Simple guide to [VM firmware recovery thread] v2

Search This thread

Will32

Senior Member
May 12, 2011
1,523
659
Benton
Judging by the time spent since your post, I'm gonna go with yes. Lol. Nailed it.



Not much out of unknown today, must be dealing with his friends. Feel bad for the guy.

Sent from my Sprint/Virgin Mobile hybrid


Yeah, hes got a lot going on.

Back on topic now, after all that other stuff, have you tried to get your AAA shared secret? After reading I found that its phone specific just like the MEID and ESN, and sprint uses it to provision the phone. I also found that "secret" is the HA shared secret and its not phone specific. Some people cant get 3g and I wonder if this matters.

Maybe you know this but ill say it for anyone interested, getting to the AAA shared secret Isnt hard once you've done it once, I was using the wrong version of QXDM, youll need version 03.11.36. open it up and go to options/communications then set target port to the port your phone is on (make sure you dial ##diag#). Now in the command window type "spc 000000" no qutoes of course and 000000 = your msl. then type "requestnvitemread ds_mip_ss_user_prof" and itll show you some stuff, look at the lower stuff called DIAG RX item. theirs 16 lines for each password (AAA & HA). the characters after 0x are the keys. Its supposed to be 30 characters total. The weird thing is, I have a few characters beside the HA lines but all my AAA lines have zeros.

Edit... that first request command was for the profile 0 passwords , this is the command to get profile 1 "Requestnvitemread ds_mip_ss_user_prof 1" , which is also all zeroed out on mine. I wish someone that didnt take the vmfw could look at theirs and tell me if its all zeroed out.

Yesterday Unknownforce said his phone worked with a testers radio config but the testers phone didnt work with it. Maybe Unknown has his pass and the tester doesnt? Just trying to stir up some ideas here...
 
Last edited:

jcfunk

Senior Member
Mar 18, 2008
901
500
32681d9b-48df-fc92.jpg



I'm jumping for joy, no more vm. Hope I can get hold of Unknown tomorrow, err today. Give him the low down so he can fix his repair tool.

Sent from my DOWNGRADED EVO 3D
 

oblivion2k

Senior Member
Mar 1, 2011
86
17
I get "Lack of Heap!" when I bootloader tries to flash the 2.17 PG86IMG.zip at the end of the guide. CRC checks out fine and I followed your direction to the letter AFAIK. Help please?
 

gingson

Senior Member
Nov 1, 2010
444
85
Nassau County, NY
This effin VM virus must really be a tough one to crack for the great minds in this forum. My only issue is the VM banner and QPST doesn't work for me and Leedroid is just masking my problem. My option of placing my phone between the concrete and my front tire (driver side so i can hear it to finally crack the virus) is very, very tempting.:)
 

jayjam99

Senior Member
Jan 28, 2011
508
222
Lima, OH
Yes, lucky one to brick. Then unbrick. Then one of the few left with a radio not working. So spent all day in front of 3 computers to fix, or break. LOL :D

OH! Phone didn't float. :eek:
WD40 hard to clean off.

Sent from my DOWNGRADED EVO 3D

I really hope this is good news and a step in the direction of having this fix released. I just want my 3G back! :(
 

jayjam99

Senior Member
Jan 28, 2011
508
222
Lima, OH
I dont know if it was ever mentioned here but thanks to buddywiser (In Vins other thread about this whole mess) I have now managed to regain my 3G connection! :)
It was nothing more than changing the setting in EVDO from "CDMA only" to "automatic". (In the ##3282# menu)
So now the only thing im still dealing with is the VM banners. (My PRI is downgraded and I have 3G again.)
 
  • Like
Reactions: buddywiser

ministersin

Senior Member
Aug 25, 2008
163
12
My experience:

Flashed VM Firmware (without Hboot) the night it came out and flashed the Virgin leak. Everything worked great.

Switched to CleanROM RC1 (for Wifi Tether) with no issues. Everything worked great. (Actually increased both 3G and 4G speeds)

Had a couple of SMS data errors when sending messages, but corrected itself and all messages sent except one.

Changed realm to "sprintpcs.com" instead of Virgin settings

Finally YESTERDAY all things went weird. Data Roaming started coming on all the time. Voice was roaming and horrible reception (even when bars appeared full). Call quality was gone. Had to start using VOIP for calls.

Then 3G disappeared that same day. 4G continued to work, but at slower speeds.

Tried a couple of settings in EPST ##DATA# (changed profiles from 0 to 1 and made sure EVDO was auto). No help.

Flashed the Roaming setting and 3D fix and changed roaming to sprint only. Helped for a little bit, but when I woke up this morning it was no 3G again.

Used chads PRI fix to get to _145. Updated PRL and Updated Profile and everything works great again. Still showing VM banners obviously. But chad's PRI fix certainly solved the data/voice/roaming issues and I have nice solid connection and high speeds on 3g and 4G.


Don't know if this helps anyone, but just thought I would share. I guess the important thing here is: Even if you think you are fine after flashing the VM firmware (like I was) you are probably facing disaster at some point. I would keep chad's PRI fix handy on your SD if I were you.

