{"id":26,"date":"2011-01-03T18:02:45","date_gmt":"2011-01-03T23:02:45","guid":{"rendered":"http:\/\/ahdesign.us\/blog\/?p=26"},"modified":"2012-01-12T16:37:09","modified_gmt":"2012-01-12T21:37:09","slug":"motorola-droid-1-cricket-wireless","status":"publish","type":"post","link":"https:\/\/ahdesign.us\/blog\/motorola-droid-1-cricket-wireless\/","title":{"rendered":"Motorola Droid 1 &#8211; Cricket Wireless"},"content":{"rendered":"<p>I finally was able to get my hands on a Motorola Droid 1 a little over a year after it came out.\u00a0 I&#8217;ve wanted one for a while now, but I didn&#8217;t want to pay for the monthly $30 data plan (apparently unlimited texting is another $10 on top of that, ripoffness).<\/p>\n<p>In this post, I&#8217;ll tell you how I flashed my droid 1 to CricKet without needing CDMA Workshop 2.7 or paying anyone a single cent to accomplish this (surprisingly all legally&#8230;.)<\/p>\n<p><!--more-->Droids are available all over the place like craigslist, ebay, the subway&#8230;etc.\u00a0 I snagged on off ebay for a decent price (which may have come from the subway&#8230;).\u00a0 It was cheap mainly because it has a bad ESN.\u00a0 What this means is that the owner did one of the following: lost it\/got it stolen and reported it as such and got an insurance claim on it, didn&#8217;t pay their verizon bill, or found\/stole it from someone else and the person that owned it in the 1st place reported it stolen\/lost.\u00a0 Anyways&#8230;.when that stuff happens, Verizon has this big ol blacklist that when you go to try to activate your phone and it&#8217;s unique identifier is on their list of evil phones, they won&#8217;t activate it.\u00a0 And as far as I know, it can never be activated with them.\u00a0 That&#8217;s all fine and dandy except that unlike GSM carriers, you can&#8217;t really just go and get another carrier&#8217;s SIM card and pop it it and away you go.\u00a0 Verizon&#8217;s network is CDMA, which means there&#8217;s no SIM card to pop out and go to another network with.\u00a0 Plus Verizon has really the only large CDMA network around so&#8230; blacklisting is good on their part as it requires you to buy another one of their phones to work on their network.<\/p>\n<p>Unless&#8230;..you flash the bad ESN phone to CricKet or MetroPCS!\u00a0 Or, on the highly illegal\/go to jail side of things you can change your ESN\/MEID, but that kinda scares me and I&#8217;m not doing that.\u00a0 It&#8217;s actually totally legal to flash your Verizon phone to another carrier.\u00a0 CricKet has some nice cheapo plans that have no contract, and you can terminate at any time.\u00a0 I really despise Verizon and all their nickle and diming you to use their network for meaningless and trite things network-wise like text messaging.\u00a0 Anyways, not having a $30-$40 a month fee for using the phone on Verizon&#8217;s network but still being to screw around with the droid sounds good to me!\u00a0 The only downside&#8230;..major downside to CricKet is their coverage area.\u00a0 They pretty much cover the major interstates and major towns\/cities.\u00a0 Other than that you&#8217;re roaming, and we&#8217;re back to year 2000 and having to deal w\/ roaming charges.\u00a0 Interestingly, you end up using Verizon&#8217;s network when you&#8217;re roaming&#8230;.\u00a0 Oh I should also note that the only thing you &#8220;need&#8221; carrier activation for is calls and text messaging.\u00a0 Everything else you can do via wifi.<\/p>\n<p>Luckily this has been done by many people before, but you need a piece of software that isn&#8217;t easily obtainable via the internet (aka filthy piracy).\u00a0 I tried and tried to find CDMA Workshop 2.7 (anything newer than that supposedly isn&#8217;t piratable as they validate your computer over the internet) to no avail.\u00a0 I did find a way to do this using two other tools, which it doesn&#8217;t appear to have been done (or at least not documented) by anyone else.<\/p>\n<p>Basically I followed the directions here on the 1st page: <a href=\"http:\/\/www.howardforums.com\/showthread.php\/1643218-Motorola-Droid-Full-Solution-Updated\" target=\"_blank\">Flash Droid 1 to CricKet<\/a> I think I did follow the 1st steps about how the author rooted their phone, but eventually I downloaded the ROM Manager app from the Android Marketplace (the free one, although the paid version sounds quite nice too) and installed Chevyno1&#8217;s Simply Stunning ROM (this is by default rooted).\u00a0 I don&#8217;t think you need to use RSD Lite if you use ROM Manager (and install clockwork recovery from ROM Manager), but I don&#8217;t know for sure.