[Script] AAHK2 - Root, Debrand, SIM Unlock, S-OFF, SuperCID & Custom Recovery

Search This thread

tarouka10

New member
Jan 30, 2014
1
0
Nothing done

Heyy , really i need help!!

The hake device it'st mention a gg but under that i'ts write "rm failed for data/local.prop

After that it's boot into the hboot mode but nothing appears its just the hboot mod

i need help , why ?
 

Phiber2000

Senior Member
May 23, 2010
243
129
Don't worry! Just reboot. Your USB-Controller isn't compatible.
Use an USB2-Port on your mainboard directly and try again!
 

scotty1223

Inactive Recognized Contributor
Jan 3, 2011
2,813
3,056
Still think its a good idea to automate this process? ;)

Sent from my HTC PG09410 using Tapatalk 2
 

scotty1223

Inactive Recognized Contributor
Jan 3, 2011
2,813
3,056
hi, bitdefender keeps removing zergrush from the download :( any ideas?

turn it off ;)

zergrush is seen as a potential threat by all anti virus and security programs. you will have to temporarily disable all security and firewalls in order to download it. or possibly bury the original download inside 2 or more other zip files(that has worked for me in the past)
 

jocker01

Member
Apr 7, 2007
24
0
42
Winnipeg
turn it off ;)

zergrush is seen as a potential threat by all anti virus and security programs. you will have to temporarily disable all security and firewalls in order to download it. or possibly bury the original download inside 2 or more other zip files(that has worked for me in the past)

I can't turn bitdefender off :( looks like I gonna need to start other laptop without antivirus!

done! thx
 
Last edited:

scotty1223

Inactive Recognized Contributor
Jan 3, 2011
2,813
3,056
How to automate switching an USB-Port? :silly:

Haha You knew what I meant. People do not seem to be having any less trouble with this they did the original. There are too many factors, and too many variants for this to be a one click

Sent from my HTC6435LVW using Tapatalk
 

Phiber2000

Senior Member
May 23, 2010
243
129
Wide more than 10 000 Downloads and this few problems speak another language...
The problems are and will be the PC systems in over 90%. Definitely rare the devices!
If you can do it better and do the support - you're welcome! Really! ;)
 
  • Like
Reactions: 3498BoyZ

3498BoyZ

Senior Member
May 20, 2013
402
155
Nobody is forced to use it. Its an alternative. People have the choice between aahk2 or manual way

Gesendet von meinem One X mit Tapatalk
 

scotty1223

Inactive Recognized Contributor
Jan 3, 2011
2,813
3,056
Wide more than 10 000 Downloads and this few problems speak another language...
The problems are and will be the PC systems in over 90%. Definitely rare the devices!
If you can do it better and do the support - you're welcome! Really! ;)

has anyone ported a 3.xx kernel to ACE? if so there may be a much better way involving no downgrades,etc. just unlock,flash rom and kernel,run tool. since official support stopped a GB there are likely no allready available kernels that will work. :(

i do have a guide... wich i support. but it is teaching the manual way. from a couple years worth of helping troubleshoot the original AAHK and the manual method,i personally believe the manual way to be less prollematic for the user,and i believe its good for folks that feel they need s off to learn some command window skills.

the folks that do not need s off,or are unwilling to learn,IMO can easily,and more safely,stick with htcdev.

again,just my 2 cents. :p
 

dinidumr

Member
Oct 18, 2012
5
1
Thank you!

i coulnd t use this tool. it didnt run on windows xp SP2.
so i copied PDIMG98.zip manually to my SD card and relocked my bootloader and boot with hoot.
then it automatically updated to old version. then i run the AAHK older version and
Now it says S-OFF and Clockworkmod recovery complete!

Thank you everyone!!!!!! tadaaaaa!!!!!
:laugh::laugh::laugh::laugh::laugh::laugh::laugh:
:good::good:
 
  • Like
Reactions: 3498BoyZ

bobman33

New member
Feb 6, 2014
2
0
The script appears to have become stuck. I was running a bone stock DHD on 2.3.5, so the script performed a downgrade, which worked fine. I checked in the settings that it had been downgraded ok. I then re-ran the script and received the following output:

Code:
[Select and press Enter]1
Android version is exploitable.
2404 KB/s (19240 bytes in 0.007s)
2664 KB/s (4564992 bytes in 1.672s)
2783 KB/s (4458496 bytes in 1.564s)
2571 KB/s (557962 bytes in 0.211s)
1632 KB/s (9796 bytes in 0.005s)
2967 KB/s (572752 bytes in 0.188s)
2800 KB/s (134401 bytes in 0.046s)
1746 KB/s (13968 bytes in 0.007s)
ro.build.version.release=2.3.3
Setting up for Gingerbread restore...
2712 KB/s (2801664 bytes in 1.008s)
2813 KB/s (2830336 bytes in 0.982s)
2859 KB/s (285981 bytes in 0.097s)
2749 KB/s (285981 bytes in 0.101s)
        1 file(s) copied.
Linux version 2.6.35.10-gd2564fb (htc-kernel@and18-2) (gcc version 4.4.0 (GCC) )
 #1 PREEMPT Thu Jun 9 14:20:29 CST 2011
Kernel version is Gingerbread...  Using fre3vo to temproot...
fre3vo by #teamwin
Please wait...
Attempting to modify ro.secure property...
fb_fix_screeninfo:
  id: msmfb
  smem_start: 802160640
  smem_len: 3145728
  type: 0
  type_aux: 0
  visual: 2
  xpanstep: 0
  ypanstep: 1
  line_length: 1920
  mmio_start: 0
  accel: 0
fb_var_screeninfo:
  xres: 480
  yres: 800
  xres_virtual: 480
  yres_virtual: 1600
  xoffset: 0
  yoffset: 800
  bits_per_pixel: 32
  activate: 16
  height: 106
  width: 62
  rotate: 0
  grayscale: 0
  nonstd: 0
  accel_flags: 0
  pixclock: 0
  left_margin: 0
  right_margin: 0
  upper_margin: 0
  lower_margin: 0
  hsync_len: 0
  vsync_len: 0
  sync: 0
  vmode: 0
Buffer offset:      00000000
Buffer size:        8192
Scanning region faa90000...
Scanning region fab80000...
Scanning region fac70000...
Scanning region fad60000...
Scanning region fae50000...
Scanning region faf40000...
Scanning region fb030000...
Scanning region fb120000...
Scanning region fb210000...
Scanning region fb300000...
Scanning region fb3f0000...
Scanning region fb4e0000...
Scanning region fb5d0000...
Scanning region fb6c0000...
Scanning region fb7b0000...
Scanning region fb8a0000...
Scanning region fb990000...
Scanning region fba80000...
Scanning region fbb70000...
Potential exploit area found at address fbb9b200:e00.
Exploiting device...
/dev/block/vold/179:65 /mnt/sdcard vfat rw,dirsync,nosuid,nodev,noexec,relatime,
uid=1000,gid=1015,fmask=0702,dmask=0702,allow_utime=0020,codepage=cp437,iocharse
t=iso8859-1,shortname=mixed,utf8,errors=remount-ro 0 0
tmpfs /mnt/sdcard/.android_secure tmpfs ro,relatime,size=0k,mode=000 0 0
Creating goldcard...
HTC android goldcard tool Copyright (C) 2011, Wayne D. Hoxsie Jr.
Original code by B. Kerler. Special thanks to ATTN1 and the XDA team.
Donations can be made to the Electronic Frontier Foundation:
-EFF link removed
or to B. Kerler:
-revskills link removed
0+1 records in
0+1 records out
384 bytes transferred in 0.006 secs (64000 bytes/sec)
Setting mainver lower to allow downgrade...
--set_version set. VERSION will be changed to: 1.31.405.6
Misc partition is "/dev/block/mmcblk0p17"
Patching and backing up misc partition...
Starting flash process...
erasing 'cache'...
OKAY [  0.356s]
finished. total time: 0.356s
Sending update...
This takes time. Please be patient!
sending 'zip' (18223 KB)...
OKAY [  2.996s]
writing 'zip'...
(bootloader) adopting the signature contained in this image...
(bootloader) signature checking...
(bootloader) zip header checking...
(bootloader) zip info parsing...
(bootloader) checking model ID...
(bootloader) checking custom ID...
(bootloader) checking main version...
(bootloader) start image[boot] unzipping & flushing...
(bootloader) [RUU]UZ,boot,0
(bootloader) [RUU]UZ,boot,31
(bootloader) [RUU]UZ,boot,68
(bootloader) [RUU]UZ,boot,99
(bootloader) [RUU]UZ,boot,100
(bootloader) [RUU]WP,boot,0
(bootloader) [RUU]WP,boot,100
(bootloader) start image[recovery] unzipping & flushing...
(bootloader) [RUU]UZ,recovery,0
(bootloader) [RUU]UZ,recovery,20
(bootloader) [RUU]UZ,recovery,44
(bootloader) [RUU]UZ,recovery,66
(bootloader) [RUU]UZ,recovery,89
(bootloader) [RUU]UZ,recovery,100
(bootloader) [RUU]WP,recovery,0
(bootloader) [RUU]WP,recovery,100
(bootloader) start image[radio] unzipping & flushing...
(bootloader) [RUU]UZ,radio,0
(bootloader) [RUU]UZ,radio,8
(bootloader) [RUU]UZ,radio,13
(bootloader) [RUU]UZ,radio,20
(bootloader) [RUU]UZ,radio,25
(bootloader) [RUU]UZ,radio,33
(bootloader) [RUU]UZ,radio,41
(bootloader) [RUU]UZ,radio,49
(bootloader) [RUU]UZ,radio,57
(bootloader) [RUU]UZ,radio,62
(bootloader) [RUU]UZ,radio,70
(bootloader) [RUU]UZ,radio,79
(bootloader) [RUU]UZ,radio,86
(bootloader) [RUU]UZ,radio,94
(bootloader) [RUU]UZ,radio,99
(bootloader) [RUU]UZ,radio,100
(bootloader) [RUU]WP,radio,0
(bootloader) [RUU]WP,radio,6
(bootloader) [RUU]WP,radio,14
(bootloader) [RUU]WP,radio,19
(bootloader) [RUU]WP,radio,27
(bootloader) [RUU]WP,radio,36
(bootloader) [RUU]WP,radio,44
(bootloader) [RUU]WP,radio,51
(bootloader) [RUU]WP,radio,59
(bootloader) [RUU]WP,radio,68
(bootloader) [RUU]WP,radio,76
(bootloader) [RUU]WP,radio,85
(bootloader) [RUU]WP,radio,95
(bootloader) [RUU]WP,radio,100
OKAY [ 95.165s]
finished. total time: 98.162s
rebooting...