NOTES: HW0002, HBoot 1.4 S-off, CWM
 
Last edited:

Unknownforce

Retired Recognized Developer
Nov 18, 2008
2,044
4,268
You guys are lucky, haha... I was about to give up hope on this and have to go back to the drawing boards, because a 50/50 chance of either fixing or completely breaking, is just unacceptable...

But, jcfunk got his working again, it's going to add a few steps I think... But I'm going to look into this more in depth. Hopefully to keep it simple and keep it in the "all-in-one" tool that it is right now.
 

ftc_osiris

Senior Member
Dec 18, 2008
156
27
Austin, TX
My experience:

Flashed VM Firmware (without Hboot) the night it came out and flashed the Virgin leak. Everything worked great.

Switched to CleanROM RC1 (for Wifi Tether) with no issues. Everything worked great. (Actually increased both 3G and 4G speeds)

Had a couple of SMS data errors when sending messages, but corrected itself and all messages sent except one.

Changed realm to "sprintpcs.com" instead of Virgin settings

Finally YESTERDAY all things went weird. Data Roaming started coming on all the time. Voice was roaming and horrible reception (even when bars appeared full). Call quality was gone. Had to start using VOIP for calls.

Then 3G disappeared that same day. 4G continued to work, but at slower speeds.

Tried a couple of settings in EPST ##DATA# (changed profiles from 0 to 1 and made sure EVDO was auto). No help.

Flashed the Roaming setting and 3D fix and changed roaming to sprint only. Helped for a little bit, but when I woke up this morning it was no 3G again.

Used chads PRI fix to get to _145. Updated PRL and Updated Profile and everything works great again. Still showing VM banners obviously. But chad's PRI fix certainly solved the data/voice/roaming issues and I have nice solid connection and high speeds on 3g and 4G.


Don't know if this helps anyone, but just thought I would share. I guess the important thing here is: Even if you think you are fine after flashing the VM firmware (like I was) you are probably facing disaster at some point. I would keep chad's PRI fix handy on your SD if I were you.

NOTES: HW0002, HBoot 1.4 S-off, CWM
Austin had a really bad Sprint day yesterday (5/15). All phones had bad coverage not just yours.

You can see this on the Sprint Community forums that they had (or may still have) outages for any Sprint phone at ~170 towers in the Austin/San Marcos market.
 
Last edited:

oblivion2k

Senior Member
Mar 1, 2011
86
17
You guys are lucky, haha... I was about to give up hope on this and have to go back to the drawing boards, because a 50/50 chance of either fixing or completely breaking, is just unacceptable...

But, jcfunk got his working again, it's going to add a few steps I think... But I'm going to look into this more in depth. Hopefully to keep it simple and keep it in the "all-in-one" tool that it is right now.
I'm really excited for this tool, I tried fixing it manually but I'm getting a weird error when I try to flash the 2.17 PG86IMG.zip, here's hoping your tool will work where I could not. Will you make a new thread once the tool is ready to be published?
 

linty

Senior Member
May 9, 2012
61
4
Quakertown, PA
I tried over the past couple of days. Copied the partition before applying firmware. Stupidly applied firmware and made partition, then "downgraded". Fun fun. Everything is STILL not wonderful but I had fun ;)
 

Top Liked Posts

  • There are no posts matching your filters.
  • 39
    So, who's ready for good news? :)

    One phone that was getting no signal... has been brought back to life and re-activated... All sprint banners, and I just spoke to him on that phone ;)

    So, we have a fix, but I'm going to spend some time getting this down to a little less complicated of a process hopefully.

    I've got a few more testers making sure that certain things go according to plan. Once I get a few successful tests in a row, I'll consider it stable and release to public.
    28
    Close guys. I'm lucky to have two phones right now to try different things on and have been pretty much out of service for the past two days trying to get this sorted out. Unknownforce has been putting in overtime trying to fix this and i've been trying out his creations :D
    27
    The thread is created, but just not ready yet. I have just sent out another wave of "test" PM's to have a few more people test this... Hoping for positive results here. Fingers are crossed.

    Not trying to keep everyone waiting, but I don't want to be the cause of Sprint getting an influx of "dead" devices.

    I'm trying to get this done as quickly as possible, I need a break from this :eek:
    26
    As a mini update, I'm taking a few steps back and starting over a little bit here. The patch still isn't producing the results I'm looking for. As such, I have a new phone coming shortly, and someone else has a new phone that they are willing to test with me as well, so we're both going to pull complete emmc partition dumps and I'm going to study them to the T and find all the changed parts...

    This will take some time, but it will be the correct way to do it. with the mixed results I've gotten so far, I'm thinking that it's possible that something other than the radio_config has changed here... and if that's the case, I need to find where that is, so that we can make sure we're not missing anything.

    So, while this will set us back a little bit, it will also help find anything that I could be missing, and ultimately get a proper patch and also open up the door to some interesting abilities for the new tool. (refurb status reset, RELOCKED -> LOCKED, lifetime stats reset, and possibly more)

    Basically the more I study it the better it's going to be.
    22
    Ran into a few issues when freeza tried it, delayed a little bit... will update tomorrow. Be patient guys.