LG .kdz firmwares for all models. - G2 General

Hello.
Maybe you guyz don't know me but I deal with sharing links for normal and beta .kdz firmwares for all LG devices since 2009.
Now it very hard since LG has changed links from /swdata/WDLSW/Model/Suffix/V99X_00/V99X_00.kdz to /dn/downloader.dev?fileKey=FWXXXX86573210987654321/V99X_00.kdz
We can't generate manually links for firmware cause this XXXX defines all (model+suffix+kdz version).
It would be great if someone he could crack the code but I'm afraid that this is random I mean every next relased file for any phone have another number.
I have a great automatic script that shows all normal .kdz firmwares links for all phone models but it need very good server cause it uses a lot of data + cpu usage. I also don't know how much time it will work since LG is changing sites links every day.
It's very hard now. Nobody has access to B2B.
I got also email from lg-phone-firmware.com admin that if I will not help him he will be forced to close the page cause he is generating links manually.
About beta firmwares it's almost impossible to download links.
We must convert new file type firmware link to old file type firmware link and do some trick to download it.
All old firmware links are not working now.
Today LG has changed download method of Service Manuals, SIB's etc. Every action need user name and password so if you are not employee you will do nothing. Old method is working today but tomorrow may not work.
I've decided to post it in G2 section cause this phone is new and probably everyone would like to have all the latest and unbranded firmware.
LG may force us to change the firmware to other firmware that is offered by your branding operator will be impossible.
We need to help each other. Everybody is welcomed.
If know anything about php, javascript, etc.you can help me to create site with scripts for "the necessary software" for everyone who has LG mobile ;]
If you can decompile programs, you know reverse engineering mail me on PM or in this topic and I will tell you what you can do to help.
If you have any idea about hosting server (I don't have any job so I don't have a money to pay for good server) post it.
Everyone is obliged to comment on the sharing of ideas ;]

hey think you can post some examples of old style links against new style links please?
edit:
would be better if you can show up in irc. can bounce information between us
#Lproj @ freenode (see my signature)
edit 2:
looking at the way this is done, I would agree that this is random. however I feel this is going to change again soon. probably to include all the static numbers in the randomisation. your best bet is to try to get behind the site and see the actual database, which isn't going to happen
edit 3:
you'd be able to access a searcher which the new b2c software uses. I have a friend who is good with software. I'm seeing if they can help out on this
edit 4:
ok I'm making progress. I've managed to get the info for all the drivers so far based on the country with the new method of fetching files
http://csmg.lgmobile.com:9002/csmg/b2c/client/web_model_list.jsp?country=GB
got to get food. will be back soon
edit 5:
got a method to get them, but it needs the imei number. not ideal

Try this link and get off my LG L9 forum unless you can unlock our bootloader.

not for all models, but if you know the imei following thread may help
http://forum.xda-developers.com/showthread.php?t=2484476
Sent from my LG-D802

Guyz I don't need any IMEI numbers. I can have all firmware links for any model.
The question is how much time it will work.
New links are same as old but you need a permisson to download from old link.
You cannot also download test firmwares even in new links since 30 oct.
I have some trick. You need some page that allow you to download files. It's like you are downloading by internal IP server (use csmg page to download files from csmg pages).

Guyz I don't need any IMEI numbers. I can have all firmware links for any model.
The question is how much time it will work.
New links are same as old but you need a permisson to download from old link.
You cannot also download test firmwares even in new links since 30 oct.
I have some trick. You need some page that allow you to download files. It's like you are downloading by internal IP server (use csmg page to download files from csmg pages).

RW firmware is other than FW ;]
If you have all FW links for 1 model you should sort it by relase date. Only 1st number is changing for example FW3 than FW6 than FW9 and whe have 3 firmwares with same name for same model relased in same time. So I think it just each successively released firmware gets sequence number.

does this help?
http://forum.xda-developers.com/showpost.php?p=47074102&postcount=113

Yea it will help you if you have bag of money ;]
I have access to view all normal .kdz files and to download service manuals + sibs but not .dz firmwares.

try inserting your fancy links into JDownloader to pass trough the encryption and permission problems... I have been amazed by that software a few times so far
Greetings

hello bigboyPL
BigBoyPL said:
Guyz I don't need any IMEI numbers. I can have all firmware links for any model.
The question is how much time it will work.
New links are same as old but you need a permisson to download from old link.
You cannot also download test firmwares even in new links since 30 oct.
I have some trick. You need some page that allow you to download files. It's like you are downloading by internal IP server (use csmg page to download files from csmg pages).
Click to expand...
Click to collapse
It is easy to grab the download link of the .kdz file even without IMEI, but it seems that i can only get the model kdz file for those support web upgrade. Those firmware pushed via OTA like the LG E970 can not download after LG BLOCK THE B2B ACCESS
---------- Post added at 06:47 AM ---------- Previous post was at 06:42 AM ----------
BigBoyPL said:
Yea it will help you if you have bag of money ;]
I have access to view all normal .kdz files and to download service manuals + sibs but not .dz firmwares.
Click to expand...
Click to collapse
Hi, BIgboyPL.
Can you access the service manual?, how about tot firmware?

I have created some page:
http://csmgb2b.zz.mu/test_csmg.php?model=LGD802
if you will change model to other it will show you other.
I can't access Service manuals and .tot or .dz but I have SIBs.

Delete

hi bigboy
Hi master,
May you please share how did you get this work via PM?
Do you have a facebook or Google Plus, i can reach you..
I found some hidden menu from the "NotiAgent.exe" and "B2BFileUpdateAgent.exe", have you ever able to access that?
I can access the ARC area now, Need to further find out how to continue..

