Tecno Pop 4 LTE FRP Lock Remove with Hydra Tool
- Keep Press Boot Info
- Select FRP Remove and Click Execute
- Keep Press Boot Info
Code:
-------------------------------------------------------
To Enable BROM Mode :
Method 1 - Bootkey (Vol + - Power) or any combination
Method 2 - Enable Preloader to brom(crashing Method)
Method 3 - Test Point Data0 + ground
To Enable Preloader Mode :
Method 1 - Just Insert cable
-------------------------------------------------------
Searching for MTK Device...Found
MTK Port Type : Flashmode Preloader
FriendlyName : MediaTek PreLoader USB VCOM_V1632 (Android) (COM9)
Device : /5&33881217&0&2
SymbolicName : \\?\usb#vid_0e8d&pid_2000#5&33881217&0&2#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Driver Ver : 01/22/2015,3.0.1504.0
Service : wdm_usb
Openning Port [COM9] Ok
Handshaking...Ok
HwCode : 0699 {MT6739/MT6731}
Hwver : 0000
Target config : 05
SBC : 01 (True)
SLA : 00 (False)
DAA : 04 (True)
SWJTAG : 04 (True)
EPP : 00 (False)
CERT : 00 (False)
MEMREAD : 00 (False)
MEMWRITE : 00 (False)
CMD_C8 : 00 (False)
Connection : Preloader
HW Subcode : 8A00
HW Subcode : CA00
SW Ver : 0000
ME_ID : E195965CE8086819E1A38D1FE762390B
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Preloader To Brom Function.....
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Method 1 Exploit Executed..... [Successfully Crash Preloader.]
Device now is BROM Port
Exploiting Device...
Successfully Exploited..
Handshaking...Ok
Dumping Preloader from Bootrom..
Seeking preloader address..Found @ 0x00200BC4
Starting to dump...
Prel Size : 0x0001CC70
Successfully dump preloader.. [C:\Users\alvin\Desktop\hydra\Boot\PreloaderDump\preloader_k39tv1_bsp.bin]
Target config : 00
SBC : 00 (False)
SLA : 00 (False)
DAA : 00 (False)
SWJTAG : 00 (False)
EPP : 00 (False)
CERT : 00 (False)
MEMREAD : 00 (False)
MEMWRITE : 00 (False)
CMD_C8 : 00 (False)
Connection : BROM
Preparing Download Agent..[MTK_AllInOne_DA_5.2152.bin]
Patching da2 ... Ok
Uploading Stage 1....
Successfully uploaded stage 1, jumping ..
Executing JUMP_DA Address @ 0x00200000
Jumping to 0x00200000 Ok 0xC0
Successfully received DA sync
ONNECTION_AGENT : brom
Sending auto preloader from dump... [preloader_k39tv1_bsp.bin]
Sending emi data.. [DRAM setup passed.]
Sending emi data succeeded.
Uploading stage 2...
Upload data was accepted. Jumping to stage 2...
Successfully uploaded stage 2
ERAM Size : 0x0000000000020000-128 KB
IRAM Size : 0x0000000080000000-2 GB
EMMC Boot1 Size : 0x0000000000400000-4 MB
EMMC Boot2 Size : 0x0000000000400000-4 MB
EMMC RPMB Size : 0x0000000001000000-16 MB
EMMC USER Size : 0x0000000747C00000-29.121 GB
EMMC CID : 150100514436334D4201202306D2688B - QD63MB
HW-CODE : 0x699
HWSUB-CODE : 0x8A00
HW-VERSION : 0xCA00
SW-VERSION : 0x0
CHIP-EVOLUTION : 0x0
DA-VERSION : 1.0
Speed : high-speed
Upload data was accepted. Jumping to stage 2...
DA Extensions successfully added
Reading Partition Table ..
