn't prompting me for the wire trick

UPDATE: Started over and it is still doing the same thing. Says rebooting to fastboot....QUIT hit enter to exit. I pulled the battery and it went to fastboot so I re ran the program hoping it would continue from where it left out but it instead it rebooted from bootloader back to the black screen with the JuopunutBear image. For some reason it will NOT boot into fastboot on its own. I just need to figure out why. I know adb and fastboot are working since I just checked adb devices and just used fastboot to flash the recovery and boot imgs. Any help would be great. Thanks


"black screen with the JuopunutBear image" looks right since this is where the phone is ready to work with ControlBear. This is where I would rerun ControlBear and see what info ControlBear Displays for the next clue.
 

maximus20895

Senior Member
Dec 12, 2011
449
60
can you use fastboot when the phone is booted normal or do you have to go the the hboot and fastboot usb? I can't use it when it's normal, but i can do adb commands.
 

chaos254

Senior Member
Mar 4, 2011
188
25
I am now s off!! Thanks everyone for the help, especially the juopunutbear team for the help on their IRC channel.

USE A STOCK ROOTED ROM TO S OFF!!!! I know people have gotten it with other roms and this is what messed me up. I absolutely could NOT get it to work on ineffibilis 1.4. Soon I flashed scotts clean rom 1.7.5, everything worked flawlessly and only took me 3 times to get the wire trick.
 

ogre150

Senior Member
Jun 25, 2010
107
8
Kankakee
unlimited.io has updated there site.

Newest version is 0.4
changelog:
0.4
Added backup to PC of sdcard
Fixed “must be root” error
Added some support for custom roms
Fixed backup and restore for doubleshot
Improved error messages
Added support for Amaze on ICS
Added battery level check
Fixed not found errors for JuopunutBear
Added more carrier and model support for pyramid hboot
Added version.txt to zip files

Just putting it out there.


Also,
Can someone direct me in how to get a copy of the boot.img for plain old stock GB?

Thanks.

I used to be a developer like you. Then I took an arrow in the knee...
 

DroidTemplar

Member
Mar 27, 2012
22
5
Houston
So we want HTC Sync uninstalled, right?

I agree with chaos254. The installation of the HTC drivers is a good thing. htcUPCTLoader.exe runnning as a Windows process is a bad thing since it may interfere. Dont uninstall. Use Windows Task Manager in Processes to 'show all processes' and kill htcUPCTLoader.exe if it is runnning.

Check that PDANet is not running while in Task Manager.
 

xceebeex

Senior Member
Dec 16, 2010
629
26
I finally got S-Off!!! I KNEW it wasn't my timing that was the problem. I downloaded the 0.4 Control Bear and used a new SD card and I got it on the very first try and I did nothing else different. I have a feeling it was a bad SD card.

So now I just have to figure out if I want to flash juopunut's modified hboot or the eng hboot and then take a look at what other cool stuff I can do now!

Thanks everyone for the help. I wish I had tried a different SD card earlier because I think that would have saved me a lot of headache.
 

tekhna

Senior Member
Dec 31, 2007
1,214
331
So I did some searching, and I can't seem to find an answer to this question--it tells me I have 5 seconds to hit ctrl+C, so I do, and then the program closes. Any ideas? It backs up successfully.
 

Top Liked Posts

  • There are no posts matching your filters.
  • 110
    Fixes for Internal Memory and External SD card are at bottom of post!

    May be easier to make a completely new thread instead of people searching through the "s-off discussion" thread.

    I'm going to make a huge SD Card post right at the top because it seems like people still are overlooking it in the "s-off discussion" thread... Not trying to be a ****, just making sure people don't lose crucial information on their SD cards...

    Version 0.4 should not wipe internal memory anymore and should back up your external SD card: but I would still back up both just to be sure!!!!

    Here's the link for Instructions:

    http://unlimited.io/instructions/

    Read the Instructions carefully and thoroughly at least once before attempting. This will temporarily brick your phone. Don't be lazy. Don't forget this will format your SD card so save all your contents or use a spare!!! I used my old 2GB droid incredible sd card for mine...

