A virus masked with encryption? - Security Discussion

I left my Lenovo TPT unattended for two days on.
When I've tried to use it again I got a message that encryption did not end correctly to make a reset to original values.
This was strange and because recovery was not working I did tried that step as well without success.
Due to low battery, I manage to access settings and came to realize that there are strange certificates install like TURKTRUST Digital Certificate which I came to realize is reported to be a virus http://eromang.zataz.com/2013/01/04/...ctive-attacks/
In recovery I see that I cannot mount the internal SD or data. I can connect trough ADB but I'm not an expert able to use it properlly.
Any ideas on how to recover my TPT?
Using adb I manage to get the logcat ...hope someone is expert enough to go around this problem.
I only need to format / mount SDCard and data which is blocked now ...
Thanks in anticipation.

Related

[Q] Writing to interal sdcard flash (/mnt/sdcard) galaxy s i9000 not possibe

Hello !
I have a big problem with my galaxy s.
Since January i am working with my JPY firmware quiete fine. On sunday the phone rebooted without anything done by me. Afterwards my homescreen was empty.
Most of my apps are not working now. So i have done a wipe. Nothing, the same. Interesting is, that all my data was still on the device. Then i try to format the internal sd. Not working, no error message. When I delete all files and deinstalled all apps, everthing was gone. After a reboot all data is back on the internal sd as before.
OK then i tried to flash different 1 and 3 file firmware versions with odin(also with repartitioning). But no version is really working and i never get to the homescreen. So I flashed the JPY back. Then everything is like before my first steps. All data is on the phone, i can not delete anything.
I tried do delete the storage also with recovery mode. Nothing.
I tried with adb (android sdk), deleted all files in /mnt/sdcard. After a remount all data appears back.
What can i do to get my phone working ? I have found no possibility so far.
Thanks in advance for your help!
Frederik
Fred001 said:
Hello !
I have a big problem with my galaxy s.
Since January i am working with my JPY firmware quiete fine. On sunday the phone rebooted without anything done by me. Afterwards my homescreen was empty.
Most of my apps are not working now. So i have done a wipe. Nothing, the same. Interesting is, that all my data was still on the device. Then i try to format the internal sd. Not working, no error message. When I delete all files and deinstalled all apps, everthing was gone. After a reboot all data is back on the internal sd as before.
OK then i tried to flash different 1 and 3 file firmware versions with odin(also with repartitioning). But no version is really working and i never get to the homescreen. So I flashed the JPY back. Then everything is like before my first steps. All data is on the phone, i can not delete anything.
I tried do delete the storage also with recovery mode. Nothing.
I tried with adb (android sdk), deleted all files in /mnt/sdcard. After a remount all data appears back.
What can i do to get my phone working ? I have found no possibility so far.
Thanks in advance for your help!
Frederik
Click to expand...
Click to collapse
try to update it using kies or if u have latest version then try flash your device using odn flasher
Thanks for your help harmandeep45. But all this is already done. I worked on this issue little longer and can say that there is some unrepairable problem with the internal sd. I can not delete any partition neither with adb (parted /dev/block/mmcblk0p1 rm). When I do a print everything is there. I am able to mount and unmount the partitions. No problem. But it is not possible to reorganize them. Even if i write on the sdcard partition, after a remount it is as before the write. Maybe the flash memory is broken. Does anybody had the same issue? I already tried the things written in this post, but without luck : http://forum.xda-developers.com/archive/index.php/t-845708.html
I have the same problem, i had installed another firmware on my sgs and start throwing me program errors I had before in my other firmware and when it comes to memory I saw that the folders that were there had not cleared and when I trying to delete the folders and files reappeared.
Ok, what i have tested is to flash different firmware versions. Nothing worked. I used the debug console adb to log in and tried to delete the partitions from /dev/block/mmcblk0 with parted. Nothing happens. I am not able to delete them. I don't want to send the phone to the samsung service, because there is important company data on it, like emails, banking, ebay, etc. I tried to mount it in Linux as usb memory device and used gpartet to create new partitions and overwrite all with dd if=/dev/zero of=/dev/sdb1, but after reboot everything was like before. Is there any other possibility to delete the flash???
Fred001 said:
Ok, what i have tested is to flash different firmware versions. Nothing worked. I used the debug console adb to log in and tried to delete the partitions from /dev/block/mmcblk0 with parted. Nothing happens. I am not able to delete them. I don't want to send the phone to the samsung service, because there is important company data on it, like emails, banking, ebay, etc. I tried to mount it in Linux as usb memory device and used gpartet to create new partitions and overwrite all with dd if=/dev/zero of=/dev/sdb1, but after reboot everything was like before. Is there any other possibility to delete the flash???
Click to expand...
Click to collapse
you have to flash it with jtag box riff, but I doubt you have one, you have to find a place where they have the box