Partition Count : 40
--------------- Reading build.prop content ---------------
Product : k39tv1_bsp
ID : QP1A.190711.020
SDK : 29
Release : 10
ABI : armeabi-v7a
CPU abilist : armeabi-v7a,armeabi
Locale : en-US
Description : full_k39tv1_bsp-user 10 QP1A.190711.020 1677044979 release-keys
Device : TECNO-BC1s
Display ID : BC1s-VQ653AB-QGo-OP-230221V021
Security Patch : 2023-02-05
Fingerprint : TECNO/BC1s-OP/TECNO-BC1s:10/QP1A.190711.020/AB-OP-230221V021:user/release-keys
--------------- end of build.prop content ---------------
Reading IMEI........
IMEI1 : 35082**********
IMEI2 : 35082**********
-------------------------------
Bootloader Status...
Bootloader : Locked
-------------------------------
Backing up Security..
- preloader(preloader.bin), 512 KB = Ok [preloader_k39tv1_bsp.bin]
*Creating Scatter file... C:\Users\alvin\Desktop\hydra\Backup\MTKBKUP\0699_EWWW965CE8086819E1A38D1FE762390B\Auto\0707244083426\6739_Android_scatter.txt
- pgpt(pgpt.bin), 32 KB = Ok
- nvram(nvram.bin), 5 MB = Ok
- nvdata(nvdata.bin), 32 MB = Ok
- frp(frp.bin), 1024 KB = Ok
- protect1(protect1.bin), 8 MB = Ok
- protect2(protect2.bin), 10.867 MB = Ok
- persist(persist.bin), 48 MB = Ok
- proinfo(proinfo.bin), 3 MB = Ok
- nvcfg(nvcfg.bin), 8 MB = Ok
- sec1(sec1.bin), 2 MB = Ok
- seccfg(seccfg.bin), 8 MB = Ok
- lk(lk.bin), 1024 KB = Ok
Backup Done!!!
Elapsed Time : 00:00:36

- Select FRP Remove and Click Execute
Code:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Service Function
Factory Reset Protection[FRP]
Auto
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Searching for MTK Device...Found
MTK Port Type : Flashmode BROM
FriendlyName : MediaTek USB Port_V1632 (COM6)
Device : /5&33881217&0&2
SymbolicName : \\?\usb#vid_0e8d&pid_0003#5&33881217&0&2#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Driver Ver : 01/22/2015,3.0.1504.0
Service : wdm_usb
Openning Port [COM6] Ok
Reading Partition Table ..
ERAM Size : 0x0000000000020000-128 KB
IRAM Size : 0x0000000080000000-2 GB
EMMC Boot1 Size : 0x0000000000400000-4 MB
EMMC Boot2 Size : 0x0000000000400000-4 MB
EMMC RPMB Size : 0x0000000001000000-16 MB
EMMC USER Size : 0x0000000747C00000-29.121 GB
EMMC CID : 150100514436334D4201202306D2688B - QD63MB
HW-CODE : 0x699
HWSUB-CODE : 0x8A00
HW-VERSION : 0xCA00
SW-VERSION : 0x0
CHIP-EVOLUTION : 0x0
DA-VERSION : 1.0
Speed : high-speed
Partition Count : 40
--------------- Reading build.prop content ---------------
Product : k39tv1_bsp
ID : QP1A.190711.020
SDK : 29
Release : 10
ABI : armeabi-v7a
CPU abilist : armeabi-v7a,armeabi
Locale : en-US
Description : full_k39tv1_bsp-user 10 QP1A.190711.020 1677044979 release-keys
Device : TECNO-BC1s
Display ID : BC1s-VQ653AB-QGo-OP-230221V021
Security Patch : 2023-02-05
Fingerprint : TECNO/BC1s-OP/TECNO-BC1s:10/QP1A.190711.020/AB-OP-230221V021:user/release-keys
--------------- end of build.prop content ---------------
Reading IMEI........
IMEI1 : 35082*********
IMEI2 : 35082*********
-------------------------------
Bootloader Status...
Bootloader : Locked
-------------------------------
Rebooting Device...
Reboot Option : RebootToNormal
Rebooting Operation Done!!!!
Action Result : Ok
Elapsed Time : 00:00:06
