• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Root Downgrade & Root issues

When finally applying the PD98IMG via Bootloader, you get a "version is older" or similar message, you must remake the goldcard.


Instead of Goldcard Helper.

- Open up a command prompt (Windows Key + R, type "CMD", press enter)
- connect your phone as "charge only" and have usb debugging enabled
- navigate the command prompt to the downgrade folder.
- Type:
PHP:
adb shell cat /sys/class/mmc_host/mmc2/mmc2:*/cid
-Select and copy the cid, then paste into the appropriate field on the Goldcard Generator webpage.

You will now get a proper image, that once applied, will give you a proper working Goldcard to copy the PD98IMG.zip to and downgrade your device.

Cheers.
 
  • Like
Reactions: CuBz
When finally applying the PD98IMG via Bootloader, you get a "version is older" or similar message, you must remake the goldcard.


Instead of Goldcard Helper.

- Open up a command prompt (Windows Key + R, type "CMD", press enter)
- connect your phone as "charge only" and have usb debugging enabled
- navigate the command prompt to the downgrade folder.
- Type:
PHP:
adb shell cat /sys/class/mmc_host/mmc2/mmc2:*/cid
-Select and copy the cid, then paste into the appropriate field on the Goldcard Generator webpage.

You will now get a proper image, that once applied, will give you a proper working Goldcard to copy the PD98IMG.zip to and downgrade your device.

Cheers.


Cheers for that. It's always good to have an alternate
 
Upvote 0
I'll definitely keep that in mind also next time.

I have found if using 'copy to clipboard' with Goldcard Helper it copies the mmc0 CID and this did not work no matter what SD Card I used. Manually taking the mmc2 worked first time. I could have saved 3hrs yesterday :)

Keep this in mind and use the above methods instead.
 
Upvote 0
I'll definitely keep that in mind also next time.

I have found if using 'copy to clipboard' with Goldcard Helper it copies the mmc0 CID and this did not work no matter what SD Card I used. Manually taking the mmc2 worked first time. I could have saved 3hrs yesterday :)

Keep this in mind and use the above methods instead.

When I used 'Copy to clipboard, it copied mmc2
 
Upvote 0
happy to say I've successfully managed to downgrade from 2.50.161.2, obtained permanent root with S-OFF and just about to install 1st cutom rom. :p

thanks to everyone who gave their time and effort into getting the 2.37+ version "fixed"

my potential exploit address was fbb7f800:1800

thanks again (p.s. where's the thanks button) :thinking:

thats a new address and offset I havent seen yet, thanks for the info addition :)
 
Upvote 0
I got this one first time: fbb56400:1c00

but had to restart the whole process for some reason

not sure if it helps...

Yep, i've seen that address-offset before, guy had a problem with it too and redid the method, his new address-offset was fbb6b00:1a00

I think at that offset its just a false positive, possibly a glitch in the data comparison.
 
Upvote 0
Upvote 0
Still doesn't seem to work

adb server is out of date. killing...
* daemon started successfully *
612 KB/s (0 bytes in 9796.000s)
15 KB/s (0 bytes in 15837.001s)
fre3vo by #teamwin
Please wait...
Attempting to modify ro.secure property...
fb_fix_screeninfo:
id: msmfb
smem_start: 802160640
smem_len: 3145728
type: 0
type_aux: 0
visual: 2
xpanstep: 0
ypanstep: 1
line_length: 1920
mmio_start: 0
accel: 0
fb_var_screeninfo:
xres: 480
yres: 800
xres_virtual: 480
yres_virtual: 1600
xoffset: 0
yoffset: 0
bits_per_pixel: 32
activate: 16
height: 106
width: 62
rotate: 0
grayscale: 0
nonstd: 0
accel_flags: 0
pixclock: 0
left_margin: 0
right_margin: 0
upper_margin: 0
lower_margin: 0
hsync_len: 0
vsync_len: 0
sync: 0
vmode: 0
Buffer offset: 00000000
Buffer size: 8192
Potential exploit area found at address fbb6c1ff:e01.
Payload verification failed.
----------------------------------------
- -
- Exploit Found - Data Patched -
- Please Disconnect Then Reconnect -
- Your Device -
- -
----------------------------------------
 
Upvote 0
I am on stock 2.50.405.2

2.50.405.2 CL87995 release-keys

By the way, that is the same thing I get when I use the one by the OP as well, payload verification failed.

This version has not been a problem for the temproot method for other people.
Are you running the command prompt as an admin?


If you're just wanting to back up, export the contacts with the built in ability, and make sure everything is synced (with htc sync or with the cloud - google, etc...).

if you cant gain temproot now, the only way to get temproot is if you reset the device or reload the stock rom and then doing the method again. there's something (possibly a 3rd party app or similar) preventing the changes from taking place, especially with the exploit found.... in 2 different hex addresses (should only be one).
 
Upvote 0
Hey there guys, when I load PD98IMG via Bootloader the blue bar loads and then I get a yellow bar and then I get an error saying invalid CID number, I've tried to make multiple gold cards and use different programs to make them each time and I am still getting the same error message.

Can anyone advise on what to do about this?

Thanks.

-MADROX-
 
Upvote 0
Hey there guys, when I load PD98IMG via Bootloader the blue bar loads and then I get a yellow bar and then I get an error saying invalid CID number, I've tried to make multiple gold cards and use different programs to make them each time and I am still getting the same error message.

Can anyone advise on what to do about this?

Thanks.

-MADROX-


Make sure you are copying mmc2 not mmc0
 
Upvote 0

BEST TECH IN 2023

We've been tracking upcoming products and ranking the best tech since 2007. Thanks for trusting our opinion: we get rewarded through affiliate links that earn us a commission and we invite you to learn more about us.

Smartphones