\u00a0 This is assuming not needing RSD Lite.<\/p>\n<p>Alright, so to root your phone w\/o using RSD Lite and all that jazz, get the ROM Manager app on your phone.\u00a0 Then download Simply Stunning ROM from <a href=\"http:\/\/www.droidforums.net\/forum\/chevyno1\/109484-merry-christmas-everyone-ss-4-95-under-tree.html\" target=\"_blank\">here<\/a>.\u00a0 I used the themed version.\u00a0 The unthemed version I think looks like stock&#8230;dunno though.\u00a0 Put the Simply Stunning zip file on the root of your phone&#8217;s MicroSD card either w\/ an external USB reader, or via plugging the droid into the computer via the microUSB cable.\u00a0 I think you can make a separate folder and the recovery program will still be able to open the file that way.<\/p>\n<p>Now run the ROM Manager app on the phone.\u00a0 From the main menu, select &#8220;Flash ClockworkMod Recovery&#8221;.\u00a0 ROM Manager will take care of the rest and install that for you.\u00a0 Once this recovery program is flashed on the phone, you can easily install any custom ROM you want.\u00a0 I&#8217;d suggest always choosing to backup the phone if ROM Manager asks you to.\u00a0 The phone will reboot and lots of stuff will happen, and then it&#8217;ll boot back into Verizon&#8217;s Android as if nothing ever happened.\u00a0 Go back into ROM Manager and select &#8220;Install ROM from SD Card&#8221;.\u00a0 Alternatively, if your phone is powered off, you can hold the &#8216;X&#8217; key on the keyboard and power on and get into recovery and flash ROMs that way.\u00a0 Going the ROM Manager route ensures you&#8217;re prompted to backup your phone&#8217;s current state (recommended).\u00a0\u00a0 Now select the Simply Stunning zip file from where you placed it on your phone and hit &#8220;Ok&#8221;.\u00a0 Check &#8220;Backup Existing ROM&#8221; and &#8220;Wipe Data and Cache&#8221;.\u00a0 Hit &#8220;Ok&#8221;.\u00a0 The phone will reboot and do some stuff w\/ progress bars and junk, so don&#8217;t remove the battery.\u00a0 It&#8217;d be best to plug the phone into external power for this.\u00a0 After everything happens, the phone will reboot and instead of seeing the droid eye animation, you&#8217;ll see the Simply Stunning boot animation.\u00a0 You&#8217;re now running the latest build of Froyo w\/ some extra features and junk.\u00a0 You&#8217;re also rooted.<\/p>\n<p>This I believe kills off the whole RSD Lite install smoked-glass ROM process.\u00a0 Now, turn the phone off.\u00a0 A reboot will not work for this.\u00a0 Install the motorola USB drivers if you haven&#8217;t already.\u00a0 Plug the microUSB cable into your computer, but not your phone (or vice versa).\u00a0 The USB link cannot be present when the phone turns on or else it goes into bootloader mode&#8230;.which is pretty stupid (or maybe this happens cause I followed the RSDLite directions? I dunno&#8230;)\u00a0 Once the phone is off, hold the &#8216;T&#8217; key and hold the power button till the phone&#8217;s backlight turns on.\u00a0 Keep holding the &#8216;T&#8217; key.\u00a0 Now plug in the unconnected end of the microUSB cable.\u00a0 This forces the phone to load a special network over USB driver so we can talk to the phone&#8217;s off-limits flash area.\u00a0 Keep holding &#8216;T&#8217; until you see some activity on your PC relating to the USB stuff.\u00a0 This happens sometime while the Motorola &#8216;M&#8217; is still on the droid&#8217;s screen.\u00a0 Your phone will continue to boot normally.<\/p>\n<p>Now, we need to check to make sure the driver actually loaded and created a USB networking adapter for the PC.\u00a0 Click the &#8220;Start&#8221; button and click &#8220;Run&#8221; or in the Run box on Vista\/Win7 type in cmd and then press enter.\u00a0 In the command window, type &#8220;ipconfig \/all&#8221;.\u00a0 Somewhere in the pile of information returned there should be something that says Motorola USB Networking Driver and it should have an IP address of 192.168.16.1.\u00a0 If you do not see the Motorola entry in the list of stuff, power off the phone and try the process again. For me, the driver didn&#8217;t load the 1st time cause Windows was installing the new hardware.\u00a0 You cannot just reboot the phone to get into this special mode, it needs to be powered off.<\/p>\n<p>Once you know the phone has an IP address of 192.168.16.1, open up HW Virtual Serial Port (the demo will work fine for this).\u00a0 Click the &#8220;login&#8221; button in HWVSP and put in the default password of admin.