finished. total time: 0.261s
Radio downgrade complete. Starting unlock process...
Linux version 2.6.32.21-gf3f553d (htc-kernel@and18-2) (gcc version 4.4.0 (GCC) )
 #1 PREEMPT Thu Oct 28 13:24:11 CST 2010
Final rooting, setting super-cid and installing recovery now...
This takes time. Please be patient!
--secu_flag off set
--cid set. CID will be changed to: 11111111
--sim_unlock. SIMLOCK will be removed
Section header entry size: 40
Number of section headers: 44
Total section header table size: 1760
Section header file offset: 0x000138b4 (80052)
Section index for section name string table: 41
String table offset: 0x000136fb (79611)
Searching for .modinfo section...
 - Section[16]: .modinfo
 -- offset: 0x00000a14 (2580)
 -- size: 0x000000cc (204)
Kernel release: 2.6.32.21-gf3f553d
New .modinfo section size: 204
Attempting to power cycle eMMC... OK.
Searching for mmc_blk_issue_rq symbol...
 - Address: c02a9e00, type: t, name: mmc_blk_issue_rq, module: N/A
Kernel map base: 0xc02a9000
Kernel memory mapped to 0x40000000
Searching for brq filter...
 - Address: 0xc02a9e00 + 0x34c
 - 0x2a000012 -> 0xea000012
Patching and backing up partition 7...
Error opening copy file.
Error opening copy file.
^^^^^^^^^^^^^^^^^^^^^^^^
I- NORMAL  ERROR HERE -I
* daemon not running. starting it now on port 5037 *
* daemon started successfully *
--secu_flag off set
--cid set. CID will be changed to: 11111111
--sim_unlock. SIMLOCK will be removed
Section header entry size: 40
Number of section headers: 44
Total section header table size: 1760
Section header file offset: 0x000138b4 (80052)
Section index for section name string table: 41
String table offset: 0x000136fb (79611)
Searching for .modinfo section...
 - Section[16]: .modinfo
 -- offset: 0x00000a14 (2580)
 -- size: 0x000000cc (204)
Kernel release: 2.6.32.21
New .modinfo section size: 196
Attempting to power cycle eMMC... OK.
Searching for mmc_blk_issue_rq symbol...
 - Address: c02db21c, type: t, name: mmc_blk_issue_rq, module: N/A
Kernel map base: 0xc02db000
Kernel memory mapped to 0x40009000
Searching for brq filter...
 - Address: 0xc02db21c + 0x34c
 - 0x2a000012 -> 0xea000012
Patching and backing up partition 7...
patching secu_flag: 0
Done.
rm: can't remove '/system/bin/su': No such file or directory
rm: can't remove '/system/xbin/su': No such file or directory
rm: can't remove '/system/bin/.ext/.su': No such file or directory
rm: can't remove '/system/app/Superuser.apk': No such file or directory
rm: can't remove '/system/app/Superuser.odex': No such file or directory
rm: can't remove '/system/app/SuperUser.apk': No such file or directory
rm: can't remove '/system/app/SuperUser.odex': No such file or directory
rm: can't remove '/system/app/superuser.apk': No such file or directory
rm: can't remove '/system/app/superuser.odex': No such file or directory
rm: can't remove '/system/app/Supersu.apk': No such file or directory
rm: can't remove '/system/app/Supersu.odex': No such file or directory
rm: can't remove '/system/app/SuperSU.apk': No such file or directory
rm: can't remove '/system/app/SuperSU.odex': No such file or directory
rm: can't remove '/system/app/supersu.apk': No such file or directory
rm: can't remove '/system/app/supersu.odex': No such file or directory
rm: can't remove '/data/dalvik-cache/*com.noshufou.android.su*': No such file or
 directory
rm: can't remove '/data/dalvik-cache/*Superuser.apk*': No such file or directory

