Full HTC Desire HD (sense 3.0/android 2.3.5) guide to root, S-OFF/Sim Unlock

Search This thread

dejson

Senior Member
May 21, 2007
602
375
Sarajevo
I had a similar problem.

You shouldn't unloch with HTC DEV, because in AAHK it is all included, actually what I did is that I relocked the bootloader ( previosly unlocked with HTC DEV :), and I had the same HBOOT version 0,29 but AAHK did the job once I found the proper P98 img and did the downgrade and everything. It took me 2 or 3 hours to catch all necessary details.

If you still have a message adb server is out of date. killing... you should try to repair ADb with tool adbfix or similar and restart the PC or laptop.

There is a thread with PD98 original images for AAHK.

I would like to upload mine for which I know that it is working properly but I have a very bad upload speed at home.
 
Last edited:

hacktrix2006

Senior Member
Jan 15, 2011
1,681
567
Also before anyone continues make sure you run cat /proc/kmsg | grep 'mmc0:0001' If you have a M4G2DE EMMC stop do no use clockworkmod recovery or even try to root as you will fry your EMMC.

If you have SEM04G EMMC then your safe to continue.

If your using the PD98IMG.zip from the retired AAHK just remember its no longer support.

Personally i would use the firmware.zip file from the tutorial which is included in the http://tau.shadowchild.nl/files/ace-tools.zip its safer that way just remember to backup your boot.img as its important if you want to boot back into sense 3.0.

Trust me this tutorial works.
 

skiflyer

Senior Member
Jul 16, 2011
188
36
it does not, at least for me. i don't know exactly if i'm simlocked, but i hang on this step:

c:\ace-tools>adb shell dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img
/dev/block/mmcblk0p22: cannot open for read: Permission denied

but i know that my hd is rooted, and i was able to install the pre-rooted rom.

i come from stock hboot, and stock 3.12. firmware.


EDIT: first try, then post. it helped when i type in:

adb shell
su

and afterwards

dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img

EDIT2: had to do it always when it said "permission denied"

but at the last operation, i get this error:
/tmp/gfree -f
--secu_flag off set
--cid set. CID will be changed to: 11111111
--sim_unlock. SIMLOCK will be removed
Section header entry size: 40
Number of section headers: 44
Total section header table size: 1760
Section header file offset: 0x00015398 (86936)
Section index for section name string table: 41
String table offset: 0x000151df (86495)
Searching for .modinfo section...
- Section[16]: .modinfo
-- offset: 0x000011cc (4556)
-- size: 0x000000c4 (196)
Kernel release: 2.6.32.21
New .modinfo section size: 196
Attempting to power cycle eMMC... Failed. (Not fatal)
Module tried to power cycle eMMC, but could not verify write-protect status.
Searching for mmc_blk_issue_rq symbol...
- Address: c02db21c, type: t, name: mmc_blk_issue_rq, module: N/A
Kernel map base: 0xc02db000
Kernel memory mapped to 0x40002000
Searching for brq filter...
- Address: 0xc02db21c + 0x34c
- ***WARNING***: Found fuzzy match for brq filter, but conditional branch isn't
. (0xea000012)
Backing up current partition 7 and patching it...
Error reading input file.

EDIT3: i gave up this method and tried AAHK2 instead. (got it from a german forum, google aahk2 v 1.75) my mistake was that i had to relock the bootloader to downgrade from 3.12 to 2.x in order to get s-off.... :) now i'm finally on 2.5

EDIT4: the only difference to the screenshots in post #1 is that i'm on hboot v 0.85.2425... but s-off, yay
 
Last edited:
  • Like
Reactions: ckanish and Bielik

Steam.

Senior Member
Jun 7, 2012
1,070
255
Skopje
Is getting S-OFF doable from a custom ROM?I'm on MIUI now, unlocked BL and all, but no S-OFF.

Can I run gfree within MIUI?
 

Steam.

Senior Member
Jun 7, 2012
1,070
255
Skopje
well, i ran it, the last and only line i was able to read before the screen went off and rebooted, was attempting to power cycle, but after that i still had s-on.

C:\Documents and Settings\Damjan\Desktop\ADB-Tools>adb shell /t
--secu_flag off set
--cid set. CID will be changed to: 11111111
--sim_unlock. SIMLOCK will be removed
Section header entry size: 40
Number of section headers: 44
Total section header table size: 1760
Section header file offset: 0x00015398 (86936)
Section index for section name string table: 41
String table offset: 0x000151df (86495)
Searching for .modinfo section...
- Section[16]: .modinfo
-- offset: 0x000011cc (4556)
-- size: 0x000000c4 (196)
Kernel release: 2.6.35.14-cyanogenmod-g34e3a7a
New .modinfo section size: 216
Attempting to power cycle eMMC... Failed.
Module returned an unknown code (No such file or directory).
 
