• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Root root,s-off,simunlock,superCID htc merge

other than making some phone calls to various carriers and asking if the MEID/ESN are activatable,im not real sure.if the phone has not been modified yet,you could find the CID,wich would give a pretty strong clue.

first download and install these drivers: revolutionary drivers

then,download this small file:
mini-adb.zip

-unzip it,and place the unzipped folder onto the root of your C drive(not inside a folder)

-open a cmd window(with win 7,click start bubble,type "command" or "cmd" in hte search box)

-now change to your mini-adb directory(assuming you didnt chagne the name). type in the black cmd window that opened on your PC:
cd c:\mini-adb

-pull the battery in your phone for a few seconds. hold volume down,then power. hold them both until you see the white/colored writing hboot screen

-select "fastboot" from the hboot menu with the vol rocker/power button

-in your cmd window type:
fastboot devices

it should output your phones serial number. if so youre good to go. if not,youre apparently having a driver issue. i usually recomend these drivers from Revolutionary: modified htc drivers download and install the drivers(you should just have to run that file). afterwards,unplug your phone,plug it back in. make sure its in fastboot. as soon as you get a result from "fastboot devices" your ready to procede to the next step.

-in your cmd window,type(or copy/paste,is much easier):
fastboot getvar all

-copy the info that outputs here. right click in your cmd window,click mark,highlight it all in white. hit enter. paste the info here. :)
 
By any chance could someone link me to that froyo chinese test ruu?

I'm interested in the build.prop and ril libs of that rom.
 
By any chance could someone link me to that froyo chinese test ruu?

I'm interested in the build.prop and ril libs of that rom.

you can find it in footballs folder: FileFactory Folder View - Lexikon

again,for those reading this,dont flash it! we dont know why its killed a couple of phones.

jianC,feel free to pm me if you find anything interesting in this rom,or have any theories. also if you have trouble downloading the ruu,i do have it saved so i can upload it somewhere if you need it
 
Awsome! I'll give it a flash later on today.

Lotsa folks will be thrilled with this news- might consider giving it its own thread :cool:
 
Great rooting guide - many thanks! Worked flawlessly on my wife's Verizon Merge.

Anyone know where I could find one or more of the 2fastroms Merge ROMs now that the 2fastroms site is down?
 
Hi Scotty85,

Please help me. I've bought HTC merge that had some chinese firmware installed. It was unlocked for all cdma & gsm. I wanted to S-off & root it. Hence I downloaded above files & followed ur instructions.

Initially I placed renamed & placed "PD42IMG-vzw-leak.zip" but got stuck at :
# dd if=/dev/block/mmcblk0p17 of=/sdcard/misc-stock.img bs=4096
I got error : Access Denied.

Then I replaced the zip file with "PD42IMG_customGBupgrade" & renamed it as "PD42IMG.zip", rebooted & updated.

This time I proceeded much further. But now I got stuck at:
$ /data/local/psneuter
Failed to set prot mask (Inappropriate ioctl for device)


Please help me to S-Off, root, & unlock it. I've downloaded all necessary files (I guess)

Thanks
 
I would pretty strongly recomend that you do not mess with the Chinese firmware. I know of a couple phones that have been bricked trying to change from it,back to US firmware. We just do not know enuff about it to do it safely. If you flash the downgrade vzw firmware,it may leave you with an unusable(i.e. hard bricked and unrecoverable) phone.

Having said that,your first error may have been lack of an sd card(not present or mounted to the pc.as a disk drive).

Your second error is because you are not on the downgrade vzw firmware,so the psneuter exploit does not work. Neither of these errors have anything to do with the particular PD42IMG file you have on your sd card.

Where did you get this phone running Chinese firmware,and what is the info on its hboot screen?
 
Great rooting guide - many thanks! Worked flawlessly on my wife's Verizon Merge.