BigBoyPL said:
I have created some page:
http://csmgb2b.zz.mu/test_csmg.php?model=LGD802
if you will change model to other it will show you other.
I can't access Service manuals and .tot or .dz but I have SIBs.
Click to expand...
Click to collapse
LG blocked all access again,,

{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
That's why it's not working ;]

BigBoyPL said:
That's why it's not working ;]
Click to expand...
Click to collapse
i got this too when I want to upgrade

Guyz everything is working now ;]

Related

Guaranteed working(JIT V2)-SK_007(Stock)Rom_final-JIT-v2-[For Xrecovery]-30/12/10-

Details:This is a Stock SonyEricsson 2.1 2.0.2.A.0.24 Rom(rooted with JIT v2 Enabled) baseband 2.0.49,Xrecovery installed.it has been updated now,all the previous problems,for e.g old baseband,google account problems and others have been rectified and now it is with the latest JIT v2,all the previous download links have been updated to this new ROM.
How to install:
There are two steps to install,u can opt for any of them if one does not work
1.Copy the zip file[SK_007(Stock)Rom_final-JIT-v2.zip] to the root of your sd card,then reboot into xRecovery and click intall custom zip,then select SK_007(Stock)Rom_final-JIT-v2.zip ,it will start installing it,when finished reboot your device and Voila! its done,Enjoy.....
2.After downloading [SK_007(Stock)Rom_final-JIT-v2.zip] extract it,you will find a folder named "2010-12-29.18.53.53".Copy the following folder in xrecovery/backup folder in your sd card,after that reboot your X10 into xrecovery mod and restore "2010-12-29.18.53.53",and Voila.its done,Enjoy....
3.Go in xrecovery/backup folder(u can use root explorer or u can simply plug in your X10 to your pc with sd card mounted),there will be atleast one folder in it(if u have created a any backup(if not then first reboot into xrecovery and create a backup),replace all the 4 files,i.e cache,data,nandroid,system(img) with the 4 files u find in the extracted filer(2010-12-29.18.53.53),after that reboot your X10 in xrecovery and restore that folder,and yeah it will start restoring,enjoy.
Special Note:if u ant the latest baseband then after this u also have to flash sin files using flasher gui or non gui(prefered).
Note:Though the first step sounds a bit easy but i would presonally recommend second or third step,coz it always work and you will never see MD5 mismatch.
Whats included in this Rom:
1.It is based on the latest 2.0.2.A.0.24 Rom
(Firmware version 2.1-rooted-zdz)
(Baseband version 2.0.4.9)
(Kernel version 2.6.29
[email protected]#1)
2.Off course it is rooted
3.it is latest JIT v2 enabled(previously it was JIT v1 enabled)now you can get a score of upto 35 Mflops in linpack
4.latest market
4.What else can be in it as it is a stock ROM and i created it only coz some people asked me to do so....
Download links:
Mediafire
http://www.mediafire.com/?c729vdhheqx2sgj
Hotfile
http://hotfile.com/dl/92884984/40a536f/SK_007(Stock)Rom_final-JIT-v2.zip.html
Uploading.com
http://uploading.com/files/5ad852m2/SK_007%28Stock%29Rom_final-JIT-v2.zip/
I havent uploaded on popular servers like rapidshare and megaupload as they delete files in 48 hours and it is inccessible in some countries(according to some users at XDA)
Screenshots:
I am also adding some screenshots as everyone was asking for them,and so that you can confirm that it is based on latest firmware 2.0.2.A.0.24 and baseband version 2.0.49,and two snaps to show that it is JIT v2 enabled,now u can get a score of 35MFlops in linpack and above 820 in quadrant
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Note:I hope you will like my work,dont forget to thank me,Regards....
Special Note:I can personally guarantee that this time you will not experience any problem regarding installation or any google or other accounts...
Cheers for this
1) my usual question:
how is the camera and audio on this rom??
2) can we get some screen shots please!?
3) what screen lock are you using?
So all you've done is mirror this thread - Generic 2.0.2.A.0.24 firmware (21/12/2010) | rooted | for xRecovery + X10flasher?
ballubas said:
1) my usual question:
how is the camera and audio on this rom??
2) can we get some screen shots please!?
3) what screen lock are you using?
Click to expand...
Click to collapse
