Finally... unbrick your Lumia device QHSUSB_DLOAD without JTAG

parker_lewis

New member
Jul 10, 2008
1
0
0
Boys... this is my first post in years (my last one was probably about a HTC Diamond Touch... yes, that long).

My Lumia 920 was completely dead. With trogper's method, it's now running again. Tony the tiger says: GGGRRREEEAT!

Thank you!
 

DilanChd

Inactive Recognized Contributor
Jun 12, 2012
2,373
1,632
0
Paris
As my PCs refused to detect my Lumia 620 in emergency mode (detected as Nokia Flash, even with the good driver), I succeeded unbrick my Lumia device (red screen Nokia UEFI). I just use the UEFI mode by entering this command:

Code:
thor2 -mode uefiflash -ffufile ffu.ffu
 

djamol

Senior Member
Jun 3, 2014
444
405
0
29
Pune
www.twitter.com
As my PCs refused to detect my Lumia 620 in emergency mode (detected as Nokia Flash, even with the good driver), I succeeded unbrick my Lumia device (red screen Nokia UEFI). I just use the UEFI mode by entering this command:

Code:
thor2 -mode uefiflash -ffufile ffu.ffu
You are right, But it is not complete step. You need to sign everything as does .vpl programming.
All recovery/flashing tool uses .vpl flashing.
1. Direct write .FFU will work as MSFT.
2. Writing with .Vpl file will work as OEM.
It is all same thing, but try to understand between two diff things.

Some security will get tight or can vulnerable. (Actual I mean, OS will run with more differential)

---------- Post added at 03:43 AM ---------- Previous post was at 03:34 AM ----------

How to get device authentication ?
When i flashed my modified ROM or restoring any other partition. It always say's me to "Required Device Authentication" or "Write RDC or /open rw & sw"
anyone can help me ?
 
  • Like
Reactions: K3VYNC and DilanChd

djamol

Senior Member
Jun 3, 2014
444
405
0
29
Pune
www.twitter.com
Ok, thanks.
He flash all files, without exception, indicated in the VPL file or not?
Does the sim-(un)lock is done by NWP8_simlock_xxxxx.bin file? If yes, and if the VPL flash all files, we can, for example, sim-unlock the devices by this way?
I don't know about the sim lock/unlock, or how they work.
But I've noticed that some hack are not working if i dir. flashed image with ffutool.
For Example:
My "Root Tool" app hack doesn't work if i flash in that way. (and some another programs)

But After .vpl flashing works fine without any prob. (so that's the difference)
_____________________________________________________________________________________
Do you know any way to get device authentication to restore "MainOS" partition or restore "EFIESP" partition ?
 

Habith

Member
Jul 12, 2013
19
1
0

Habith

Member
Jul 12, 2013
19
1
0
Thank you, really.

But, not working for me :( ... I tried everything and nothing... May be my phone is really dead.


This is my log

Code:
C:\Program Files (x86)\Microsoft Care Suite\Windows Phone Recovery Tool>thor2 -m
ode emergency -hexfile "C:\Lumia\HEX.hex" -mbnfile "C:\Lumia\msimage.mbn" -orig_
gpt
THOR2 1.8.2.15
Built for Windows @ 13:33:08 Mar 11 2015
Thor2 is running on Windows of version 6.1
thor2 -mode emergency -hexfile C:\Lumia\HEX.hex -mbnfile C:\Lumia\msimage.mbn -o
rig_gpt
Process started Thu May 14 08:01:58 2015
Logging to file C:\Users\MAXEEL~1\AppData\Local\Temp\thor2_win_20150514080158_Th
readId-3120.log
Debugging enabled for emergency

Initiating emergency download
Using default emergency protocol
ALPHA EMERGENCY FLASH START
Emergency Programmer V1 version 2014.10.31.001
Hex download selected
Check if device in Dload
Connection to DLOAD mode succeeded
Get Dload parameters
Sending HEX flasher to the device
Sending GO command if HEX flasher successfully uploaded.
Emergency Programmer V1 version 2014.10.31.001
Mbn download selected
Waiting for connection to flash programmer
Connecting to flash programmer
Received valid HELLO_RSP
Safe version=true, transfer size=15360
Received valid SECURITY_RSP
Successfully connected to flash programmer
Connection to flash programmer succeeded
Uploading bootloader(s), UEFI, etc from MBN image to the eMMC. This will take up
to 20 seconds
Reading GPT from binary
-- GPT STARTs--
name: DPP
startLBA: 4096
endLBA: 20479
size: 0x0000000000800000 bytes
attributes: 0x0