Anyone know where I could find one or more of the 2fastroms Merge ROMs now that the 2fastroms site is down?

liamf1 has a thread in the forum here,for cm7,and also has started a website with a merge section: Merge (Lexikon)

other than that,you might try rootzwiki: Merge - RootzWiki

i dont really know other than that,except keep trying back at 2fast. its disapeared and reapeared before,so maybe it will pop back up again.

also sorry for the delayed response,i saw this in an email,and apparently forgot to come here and actually comment on it :o
 
I would pretty strongly recomend that you do not mess with the Chinese firmware. I know of a couple phones that have been bricked trying to change from it,back to US firmware. We just do not know enuff about it to do it safely. If you flash the downgrade vzw firmware,it may leave you with an unusable(i.e. hard bricked and unrecoverable) phone.

Having said that,your first error may have been lack of an sd card(not present or mounted to the pc.as a disk drive).

Your second error is because you are not on the downgrade vzw firmware,so the psneuter exploit does not work. Neither of these errors have anything to do with the particular PD42IMG file you have on your sd card.

Where did you get this phone running Chinese firmware,and what is the info on its hboot screen?

In fact, I've already messed with it:D. When I booted using "PD42IMG-vzw-leak.zip" my phone showed "Verizon" splash. In that mode I checked & was able to get calls but I couldn't call (I am in India).

Then When I booted using "PD42IMG_customGBupgrade.zip" my phone showed "US Cellular" splash. Now its working fine (donno how) I get calls, I can make calls. Everything is perfect! All cards (carriers) cdma & gsm networks work fine.

I bought it on ebay, initially when I bought it did not show any particular splash screen except htc. But in menu there were many chinese apps installed.

My hboot screen shows this:

LEXIKON XB SHIP S-OFF
HBOOT-0.88.0000
RADIO-1.08.00.0804
eMMC-boot
Dec 2 2010, 16:07:41

Some more info if needed:

--Network--
Operator name: Bluegrass (where as I think it should be Tata-CDMA, thats what I am using)
Service State: In service
Roaming: Not roaming

--Phone Identity--
Model number: USCCADR6325US

--Software info --
Android version: 2.3.4

HTC Sense ver: 2.1

Software number: 3.10.573.1

Kernel version: 2.6.35.10-gd6999855 htc-kernel@and18-2#1
Fri Jul 22 04:25:17 CST 2011

Build number: 3.10.573.1 CL141744 release-keys
-------------

I guess now the chinese firmware has gone off from my mobile & now it has become US Cellular specific, since I already mentioned that splash shows 'US Cellular' & (God knows how) it is working perfect fine on all n/w. I successfully tested it on GSM Virgin & currently using successfully on Tata-cdma.

I know this is a lot of info, but I just wanted to make it clear.

Now can you please guide me to S-off, root, & unlock it (I guess its already unlocked as I can use any sim)

Thanks!
 
Now can you please guide me to S-off, root, & unlock it (I guess its already unlocked as I can use any sim)

Thanks!
someone has beat you to the punch(or you got a rare one that came that way):

My hboot screen shows this:

LEXIKON XB SHIP S-OFF <--you are s off
HBOOT-0.88.0000
RADIO-1.08.00.0804
eMMC-boot
Dec 2 2010, 16:07:41

you are allready are s off. you are likely allready superCIDed as well,as you wouldnt have been able to install the vzw leak and custom BG upgrade otherwise. in short- you have no use for this guide ;)

In fact, I've already messed with it. When I booted using "PD42IMG-vzw-leak.zip" my phone showed "Verizon" splash. In that mode I checked & was able to get calls but I couldn't call (I am in India).

Then When I booted using "PD42IMG_customGBupgrade.zip" my phone showed "US Cellular" splash. Now its working fine (donno how) I get calls, I can make calls. Everything is perfect! All cards (carriers) cdma & gsm networks work fine.

im glad this had a good outcome for you. likely it worked since you used the full,signed vzw leak. if you had used the custom upgrade first,it may not have worked this way. i personally have flashed the "confidential" chinese firmware,and then run a .exe ruu to get back. i personally killed that same merge flashing an unsigned hboot trying to get a recovery installed. there haVE been other cases where folks tried to flash a custom(unsigned) ruu and ended up with a dead phone. as i said,we just dont know much about what hooks the firmware has.