It is stock rom, only rooted. Read everything will work because it is a SE stock rom. This is not custom rom, only rooted and with Jit. Is it x10i??
XperiaX10iUser said:
So all you've done is mirror this thread - Generic 2.0.2.A.0.24 firmware (21/12/2010) | rooted | for xRecovery + X10flasher?
Click to expand...
Click to collapse
Not mirrored. itht that thread you have to flash after using update.zip.
With this, you don't have to flash, just use Xrecovery. Nothing else.
superleeds27 said:
Not mirrored. itht that thread you have to flash after using update.zip.
With this, you don't have to flash, just use Xrecovery. Nothing else.
Click to expand...
Click to collapse
Plus it comes already JIT'ed.
No this seems to be a port of the newest firmware with jit enabled
also im not deleting work just because another user has already done it
superleeds27 said:
Not mirrored. itht that thread you have to flash after using update.zip.
With this, you don't have to flash, just use Xrecovery. Nothing else.
Click to expand...
Click to collapse
If you don't flash, your baseband will not change.
Has anyone try it Android pls some screenshots.
Sent from my X10i using XDA App
cobrato said:
If you don't flash, your baseband will not change.
Click to expand...
Click to collapse
I dont think the baseband has changed anthing tbh! Well, we havent figured out any changs as of yet.
Thanks, but can you upload to somewhere else.
Download not available
The following download is not available:
http://rapidshare.com/files/439653899/SK_007_Stock_Rom.zip192378 KB
The file of the above link no longer exists. This could be for several reasons:
■The uploader deleted the file
■The file contained illegal contents and was deleted from our Abuse team
■The file is incorrect
■The server is busy and can not process the request.
Unassigned file limit of 10 downloads reached.
gregy74 said:
Thanks, but can you upload to somewhere else.
Download not available
The following download is not available:
http://rapidshare.com/files/439653899/SK_007_Stock_Rom.zip192378 KB
The file of the above link no longer exists. This could be for several reasons:
■The uploader deleted the file
■The file contained illegal contents and was deleted from our Abuse team
■The file is incorrect
■The server is busy and can not process the request.
Unassigned file limit of 10 downloads reached.
Click to expand...
Click to collapse
Ok,recheck the first post within half an hour,another download link would be available,currently uploading..............
Download links updated,Enjoy............
Totally messed this up?
Left your Gmail account half signed in, keeps asking for a password.
Also states that the firmware is .504?
superleeds27 said:
Totally messed this up?
Left your Gmail account half signed in, keeps asking for a password.
Also states that the firmware is .504?
Click to expand...
Click to collapse
As far as the gmail account password is concerned,did u do a factory reset after installing this ROM,i suggest you to do it,it will resolve that problem,and the second problem firmware .504,r u serious,no one has complained me so far about this,but if u say i can recheck it,give me some time..
Regards..
superleeds27 said:
Left your Gmail account half signed in
Click to expand...
Click to collapse
That should be the first thing you sort out.
XperiaX10iUser said:
That should be the first thing you sort out.
Click to expand...
Click to collapse
I have already told him how to sort this out,read the post above your post,btw for your kind information
he is the only person who has complained about this,many other people who downloaded this are using flawlessly(recieved some PM's from some members)I hope that his problem will be rectified as well.
Regards....
Dont think you have to explain yourself, especially to someone who does not like that you have put your ROM for download, btw its perfect no probs with it. :+)
Sent from my AOSP on Xperia (US) using Tapatalk
briandevlin said:
Dont think you have to explain yourself, especially to someone who does not like that you have put your ROM for download, btw its perfect no probs with it. :+)
Sent from my AOSP on Xperia (US) using Tapatalk
Click to expand...
Click to collapse
Actually you r right buddy,Thank God as it is working fine and thank you very much as you liked my work and gave your positive feedback.
Regards.....