Last edited:

varpar

Senior Member
Aug 7, 2011
78
6
it does not, at least for me. i don't know exactly if i'm simlocked, but i hang on this step:

c:\ace-tools>adb shell dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img
/dev/block/mmcblk0p22: cannot open for read: Permission denied

but i know that my hd is rooted, and i was able to install the pre-rooted rom.

i come from stock hboot, and stock 3.12. firmware.


EDIT: first try, then post. it helped when i type in:

adb shell
su

and afterwards

dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img

EDIT2: had to do it always when it said "permission denied"

but at the last operation, i get this error:


EDIT3: i gave up this method and tried AAHK2 instead. (got it from a german forum, google aahk2 v 1.75) my mistake was that i had to relock the bootloader to downgrade from 3.12 to 2.x in order to get s-off.... :) now i'm finally on 2.5

EDIT4: the only difference to the screenshots in post #1 is that i'm on hboot v 0.85.2425... but s-off, yay

Could you please share aahk2 script or the link to download it?
 

crossmission

Senior Member
Feb 16, 2010
313
57
Swindon, UK
I think I did a bad thing, instead of "fastboot flash recovery" command I used "fastboot flash boot" as I got carried away from my one x days, just finished installing the recovery and the romm eventually but I haven't gotten to step 6 yet for fear of bricking, any help? thanks


update: it only boots into recovery now

update 2: I'm all good now, just followed the logical step to flash the posted boot.img and go on my way from there

It's nice to be on a HTC S-OFF device even this old :)
 
Last edited:
Awsome Job man it helped alot, however i need your assistance

so i was following your guide and everything was going ok once i got proper preperations ready, when i hit this bump and i have spent roughly about 3 hours figuring out how to get pass this. any help will be apreciated thank you

the bump is right before step 7 when there are those commands there i ahve been stuck.

• adb shell cat /sys/class/mmc_host/mmc2/mmc2:*/cid
take note of the string of numbers and letters that appear. (got the number written down)
then:
• adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local /tmp/goldcard.img (inserted the number and excuted the command) the it gives me this error that

pic.jpg

need help
 

siera_lion

Senior Member
Feb 5, 2012
131
26
so i was following your guide and everything was going ok once i got proper preperations ready, when i hit this bump and i have spent roughly about 3 hours figuring out how to get pass this. any help will be apreciated thank you

the bump is right before step 7 when there are those commands there i ahve been stuck.

• adb shell cat /sys/class/mmc_host/mmc2/mmc2:*/cid
take note of the string of numbers and letters that appear. (got the number written down)
then:
• adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local /tmp/goldcard.img (inserted the number and excuted the command) the it gives me this error that

View attachment 1907175

need help

I get exactly the same error
 

howasparty

Senior Member
Aug 23, 2009
208
38
so i was following your guide and everything was going ok once i got proper preperations ready, when ...


•adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local /tmp/goldcard.img (inserted the number and excuted the command) the it gives me this error that

View attachment 1907175

need help


Delete the space between local & tmp and hit thanks if it helps

________________________________
HTC Desire HD
Sabsa Prime 16
 

siera_lion

Senior Member
Feb 5, 2012
131
26
Delete the space between local & tmp and hit thanks if it helps

________________________________
HTC Desire HD
Sabsa Prime 16

Thank you, that actually helped out. But I get a second error for some reason

On step 8, I boot into recovery, and try out the first line "adb push gfree /tmp/" it gives me an error: Error: device is offline. What could be the problem?

EDIT: I was able to fix it. Unpluged my phone, rebooted recovery, reinstalled the htc drivers, pluged in the phone again and it was working. Now I am S - Off (Finally after all this time lol)
 
Last edited:

howasparty

Senior Member
Aug 23, 2009
208
38
Thank you, that actually helped out. But I get a second error for some reason

On step 8, I boot into recovery, and try out the first line "adb push gfree /tmp/" it gives me an error: Error: device is offline. What could be the problem?

EDIT: I was able to fix it. Unpluged my phone, rebooted recovery, reinstalled the htc drivers, pluged in the phone again and it was working. Now I am S - Off (Finally after all this time lol)

"after all this time" - really true! For me it was just 3 days ago that I managed it with this guide, after several other attempts.