to further compicate things there are XB,XC,and i believe CT merges:
LEXIKON XB SHIP S-OFF
HBOOT-0.88.0000
RADIO-1.08.00.0804
eMMC-boot
Dec 2 2010, 16:07:41
and we have no idea how that changes things,either. this is a neat little phone,but unfortunately they were never real popular in the root comunity.

so lets review:
-you are allready s-off.
-you can flash any ruu that you wish,so you likely are superCID as well.
-you are allready sim unlocked.
-if you are allready on a custom upgrade ruu you should have a custom recovery,you just need to flash root files if thats not a pre-rooted ruu.

if youre not on the software you want to run,you just need to run the ruu that you choose,if its a factory ruu you can install amon recovery as a PD42IMG,then flash root files.

alternately,you can try flashing some custom roms(if you can find some)

one last bit of advice,you are no longer on the chinese test rom,and id recomend not going back to it :eek:

what were your goals for becoming s off? you can achieve them now :)
 
Hi Scotty85,

Its good to here that my cell is already S-off & unlocked, however; I don't think its rooted. I think one of the best way to check if the mobile is root is to type 'su' & check the response. Well when I tried this I got "Access denied" error

I also tried to check with one of the app "check root" The result was same, even that app said that busybox has not been installed.

What does this mean? I guess still my mobile is not rooted?
 
no,you are still not rooted. as i said above,you can install amon recovery as a PD42IMG file if you havent run a custom upgrade ruu(if you have,then you have a recovery allready)

once you have recovery,its a simple matter if flashing root files. you can flash the eng merge toolkit linked in the first page,but some folks have had prollems with it on GB.

you may want to forgo the toolkit,and just flash "superSU" from this thread:
http://forum.xda-developers.com/showthread.php?t=1538053

you must flash the zipfile from recovery. you cant simply install it from the market,wich is a common error after reading that post. the download link you want is about halfway down the page and labled UPDATE-SuperSU-v1.25.zip

i dont want to put up a direct link,as when he updates it the link breaks,leaving folks looking for it in the future out of luck.

so to recap:
-check if you have amon recovery installed. if not download and install it as a PD42IMG file in hboot
-download supersu
-flash supersu in amon recovery

you will be rooted :)
 
Hi,

I got HTC Merge about a year or more ago (US Cellular). I'm using it in Europe (GSM). After changing couple of SIM cards from different carriers the phone started to restart while SIM card is inserted. It operates normally when there is no SIM card present. I was a bit disappointed and went on and bought another phone since HTC service in Europe refused to take in into the shop it since it's US model.

Alternately missing the hardware keyboard and all i order a replacement SIM/SD Card reader part from ebay (thinking it's a parts fault). Unfortunate it wasn't. The same thing happens with the new part. Could this be a software issue?

In the recovery it says:

*** LOCKED (00W) ***
LEXIKON PVT SHIP S-ON
HBOOT-0.089.0000
RADIO-1.08.00.0106

Is there anyone willing to help / suggest what to do? I would like to use the phone only in GSM networks so any solution giving me GSM is fine with me :)

Sorry for the possible off topic. Don't know what do anymore :(
 
are you still using the us cellular rom? have you checked the mobile networks settigns and made sure youre on a gsm or global setting?

if there is not a menu setting,you can try getting to phone info from the dialer by dialing *#*#4636#*#* try switching to wcdma,or gsm only depending on what your carrier uses
 
are you still using the us cellular rom? have you checked the mobile networks settigns and made sure youre on a gsm or global setting?

if there is not a menu setting,you can try getting to phone info from the dialer by dialing *#*#4636#*#* try switching to wcdma,or gsm only depending on what your carrier uses

I'm still on US Cellular stock ROM 3.20 / Android 2.3.4.

*#*#4636#*#* to GSM only does the trick. The phone doesn't restart but new issue emerges. Mobile internet stuck in EDGE mode. No UMTS or HSDPA/HSUPA (which is available)

*#*#4636#*#* to any other option and the random restarting (within minutes from power on) is back again :(

This is a huge improvement but EDGE is annoying as hell. Any thoughts?