[Guide] Flash stock firmware when boot loop (F320- Korea G2 version), Unbrick LG G2

I tested on LG G2 Korea Version F320S, F320L, F320K
- Why bootloop?: Some people Update OTA after flash CWM or TWRP so it will be bootloop. Or some strange reasons
- What should we do when we can not flash Stock firmware by FlashTool.1.0.54?
Let do follow this guide:
- Download file:
Flashtool V1.5 --> http://www.fshare.vn/file/TNVQZ9N74T ( tks to GSM Hosting forum )
Crack Flashtool : http://www.fshare.vn/file/TS1SGGVYWT ( tks to GSM hosting Forum )
File .TOT firmware :
F320S ->>> http://www.fshare.vn/file/T3SZR52W6T
F320K ->>> http://www.fshare.vn/file/TZRVMVMPFT
F320L V11c -->>> http://www.fshare.vn/file/TVR9DPAC7T
.dll file F320S/L/K >----- http://www.fshare.vn/file/TKW8J7QPQT
Driver: http://tool.xcdn.gdms.lge.com/dn/downloader.dev?fileKey=UW00120120425
- Let do:
Step1: Install Flashtool V1.5. Default install folder C:\LG\LGFlashtool
Copy crack file Megalock.dll to C:\LG\LgFlashtool
Step2: Enter download mode: Turnoff, push vol+ and plug USB cable in
Open Device Manager on your computer and choose COM41 for phone connection:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Step3: Open Flashtool, choose .dll and .tot file, then fresh yellow icon like this:
Step4: When Flashtool show Realdy, push USB out for 5secs and plug in again. Flash tool will automatic run
Step5: Wait for finishing:
Read more: http://choimobile.vn/threads/huong-dan-cuu-soft-brick-lg-g2-f320s-l-k.12932/#ixzz2h8Fy9fJB
Suggest you read the rules for XDA no warez allowed, CRACKED SOFTWARE = WAREZ!
fma965 said:
Suggest you read the rules for XDA no warez allowed, CRACKED SOFTWARE = WAREZ!
Click to expand...
Click to collapse
This is extremely useful, please blackout offending list and leave the post alone.
JoeTF said:
This is extremely useful, please blackout offending list and leave the post alone.
Click to expand...
Click to collapse
As a RC i can't do that.
Even though it is cracked, we don't see it as "warez". Almost every device has it cracked, so noone would be able to use it if we wouldn't allow it.
I mean, we also "crack" the bootloader of devices, which would be considered as warez, too, in that case
Cheers
laufersteppenwolf said:
Even though it is cracked, we don't see it as "warez". Almost every device has it cracked, so noone would be able to use it if we wouldn't allow it.
I mean, we also "crack" the bootloader of devices, which would be considered as warez, too, in that case
Cheers
Click to expand...
Click to collapse
hmm i guess, the way it was worded seems like you were cracking software tbh. my bad
fma965 said:
hmm i guess, the way it was worded seems like you were cracking software tbh. my bad
Click to expand...
Click to collapse
oops, may be a bit unluckily worded... the first "we" was meant as the mod staff, and the 2nd "we" as xda in general
laufersteppenwolf said:
oops, may be a bit unluckily worded... the first "we" was meant as the mod staff, and the 2nd "we" as xda in general
Click to expand...
Click to collapse
sorry, yeah i meant the OP not your reply
fma965 said:
sorry, yeah i meant the OP not your reply
Click to expand...
Click to collapse
Good post. Please leave this post coz I am also the lucky guy can get repair my bricked G2 using this usefuly TOT recovery method.
If possible, remind to set back correct version number (F320 L / K / S) in build info. which match with your IMEI#.
dokyson said:
I tested on LG G2 Korea Version F320S, F320L, F320K
- Why bootloop?: Some people Update OTA after flash CWM or TWRP so it will be bootloop. Or some strange reasons
- What should we do when we can not flash Stock firmware by FlashTool.1.0.54?
Let do follow this guide:
- Download file:
Flashtool V1.5 --> http://www.fshare.vn/file/TNVQZ9N74T ( tks to GSM Hosting forum )
Crack Flashtool : http://www.fshare.vn/file/TS1SGGVYWT ( tks to GSM hosting Forum )
File .TOT firmware :
F320S ->>> http://www.fshare.vn/file/T3SZR52W6T
F320K ->>> http://www.fshare.vn/file/TZRVMVMPFT
F320L V11c -->>> http://www.fshare.vn/file/TVR9DPAC7T
.dll file F320S/L/K >----- http://www.fshare.vn/file/TKW8J7QPQT
Driver: http://tool.xcdn.gdms.lge.com/dn/downloader.dev?fileKey=UW00120120425
- Let do:
Step1: Install Flashtool V1.5. Default install folder C:\LG\LGFlashtool
Copy crack file Megalock.dll to C:\LG\LgFlashtool
Step2: Enter download mode: Turnoff, push vol+ and plug USB cable in
Open Device Manager on your computer and choose COM41 for phone connection:
Read more: http://choimobile.vn/threads/huong-dan-cuu-soft-brick-lg-g2-f320s-l-k.12932/#ixzz2h8Fy9fJB
Click to expand...
Click to collapse
can't eneter in download mode i am stuck!!! help!!!
can someone give me the files for my D80210a
Stuck
Every time I try to press vol.up and plug in I still load right into twrp
ocarlty said:
Every time I try to press vol.up and plug in I still load right into twrp
Click to expand...
Click to collapse
I have the same problem with the CWM.
when i press the yellow arrow it gives me this error
i press ok and it continues to the step i have to reconnect the phone.
i reconnect it and i get this
i have changed the com number
i don't know what is the problem...
taxexpert said:
I have the same problem with the CWM.
Click to expand...
Click to collapse
Me too. Ever get this figured out?
I think what this boils down to is USB debugging was disabled by the factory reset. I had reset my device to prepare to sell it. When it booted back up I got an OTA offer and, not thinking, I accepted it. However, I still had CWR and root. I think OTA'S require stock recovery to work properly. So, no USB debugging and CWR as the recovery = soft brick. And, since CWR does not have a terminal option, there's no way to enter commands. I'm thinking this is going to be a warranty claim for me.
Will it work to restore a D805?
dokyson said:
I tested on LG G2 Korea Version F320S, F320L, F320K
- Why bootloop?: Some people Update OTA after flash CWM or TWRP so it will be bootloop. Or some strange reasons
- What should we do when we can not flash Stock firmware by FlashTool.1.0.54?
...
Click to expand...
Click to collapse
Hi!
Thank you for this n.n
Will it work to restore a D805? If not, then I better be careful with OTAs, or I better don't use any recovery as I'm not going to
flash any custom ROM till the G2 is done with official updates (2015?).
Thanks again n.n
- L.
I get this problem any help would be appreciated. thanks.
Could someone give another link on file for F320S > LGF320SAT-00-V10e-SKT-KR-JUL-29-20130
Becuse I have tried to download it by link in the topic. It takes me more than 8 hour, but file was corrupted (2.3 GB not 2.5 GB).
Please - I need TOT for F320
Sorry, if I interrupt here. I'm very new to forum.
My LG G2 F320S having Boot Loop after i updated on 4th Jan 2014.
I try to get TOT file for - 320S ->>> Given location But it seems not working. (I meant not downloading. I tried several days).
If anybody having it please please share with me.
Thanks Lot.
LK
Weird issue
Hi All,
tried using flashtool but I get the error that I need to check my phone model or the DLL.
I bought this phone from the Philippines with model number LG D802. I had flashed other roms for this with D802.
But when I was trying a while ago since I got a bootloop issue, the phone's downlaod mode is in korean and says in the phone and flashtool that my phone is running F320K? but it's so weird since I had D802 before even in the IMEI sticker in the back and to think I installed rayglobe ROM, before having the boot loop.
Any help would be appreciated.
THanks!