Regards,
Mark
 

llmoose

Member
Nov 11, 2009
7
0
Hi Guys,

I am using my dads old HTC Desire HD and trying to put a custom rom on it and spent the day reading up trying to figure it all out. Thus far I have the bootloader screen (HBOOT) up but can't seem to get any further.

I am on HTC Sense 3.0 and Android 2.3.5.

I am getting to step 4 and when I type fastboot recovery1.img into the cmd prompt it just gives me the list of commands (I have attached a screencap of it)

I know I'm just doing something stupid wrong but any help would be great!
 

Attachments

  • waaaaa.jpg
    waaaaa.jpg
    43.5 KB · Views: 431

howasparty

Senior Member
Aug 23, 2009
208
38
Hi Guys,

...

I am getting to step 4 and when I type fastboot recovery1.img into the cmd prompt it just gives me the list of commands (I have attached a screencap of it)

I know I'm just doing something stupid wrong but any help would be great!

Well the command should be:
fastboot flash recovery <name of the recovery image >

________________________________
HTC Desire HD
Sabsa Prime 16
 
"C:\Users\Smoke\Desktop\Root Stuff\ace-tools>fastboot flash zip firmware.zip
sending 'zip' (18223 KB)... OKAY [ 2.999s]
writing 'zip'... INFOadopting the signature contained in this i
mage...
INFOsignature checking...
INFOzip header checking...
INFOzip info parsing...
INFOchecking model ID...
INFOchecking custom ID...
INFOchecking main version...
FAILED (remote: 43 main version check fail)
finished. total time: 15.412s"

Whats the connection between these two.


"C:\Users\Smoke\Desktop\Root Stuff\ace-tools>adb shell /tmp/gfree -f"
--secu_flag off set
--cid set. CID will be changed to: 11111111
--sim_unlock. SIMLOCK will be removed
Section header entry size: 40
Number of section headers: 44
Total section header table size: 1760
Section header file offset: 0x00015398 (86936)
Section index for section name string table: 41
String table offset: 0x000151df (86495)
Searching for .modinfo section...
- Section[16]: .modinfo
-- offset: 0x000011cc (4556)
-- size: 0x000000c4 (196)
Kernel release: 2.6.32.21
New .modinfo section size: 196
Attempting to power cycle eMMC... Failed.
Module failed to power cycle eMMC."

why is it not happening i get everything done but these two steps are the trouble. got my CID and does this affect aswell?

"C:\Users\Smoke\Desktop\Root Stuff\ace-tools>adb shell /data/local/tmp/misc_version
-s 1.11.111.1
--set_version set. VERSION will be changed to: 1.11.111.1
Misc partition is "/dev/block/mmcblk0p17"
Patching and backing up misc partition...
Error opening input file."

Need Help Fellas Kindly this one is giving issues. i already have bootloader unlocked and the rooted rom installed cwm is there too.... and when i enter >fastboot oem rebootRUU=====> it goes to screen with HTC logo but doesent show any other thing but the logo i think it suppose to show when the RUU is being updated

also i have the same bootloader on the OP pic but i dont have the same Radio.
My Radio is 26.14.04.28_M


any help is apreciated
thnx
 
Last edited:

howasparty

Senior Member
Aug 23, 2009
208
38
"C:\Users\Smoke\Desktop\Root Stuff\ace-tools>fastboot flash zip firmware.zip
sending 'zip' (18223 KB)... OKAY [ 2.999s]
....

why is it not happening i get everything done but these two steps are the trouble. go

also i have the same bootloader on the OP pic but i dont have the same Radio.
My Radio is 26.14.04.28_M


any help is apreciated
thnx

Try to follow there original guide http://tau.shadowchild.nl/attn1/?cat=6

You have to use the recovery in the ace tools or it won't work!


________________________________
HTC Desire HD
Sabsa Prime 16
 
  • Like
Reactions: Critical_DoubleShot

Top Liked Posts

  • There are no posts matching your filters.
  • 50
    Aahk2 is out please use that method instead, fully automated and much easier :) :

    http://xdaforums.com/showthread.php?t=2367322





    Warning thanks to hacktrix2006:
    Also before anyone continues make sure you run cat /proc/kmsg | grep 'mmc0:0001' If you have a M4G2DE EMMC stop do no use clockworkmod recovery or even try to root as you will fry your EMMC.

