All about papua here-->newest versions-->questions

  • Thread starter Thread starter Chris02
  • Start date Start date
I unlocked C72 V16 with this methode :

First find ESN SKEY BKEY same as old C65
and after go in FLASH meni and check REPLACE 76,5008,5009,5077
press DO JOB and phone unlocked
the phone unlocked and work fine
 
@chaos



absolutely fantastic

tested on my new SL75 (SL7F) v.39 and work perfect


thank you and best regards
 
some good information about papua is here too

http://www.mobilewala.net/showthread.php?t=182



WBR
Kuku
 
Hi

Here is last version of Papuautils 0.9.1a translated in english (big thanks to papuasoft team for her great work and Gehstock for update)

http://rapidshare.de/files/33717709/x65PapuaSoft.exe
 
Tronad0r, how is this method?
is not like the fake "direct mode" from others tools that use the midlet too(then not so direct) with Leds powered off?
 
with C81 v40 works perfect

After calculate and Send Skey with Papuas 0.9.3 , changed HASH in my phone .New HASH is FFFFFFFFFFFFFFFF
I don't know why ?
Phone working perfect
 
for me work good for all siemens phones exept one siemens cx65 its can be unlocked he hase brocken track can every one have pinout repare for this phone please ..........big thank
 
hello guys,
M75 dead, use TP

Auto Ignition...
Transfer boot...
BOOT is loaded...
Pause 2 sec...
Getting Information...
FlashID: 0089,C80D
Mw5@ SIEMENS@ 3u6t2t0p0t5r8p7
Information incorrect!
HASH: 45DC1A7D6C462E74B6408857AFE1F94B
OTP ESN: 2F09E117
OTP IMEI: 356024040456808
Boot released.


when calc SKEY + BootKEY it says "key not found!"
what am i supposed to do..?
thanks!
 
A little update for fixing AMD-Spansion flashes 0001/227E : ver. x65PapuaUtilsV079e English !
(problems appeared only in "Flash" page [TestPoint] and only for AMD previously....Java Midlet method always worked !)

-get correct OTP IMEI
-get right OTP ESN !
-"Save EEP blocks" to work correctly and save All blocks...
(previously missing blocks from 1FE0000 for some x75 models)
-"Read Fullflash" to work correctly....
( in original russian 079c & 079d you get all FFs after 0x1000000 for AMD flash types !)

Also "PV VKD" produces boot-loader for V_Klay supporting AMD flashes
and "New VKD" produces boot-loader from Chaos 'x65flasher-1094' which supports AMD flashes also.

http://briefcase.pathfinder.gr/download/527588

Sample session :

Auto Ignition...
Transfer boot...
BOOT is loaded...
Pause 2 sec...
Getting Information...
FlashID: 0001,227E (32Mb) ...(amd)
ME75 SIEMENS 35798xxxxxxxxxx
HASH: B40E11B42B7032DAD9B7B175xxxxxxxx
OTP ESN: FEB028F3
OTP IMEI: 35798xxxxxxxxxx
Established speed 1228800 Baud.
Test data bus D0..D15...OK.
Test address bus A2..A22...OK.
Search for the EELITE segment...
Search for EEFULL segments...
Total EEP blocks: 234
Blocks saved in .\Backup\ME75_FEB028F3_EEP_060513212027.eep
Saving block Boot Info...
Block Info saved in .\Backup\ME75_FEB028F3_Info_060513212027.bin
Boot released. Everything is closed.


Use it with real cases with AMD 0001,227E flash types and report results !

P.S. Operation for Intel flashes is exactly the same as previously !
 
I found by accident in a site this Java midlet, that appears to work very fast
in producing HASH & ESN !...
 
Hey!

I try to unlock c72 ver. 16 vith method like c65 with papua.
I made a test point, start program, Autoignition OK, I push power ON,
Transmit Boot...
Boot Loaded
Pause 2 sec....
I remove test point and do nothing
after that
Retrieve information
No answer to boot
Boot unlock.

and here ends everything

Did I need to push anything when I remove test point after "Pause 2sec" ?
Do I need to do anything else?
Please help me.

Regards,
Dejan
 
It means if phone is in Factory or Customer mode. First one is an effect of loading SKey to phone.
 
Like i said Papua in english . Much easier

http://www.repairing.nl/d_repairing/index.html

enjoy
 
1. Make Testpoint and Read the Bcore and a Fullflash
2. Enter your IMEI, ESN and HWID in Papua
3. Enter 8 Digits in Skey(0-9)
4. Calc Hash and BKey
5. Open your BCore with Winhex and enter your new Hash on the 2 Places
6. Write your new BCore over Testpoint in the Device
7. Check "Neuer Skey" in Papua then Button "Sende Skey"
8. Now is Time for Unlock over Button "5008 Unlock"
 
Back
Top