    Prerequisites said:
    Prerequisites

    In order to use JuopunutBear you must meet the following pre-requisites:

    Be unlocked using the HTCdev bootloader unlock
    Be rooted (have superuser and/or an unsecured boot image installed)
    Have a spare microSD card, or to have backed up all contents of your SDcard
    Have fastboot and adb drivers installed and working (windows)
    Have usb debugging enabled
    Have a legth of insulated wire of sufficient length to join the contact points for your device. See images and videos for device specific information.

    Some notes:

    Make sure back cover is off before running program.
    Plug in phone before running program.
    Boot phone into ROM before running program, it will automatically boot into fastboot by itself.
    Don't do wire trick until after you run the program and tells you to do so!!!
    Make sure you have "USB debugging" enabled!
    If in Windows, right click program and make sure you click "Run as Administrator"

    This post sums up everything nicely...

    http://xdaforums.com/showpost.php?p=25154023&postcount=1289

    Instructions said:
    Instructions

    (Optional) Perform a full backup and replace your sdcard with one that you are willing to wipe.
    Ensure that your battery is fully charged.
    Choose the correct download for your device and operating system
    Extract the zip file to a new directory
    Verify the MD5 checksum for your download
    Read and/or watch the video for the device specific information for your device
    Run controlbear as admin(windows) or root or using sudo on linux
    Follow the on-screen instructions from ControlBear
    Do not press any of the buttons on the phone during the process.
    After doing the “wire-trick” yor phone will reboot. The sequence of the reboot may vary somewhat from that you see in the videos as these were taken during various stages of development.
    If you see the following message from ControlBear after doing the wire trick:
    ErrorMsg: Still sober.
    This means that you have been unsuccessful in implementing the wire-trick. Run ControlBear again.
    The usual casue for this is that you failed to perform 2 clean contacts or mistimed the wire trick.

    Your phone will reboot several times during the process, this is normal. ControlBear will tell you when it has finished whether sucessfully or not.

    Here's link for wire trick:

    http://unlimited.io/htc-rezound/

    Wire Tips:

    22ga wire fits almost perfect in the lower hole.

    Use a piece about 8 inches long and stripped the end for the lower contact about 3/8 of an inch and the other end just a small amount. Did this to two phones and it worked the first time both times.

    It was reported that the large coated paper clips work well too.

    Others are using odd objects or other weird improvised wires and having a lot of trouble. It seems to be one of the big sticking points.

    I honestly used a paperclip and it worked just fine. Not even insulated... even though they don't recommend it: you could use it as a last resort.... or wrap it with an insulated material. I didn't know the paper clip had to be because I was one of the beta testers.

    Don't make this mistake either.

    Wire Trick said:
    Wire Trick

    The “wire trick” is an essential part of the JuopunutBear S-OFF procedure.

    When instructed to do so by the program you must perform the “wire trick” which is done as follows.

    Obtain an insulated wire of appropriate length and gauge
    Insert one end of the wire into the hole where pin 1 is indicated in the picture below, ensuring that a firm contact it made with the metal contact at the bottom of the hole
    Briefly touch to other end of the wire to the contact marked GND in the picture below.
    Wait approximately 1.75 seconds and then again touch the wire to the marked GND.
    Allow the program to continue.

    Note: it may take several attempts of running the program in order to obtain the correct timing for the wire trick.

    The contact points for the “wire trick” are shown in the picture below.

    If you're not getting it after wire trick, keep trying! Timing is crucial!!!

    Don't forget this will format your SD card so save all your contents or use a spare!!!

    Picture of Points:

    rezound.jpg


    Video of Wire Trick:


    New ICS hboot should be included in the download now.
    http://xdaforums.com/showpost.php?p=25147001&postcount=1141

    Very nice thread walkthrough thread for fixing external SD right here!
    Fix for external SD is as follows:

    1. Install busybox
    2. adb shell busybox fdisk /dev/block/mmcblk1
    3. type o
    4. type w
    5. adb shell busybox fdisk /dev/block/mmcblk1
    6. type n
    7. select primary, then 1
    8. chose default sizes
    9. type w
    10. adb shell busybox mkfs.vfat /dev/block/mmcblk1p1

    For those of you having problems with internal storage, my apologies. We accidentally included the GB hboot.