\u00a0 Follow the directions as shown in the HowardForums link I specified above for the HW Virtual Serial Port.\u00a0 If everything worked right, the &#8220;LAN Status&#8221; in HWVSP will say &#8220;Connected&#8221;.\u00a0 Now you&#8217;ll need to acquire QXDM and QPST.\u00a0 Try and get the latest versions as older versions don&#8217;t support the Droid.\u00a0 I used QPST 2.7 build 323 and QXDM 3.11.36.\u00a0 We&#8217;ll use QXDM to write the NVItems specified in the HowardForums link and QPST to do the rest.\u00a0 Make note of the com port number that HW Virtual Serial port created.<\/p>\n<p>Before going too far, we should backup the phone in case something goes wrong.\u00a0 I don&#8217;t believe this is the same as a nandroid backup as this should be saving NVItems and all that junk (on the other hand, I don&#8217;t know if this backs up the OS too&#8230;.).\u00a0 Open up QPST Software Download.\u00a0 Click the &#8220;Backup&#8221; tab and click &#8220;Browse&#8221; to choose the phone&#8217;s com port.\u00a0 Give the QCN file a name and a place to store it.\u00a0 The SPC code should be 000000 (six zeros) unless someone changed it.\u00a0 If someone changed that code, I believe you will need CDMA workshop to find out the new code.\u00a0 Anyways, it should be six zeros.\u00a0 Click &#8220;Start&#8221; and QPST will download all your phone&#8217;s settings to the specified QCN file.\u00a0 This will take some time to do.<\/p>\n<p>At this point, you should also have an account w\/ CricKet and you should have gotten your phone number (MDN), their MIN, system ID, and maybe some other info.\u00a0 Then go to <a href=\"http:\/\/www.whiterabbit.org\/android\/\" target=\"_blank\">http:\/\/www.whiterabbit.org\/android\/<\/a> and get your NVItems by filling in your CricKet login info and click &#8220;Generate&#8221;.\u00a0 It doesn&#8217;t matter if you generate the NVItems for CDMA WS 2.7 or 3.5 as we&#8217;re using neither of them, but you need the data in the files.\u00a0 This is the 12 NVItems mentioned on the HowardForums link.\u00a0 Alternatively you can use the 5 NVItems linked to in the HowardForums post.\u00a0 The 12 NVItems just fills in some junk that we&#8217;ll be doing in QPST later on.\u00a0 In either of the NVItems files, you&#8217;ll see something like the following:<\/p>\n<p>8091 (0x1F9B)\u00a0\u00a0 &#8211;\u00a0\u00a0 OK<br \/>\n40 6D 79 63 72 69 63 6B 65 74 2E 63 6F 6D 00 00<br \/>\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00<br \/>\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00<br \/>\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00<br \/>\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00<br \/>\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00<br \/>\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00<br \/>\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00<\/p>\n<p>In the example above, this is NVItem 8091 (decimal).\u00a0 Don&#8217;t worry about the hex representation of this as we&#8217;re going to use the decimal version of it in QXDM.\u00a0 Everything past &#8220;OK&#8221; above is the data that gets written to location 8091, but these numbers are all in hex.\u00a0 The only issue here is if &#8220;0x&#8221; (yes, that&#8217;s a zero) does not precede a hexadecimal number in QXDM, it somehow thinks the number is decimal even though there&#8217;s letters in the mix.\u00a0 We&#8217;ll need to fix that for the numbers other than 0.\u00a0 &#8216;0&#8217; in hex and decimal mean the same thing, so we won&#8217;t bother adding the &#8216;0x&#8217; in front of them later on.\u00a0 Find-&gt;Replace in a text editor would probably work well for this&#8230;<\/p>\n<p>Now, open up QXDM (QPST must be installed too) and set the connection to the com port created in the previous step if required.\u00a0 Actually you might need to set the COM port in the QPST server that loads up.\u00a0 If everything is setup correctly, QXDM should connect to the phone automatically.\u00a0 There is a NVItems Browser, but some of the NVItems we&#8217;ll be changing aren&#8217;t listed in the browser, but luckily there&#8217;s commands we can type to send to the phone to do stuff this QXDM GUI doesn&#8217;t seem to have support for.\u00a0 Once you&#8217;re connected to the phone, in the command entering box right below &#8220;View&#8221;, type in&#8221;mode offline-d&#8221;.\u00a0 This command will turn the cellular radio off (probably good since we&#8217;re mucking w\/ baseband settings here).