Jiayu G4S TROJAN/MALWARE WARNING for custom and stock ROMs May/June

Hi all Jiayu users,
a recent stock ROM and many custom ROMs based on it, have been reported to have at least 2 trojans integrated.
Organizational:This has already been discussed in this general thread: http://forum.xda-developers.com/showthread.php?t=2746900&page=33
But there it goes out of sight very quickly so we should use this new thread to discuss security concerns with Jiayu ROMs in general.
I will update the thread title as soon as other models are reported to have it, too (that is likely).
I will also update the title if we find it is a false alarm (which I stopped to hope).
Any suggestions to improve this posting, or to move it to a better forum, are very appreciated.
It would be nice, if everyone could try not to clutter this thread with unnecessary things. For example, if you have suggestions what I should edit here, better contact me directly, instead of posting a reply that becomes obsolete quickly.​I've downloaded G4S-20140609-211642-SD.rar and G4SL-20140618-194209-SD.rar from needrom and verified the following facts myself. I did not test the stock ROMs, but in the general thread others reported that they have it, too. I don't know if they really came from an official source. April ROMs seem not to have it.
Many trustworthy virus/malware scanners detect trojans in system/app/ - see a list of reports in the virustotal links:
fonts 6.26
com.lovelyfonts
lovelyfonts_vanzo_noicon_6.26.apk
http://www.avgthreatlabs.com/android-app-reports/app/com.lovelyfonts/
https://www.virustotal.com/en/file/...e90eaa5e9e8a1dec4db0d4ece4a82be1185/analysis/
Unlock 2.144
com.yunlan.syslockmarket
SysMarket_92_NoIcon.apk
https://www.virustotal.com/en/file/...cd75a5543725b049c974735dcc66c526940/analysis/
Maybe one of them seems to download a third one and does it again if I delete it, which is clearly malicious behavior:
com.skymobi.pay.plugin 2.0.0.6
placed here: /storage/sdcard0/Android/data/com.skymobi.pay.app/plugins/com.skymobi.pay.opplugin_V2006.apk 174.95 KB
http://www.avgthreatlabs.com/android-app-reports/app/com.skymobi.pay.opplugin_v2006.apk/
https://www.virustotal.com/en/file/...19bf34f6884fa397f062e9b9e4ee4d9be0a/analysis/​I was able to delete both apps using Titanium Backup. Everything still works and the third app didn't come back anymore.
After deletion of the "fonts" app, without reboot, a chinese menu entry appears under settings/display. It translates to "font settings" and crashes when tapped. Maybe that's interesting.
Both apps caused wakelocks, consumed battery and sent data to the internet. They have lots of rights, and their names alone are suspicious.
Other Jiayu users with ROMs of May or June should check for these apps, too. Please report your results here. You can extract the ROM file on your PC and scan it with a virus scanner, or submit above apk files to virustotal or other online services.
Or, on your device, check for existence of the "fonts" and "Unlock" apps. You can do so under Settings/Apps, or in Titanium Backup, or Wakelockdetector and so on.
-Alex
Can you suggest tools to analyze what goes on on my device? Like a good task manager with lots of features showing useful info.
I would also like to see a list of open connections, and who caused them, is that possible?
I just downloaded and installer titanium to check for that apps, i dont seem to have any of those installed.
The rom i have its the official from jiayu.es, based on the 20140418-120537.
Anyways i wanted to check it manually, should I upload all my rom to virustotal?
Thanks
petete159 said:
I just downloaded and installer titanium to check for that apps, i dont seem to have any of those installed.
The rom i have its the official from jiayu.es, based on the 20140418-120537.
Anyways i wanted to check it manually, should I upload all my rom to virustotal?
Click to expand...
Click to collapse
This is an April ROM, and there are also other reports that they are not affected.
Since a few days, jiayu.es also has the June ROM for download.
No, you can't upload the whole ROM. You can unrar/unzip it on a PC and upload single apk files from /system/app/ - or directly upload from your phone (you can use ES file explorer to access that directory).
This warning is now in multiple forums, but no one seems to really care.
Where should I post to get attention?
Some say, I should just delete the suspicious apps and everything is ok. I did that, but I'm not feeling safe, of course. How can we find out more?
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
I found this out also.
I've checked the app and it has suspiciously many rights...
mainstreamer said:
I found this out also.
I've checked the app and it has suspiciously many rights...
Click to expand...
Click to collapse
Thanks a lot, can you tell what ROM version you use and where you got it from. And if not G4S, what model?
What about the other 2 apps?
Stock Rom from jiayu.es (the latest). I have the g4s.
mainstreamer said:
Stock Rom from jiayu.es (the latest). I have the g4s.
Click to expand...
Click to collapse
for the records, that is:
(4.2.2)Rom Oficial Jiayu China 20140609-211642
http://www.jiayu.es/software.php?soft&jiayu=G4S
Alex1a said:
for the records, that is:
(4.2.2)Rom Oficial Jiayu China 20140609-211642
http://www.jiayu.es/software.php?soft&jiayu=G4S
Click to expand...
Click to collapse
Indeed. Somehow it's already included in the official rom.
Maybe it's time to contact jiayu directly?
mainstreamer said:
Indeed. Somehow it's already included in the official rom. Maybe it's time to contact jiayu directly?
Click to expand...
Click to collapse
I contacted jiayu.de at 30.6., they think it's harmless, but are looking at it - no further info until now.
I then contacted jiayu.es yesterday, but got no answer at all until now.
The latest official software posted on http://www.ejiayu.com/en/News.html is from April. How do we know, that 0609 and so on is really officially from them? Is there another official source?
I sent a detailed email to ejiayu.com and will post any comments here.
Answer from Jiayu Official Store España:
"Hello. We do not know anything about this issue because it is working right at this moment. Please contact to Jiayu China or ejiayu to talk about this issue with them."
EDIT: I then asked for help contacting Jiayu China and got this reply after some days:
"Hi. This rom is made bu Jiayu China not by us. We do not know anything from that,. Try to keep in contact with them because we can do nothinfg to fix it."
Hmm ok thanks.
Strange that nobody knows what might be going on. Is the latest rom maybe bogus?
Anyone got a good rom alternative for my jiayu g4s?
Here are the details:
http://securelist.com/blog/virus-watch/59356/caution-malware-pre-installed/
Zopo also does this: recent official KitKat has the fonts troyan, and it is embedded into Settings!
This is clearly intentionally done.
We, simple people, think we pay less for decent phones, and in fact, phone sellers and manufacturers sell out secrets to 3rd party without asking us.
Latest info: there's a new official kitkat ROM for this phone, and it has exactly the same 2 trojans
I really wonder why this security thread is that short. Is it the wrong place here, or doesn't anyone care? I don't feel secure after deleting those apps and don't want to use such ROM. So I restored the april stock ROM...
From official sources nothing new about this issue.
answer from german flagship store
Alex1a said:
From official sources nothing new about this issue.
Click to expand...
Click to collapse
I received an answer from the German branch (flagship store in germany: url jiayu dot de).
The applications are designed for remote maintenance.
I hope they are right.
cepria said:
I received an answer from the German branch (flagship store in germany: url jiayu dot de).
The applications are designed for remote maintenance.
I hope they are right.
Click to expand...
Click to collapse
Never ever, german store is more or less just a reseller with the same poor customer service than a chinese one, why should they confirm that the company who they earn the money with is distributing malware, this would kill their Business immediately
any news on this issue?
I'm planning to buy this phone, but only if the malware is 100% removable.
Can someone confirm that simply removing the APKs does the trick?
Are they located in /system/apps/?
Confirmed, or just flash a different rom, can suggest borx rom gold v3

