Jump to content
AVIC411.com

Condi's HACKMODE v2.2 - AUTOINSTALL! working also with F40BT, X940BT etc! [updated: 27.09.2012]


Recommended Posts

  • Replies 1.2k
  • Created
  • Last Reply

Top Posters In This Topic

...for now I can tell you that i've got f30bt with 'semi-working' f40bt firmware.

and of course - like in f40bt - i have testmode-copy/paste disabled lol

Glad to see you again!

Can you delete PRG.FLG file from your limited testmode? it will make PRG0 active and you will have working testmode (and software from F30) again.

I assume that you have updated your device (and got PRG.FLG file he-he...)

 

Which features are not working on your 'semi-working' f40bt firmware?

Link to post
Share on other sites

Glad to see you again!

Can you delete PRG.FLG file from your limited testmode? it will make PRG0 active and you will have working testmode (and software from F30) again.

I assume that you have updated your device (and got PRG.FLG file he-he...)

 

Which features are not working on your 'semi-working' f40bt firmware?

 

I'm very busy lately, 1st day on new place :)

Please tell me - whats the source of this 'patched testmode exe' ?

And whats the solution to run it on f40bt which cant be written etc?

Or such solution doesnt exists?

 

Got to dismantle my avic, I've bought ac adapter for 'home-use'.

I've flashed all modules from F40BT on my F30BT - .PRG files, including EU090BOT - bootloader :)

 

Also the good news is that there is no 'version-check',

so there is no problem with upgrade, but also downgrade.

 

Another thing that I've found is that files which are on PRG0/PRG1, APL directories,

are not important as far as testmode is concerned.

 

In one word - you can delete all APL(ication) directory,

and AVIC will still boot - with 'no applicable software' message.

And it will still boot into testmode :)

 

Propably the solution for working copy/paste testmode

is to flash EU090RGD.PRG (and maybe EU090PLT.PRG)

v3 version from my F30bt for example, on locked F40bt device.

 

Gonna try to downgrade my v4 f30 modules when I will get some free time.

To be 100% sure of what I've wrote I've got to flash all PRG's with old v3,

write back v3 APL and check if my avic will boot correctly :)

 

Until then - everything what you do is on your own risk ;) ;)

Oh and I will post some video proof lol.

 

br

condi

Link to post
Share on other sites

I'm very busy lately, 1st day on new place :)

Please tell me - whats the source of this 'patched testmode exe' ?

One guy in Russia did this (I think his nickname here is Ktoto). He've decompiled Testmode.exe and fixed it. But... it is part of EU090PLT.PRG file, so we need to reassemble it back to EU090PLT.PRG file.

And whats the solution to run it on f40bt which cant be written etc?

Or such solution doesnt exists?

Other guy made modified firmware (EU090PLT.PRG) but it heven't been tested yet. I can pm you a link to it but I gess it is too dangerous to put it here.

I've flashed all modules from F40BT on my F30BT - .PRG files, including EU090BOT - bootloader :)

Where did you get ALL modules from F40BT? or you talking about that update archive?

Also the good news is that there is no 'version-check',

so there is no problem with upgrade, but also downgrade.

That is a good news!

Another thing that I've found is that files which are on PRG0/PRG1, APL directories,

are not important as far as testmode is concerned.

 

In one word - you can delete all APL(ication) directory,

and AVIC will still boot - with 'no applicable software' message.

And it will still boot into testmode :)

That's right. Testmode is part of windows and sits inside EU090PLT.PRG. And if we start testmode it runs before anything from APL folder.

Propably the solution for working copy/paste testmode

is to flash EU090RGD.PRG (and maybe EU090PLT.PRG)

v3 version from my F30bt for example, on locked F40bt device.

 

Gonna try to downgrade my v4 f30 modules when I will get some free time.

To be 100% sure of what I've wrote I've got to flash all PRG's with old v3,

write back v3 APL and check if my avic will boot correctly :)

 

Until then - everything what you do is on your own risk ;) ;)

Oh and I will post some video proof lol.

 

br

condi

 

Also you haven't posted list of new features that work if you run F40 software om F30. And also list of features that doesn't work.

Link to post
Share on other sites

I hope there is a helpfull information:

Oficial navi.exe reads data from system library using function GpsGetPos and have no idea about NMEA or COMpots.

So... to have working IGO (or something else) we need software that reads it same way, convert data and output it to virtual com port, or teach IGO to read from same library. How it was in F900?

 

format of PRG files:

 

offset 0 length 32 bit - platform signature 0xA55A5AA5

offset 4 length 32 bit - length of the file without header

offset 8 length 32 bit - CRC32 crc from 0x200 till the end of the file

offset 0xC length 8 bit - unknown, always =0

offset 0xD length 8 bit - for bootloader =0 , for PLT or RGD =1 (most likely type of the file) if =0 - file format is 0xB000F, if =1 - nb0

offset 0xE length 32 bit - unknown, always 00040400

offset 0x18 length 64 bit - file name without exstension.

offset 0x200 till the end of the file - DATA.

 

Testmode.key and update scripts use NPSysCtrlHandler.dll.

 

All credits for this knowaledge goes to 3 russian hackers, I just translated it to extence if my understanding.

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...



×
×
  • Create New...