    If you have SEM04G EMMC then your safe to continue.

    If your using the PD98IMG.zip from the retired AAHK just remember its no longer support.

    Personally i would use the firmware.zip file from the tutorial which is included in the http://tau.shadowchild.nl/files/ace-tools.zip its safer that way just remember to backup your boot.img as its important if you want to boot back into sense 3.0.

    THIS GUIDE IS MAINLY this guide (http://tau.shadowchild.nl/attn1/?cat=6) SIMPLIFIED TO SOME EXTENT. with parts that werent included in the guide added to the guide and resources added to the ace-tools folder that would have to be downloaded separately.

    PREFACE:

    Download this and unzip it somewhere (reccommend C:\ root folder): http://www.multiupload.nl/MXW371YT87

    Full HTC Desire HD guide to root, S-OFF/Sim Unlock



    1.Unlock the bootloader at http://htcdev.com/bootloader/
    2.Copy your Unlock_code.bin file that you got in the email to the ace-tools folder.

    step 2.2: reboot into fastboot
    step 2.3: execute in cmd-prompt "fastboot flash unlocktoken Unlock_code.bin"

    3.Download rooted stock rom: http://www.multiupload.nl/20T9R21IGY
    (link to rom thread: http://xdaforums.com/showthread.php?t=1382235&highlight=rooted+stock )
    step 3.2 Make a effen GOLDCARD!!!
    3.3 copy the ROM zip file to your SD card.

    4.Install recovery image:
    Open cmd and type:
    •cd (eg cd C:\ace-tools)
    Ensure your phone is connected to your PC and then boot into bootloader, then navigate to fastboot.

    In cmd:
    •fastboot flash recovery recovery1.img

    5.boot into recovery through bootloader and Install the ROM you placed on the SD card, (via install zip fileselect the rom zip)
    6.Reboot the phone, ensure the rom is working fine and you have root access you can test this by turning on usb debugging then:
    •Adb shell
    •Su
    You should see the $ turn into a #. If this happens, congrats you have root access.
    Then type this:
    •Exit
    Then again:
    •Exit
    Then:
    •Adb push boot.img /data/local/tmp
    •adb shell
    root
    dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img
    •adb pull /data/local/tmp/boot.img
    •adb push goldcard /data/local/tmp
    •adb shell
    root
    chmod 775 /data/local/tmp/goldcard
    •adb shell
    root
    cat /sys/class/mmc_host/mmc2/mmc2:*/cid
    take note of the string of numbers and letters that appear.
    then:
    •adb shell /data/local/tmp/goldcard -c -o /data/local/tmp/goldcard.img

    •adb shell
    root
    dd if=/data/local/tmp/goldcard.img of=/dev/block/mmcblk1
    •adb push misc_version /data/local/tmp
    •adb shell chmod 775 /data/local/tmp/misc_version
    •adb shell /data/local/tmp/misc_version -s 1.11.111.1



    7.If this is all fine boot into bootloader again.
    From bootloader go to fastboot.
    Go back to the cmd window on your PC from earlier, type in:
    •Fastboot oem lock
    Then type:
    •fastboot oem rebootRUU
    •fastboot flash zip firmware.zip
    •fastboot reboot-bootloader
    unlock the bootloader again using the Unlock_code.bin you got from HTC:
    •fastboot flash unlocktoken Unlock_code.bin
    then flash boot.img in ace-tools folder:
    •fastboot flash boot boot.img
    next:
    •fastboot flash recovery recovery.img
    8.boot to recovery again then:
    •adb push gfree /tmp/
    •adb shell chmod 775 /tmp/gfree
    •adb shell /tmp/gfree -f
    reboot to bootloader and you should see it says S-OFF at the top of the screen, if It does congrats your done.

    VICTORY:
    abzdoXeu.jpg

    fr_494.jpg

    I have also posted this over at modaco:
    http://www.modaco.com/topic/361797-...-30android-235-guide-to-root-s-offsim-unlock/
    4
    Guide worked for me!!!!!

    Hi all, reporting back my experience with this guide...

    Prior to using this guide, I was already HTCDEV unlocked, rooted and custom rom (SVHD V1.3.0)

    I basically followed this guide with a few little needed changes.

    1st I backed up my rom using 4ext recovery.

    1. same
    2. same
    3. same

    4. There was no file named "recovery1.img" in ace-tools, so I just flashed the "recovery.img" (If you already have custom recovery flashed, I don't think you need to do this step but I did it anyway).