S7-931w - Failed to update modem - S7-931u

So I'm the owner of the infamous MediaPad 7 Lite [WiFi only] or S7-931w and there is hacking challenge ahead.
As Huawei rarely updates FW for S7-931w and original FW is buggy, I decided to experiment in some way: I put S7-931u FW on S7-931w tablet.
That should work perfectly as both tablets are same by hardware, except that S7-931u have 3G modem.
So after flashing and tablet boot, everything is perfect but there is annoying message on the screen: "Failed to update modem" that will sit on the screen and not go away.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Now, I seeking for a way to remove that message. As I'm not very experienced android developer, I have no idea how to remove it. Maybe to remove modem driver? Or some modifications on firmware before flashing?
I would like to stay on this firmware as it's seems to be more stable and faster than one for S7-931w.
Thanks in advance.
Well I'm not sure that removing modem driver is an easy task.. because the firmware of this tablet is a real mess - but you can try.. because you said you are experimenting. That probably includes rooting of the device, and/or maybe even custom ROM-ing
I own S7-931U with SP19 firmware version and it is not stable at all - at least on my tablet
Wifi version that you have has only reached SP01 version as you can see on this link.
But if you really want to experiment (and don't mind translating from russian) do check 4PDA forum.. they also have some stuff for MediaPad 7 Lite tablets.
Good luck.
prometej-zg said:
Well I'm not sure that removing modem driver is an easy task.. because the firmware of this tablet is a real mess - but you can try.. because you said you are experimenting. That probably includes rooting of the device, and/or maybe even custom ROM-ing
I own S7-931U with SP19 firmware version and it is not stable at all - at least on my tablet
Wifi version that you have has only reached SP01 version as you can see on this link.
But if you really want to experiment (and don't mind translating from russian) do check 4PDA forum.. they also have some stuff for MediaPad 7 Lite tablets.
Good luck.
Click to expand...
Click to collapse
It's already rooted. But I do not have experience with removing drivers on android, so yes, it will be tricky.
Ohh I see that you are also from Croatia, that explains why we both have MediaPad 7 Lite. This tablet is pure crap, but for basic task can be a bit frustrating because of it's "awesome speed". Maybe it can be less useless with better firmware.
I'll check that Russian stuff, it may help.
EDIT: I checked but I don't see anything useful. I would like to know how to edit Huawei firmware by my self like Russian guy did. I managed to open update.app with 7-zip and check all 3 archives (931U.zip, 932U.zip, 933U.zip) contained in it.
Each archive contains 2 files:
- MOBILE_CONNECT.BIN
- UpdateWizard (No extension) - File seems to be an ELF file determined by header.
I have no idea how I should edit anything of that.
This firmware is become open source but I don't know how to edit it either.
I would appreciate if someone can explain me or provide me some tutorial for such, If I get involved and done something, I'll publish it so others may also enjoy the benefits.
Well most of us got this tablet for an "T-Contract"
I don't have enough experience with customizing ROM-s, so I'm not much of a help, but here are two links which may help you disassemble original ROM.
[GUIDE] How to extract Huawei firmware (update.app)
[TOOL] Huawei Update Extractor [UPDATED: v0.9.8.0]
App on the second link is a believe easier to setup if you are on windows platform.
Btw.. you are probably on your own on this experiment, because I've search for some answers on the subject of this tablet, and got none (even nothing from Huawei!)... That is why a gave up trying.. Only thing I've seen new is open source stuff on Huawei pages.
I guess people (or even worse Huawei) are just not interested to create something better for this tablet.
At least some users on this forum and Freaktab.com, helped with rooting and TWRP custom recovery... I can only thank them for their effort
prometej-zg said:
Well most of us got this tablet for an "T-Contract"
I don't have enough experience with customizing ROM-s, so I'm not much of a help, but here are two links which may help you disassemble original ROM.
[GUIDE] How to extract Huawei firmware (update.app)
[TOOL] Huawei Update Extractor [UPDATED: v0.9.8.0]
App on the second link is a believe easier to setup if you are on windows platform.
Btw.. you are probably on your own on this experiment, because I've search for some answers on the subject of this tablet, and got none (even nothing from Huawei!)... That is why a gave up trying.. Only thing I've seen new is open source stuff on Huawei pages.
I guess people (or even worse Huawei) are just not interested to create something better for this tablet.
At least some users on this forum and Freaktab.com, helped with rooting and TWRP custom recovery... I can only thank them for their effort
Click to expand...
Click to collapse
Yeah "T-Contract", as 80% of Croats, me included.
But you helped me a lot, you bring me things I didn't even known that are exist for this tablet.
If I make some success, I'll post about it.
And yes, Huawei have NO interest for it - They even removed S7-931w support from their site - SHAME.
It's a bad tablet, slow and as you said with messy firmware, that's probable reason why almost nobody works on it, or maybe nobody have enough courage to challenge Huawei MediaPad 7 Lite? Who knows
Some update, I used extractor to extract the firmware, after extraction I extracted system.img and under bin directory found guilty script:
modem_update
The problem is that this script is probably called by another, so how to stop that chain....
I have attached recovery log file from mine S7-931u model using SP19 firmware.
Maybe it can be helpful to you, because it contains some stuff near the end of the file related to modem installation and partitions (?!)
EDIT: I forgot to mention... as I understand (not excatly sure about details!) rild is command/daemon that helps communication between modem device and Android code (I believe there is something about that on Stackoverflow forum).. so maybe this may also be your point of interest.?
As I see by viewing the log you shared, it even creates special "modem" partition.
This maybe even complicates the things, maybe I could change creating modem partition.
As experimenting with Android partitions is never good idea, I need to be extremely careful as there is possibility of bricking device.
Do you maybe know where I can find script which handles installation process?
Sorry I haven't investigate Android very deep so I don't know what is the script in charge of installation procedure.
Maybe if you check init.rc and/or init.<machine_name>.rc scripts/service or maybe even updater_script... maybe you can find some more clues, about what is going on during boot procedure and/or installation.
Okay, I'll look into it when I got some time, and I'll keep updated.
Success!
After a while, I finally managed to get some time and will to work on our poor S7-931w, and I comming with a good news!
I finally managed to remove permanent "Failed to update modem" message.
Message is caused by system application HuaweiInit.apk which I found safe to remove after message appears, as after removal there is no annoying message nor bugs.
Also, now all telephony apps could be removed since S7-931w doesn't have any way to use it.
Now we can have S7-931u firmware on our S7-931w. For me, it seems that u firmware is more responsive.
Using S7-931u firmware also brings back USB Mass storage mode which was removed in latest S7-931w firmware.
However, it's still a lot of thing to done, there is annoying empty(gray) GSM signal icon next to the battery, and we should do something more serious with it like optimizing it.
Later I'll post brief tutorial, and maybe release modded S7-931u rom for S7-931w.