Can anyone try switching to GSM only to check out is this a case or it's just my phone?

Thanks!
 
sorry,i just realized you had edited your post above and it was different than the last time id seen it :o glad switching to gsm only did the trick,but as for data im not really sure what we may need to do there. do you know what bands your carrier is using?

the specs are here: HTC Merge - Full phone specifications

if your carrier is sending out 3g/hspa+ on those bands,it may need some changes in the rom somehow,since its designed to be used on a cdma network and only "roam" overseas while a us cellular customer is on vacation... i honestly have no idea where me may need to look or make changes.

i can try swapping my settings around later and see if anything casues reboots. i use it on us t mobile,so all i get on it is edge data,no matter what,unfortunately.

thanks for the link,im sure it will come in handy :)
 
do you know what bands your carrier is using?

900mHz GSM and UMTS (W-CDMA obviously) ... LTE is only in test phase but Merge doesn't support it anyway.

The phone did work fine when i got it from US for about 6 month.

When i did some traveling in the region i did swap a number of prepaid SIM cards. My guess is that maybe somehow something got partially locked.

So when the GSM part starts the phone is ok but when it tries to establish W-CDMA data connection it restarts because of unexpected exception.

The phone was bought from ebay as brand new with clean ESN if this means anything.
 
Have you tried a factory reset?

Are you s off /supercid? You might try one of the other ruus.possibly even just rerun the USC ruu.

If its a software issue that's changed after you recieved the phone,a combination of ruu and factory reset with the stock recovery still in place may do the trick
 
I did try the factory reset and have tried US Celluar RUU from Shipped ROMs

Are you suggesting i use other carrier RUU?

I'm not s-off/supercid so i assume i must be supercid first. Will try this later today and let you know.
 
*** UNLOCKED***
LEXIKON PVT SHIP S-ON
HBOOT-0.89.0000
RADIO-1.08.0106
eMMC-boot
DEC 21 2011,05:29:44

hi , im trying to s off my htc merge but for some reason i just cannot do it
every time i tried zergRush i get this

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\adalidh>cd c:\miniadb_merge

C:\miniadb_merge>adb devices
adb server is out of date. killing...
* daemon started successfully *
List of devices attached
HT17VM800243 device


C:\miniadb_merge>adb push zergRush /data/local/
720 KB/s (0 bytes in 23060.000s)

C:\miniadb_merge>adb shell
$ chmod 755 /data/local/zergRush
chmod 755 /data/local/zergRush
$ /data/local/zergRush
/data/local/zergRush

[**] Zerg rush - Android 2.2/2.3 local root
[**] (C) 2011 Revolutionary. All rights reserved.

[**] Parts of code from Gingerbreak, (C) 2010-2011 The Android Exploid Crew.

[+] Found a GingerBread ! 0x00000118
[*] Scooting ...
[*] Sending 149 zerglings ...
[*] Sending 189 zerglings ...
[-] Hellions with BLUE flames !
$

wich by reading thru the whole post i foun that Hellions with BLUE flames ! means zergRush was not push

then i tried this

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\adalidh>cd c:\miniadb_merge

C:\miniadb_merge>adb devices
List of devices attached
HT17VM800243 device


C:\miniadb_merge>adb push psneuter /data/local/
1664 KB/s (0 bytes in 585731.000s)

C:\miniadb_merge>adb push busybox /data/local/
1703 KB/s (0 bytes in 1062992.000s)

C:\miniadb_merge>adb push wpthis /data/local/
1516 KB/s (0 bytes in 679475.000s)

C:\miniadb_merge>adb push gfree /data/local/
1658 KB/s (0 bytes in 716548.000s)