\u00a0 A new window will open up showing the command that was just sent and the phone&#8217;s response.<\/p>\n<p>Now to write the NVItems. You&#8217;ll be using the RequestNVItemIDWrite command to write the NVItems to the phone, and RequestNVItemIDRead to read back what was just written to make sure it matches what&#8217;s in the NVItems file.\u00a0 We&#8217;ll take the example above again.\u00a0 To write that to the phone, put the following into the command bar (obviously w\/o the quotes): &#8220;RequestNVItemIDWrite 8091 0x40 0x6D 0x79 0x63 0x72 0x69 0x63 0x6B 0x65 0x74 0x2E 0x63 0x6F 0x6D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\u00a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&#8221;.\u00a0 I&#8217;m not sure how this will copy out of this blog, so paste it into notepad or something first.\u00a0 What you want is one really long line of data, no new-lines or any of that.\u00a0 Paste the single line command above into the command entering thingy in QXDM and press enter.\u00a0 That should have written all that data to location 8091 (QXDM will probably convert that to hex in the command response window).\u00a0 To check, issue a &#8220;RequestNVItemIDRead 8091&#8221; command.\u00a0 The response will be cutoff in the response window, so left-click on the blue response line that&#8217;ll start with &#8220;0x26&#8221; to select that item, then right-click on it and select copy text.\u00a0 Then paste the response into notepad or some other text editor.\u00a0 You&#8217;ll need to ignore the 0x26 and the two data bytes after the 0x26.\u00a0 0x26 is the command we just sent to the phone, and the next two bytes are the hex location we just specified (for 8091 you&#8217;ll see 9B 1F, which is byte-swapped as 8091 in hex is 1F 9B).\u00a0 The data after the command ID and two-byte NVItem location should match up completely with the data for 8091 in the NVItems (QXDM strips off the 0x&#8217;s in front of the hex data).\u00a0 If everything matches up, do the exact same thing for all the other NVItems in the 5 or 12 NVItems files.\u00a0 If not, check to make sure you didn&#8217;t forget a byte of data or you possibly forgot to put &#8220;0x&#8221; in front of all the data bytes.\u00a0 Don&#8217;t reboot the phone as we need to still write some stuff w\/ QPST.\u00a0 It may be possible to do everything in QXDM, but I don&#8217;t know enough about it to do it.\u00a0 Close QXDM.<\/p>\n<p>Open up QPST-&gt;Service Programming.\u00a0 Select your phone from the top window (QPST should have automatically detected it) and click ok.\u00a0 Once QPST connects to the phone, click the &#8220;Read from phone&#8221; button and put in the phone&#8217;s SPC code (should be six zeros) and hit ok to that to populate all the tables w\/ the phone&#8217;s current values.\u00a0 If you did the 12 NVItems above, some of this will be filled in correctly already.\u00a0 If not, no big deal.\u00a0 This will take some time to read everything from the phone.<\/p>\n<p>First thing we&#8217;ll do is load a CricKet PRL into QPST (it won&#8217;t load anything to the phone till &#8220;Write to phone&#8221; is clicked).\u00a0 Click the &#8220;Roam&#8221; tab and click the browse button to find your CricKet PRL.\u00a0 I used PRL 38515.\u00a0 Find your PRL and click open.\u00a0 The PRL is now loaded into QPST and will be put on the phone when the &#8220;Write to Phone&#8221; button is pressed.\u00a0 Don&#8217;t do it yet though.<\/p>\n<p>Click the CDMA tab.\u00a0 Fill in the NAM field with your MDN.\u00a0 I&#8217;m not sure if it matters what you put in here.\u00a0\u00a0 The IMSI_S number is the same thing as the MIN.\u00a0 CricKet will proivide the MIN as it is different than your phone number.\u00a0 The MDN is your 10 digit phone number.\u00a0 Put the MDN in for the &#8220;Directory #&#8221;.\u00a0 The MCC should be 310.\u00a0 There&#8217;s other MCC numbers, but it seems like 310 is the one that should be used. &#8220;11_12&#8221; should be &#8220;00&#8221; (two zeros).\u00a0 Make sure class 1 is unchecked.\u00a0 Leave everything else on the CDMA tab alone.\u00a0 Click the CDMA-2 tab and uncheck the class-1 checkbox and fill out CDMA-2 with the same stuff as CDMA tab.\u00a0 I don&#8217;t know if anything in the AMPS tab needs to be changed, but you could change the SID to the CricKet SID for your area.\u00a0 Here&#8217;s a list of large cities and their SID numbers: <a href=\"http:\/\/cdmagurus.com\/forum\/showthread.php?1497-Cricket-SIDs-by-market\" target=\"_blank\">http:\/\/cdmagurus.com\/forum\/showthread.php?1497-Cricket-SIDs-by-market <\/a><\/p>\n<p>Now move on to the System tab. All you need to edit here are the SID\/NID pairs.