Trojan on Gretel A9 smart phone

Hello, I have been having trouble for months with a Gretel A9 smart phone provided by my employer.
The thing seems to be infected by a Trojan which cannot be removed by Factory Restore, or any virus program I have been able to find. (Malwarebytes will detect and clear it, but it comes back straight away).
Here are the symptoms:
-Horrendous pop-ups advertising games
Such as "Grumpy Gorrilla", "Oh No", "99 Balls", and "Sticky Glue). These pop ups are difficult to remove and require scrolling on the advert to find the X to remove, which often leads to clicking on the pop up itself.
This ended up with the phone being subscribed to "Demon Games", running up a £50 phone bill with the network provider.
-Constant browser pop ups to a website called "Aiboo.cc" which I am sure has something to do with it.
-An app called "Magic" which comes up as a virus on malware bytes, and keeps reappearing on the phone, with a little picture of a blue Octopus.
-Constantly tells me I have a new Whatsapp message, but when clicked on, something called "H5 Games" comes up.
-Lake worth ISD is another dodgy app that keeps appearing.
The phone is running Android 6.0.1
Please, help me if you can. I have tried resetting numerous times, and I've researched everything I have found but there's no information online about any of these things.
If it's provided by your employer than return it to him and refuse to use it until fixed or received new one.
To remove any files from system you need a root access. You have to root your device first but you lose warranty
If I return it, they will only provide me with a tiny 'Alcatel Pixi' phone, which is just awful to use.
I think I may try to Root it, but I have no experience doing this
Huscarl said:
I think I may try to Root it, but I have no experience doing this
Click to expand...
Click to collapse
Please post a screenshot of 'About phone' and also run Anti-virus Dr.Web Light (https://play.google.com/store/apps/details?id=com.drweb&hl=en) and post the results. Feel free to post the results from Malwarebytes as well.
Palm Trees said:
Please post a screenshot of 'About phone' and also run Anti-virus Dr.Web Light (https://play.google.com/store/apps/details?id=com.drweb&hl=en) and post the results. Feel free to post the results from Malwarebytes as well.
Click to expand...
Click to collapse
Ok, I will figure out how to get this done and post it tomorrow night (it's late here now and I need to figure out how to do it).
I will also keep a log of what appears on the phone during the day, as I get various messages and pop-ups.
Really do appreciate any help on this, as it has me and my work stumped. It would be a decent phone to use were it not for this terrible virus/trojan.
A quick scan on Malwarebytes came up with this:
2 Malware found
-Android/Trojan.Agent.ASH
(Installed Application - Settings) [I repeatedly get a fake application called Settings]
--------------
-Android/Trojan.Dropper.Agent.CKA
(Installed Application - Magic) [This is the app with the Octopus Icon which I mention earlier]
Tried wiping these off the phone numerous times, both manually and using Malware bytes and other virus apps, but they persistently come back.
Huscarl said:
Really do appreciate any help on this, as it has me and my work stumped. It would be a decent phone to use were it not for this terrible virus/trojan.
Click to expand...
Click to collapse
Did my own research. A number of phones came pre-installed with the Triada malware/virus, which is a well-known case. Unfortunately, Gretel A9 was one of those.
I downloaded the stock rom 3.04 and 3.02 both are infected and the only solution I see is replacing the lib which is causing this and deleting the .apk that is also causing this (based on what I could tell). However, I need to know specifically which version you are running and also what the result of the Dr. Web scan is (please post a screenshot). We could try to repack the cleaned system.img and then you can flash that. However, there are no guarantees it'll work.
TWRP and a few custom roms are available for your phone + general discussion here: https://4pda.ru/forum/index.php?showtopic=807386.
I have posted a Dropbox link to a screenshot of my About Phone..
https://www.dropbox.com/s/lie3868wcrquchg/LongShot_20190415_092503.png?dl=0
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Currently running a full scan with Dr Web Lite and it has detected 20 threats so far, that's far more than malware bytes or any other virus scanner I have used.
Once that's done I will post the results
Huscarl said:
Currently running a full scan with Dr Web Lite and it has detected 20 threats so far, that's far more than malware bytes or any other virus scanner I have used.
Once that's done I will post the results