C:\miniadb_merge>adb shell
$ chmod 0755 /data/local/psneuter
chmod 0755 /data/local/psneuter
$ chmod 0755 /data/local/wpthis
chmod 0755 /data/local/wpthis
$ chmod 0755 /data/local/gfree
chmod 0755 /data/local/gfree
$ /data/local/psneuter
/data/local/psneuter
Failed to set prot mask (Inappropriate ioctl for device)
$ /data/local/wpthis
/data/local/wpthis
Build: 25
Section header entry size: 40
Number of section headers: 45
Total section header table size: 1800
Section header file offset: 0x00014e90 (85648)
Section index for section name string table: 42
String table offset: 0x00014cc7 (85191)
Searching for .modinfo section...
- Section[16]: .modinfo
-- offset: 0x00000f80 (3968)
-- size: 0x000000c4 (196)
Kernel release: 2.6.35.10-gcdc8ad4
New .modinfo section size: 204
Loading module... Failed.
Module returned an unknown code (Operation not permitted).
$ /data/local/gfree -f
/data/local/gfree -f
--secu_flag off set
--cid set. CID will be changed to: 11111111
--sim_unlock. SIMLOCK will be removed
Section header entry size: 40
Number of section headers: 44
Total section header table size: 1760
Section header file offset: 0x000138b4 (80052)
Section index for section name string table: 41
String table offset: 0x000136fb (79611)
Searching for .modinfo section...
- Section[16]: .modinfo
-- offset: 0x00000a14 (2580)
-- size: 0x000000cc (204)
Kernel release: 2.6.35.10-gcdc8ad4
New .modinfo section size: 204
Attempting to power cycle eMMC... Failed.
Module returned an unknown code (Operation not permitted).
$ exit

after this i try fre3vo

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\adalidh>cd c:\miniadb_merge

C:\miniadb_merge>adb devices
List of devices attached
HT17VM800243 device
c:\tbolt2>adb push fre3vo /data/local/tmp
956 KB/s (9796 bytes in 0.010s)

c:\miniadb_merge>adb shell chmod 777 /data/local/tmp/fre3vo

c:\miniadb_merge>adb shell /data/local/tmp/fre3vo -debug -start F0000000 -end FFFFFFFF
fre3vo by #teamwin
Please wait...
Attempting to modify ro.secure property...
fb_fix_screeninfo:
id: msmfb
smem_start: 802160640
smem_len: 3145728
type: 0
type_aux: 0
visual: 2
xpanstep: 0
ypanstep: 1
line_length: 1920
mmio_start: 0
accel: 0
fb_var_screeninfo:
xres: 480
yres: 800
xres_virtual: 480
yres_virtual: 1600
xoffset: 0
yoffset: 0
bits_per_pixel: 32
activate: 16
height: 94
width: 56
rotate: 0
grayscale: 0
nonstd: 0
accel_flags: 0
pixclock: 0
left_margin: 0
right_margin: 0
upper_margin: 0
lower_margin: 0
hsync_len: 0
vsync_len: 0
sync: 0
vmode: 0
Buffer offset: 00000000
Buffer size: 8192
Scanning region f0000000...
Scanning region f10e0000...
Scanning region fb6d0000...
Scanning region fb7c0000...
Scanning region fb8b0000...
Scanning region fb9a0000...
Scanning region fba90000...
Potential exploit area found at address fbb54e00:1200.
Payload verification failed.
Scanning region fbb80000...
Scanning region ffd20000...
Scanning region ffe10000...
Scanning region fff00000...
Scanning region ffff0000...

C:\miniadb_merge>adb shell
# exit
exit
then follow by

C:\miniadb_merge>adb push busybox /data/local
1703 KB/s (0 bytes in 1062992.000s)

C:\miniadb_merge>adb shell
# chmod 0755 /data/local/busybox
chmod 0755 /data/local/busybox
# dd if=/dev/block/mmcblk0p17 of=/sdcard/misc-stock.img bs=4096
dd if=/dev/block/mmcblk0p17 of=/sdcard/misc-stock.img bs=4096
64+0 records in
64+0 records out
262144 bytes transferred in 0.019 secs (13797052 bytes/sec)
# /data/local/busybox md5sum /sdcard/misc-stock.img
/data/local/busybox md5sum /sdcard/misc-stock.img
4fe37c64b21d1d4542a801779fad5c57 /sdcard/misc-stock.img
# /data/local/busybox md5sum /dev/block/mmcblk0p17
/data/local/busybox md5sum /dev/block/mmcblk0p17
4fe37c64b21d1d4542a801779fad5c57 /dev/block/mmcblk0p17
# exit
exit