[Q] Need to recover data after oem unlock

I forgot that after oem unlock all data + sdcard is wiped out. So i had some photos that i need to recover from that device. Is there any thing that i can do to recover them. Any good software alternatives?. I tried testdisk but it couldn't do much , since it couldn't detect partition table type. Currently i am using PC Inspector File Recovery, but lets c what happens. Meanwhile I need some recommendation from the forum?
I don't know if it can help you but take a look at Recuva from Piriform (less than 10 posts, cannot paste a link :'( )
Don't transfer data to the sdcard. Use cwm to mount the sdcard to a computer. Then use a couple of different recovery apps to try and piece your drive back together through the comp.
Its not a thorough wipe so as long as you don't write to the sdcard you should get a decent amount back. This is the most important step. Even booting into android could force writes you don't want.
I am in through CWM
Yeah I am mounting USB via CWM, actually i wanted to copy all the data to the pc and then install CM9 but i saw that there was nothing else remaining
Let see what happens I will be using some recovery software. I will be reporting back if I find something that works better than others

[Q] Failed to mount /data

Hello, I wanted to know if any of you could help me.
My GT-N8000 suddenly shut down, which wouldn't have been that strange if not for the fact that it did so without the usual "shutting down" message. I plugged it in the charger and was greeted on boot by the message "encryption failed, please perform a factory reset" (actual message : "echec du chiffrage"). I have no root nor cfw (I planned on waiting until the end of the warranty, that is next month). I also didn't update to kitkat so the only reason I can see to this problem would be the tablet having shut down improperly as it was low on battery.
I already tried rebooting several times with and without the sd and sim, to no avail, so it seems I will have to reset. Recovery says /data cannot be mounted, so i was wondering if it affected the internal sd and if there was a way to recover the data on it or is it definitely lost ?
I have attached the recovery below. Thank you for your help.
[edit] although I wasn't counting much on it working, I tried to update to Kitkat trough Odin3 just in case. The only change is that now i've got a prettier error message (and startup sound).
Seems like my files are gone for good, but i'm giving an update in case someone has the same kind of problem but more luck than me.Most of the important stuff was backed up but it still sucks.
I wanted to do an adb pull, but due to the fact that it prevented my note from being detected when in MTP mode, I had USB debugging disabled (though I don't know if the note remembered my settings at that point). I installed Clockwork Recovery via Odin to enable adb and did my pull...
C:\Users\XXXXXX\Desktop\adt-bundle-windows-x86-20140321\sdk\platform-tools>adb pull /data
pull: building file list...
0 files pulled. 0 files skipped.
so it cannot be pulled (not surprising as it cannot be mounted). But this could be useful for someone who has a minor error preventing them to boot, but who can access recovery and download mode and would like to make a backup before wiping.

Mounting a supposedly corrupted adopted-SD with TWRP?