Click to expand...
Click to collapse
Sounds good! Did some more research, Alberto96 posted this in 2017 (huge thanks for providing both TWRP + the K10 and A9 firmware) https://forum.xda-developers.com/showpost.php?p=77545922&postcount=7 and I've succesfully compared the firmware. My thinking here is - replace the clean files from the Oshiyama K10 stock firmware with the infected ones from the Gretel A9. Repack system.img and then you can try flashing the new system.img via SP Flash Tools. Alternatively, flash TWRP and we'll have to figure out how to create a new flashable system.img script.
I'm having a hard time getting it onto one screenshot despite trying to save it as a long shot, but here is some of the Dr Web diagnosis..
https://www.dropbox.com/s/na47qmq9ek4fvs0/LongShot_20190416_084021.png?dl=0
Palm Trees said:
Sounds good! Did some more research, Alberto96 posted this in 2017 (huge thanks for providing both TWRP + the K10 and A9 firmware) https://forum.xda-developers.com/showpost.php?p=77545922&postcount=7 and I've succesfully compared the firmware. My thinking here is - replace the clean files from the Oshiyama K10 stock firmware with the infected ones from the Gretel A9. Repack system.img and then you can try flashing the new system.img via SP Flash Tools. Alternatively, flash TWRP and we'll have to figure out how to create a new flashable system.img script.
Click to expand...
Click to collapse
Just looked through this thread and I can confirm they were getting the exact same symptoms. Everything they described is what is happening with my phone.
Huscarl said:
I'm having a hard time getting it onto one screenshot despite trying to save it as a long shot, but here is some of the Dr Web diagnosis..
https://www.dropbox.com/s/na47qmq9ek4fvs0/LongShot_20190416_084021.png?dl=0
Click to expand...
Click to collapse
Thanks. If you can pull the full detection list that would be great.
I need to know what some of the detections are associated with, so can you run 'adb shell' and then 'pm list packages –f' like this example:
Then copy the list and post it here as .txt preferably.
Currently decompiling the rest of the 3.04 firmware to see if they've hidden malware in the other partitions as well. If not, we're all set to have you flash a test cleaned test rom if you're up for it.
deleted: \system\priv-app\SecurityService\
https://www.virustotal.com/#/file/1...2b95f86b37e1fd65d495ec4f7782a1df5b8/detection
replaced: system\lib\libandroid_runtime.so with the clean libandroid_runtime.so from the Oshiyama K10 (the device Alberto was referring to).
https://www.virustotal.com/#/file/4...63a1eaca0329162e1d5bd6a6205c1ce78ab/detection
Furthermore, I've removed these vendor apps (pre-installed bloat).
\system\vendor\operator\app\FaceBook
\system\vendor\operator\app\Gmail2
\system\vendor\operator\app\Instagram
\system\vendor\operator\app\Maps
\system\vendor\operator\app\Twitter
\system\vendor\operator\app\YouTube
Here is everything I am getting from Dr Web:
https://www.dropbox.com/s/4a8xw8838vizxul/OneShot_20190416_164440.png?dl=0
https://www.dropbox.com/s/gvl5it7ucfo0s01/OneShot_20190416_164541.png?dl=0
https://www.dropbox.com/s/04am7g7mdw1vlk1/OneShot_20190416_164604.png?dl=0
https://www.dropbox.com/s/04am7g7mdw1vlk1/OneShot_20190416_164604.png?dl=0
https://www.dropbox.com/s/e987ajlgp3hjriz/OneShot_20190416_164612.png?dl=0
Sorry about the format, I'm not so tech savvy, I'm sure that's the lot. I'll now start working on the other instructions you gave me (abd)
Still trying to figure out how to use ABD.
I am following the instructions on here:
https://www.howtogeek.com/125769/how-to-install-and-use-abd-the-android-debug-bridge-utility/
I have download the SDK tools, and unzipped them to a new folder, but I do not see the SDK Manager EXE
I think that it would be easier to flash new rom from the link few posts above - xda site
a602820922 said:
I think that it would be easier to flash new rom from the link few posts above - xda site
Click to expand...
Click to collapse
The problem is, it won't boot. You need to flash the system.img only - but the K10 system.img needs to have the required libs from the A9, e.g. fingerprint, cam libs. Though there's no indication hereof, the K10 may pack malware as well. But like I said, I can repack the K10 system.img with the required A9 files and Huscarl can test it. This can likely be omitted, if we can repack the stock rom with the clean files from the K10 system.img. That's why I need to know what packages are linked to the Dr. Web detections aside from SecurityService and libandroid_runtime.so.
An alternative quick fix: flash TWRP, root the phone, run Dr. Web and let it remove the malware. However, as research indicates, the problem still persists for some users.

Categories

Resources