    Download this:

    http://dl.dropbox.com/u/14779955/jb_hboot.zip MD5: b05336c08f709bf0a909205bcb95b951

    Put the phone in fastboot mode, then run the follwoing commands:
    Code:
    fastboot oem rebootRUU
    fastboot flash zip jb_hboot.zip
    fastboot reboot

    Ignore the green bar.

    Pretty much copied everything off the site, but it may be easier to use instead of switch tabs/windows... Good Luck...

    Disclaimer: I am not responsible for bricked devices or anything happening to your handset!!!! Just relaying the message


    If you're still having issues... The search button is your friend. :) There's a high chance your problem has already been solved. Either search this thread or the discussion of s-off thread. Don't know how to search? WELL NOW YOU CAN IN THIS SIMPLE TUTORIAL!!!!!

    Some more threads you might want to check out!!!!

    AR recovery and s-off ( fix )

    [FAQ] S-Off

    just got s-off? please read this.


    Oh yeah... ENJOY S-OFF!!!!!

    These guys put in a hell of a lot of effort into doing this process... Any donation would be greatly appreciated!

    Donate to JuopunutBear Team!!!
    9
    There really is a need for a comprehensive set of instructions (but I'm not quite free enough to do it myself). NOTE - THESE INSTRUCTIONS ARE FOR THOSE ALREADY ON THE ICS LEAK WITH HBOOT 2.21 AND AN HBOOT THAT READS "TAMPERED - UNLOCKED." If you are on hboot 2.11 or any other hboot, I can't say for sure whether the following applies to you. If you are on GB, I can't say whether the following applies to you. It was my experience only, and I was successful, and I'm just sharing because after 100+ pages of pretty much the same 10-12 issues, I figure I can at least try to make things easier.

    1. Don't try to get S-OFF if you are unrooted or have a locked bootloader. Read the darn instructions through from beginning to end, and review the OP's in this thread, and search for any issues about which you are curious. In fact, go read them again from beginning to end just to make sure you get it right, then come back here.

    2. BEFORE YOU START, make sure you have available both an *.img file and PH98IMG.ZIP of (1) your recovery; and (2) your boot image.

    3. PULL YOUR SDCARD AND USE A DIFFERENT CARD FIRST. I'm sorry, anyone who has whined about wiping their only card --- you shouldn't play with grown-ups; you didn't read the instructions. If you only have one card BACK IT THE HELL UP, cause it's gonna get wiped.

    4. Back up your "internal" SD card. If you're running 0.2 version of ControlBear, it shouldn't get wiped, but you never know what else is going to happen that could wipe it. (Mine was untouched).

    5. Gee, you could also do a Nandroid and save it to your PC.

    6. All the Juopunut files go in the same file directory on your PC as fastboot.exe and adb.exe.

    7. Kill HTC Sync if you're really still running it.

    8. Open a command line box; navigate to the directory where you have adb and fastboot (and controlbear.exe and the two supporting files, it's own boot image and its hboot.)

    9. Make sure you are admin on your PC.

    10. Make sure your Rezound is fully charged, back cover off, connect to a cable (but not yet connected to PC) and you have your insulated paperclip or whatever tool you're going to use. LOOK AT THE PICTURE to be sure you know where you need to touch the wires. You will have time. Put the phone face down on a table or desk.

    11. Consider having a metronome around or something to beat out 34 bpm so you know the frequency. Here's a 35 second track (in *.aac format) you can loop on your computer while you're doing it so you have a feel for the interval. I used this when I got S-OFF.

    12. Run Controlbear. When it tells you, connect the device.

    13. If it doesn't seem to see the device after a few minutes, kill it and start it over. Leave your phone alone.

    14. Eventually, your phone's going to start rebooting and you'll get a prompt to do the wire trick. You will get that prompt for a few minutes and you'll have repeated chances to do the trick. After that, ControlBear talks about beer and other nonsense, and either tells you that you are still sober (exploit failed) or otherwise just sort of sits there. After a few minutes, if you seem to be nowhere, kill ControlBear (close the DOS box) and restart it. Leave your phone alone. Ignore any prompts from the PC about devices connecting.