C:\miniadb_merge>adb push misc-downgrade.img /sdcard/
1638 KB/s (0 bytes in 262144.000s)

C:\miniadb_merge>adb shell
# dd if=/sdcard/misc-downgrade.img of=/dev/block/mmcblk0p17
dd if=/sdcard/misc-downgrade.img of=/dev/block/mmcblk0p17
512+0 records in
512+0 records out
262144 bytes transferred in 0.096 secs (2730666 bytes/sec)
# sync
sync
# exit
exit

C:\miniadb_merge>adb reboot bootloader

C:\miniadb_merge>
then ithis shows up

PHP:
HBOOT 

[1] parsing ... [SD ZIP] ok
[2] boot                 ok
[3] recovery             ok
[4] system               ok 
[5] splash1              ok
[6] partition            ok
[7] user data            ok
[8] tp                   ok 
[9] tp                   ok

after this i just keep on going to the next step I was intrigued

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\adalidh>cd c:\miniadb_merge

C:\miniadb_merge>adb push psneuter /data/local/
adb server is out of date. killing...
* daemon started successfully *
1743 KB/s (0 bytes in 585731.000s)

C:\miniadb_merge>adb devices
adb server is out of date. killing...
* daemon started successfully *
List of devices attached
HT17VM800243 device


C:\miniadb_merge>adb push psneuter /data/local/
1926 KB/s (0 bytes in 585731.000s)

C:\miniadb_merge>adb push busybox /data/local/
1581 KB/s (0 bytes in 1062992.000s)

C:\miniadb_merge>adb push wpthis /data/local/
1846 KB/s (0 bytes in 679475.000s)

C:\miniadb_merge>adb push gfree /data/local/
1947 KB/s (0 bytes in 716548.000s)

C:\miniadb_merge>adb shell
$ chmod 0755 /data/local/psneuter
chmod 0755 /data/local/psneuter
$ chmod 0755 data/local/wpthis
chmod 0755 data/local/wpthis
$ chmod 0755 data/local/gfree
chmod 0755 data/local/gfree
$ adb shell
adb shell
adb: permission denied
$ /data/local/wpthis
/data/local/wpthis
Build: 25
Section header entry size: 40
Number of section headers: 45
Total section header table size: 1800
Section header file offset: 0x00014e90 (85648)
Section index for section name string table: 42
String table offset: 0x00014cc7 (85191)
Searching for .modinfo section...
- Section[16]: .modinfo
-- offset: 0x00000f80 (3968)
-- size: 0x000000c4 (196)
Kernel release: 2.6.32.17-g788be6b3
New .modinfo section size: 204
Loading module... Failed.
Module returned an unknown code (Operation not permitted).
$ /data/local/gfree -f
/data/local/gfree -f
--secu_flag off set
--cid set. CID will be changed to: 11111111
--sim_unlock. SIMLOCK will be removed
Section header entry size: 40
Number of section headers: 44
Total section header table size: 1760
Section header file offset: 0x000138b4 (80052)
Section index for section name string table: 41
String table offset: 0x000136fb (79611)
Searching for .modinfo section...
- Section[16]: .modinfo
-- offset: 0x00000a14 (2580)
-- size: 0x000000cc (204)
Kernel release: 2.6.32.17-g788be6b3
New .modinfo section size: 204
Attempting to power cycle eMMC... Failed.
Module returned an unknown code (Operation not permitted).
$ exit
exit
then i follow the instructions step by step
and thanks to you guys now im soff supercid and all tah

i must say that is not easy but is possible to do it at one shot

thanks for the help this post give me
:smokingsomb:


thanks Android Forums - View Profile: scotty85
 
Back
Top Bottom