DirtyRacun S-OFF Public Beta

DirtyRacun is the third release from Team Unlimited. It is a tool for gaining (radio) S-OFF and flashing a custom bootloader that supports full write/erase fastboot commands.

DirtyRacun does not provide root access, however with S-OFF this is a simple process of flashing superuser from recovery once you have finished this process.

DirtyRacun comes with NO WARRANTY (express or implied), and NO GUARANTEE OF FITNESS for any particular task. We have made every effort we can to make this a safe process for users however the authors disclaim any liability for damage to your phone or other materials or devices used during this process. The entire risk of running DirtyRacun lies with you, the user. By downloading and/or using any software, video file or text from this website you acknowledge and accept that the authors are not liable for any loss, material or otherwise howsoever caused.

DirtyRacun will permanently unlock NAND flash write protection on all supported devices.

WARNING: If your device hard-bricks you will need to contact HTC for a replacement. There is no way for Team Unlimited to help you if your device hard-bricks. Be sure that you are following ALL of the directions on this page and in the tool exactly.


Supported Devices:

This version of DirtyRacun supports the following device:

    HTC J (Valentewx) - HBOOT 1.17.0000 ONLY!



  1. Supported Operating Systems:

    We only support Ubuntu 12.04 (and newer) 32bit, you may use a LiveCD if you have the wrong OS installed natively. LiveUSB will NOT work!

    Ubuntu 64bit, Ubuntu versions lower than 12.04, other Linux distros, Virtual Machines and Mac's will NOT work - we will not help you if you break your device!

  2. External SD card (2GB - 16GB) in your device.

  3. The original HTC USB cable for your device.

  4. Ensure that your battery is fully charged.

  5. You must be directly connected to a USB 2.0 port on your computer - USB 3.0 and USB hubs will NOT work!



  • Backup the contents of your phone and external SD card before running this procedure. All data will be wiped from your device during the RUU process and there is small risk that data could be lost from your SD card.

  • Download DirtyRacun:

  • Untar ALL files from the download into a new folder. Do not unzip these files in Windows!

  • cd into the folder where you extracted and run the following cmd:
    Note: This cmd returns a blank new line if you have done it correctly.

    • chmod 755 RabiesShot adb fastboot
  • Relock your device (with your phone in fastboot):

    • Open terminal and cd into your DirtyRacun folder, type:
    • sudo ./fastboot oem lock
  • Download the RUU for your current HBOOT and put it in your DirtyRacun folder:
    This step is REQUIRED even if you are on Stock RUU already!

  • RUU your device (with your phone in fastboot):*
    Please note: After the second cmd your device should have a black background and silver HTC logo. When you see this screen proceed with the third cmd.

    • sudo ./fastboot erase cache
    • sudo ./fastboot oem rebootRUU
    • sudo ./fastboot flash zip RUU.zip
  • If you get the following after you run RUU: "FAILED (remote: 90 hboot pre-update! please flush image again immediately)" then you need to rerun the sudo ./fastboot flash zip RUU.zip command again. Press the up arrow and enter.

  • After you have verified that RUU completed sucessfully type the following cmd:

    • sudo ./fastboot reboot
  • Enable USB Debugging on your device

  • Temproot your phone via any method available - we cannot help with this step and it is REQUIRED!

  • Put your phone into emulator mode by typing the following:

    • sudo ./adb shell
    • su (Skip this step if you see # already. If you still see $ after doing this your temproot failed)
    • echo "ro.kernel.qemu=1" > /data/local.prop
    • exit
    • sudo ./adb reboot
  • Run RabiesShot from terminal

    • sudo ./RabiesShot
  • Wait for the process to complete!

  • Once you are done with S-OFF proceedure and ONLY when you are done...
    Exit emulator mode by typing the following into cmd (with your phone booted into the Android OS)

    • sudo ./adb shell
    • rm /data/local.prop
    • exit
    • sudo ./adb reboot

    Troubleshooting / Errors:

    If at any point during the process the phone turns of and is completely unresponsive for more than 5 minutes and the devices shows as QHSUSB_DLOAD proceed to the instructions for running RacunHunter.


    Linux DirtyRacun

    Stock RUU's:

    RUU 2.05.970.3 - HBOOT 1.17

    Instructions for RUUing in Step 8

    DirtyRacun HBOOTs:

    You must already be DirtyRacun S-OFF to use these HBOOTs.
    With your phone in fastboot type the following cmds:

    • sudo ./fastboot erase cache
    • sudo ./fastboot oem rebootRUU
    • sudo ./fastboot flash zip [file name]
    • sudo ./fastboot reboot

    HBOOT 1.17


    Stuck in QHSUSB_DLOAD?

    Get the RacunHunter!

    Support for DirtyRacun is on IRC channel #unlimited on freenode. If you do not have an IRC client you can use the link below.

    WebUI IRC