    5. Because I was already on custom rom with different kernel (boot.img) than stock (rooted) rom, before I reboot into recovery, I extracted boot.img from stock rooted zip downloaded from the link and flashed it from fastboot (if you don't do this your rom may not boot).

    5a. reboot into recovery and flashed rom

    6. there was a typo in the line
    "• adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local /tmp/goldcard.img"
    there is an extra space between local & /tmp/ at the end of line, the command line should read
    • adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local/tmp/goldcard.img"

    7. If this is all fine boot into bootloader again.
    From bootloader go to fastboot.
    Go back to the cmd window on your PC from earlier, type in:
    • Fastboot oem lock<------ phone rebooted itself after this command so needed to go back to bootloader fastboot (I did a quick battery pull)
    Then type:
    • fastboot oem rebootRUU

    everything else was good....

    My Hboot screen is the same as OP screen shot.

    I reflashed the 4ext recovery I previously had, then did a system restore of my backup and booted into SVHD with out a hitch.

    I pretty sure that's all, I hope this helps.

    I probably won't ever update this.

    THIS GUIDE IS MAINLY this guide (http://tau.shadowchild.nl/attn1/?cat=6) SIMPLIFIED TO SOME EXTENT. with parts that werent included in the guide added to the guide and resources added to the ace-tools folder that would have to be downloaded separately.

    PREFACE:

    Download this and unzip it somewhere (reccommend C:\ root folder): http://www.multiupload.nl/MXW371YT87

    Full HTC Desire HD guide to root, S-OFF/Sim Unlock



    1. Unlock the bootloader at http://htcdev.com/bootloader/
    2. Copy your Unlock_code.bin file that you got in the email to the ace-tools folder.

    3. Download rooted stock rom: http://www.multiupload.nl/20T9R21IGY
    (link to rom thread: http://xdaforums.com/showthread.php?t=1382235&highlight=rooted+stock )
    copy the ROM zip file to your SD card.

    4. Install recovery image:
    Open cmd and type:
    • cd <the directory of the ace-tools folder> (eg cd C:\ace-tools)
    Ensure your phone is connected to your PC and then boot into bootloader, then navigate to fastboot.

    In cmd:
    • fastboot recovery1.img
    5. boot into recovery through bootloader and Install the ROM you placed on the SD card, (via install zip fileselect the rom zip)
    6. Reboot the phone, ensure the rom is working fine and you have root access you can test this by turning on usb debugging then:
    • Adb shell
    • Su
    You should see the $ turn into a #. If this happens, congrats you have root access.
    Then type this:
    • Exit
    Then again:
    • Exit
    Then:
    • Adb push boot.img /data/local/tmp
    • adb shell dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img
    • adb pull /data/local/tmp/boot.img
    • adb push goldcard /data/local/tmp
    • adb shell chmod 775 /data/local/tmp/goldcard
    • adb shell cat /sys/class/mmc_host/mmc2/mmc2:*/cid
    take note of the string of numbers and letters that appear.
    then:
    • adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local /tmp/goldcard.img
    • adb shell dd if=/data/local/tmp/goldcard.img of=/dev/block/mmcblk1
    • adb push misc_version /data/local/tmp
    • adb shell chmod 775 /data/local/tmp/misc_version
    • adb shell /data/local/tmp/misc_version -s 1.11.111.1



    7. If this is all fine boot into bootloader again.
    From bootloader go to fastboot.
    Go back to the cmd window on your PC from earlier, type in:
    • Fastboot oem lock
    Then type:
    • fastboot oem rebootRUU
    • fastboot flash zip firmware.zip
    • fastboot reboot-bootloader
    unlock the bootloader again using the Unlock_code.bin you got from HTC:
    • fastboot flash unlocktoken Unlock_code.bin
    then flash boot.img in ace-tools folder:
    • fastboot flash boot boot.img
    next:
    • fastboot flash recovery recovery.img
    8. boot to recovery again then:
    • adb push gfree /tmp/
    • adb shell chmod 775 /tmp/gfree
    • adb shell /tmp/gfree -f
    reboot to bootloader and you should see it says S-OFF at the top of the screen, if It does congrats your done.

    VICTORY:
    abzdoXeu.jpg

    View attachment 1858622

    I have also posted this over at modaco:
    http://www.modaco.com/topic/361797-...-30android-235-guide-to-root-s-offsim-unlock/

    help me out if you feel like it :) by signing up to dropbox with my refferal link:
    Always have your stuff when you need it with @Dropbox. Sign up for free! http://db.tt/G8qfL77X
    3
    Also before anyone continues make sure you run cat /proc/kmsg | grep 'mmc0:0001' If you have a M4G2DE EMMC stop do no use clockworkmod recovery or even try to root as you will fry your EMMC.