Hi all. Apologies for the wall of text, I have a few questions following all of the background below.
Device info: Samsung Galaxy S7 32GB running LineageOS 16.0, NOT rooted; SD Card in question is a 128GB Sandisk MicroSD. All commands being run on computer running Ubuntu 19.10.
Yesterday, my phone gave me the "SD Card Missing" notification suddenly, and in the settings it said it was corrupted. I had had it set up as adopted storage, so it isn't a matter of just losing photos and such unfortunately - it seems as though there's important app and system data on it.
After trying several recovery programs to no avail, I came across this thread:
https://forum.xda-developers.com/general/help/corrupted-sd-card-adoptable-storage-t3801250
Which is very similar to my situation. Unfortunately I didn't find a fix here, but I did manage to make a full .img copy of the card itself, and find the encryption key at "/data/misc/vold/expand_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.key" as per https://nelenkov.blogspot.com/2015/06/decrypting-android-m-adopted-storage.html . The problem I ran into with this guide was that I couldn't get the dmsetup command to work. However, when reading the comments of the post to see if anyone else had the problem, I saw someone mention retrieving the files through TWRP. So, I put the card back in the phone, and booted into TWRP.
In TWRP, I was able to browse through the SD Card perfectly normally with the file manager, despite the fact that it still read as corrupted when booting back into the system. So, I used adb pull (side question on this later) to retrieve the folders I was most worried about - largely what I could find of app data, my photos and videos, etc. I did not just pull the whole card at once, and I'll elaborate on why when I get to the side question about adb pull.
So, here are my questions:
1. Is it possible to mount this SD Card back to normal through TWRP? If so, how? I'd like just enough so that I can restore my apps as is onto the phone, and then convert the card to portable storage to avoid this mess again. While I do have the data pulled, it's little things like NewPipe playlists that I've got in mind here.
2. If above is not possible, how much loss am I looking at if I choose to 'forget' the adopted card? Will I have to do a factory reset?
3. (adb) When doing the adb pull, it was unable to skip any files it couldn't copy - i.e. corrupted images - and would simply stop on finding one. This means that, for example, in one folder it hit a corrupted file after 3400 successes, and stopped without copying the remaining 300. Naturally, if I had just done 'adb pull /external_sd/', then I probably would have lost a lot more because of this. Can I add any options to the command adb pull to circumvent this? I was unable to find any decent documentation on the command, but maybe I was searching for the wrong thing.
Any and all help is much appreciated, thanks in advance!
johnfr92 said:
Hi all. Apologies for the wall of text, I have a few questions following all of the background below.
Device info: Samsung Galaxy S7 32GB running LineageOS 16.0, NOT rooted; SD Card in question is a 128GB Sandisk MicroSD. All commands being run on computer running Ubuntu 19.10.
Yesterday, my phone gave me the "SD Card Missing" notification suddenly, and in the settings it said it was corrupted. I had had it set up as adopted storage, so it isn't a matter of just losing photos and such unfortunately - it seems as though there's important app and system data on it.
After trying several recovery programs to no avail, I came across this thread:
https://forum.xda-developers.com/general/help/corrupted-sd-card-adoptable-storage-t3801250
Which is very similar to my situation. Unfortunately I didn't find a fix here, but I did manage to make a full .img copy of the card itself, and find the encryption key at "/data/misc/vold/expand_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.key" as per https://nelenkov.blogspot.com/2015/06/decrypting-android-m-adopted-storage.html . The problem I ran into with this guide was that I couldn't get the dmsetup command to work. However, when reading the comments of the post to see if anyone else had the problem, I saw someone mention retrieving the files through TWRP. So, I put the card back in the phone, and booted into TWRP.
In TWRP, I was able to browse through the SD Card perfectly normally with the file manager, despite the fact that it still read as corrupted when booting back into the system. So, I used adb pull (side question on this later) to retrieve the folders I was most worried about - largely what I could find of app data, my photos and videos, etc. I did not just pull the whole card at once, and I'll elaborate on why when I get to the side question about adb pull.
So, here are my questions:
1. Is it possible to mount this SD Card back to normal through TWRP? If so, how? I'd like just enough so that I can restore my apps as is onto the phone, and then convert the card to portable storage to avoid this mess again. While I do have the data pulled, it's little things like NewPipe playlists that I've got in mind here.
2. If above is not possible, how much loss am I looking at if I choose to 'forget' the adopted card? Will I have to do a factory reset?
3. (adb) When doing the adb pull, it was unable to skip any files it couldn't copy - i.e. corrupted images - and would simply stop on finding one. This means that, for example, in one folder it hit a corrupted file after 3400 successes, and stopped without copying the remaining 300. Naturally, if I had just done 'adb pull /external_sd/', then I probably would have lost a lot more because of this. Can I add any options to the command adb pull to circumvent this? I was unable to find any decent documentation on the command, but maybe I was searching for the wrong thing.
Any and all help is much appreciated, thanks in advance!
Click to expand...
Click to collapse
Hey...did u get dmsetup to work?

failed Lineage18.1 update, trying to regain encrypted data

Hey guys,
my first Thread/post here. cause I have a slight problem (I do hope that I'm in
Today, I wanted to make an update of LineageOS 18.1 for my Samsung S7 herolte mobile. Therefore I use the custom ROM from Ivan Meler. Since some time, a bug accures, that an update needs a complete wipe of everything, cause elseways, Lineage wouldn't boot - I don't know why. This is something I completely forgot, so I never did a backup - something I usually do.
First Idea to solve it was simply do a backup with TWRP. This fails right away, because I used my external SD Card as a expansion for the internal storage. Thats a function of android as far as I can tell you can use at first use of the sdcard. Anyways, I can't mount the sdcard so that method fails.
Second try is using adb. The Partition is encrypted, so I use
twrp decrypt "PASSWORD" as described here. But TWRP gives me Failed to decrypt data. with no further details why. I am very certain I enter the correct password. I don't understand why it fails and never found a way to find further details to it. The only and easiest way to see it would be, that the data is corrupted but I doubt it. Starting up lineage fails (restart) after the submission of the passphrase.
My third Idea is using USB OTG but I lack the hardware to do so. Well, I could use my computer to do that, but TWRP seems to not recognise the computer as a storage device.
Does anyone have an Idea how to solve that mess? I don't want to loose 6 Months of data...
Edit: As I continue to learn: maybe the recovery.log from twrp helps - I couldn't find sth useful in there.

Categories

Resources