Welcome to the Android Central Forums Create Your Account or Ask a Question Answers in 5 minutes - no registration required!
Results 1 to 7 of 7
  1. Thread Author  Thread Author    #1  
    UPEngineer's Avatar

    Posts
    87 Posts
    Global Posts
    280 Global Posts
    ROM
    dasBamf 1.4/ Adryn 4.4.2

    Default HTC Merge S-Off and Perm Root achieved

    Hello all,

    I take no credit here, just reposting a link I found.

    Evidently some devs on xda has achieved perm root and s-off on the HTC Merge.

    US Cellular phones have a couple more steps which involves a gold card but a link shows you how to accomplish this.

    Here is the XDA link:

    xda-developers - View Single Post - [Q] HTC Merge Rooting and Custom Recovery

    There is another link for a how to guide for USCC phones but they asked to not repost the link. You can find it in that thread though.

    Hope this helps someone.
  2. #2  

    Default Re: HTC Merge S-Off and Perm Root achieved

    This is great news. I'll have to do this to my phone in the near future. Now lets get a stock 2.3 ROM.
  3. #3  

    Default

    Will this work for gingerbread 2.3.4 and HTC sense 2.2? This is my first smartphone and first root. So I'm a little nervous about this whole thing. I wanna make sure I get it done right. What do I do??????
  4. #4  

    Default Re: HTC Merge S-Off and Perm Root achieved

    what do you put for the "original file md5 checksum value" to verify?
  5. #5  

    Default Re: HTC Merge S-Off and Perm Root achieved

    Has anyone figured out how to root this?! I have had it for almost 3 months and still no root I am running uscc 2.3.4 and cant find anything!!!
  6. #6  

    Default Re: HTC Merge S-Off and Perm Root achieved

    Has any one found how to S-off, root, & unlock HTC Merge.

    I've HTC Merge - USCellular & want to S-off, root, & unlock it. I googled it & followed the steps but stuck at :
    Code:
    $ /data/local/psneuter
    Failed to set prot mask (Inappropriate ioctl for device)
    Help appreciated
  7. #7  

    Default Re: HTC Merge S-Off and Perm Root achieved

    Quote Originally Posted by krishnadixit View Post
    Has any one found how to S-off, root, & unlock HTC Merge.

    I've HTC Merge - USCellular & want to S-off, root, & unlock it. I googled it & followed the steps but stuck at :
    Code:
    $ /data/local/psneuter
    Failed to set prot mask (Inappropriate ioctl for device)
    Help appreciated
    copy and paste from

    scotty85
    Senior Member

    Thread Author (OP)





    step 6 session(gain s-off,superCID,and sim unlock in exploitable firmware):
    Code:
    c:\miniadb_merge>adb devices
    List of devices attached
    HT18YM800022    device
    
    
    c:\miniadb_merge>adb push psneuter /data/local/
    1147 KB/s (585731 bytes in 0.498s)
    
    c:\miniadb_merge>adb push busybox /data/local/
    1614 KB/s (1062992 bytes in 0.643s)
    
    c:\miniadb_merge>adb push wpthis /data/local/
    1556 KB/s (679475 bytes in 0.426s)
    
    c:\miniadb_merge>adb push gfree /data/local/
    972 KB/s (134401 bytes in 0.135s)
    
    c:\miniadb_merge>adb shell
    $ chmod 0755 /data/local/psneuter
    chmod 0755 /data/local/psneuter
    $ chmod 0755 /data/local/wpthis
    chmod 0755 /data/local/wpthis
    $ chmod 0755 /data/local/gfree
    chmod 0755 /data/local/gfree
    $ /data/local/psneuter
    
    c:\miniadb_merge>adb shell
    # /data/local/wpthis
    /data/local/wpthis
    Build: 25
    Section header entry size: 40
    Number of section headers: 45
    Total section header table size: 1800
    Section header file offset: 0x00014e90 (85648)
    Section index for section name string table: 42
    String table offset: 0x00014cc7 (85191)
    Searching for .modinfo section...
     - Section[16]: .modinfo
     -- offset: 0x00000f80 (3968)
     -- size: 0x000000c4 (196)
    Kernel release: 2.6.32.17-g788be6b3
    New .modinfo section size: 204
    Loading module... OK.
    Write protect disabled.
    Searching for mmc_blk_issue_rq symbol...
     - Address: c02a2884, type: t, name: mmc_blk_issue_rq, module: N/A
    Kernel map base: 0xc02a2000
    Kernel memory mapped to 0x40001000
    Searching for brq filter...
     - Address: 0xc02a2884 + 0x34c
     - 0x2a000012 -> 0xea000012
    Done.
    # /data/local/gfree -f
    /data/local/gfree -f
    --secu_flag off set
    --cid set. CID will be changed to: 11111111
    --sim_unlock. SIMLOCK will be removed
    Section header entry size: 40
    Number of section headers: 44
    Total section header table size: 1760
    Section header file offset: 0x000138b4 (80052)
    Section index for section name string table: 41
    String table offset: 0x000136fb (79611)
    Searching for .modinfo section...
     - Section[16]: .modinfo
     -- offset: 0x00000a14 (2580)
     -- size: 0x000000cc (204)
    Kernel release: 2.6.32.17-g788be6b3
    New .modinfo section size: 204
    Attempting to power cycle eMMC... OK.
    Searching for mmc_blk_issue_rq symbol...
     - Address: c02a2884, type: t, name: mmc_blk_issue_rq, module: N/A
    Kernel map base: 0xc02a2000
    Kernel memory mapped to 0x40000000
    Searching for brq filter...
     - Address: 0xc02a2884 + 0x34c
     - ***WARNING***: Found fuzzy match for brq filter, but conditional branch isn't
    . (0xea000012)
    Patching and backing up partition 7...
    patching secu_flag: 0
    Done.
    # exit
    exit
    
    c:\miniadb_merge>adb reboot bootloader
    as before,you should now boot to fastboot. select bootloader with the power button. allow your upgrade to flash
    c:\miniadb_merge>

Posting Permissions