rm: can't remove '/data/dalvik-cache/*SuperUser.apk*': No such file or directory

rm: can't remove '/data/dalvik-cache/*superuser.apk*': No such file or directory

rm: can't remove '/data/dalvik-cache/*eu.chainfire.supersu*': No such file or di
rectory
rm: can't remove '/data/dalvik-cache/*Supersu.apk*': No such file or directory
rm: can't remove '/data/dalvik-cache/*SuperSU.apk*': No such file or directory
rm: can't remove '/data/dalvik-cache/*supersu.apk*': No such file or directory
push: tools/afr/system/app/Superuser.apk -> /system/app/Superuser.apk
push: tools/afr/system/bin/.ext/.su -> /system/bin/.ext/.su
push: tools/afr/system/xbin/su -> /system/xbin/su
3 files pushed. 0 files skipped.
2932 KB/s (1976425 bytes in 0.658s)
dnsmasq               monkey                surfaceflinger
iftop                 printenv              wpa_supplicant

**********************************************
* Installed ROOT and custom touch recovery!  *
* Security flag and and Simlock are removed! *
**********************************************

Installing updated radio and custom ENG HBOOT...
Starting flash process...
< waiting for device >

The phone itself has a black screen with the white HTC logo showing. Can I disconnect the phone safely? What is my next step?
 

Phiber2000

Senior Member
May 23, 2010
243
129
It's okay. You can close the window and then disconnect it.
Continue with the steps in "How do I install after successfully rooting the latest ROM from HTC?" from OP.
Then you're finished.

Greetings
Phiber
 
  • Like
Reactions: bobman33

bobman33

New member
Feb 6, 2014
2
0
Thanks for the quick response!

I closed the window and disconnected the phone, and afterwards it was still on the HTC screen and wasn't responsive to the power button, so I pulled the battery. The phone has now started up and seems to be ok, I'll follow the instructions for the next steps now.

Thanks for your help and for the great software tool!
 

Phiber2000

Senior Member
May 23, 2010
243
129
As intended.
HTC driver seemed to have choked, so the last fastboot command wasn't executed. At this state it doesn't matter if you proceed as i described.
But you have to flash custom recovery by yourself afterwards. Easiest way is using Apps like GooManager (Menu -> “Install OpenRecoveryScript) or 4EXT Recovery Updater. Of course you can do that using Fastboot commands too.

Phiber
 

Top Liked Posts

  • There are no posts matching your filters.
  • 54
    ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    cooltext1119380987ptyls.png

    For HTCDEV unlocked devices :
    Unlocked devices via HTCdev need to be prepared via Option 'h' in main menu.
    This will do the downgrade too.
    As you know, the AAHK has expired and is no longer being developed by the author and there is no official support more!
    For this reason, there is now Phiber's 2000 AAHK2, which has already grown according to your wishes and will continue to grow.
    The original script was adapted, bugs were fixed, and unnecessary things were removed and slightly the HBOOT was modified.This should also work with Unlocked DHDs by HTCDEV.
    Code:
    #include
    /*
    * Your warranty is now void.
    *
    * I am not responsible for bricked devices, dead SD cards
    * YOU are choosing to make these modifications, and if  you point the finger at me for messing up your device, I will laugh at you.
    */

    The Requirements:
    -PC with Windows XP, Windows 7 or (Windows 8)
    -Charged battery at least 75%
    -Original HTC USB Cable
    -Make sure that the USB cable and the USB port of your phone and PC are in order (loose contact)
    -Use USB2.0 port on the back of a PC ( Don't use an USB 3.0 port or USB Hub )
    -If you use a laptop please charge the battery and use the Charger.
    - original ROM
    Original boot image ( this is not the HBOOT)
    original Recovery
    Formatted SD card (AFAT32 4KB sector size)from one of the following brands:
    Samsung
    SanDisk
    Patriot Memory
    ADATA