    15. Repeat #14 until: (1) ControlBear reports success; or (2) Nothing seems to be happening (and your phone has a green arrow pointing down and Juopunut on the front).

    16. If things are stuck that way for >5 minutes (AND you're seeing no changes in your DOS box, no information scrolling, words such as "mmm, tasty", try to reboot into bootloader on your Phone. You might already have S-OFF (that was what happened to me, even though ControlBear never reported success). Be patient, wait a few minutes. Relax. You aren't going to brick your phone. As long as you can reboot to bootloader, ANY bootloader, you aren't bricked.

    17. If you aren't S-OFF, go back to #14, if you are, go on.

    18. Power off the phone. PULL THE SDCARD. If it isn't your "default" SDCARD, you don't need it anymore, you can put your regular card in. If it is your ONLY card, format the card Fat32 on the PC using a card reader.

    19. Using a cardreader, put Juopunut's BOOTLOADER on my SD card as PH98IMG.ZIP (i.e., rename it, it's the file with hboot in the name), reboot to bootloader and accept the update. From the "new" Juopunut's hboot, power down the phone. Remove the card again.

    20. Using a cardreader, remove the PH98IMG.ZIP of the hboot from the SD card. Put the card back in the phone.

    21. Reboot to bootloader, selected fastboot, connect to your PC, using fastboot USB reflash Amon Ra. (You could also do this as a PH98IMG.ZIP if you choose by putting it on the card).

    22. Power off. Remove card AGAIN, put boot image on card as PH98IMG.ZIP (taking off the old PH98IMG.ZIP if that's how you reflashed Amon Ra).

    23. Reboot to bootloader and flash your boot image, either via fastboot or as an PH98IMG.zip cf. step 21.

    24. Power OFF, boot normally, which should finally get you past the Juopunut splash screen. You might even bootloop once or twice (I did), but you should get a normal boot at that point.

    25. Note, if you boot to bootloader, flash recovery, then go from bootloader directly to recovery you will probably have have issues. Instead, after step 24, Power off or restart into recovery AFTER you've successfully booted your ROM. Amon Ra should behave perfectly normal at that point.

    The preceding was my experience at any rate.

    Yeah, Unrevoked was a lot easier and quick for those of us coming from Incredible, but it really isn't impossible to do this if you remain patient, pay attention, and stay calm.
    6
    for anyone whos done it what kind of wire have u used?

    I used a paperclip that was insulated. So just wrap one up with electrical tape and that will be fine.
    6
    Its actually quite fascinating to me to see so many varied results and peoples' reactions to the process. I'm also starting to realize that most of the people in here will put pretty much anything on their phone (or do pretty much anything to it..) even when they clearly have no idea what they are even doing it for.

    I mean seriously, half the people in here trying to get S-OFF and driving themselves insane probably shouldn't even be worrying about it anyway. But they will do it anyway. And then the next thing they'll do, for no apparent reason and without knowing anything at all about them, is start flashing radios. Then the next thing they will say is they can't make calls anymore and can't figure out why...
    6
    What should I do???
    Give me a hand! Thank you

    LOL really? You mean you did all this stuff to your phone that could potentially destroy it, and you didn't even read all the instructions first??! OK, now go ahead and facepalm for a second....


    ...OK lecture over.
    1) Go to the development section, find the Amon Ra recovery thread, and find somewhere in there the latest version 3.15 and download it (check around page 48)

    2) extract the .img file to a folder somewhere on your computer where you have the fastboot and adb applications located

    3) turn off the phone. Boot it into fastboot by holding volume-down and power, then selecting fastboot at the menu

    4) plug phone into computer - wait for phone to say "fastboot - usb"

    5) type the command "fastboot flash recovery recovery-ra-3.15-gnm.img" to flash the file (make sure the filename matches, that was from memory)

    6) then type "fastboot reboot recovery"

    7) Once Amone Ra boots, go to the developers menu and then select install su from there.

    Yes, I just typed all that out for you, even though its all readily available with a simple SEARCH. You're welcome.