name: MODEM_FSG
startLBA: 20480
endLBA: 26623
size: 0x0000000000300000 bytes
attributes: 0x0


name: SSD
startLBA: 28672
endLBA: 28703
size: 0x0000000000004000 bytes
attributes: 0x0


name: SBL1
startLBA: 32768
endLBA: 35767
size: 0x0000000000177000 bytes
attributes: 0x0


name: SBL2
startLBA: 36864
endLBA: 39863
size: 0x0000000000177000 bytes
attributes: 0x0


name: SBL3
startLBA: 40960
endLBA: 45055
size: 0x0000000000200000 bytes
attributes: 0x0


name: UEFI
startLBA: 45056
endLBA: 50055
size: 0x0000000000271000 bytes
attributes: 0x0


name: RPM
startLBA: 53248
endLBA: 54247
size: 0x000000000007d000 bytes
attributes: 0x0


name: TZ
startLBA: 57344
endLBA: 58343
size: 0x000000000007d000 bytes
attributes: 0x0


name: WINSECAPP
startLBA: 61440
endLBA: 62463
size: 0x0000000000080000 bytes
attributes: 0x0


name: BACKUP_SBL1
startLBA: 65536
endLBA: 68535
size: 0x0000000000177000 bytes
attributes: 0x0


name: BACKUP_SBL2
startLBA: 69632
endLBA: 72631
size: 0x0000000000177000 bytes
attributes: 0x0


name: BACKUP_SBL3
startLBA: 73728
endLBA: 77823
size: 0x0000000000200000 bytes
attributes: 0x0


name: BACKUP_UEFI
startLBA: 77824
endLBA: 82823
size: 0x0000000000271000 bytes
attributes: 0x0


name: BACKUP_RPM
startLBA: 86016
endLBA: 87015
size: 0x000000000007d000 bytes
attributes: 0x0


name: BACKUP_TZ
startLBA: 90112
endLBA: 91111
size: 0x000000000007d000 bytes
attributes: 0x0


name: BACKUP_WINSECAPP
startLBA: 94208
endLBA: 95231
size: 0x0000000000080000 bytes
attributes: 0x0


name: UEFI_BS_NV
startLBA: 98304
endLBA: 98815
size: 0x0000000000040000 bytes
attributes: 0x0


name: UEFI_NV
startLBA: 102400
endLBA: 102911
size: 0x0000000000040000 bytes
attributes: 0x0


name: PLAT
startLBA: 106496
endLBA: 122879
size: 0x0000000000800000 bytes
attributes: 0x0


name: EFIESP
startLBA: 131072
endLBA: 262143
size: 0x0000000004000000 bytes
attributes: 0x0


name: MODEM_FS1
startLBA: 262144
endLBA: 268287
size: 0x0000000000300000 bytes
attributes: 0x0


name: MODEM_FS2
startLBA: 270336
endLBA: 276479
size: 0x0000000000300000 bytes
attributes: 0x0


name: UEFI_RT_NV
startLBA: 278528
endLBA: 279039
size: 0x0000000000040000 bytes
attributes: 0x0


name: UEFI_RT_NV_RPMB
startLBA: 282624
endLBA: 282879
size: 0x0000000000020000 bytes
attributes: 0x0


-- GPT ENDs --

























Sending OPEN_MULTI_REQ
Message send failed with error code -1
Failed to get response to OPEN_MULTI_REQ
ALPHA EMERGENCY FLASH END
Emergency messaging closed successfully
Operation took about 14.00 seconds.

THOR2_EMERGENCYFLASHV1_ERROR_MSG_SEND_RECEIVE_FAILED

THOR2 1.8.2.15 exited with error code 85021 (0x14C1D)
 

knightluffy

Senior Member
Aug 30, 2012
56
7
0
Hi, many thanks for your article, but I don't understand where is the F771E62AF89994064F77CD3BC16829503BDF9A3D506D3FACEC AEF3F808C868FD & F771E62AF89994064F77CD3BC16829503BDF9A3D.bin comes from?
 

andikicker

Member
Feb 24, 2012
34
42
0
Hey

i search the hex file for my LUMIA 1520 RM-937

thanks!

Code:
Number of partitions found 28
RKH of SBL1: 3774964A7E6AC7EF7D428DDC0C0EAD71640B0D8DD3BFC3829110AF2D8ED68D7C
RKH of UEFI: 3774964A7E6AC7EF7D428DDC0C0EAD71640B0D8DD3BFC3829110AF2D8ED68D7C
 
Our Apps
Get our official app!
The best way to access XDA on your phone
Nav Gestures
Add swipe gestures to any Android
One Handed Mode
Eases uses one hand with your phone