    CAUTION: If you use an incompatible SD card, the HBOOT will not working. Android also now no longer boots. This fix is expensive and risky!
    Among others the following brands lead to a soft-brick: Agfa, Hama, Trascend, No Name

    -Enable USB-DEBUGGING : Settings » Applications » Development » USB debugging
    -Connection Type "Charge Only": Settings » Connect to PC » Default connection type » Charge only
    -HBoot-Status: *** LOCKED *** or *** LOCKED (OOW) *** or *** RELOCKED *** , or without lock status displayed
    When the mode of the bootloader is "ENG S-OFF", the LOCK status does NOT play a role!




    Instructions:
    Install HTC Drivers v4.0.1.001
    Extrackt AAHK2
    Start The script with Administrator Rights (aahk2.cmd)
    In the main menu "1" and confirm.
    Follow the instructions on the PC strictly.
    If a downgrade was necessary, the procedure must be repeated. (If you dont know you have to downgrade or not, use the script it will tell you if you need it or not)
    Flash the current, (modified by Phiber2000) HTC image to prevent later problems with GPS/WiFi and sound (see FAQ).
    Optional: Finally, copy a Custom ROM on the SD card and flash in recovery.
    Downloads:

    HTC Driver v4.0.1.001(only if you had'nt installed already driver)
    AAHK2 v2.15 - Mirror
    HTC WWE 3.12.405.1 with ROOT - GPS FIX(Radio: 12.65.60.29/26.14.04.28 M) (HBoot-Image) - Mirror
    Required RUU images are requested by the script: (In original Thread are more mirrors)
    PD98IMG DOWNLOAD LINKS


    FAQ:

    How do I get into the HBOOT loader and which version do I have?
    -Disable Fast boot: Settings »Power» Fast boot
    -Switch off you phone
    -Hold "Volume Down" and "Power" button
    -Once the HBOOT loader appears, release the keys
    -In the upper part of green written is now available the relevant information:
    -0(evtl. rosarote Zeile)Lock-Status
    1 ACE PVT...HBoot-Loader Modus & Security Flag
    2 HBoot-...HBoot-Loader Version
    3 MICROP-...not relevant
    4 TOUCH PANEL-...not relevant
    5 RADIO-...RADIO-Image Version
    6 ...not relevant

    How do I get to FASTBOOT mode?
    -Start HBOOT loader (see above)
    - Navigate with the volume keys to "FASTBOOT"
    -Confirm by pressing the Power button


    Which CID I have ?
    -Start FASTBOOT mode (see above)
    -On the PC, open existing Android SDK in CMD
    -Type "fastboot getvar all"
    -In the line "INFOcidnum ..." is now your current CID. (8 digits)
    CAUTION: Apps like CID GETTER don't work properly. Because the App asks the Build.Prop and everybody could change the build.prop.


    How do I install after successfully rooting the latest ROM from HTC(modified by Phiber)? (This also fixes problems with GPS/Wifi/Soumd on custom ROMs!)
    -Unzip the "RUU_Ace_Sense30_S_HTC_WWE_3.12.405.1_Radio_12.65.6 0.29_26.14.04.28_M_release_225512_rooted.zip"
    -Copy the "PD98IMG.zip" as a single file on the SD card
    -Start HBOOT loader and wait few seconds
    -Confirm query with "Volume Up"
    -After successfully flashing confirm the query with "Power"
    -Remove the SD card
    -Let android boot
    -Insert SD card
    -Delete the "PD98IMG.zip" from the SD card


    Credits:


    Hyuh
    attn1
    shad0wf0x
    Anthony1s
    Revskills
    Genepoole
    Phiber2000




    Donation:
    PAYPAL LINK
    If you want to help Phiber2000 to continue his work please donate to him ! The support takes also much time on Android-Hilfe.de
    9
    What to do next?
    Read some FAQs and sticky Threads
    Update the Recovery
    Make a Nandroid/Backup
    Install a Custom Rom {DHD Development List: ROMs, Kernels, and More}
    3
    There's an option for preparing HTCdev unlocked devices in main menu.

    Phiber
    3
    See #105. After that you're debrandet too.

    Phiber
    3
    I was asked to test the free download links on this.

    I was begining to think it was true that there are actually no Free download slots. I tried many times over several minutes and every time it said no free download slots. BUT after some minutes of clicking the "return to download link" it did actually give me free slots for all the downloads.

    Not ideal, but it does seem possible to get a free download.

    Mike