\u00a0 The 1st pair should be your home location (hopefully you found a SID in the link above).\u00a0 Double-click the SID\/NID pairs to edit them.\u00a0 The NID should stay at 65535 as far as I know.\u00a0 I added a few other SIDs of places I go to frequently, but it probably doesn&#8217;t matter.\u00a0 Preferred mode, Band Preference, and Roam Preference should all be set to automatic.<\/p>\n<p>Click the M.IP tab (you&#8217;ll have to click the right-arrow button to make more tabs visible).\u00a0 I&#8217;m assuming there won&#8217;t be any profiles here, so click &#8220;Add&#8221;.\u00a0 Otherwise, delete any current profiles.\u00a0 Check the profile enabled box and add your10digitphonenumber@mycricket.com for NAI and Tethered NAI.\u00a0 Home address should all be 0&#8217;s and Primary\/Secondary HA should be all 255&#8217;s.\u00a0 Hit ok.\u00a0 Mobile IP Behavior should be set to&#8221;Mob + Simp f\/back&#8221;.\u00a0 Leave everything else alone.<\/p>\n<p>Click the PPP tab.\u00a0 Click the &#8220;Um&#8221; button in this tab.\u00a0 Add your phone number to tethered NAI (if it&#8217;s not there already) and your10digitphonenumber@mycricket.com is the user id.\u00a0 Password should be blank.\u00a0 Change primary\/secondary DNS to 0&#8217;s.\u00a0 Click the &#8220;AN&#8221; button and add in the same user id.\u00a0 Password again should be blank.<\/p>\n<p>Once everything is all set with all the tabs, click &#8220;Write to phone&#8221;.\u00a0 All this stuff will then be written to the phone.\u00a0 This will take some time, and don&#8217;t interrupt this process as you could really mess up your phone.\u00a0 I guess worst case is you would have to use RSD Lite to flash a Verizon SBF file to the phone (the SBF file contains everything necessary to restore the entire phone including OS and all NVItems) and start all over again.\u00a0 Once the phone is done programming, it will reboot itself.<\/p>\n<p>Since the USB cable is still plugged in, the phone will probably reboot into bootloader mode.\u00a0 Remove the USB cable, then press and hold the power button for a second or so and release it. That will power off the phone.\u00a0 Now turn the phone back on and plug the USB cable back into the phone (and PC) once you see the Motorola M on the screen.\u00a0 Don&#8217;t hold any keys down on the Droid&#8217;s keyboard.\u00a0 You will need the use of ADB debugging via USB (normally loaded when you plug the USB cable into the Droid to transfer files to it) for the rest of the procedure.<\/p>\n<p>Now, you can go back to the HowardForums post and finish the rest of it starting at &#8220;Once phone reboots go to the market using WI-FI and download and install Autostart.exe.&#8221;<\/p>\n<p>Now you can dial *228 and you should hear &#8220;Welcome to CricKet&#8230;..&#8221; and you can go through the activation and such to make sure you have the latest PRL. and other settings\u00a0 If you messed up the MDN, MIN, IMSI&#8230;etc you can program that all on the phone itself if need be so that you don&#8217;t have to fool w\/ QPST to do it.\u00a0 To do that, use the phone dialer to dial &#8220;##PROGRAM&#8221;.\u00a0 Then enter your SPC code of 000000 (six zeros).\u00a0 You&#8217;ll be able to access a lot of the programming junk here instead of using QPST.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I finally was able to get my hands on a Motorola Droid 1 a little over a year after it came out.\u00a0 I&#8217;ve wanted one for a while now, but I didn&#8217;t want to pay for the monthly $30 data &hellip; <a href=\"https:\/\/ahdesign.us\/blog\/motorola-droid-1-cricket-wireless\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":["post-26","post","type-post","status-publish","format-standard","hentry","category-motorola-droid-1-projects"],"_links":{"self":[{"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/posts\/26","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/comments?post=26"}],"version-history":[{"count":6,"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/posts\/26\/revisions"}],"predecessor-version":[{"id":30,"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/posts\/26\/revisions\/30"}],"wp:attachment":[{"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/media?parent=26"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/categories?post=26"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ahdesign.us\/blog\/wp-json\/wp\/v2\/tags?post=26"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}