    If you have SEM04G EMMC then your safe to continue.

    If your using the PD98IMG.zip from the retired AAHK just remember its no longer support.

    Personally i would use the firmware.zip file from the tutorial which is included in the http://tau.shadowchild.nl/files/ace-tools.zip its safer that way just remember to backup your boot.img as its important if you want to boot back into sense 3.0.

    Trust me this tutorial works.
    2
    it does not, at least for me. i don't know exactly if i'm simlocked, but i hang on this step:

    c:\ace-tools>adb shell dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img
    /dev/block/mmcblk0p22: cannot open for read: Permission denied

    but i know that my hd is rooted, and i was able to install the pre-rooted rom.

    i come from stock hboot, and stock 3.12. firmware.


    EDIT: first try, then post. it helped when i type in:

    adb shell
    su

    and afterwards

    dd if=/dev/block/mmcblk0p22 of=/data/local/tmp/boot.img

    EDIT2: had to do it always when it said "permission denied"

    but at the last operation, i get this error:
    /tmp/gfree -f
    --secu_flag off set
    --cid set. CID will be changed to: 11111111
    --sim_unlock. SIMLOCK will be removed
    Section header entry size: 40
    Number of section headers: 44
    Total section header table size: 1760
    Section header file offset: 0x00015398 (86936)
    Section index for section name string table: 41
    String table offset: 0x000151df (86495)
    Searching for .modinfo section...
    - Section[16]: .modinfo
    -- offset: 0x000011cc (4556)
    -- size: 0x000000c4 (196)
    Kernel release: 2.6.32.21
    New .modinfo section size: 196
    Attempting to power cycle eMMC... Failed. (Not fatal)
    Module tried to power cycle eMMC, but could not verify write-protect status.
    Searching for mmc_blk_issue_rq symbol...
    - Address: c02db21c, type: t, name: mmc_blk_issue_rq, module: N/A
    Kernel map base: 0xc02db000
    Kernel memory mapped to 0x40002000
    Searching for brq filter...
    - Address: 0xc02db21c + 0x34c
    - ***WARNING***: Found fuzzy match for brq filter, but conditional branch isn't
    . (0xea000012)
    Backing up current partition 7 and patching it...
    Error reading input file.

    EDIT3: i gave up this method and tried AAHK2 instead. (got it from a german forum, google aahk2 v 1.75) my mistake was that i had to relock the bootloader to downgrade from 3.12 to 2.x in order to get s-off.... :) now i'm finally on 2.5

    EDIT4: the only difference to the screenshots in post #1 is that i'm on hboot v 0.85.2425... but s-off, yay
    2
    Hi all, reporting back my experience with this guide...

    Prior to using this guide, I was already HTCDEV unlocked, rooted and custom rom (SVHD V1.3.0)

    I basically followed this guide with a few little needed changes.

    1st I backed up my rom using 4ext recovery.

    1. same
    2. same
    3. same

    4. There was no file named "recovery1.img" in ace-tools, so I just flashed the "recovery.img" (If you already have custom recovery flashed, I don't think you need to do this step but I did it anyway).

    5. Because I was already on custom rom with different kernel (boot.img) than stock (rooted) rom, before I reboot into recovery, I extracted boot.img from stock rooted zip downloaded from the link and flashed it from fastboot (if you don't do this your rom may not boot).

    5a. reboot into recovery and flashed rom

    6. there was a typo in the line
    "•adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local /tmp/goldcard.img"
    there is an extra space between local & /tmp/ at the end of line, the command line should read
    •adb shell /data/local/tmp/goldcard -c <string of numbers and letters should go here> -o /data/local/tmp/goldcard.img"

    7.If this is all fine boot into bootloader again.
    From bootloader go to fastboot.
    Go back to the cmd window on your PC from earlier, type in:
    •Fastboot oem lock<------ phone rebooted itself after this command so needed to go back to bootloader fastboot (I did a quick battery pull)
    Then type:
    •fastboot oem rebootRUU

    everything else was good....

    My Hboot screen is the same as OP screen shot.

    I reflashed the 4ext recovery I previously had, then did a system restore of my backup and booted into SVHD with out a hitch.

    I pretty sure that's all, I hope this helps.

    Thanks, ill update first post again.