Unlocking the 3G iPhone (with 2.2.1 firmware) using PwnageTool in Expert mode
intel Mac & PPC
Page 2 of 2
Step 4.
If iTunes was already open you will get this pop up message. Just click OK.
You will need to unplug your USB cable, and then plug it back in. You will not receive this pop up
message. Just click OK.
iTunes should look like this. Press the Option key on your keyboard, and click the Restore button in iTunes.
In the pop up window that opens, navigate to the custom .ipsw file that was saved to your desktop by
PwnageTool during Step 3.
You will see various status bars, while the restoring process continues. If you chose a custom boot logo, you will
see it display on the iPhone at this point.
You will also see this status bar graphic on the iPhone as the installation process continues.
Once the restore process has finished you will get this message.
iTunes should prompt you to set up the iPhone. This is your big chance to restore your backup (personal
settings, programs, et. cetera) to the iPhone.
Then this screen will appear, confirming you are on 2.2.1 firmware.
Step 5.
You should now be at your SpringBoard. Cydia and Installer should be here. Note: there is no carrier
name or signal bars yet (if you have your T-Mobile SIM installed, like I do. Launch Settings, then
press General, Network and make sure that your Enable 3G switch is set to OFF.
Launch Cydia, and you will be greeted with this screen. I always choose Developer (No Filters).
This is the default screen in Cydia.
Press the Sections button at the bottom, then press All Packages toward the top. Scroll down the list,
and press yellowsn0w.
Press the Install button. Press the Confirm button.
Press the Return to Cydia button when the installation has finished. Press and hold the Power (sleep/
wake button) until the slide to power off message appears. Turn off the iPhone, then turn it back on.
When your iPhone reboots you should now see your carrier logo and have signal bars. If you launch
Settings, you will see the new Carrier entry showing your unauthorized carrier as the active cellular
connection.
If you launch Settings, and press, General, About, you can confirm your firmware versions here. I am
on 2.2.1 firmware, and my modem (baseband) was left alone. You are finished.
Never, EVER update/restore this phone using iTunes directly. If you should need to restore, then you
must use the custom firmware file you created earlier. If you don't, you will lose your unlock, possibly
permanently.
Note: I always erase my Serial Number, Wi-Fi Address, Bluetooth, IMEI and ICCID from my screen shots
for privacy reasons.
Once unlocked, when you connect to iTunes it will now display your phone number. I erased mine for
obvious reasons.