EFS password recovery. How to make and restore an NVRAM backup - Lenovo smartphones - general questions - Lenovo Forums RU How to make a backup on Android

If you sew very often or are sewing for the first time Android smartphone or tablet manufacturer Samsung, then you need to take care of the safety of IMEI. In the article How to save and restore IMEI on Samsung you will learn how to do this in 2 ways.

Method No. 1 Save and restore IMEI

1. Install on Android Device free application Android Terminal Emulator

2. Go to this application and type the commands:

su dd if=dev/block/xxxxxx of=sdcard/efs.img

In order to repair IMEI:

su dd if=/sdcard/efs.img of=/dev/block/xxxxxxx

Where xxxxxxx this is the name of the EFS block.

How to find out the EFS block name

Go to Android app Terminal Emulator and type the command:

mount

then find the section and its name (in my case the name mmcblk0p1)

su dd if=dev/block/mmcblk0p1 of=sdcard/efs.img su dd if=/sdcard/efs.img of=/dev/block/mmcblk0p1

Method No. 2 Save and restore IMEI

That’s all for the detailed article on backup and restoration of efs android, don’t lose your IMEI!

This article is about recovery
encrypted file system (efs) performance, import
keys from the old user profile in
new system for gaining access to
encrypted information. To begin with
Let's decide what you can do first
try a number of existing utilities for
this work, the work performed in the article
requires certain knowledge and skills.

  • Our favorite elcomsoft offers advanced
    efs data recovery for 2K/XP for $99 with
    available demo version.
  • Our beloved Microsoft also has in its
    arsenal recovery program
    reccerts.exe, which can be obtained via
    paid support service.
  • Well, unknown to us, Passware offers efskey,
    which is said to be slower
    aefsdr, but costs exactly the same - 95 conventional
    raccoons

Let's return to our sheep. By default names
efs in XP are colored green. If everything fails
keys are naturally lost, and when opened
file creates a blank document with
description of the error. For example:

  • notepad: cannot open the c:\documents and settings\foo\my
    documents\report.txt
  • file: make sure a disk is in the drive you specified.
  • wordpad: access to c:\docume~1\foo\mydocu~1\report.txt was denied.

This error usually appears
indicates that for everyone
users who had access to the file,
The wrong encryption key is being used.
There may be several reasons for this -
the most common is reinstallation
systems.

Everyone is recommended before the first
using efs to export
public and private keys, and
preferably on another medium (cipher /?) - these
keys are randomly generated upon creation and
when reinstalling the system
naturally do not repeat. Surprisingly,
maybe on purpose, at the first
no warnings when using efs
valiant Microsoft does not give out and there is a real
completely forget about the danger.

In 2K and XP, data on efs is here:

c:\documents and settings\user\application data\microsoft\crypto\ -
private key
c:\documents and settings\user\application data\microsoft\protect\ -
password entry to the private key
c:\documents and settings\user\application data\microsoft\systemcertificates\ -
public key. In general, not so
important.

Let's say the files have been saved and you need them
use. To work with file
the system requires the same account with the same
computer number, which is what it was originally.
You can find this data here:

c:\documents and settings\%username%\application data\microsoft\crypto\rsa\s-1-5-21-1078081533-
1606980848-854245398-1003

Computer number: 1078081533-1606980848-854245398
User number: 1003

In hex, respectively: fd374240 f094c85f 16c0ea32 and 3eb.

Go to hklm\sam\sam\domains\account\users\%usernumbers% and
check if there is an account with the same number in
system. If there is, then you need to find the name
user and create a profile with
original password. If it doesn’t exist, we create it,
having previously changed hklm\sam\sam\domains\account\f to
offset 48 to the required number, and add
him to the admin group. Next: in
hklm\sam\sam\domains\builtin\aliases\00000220\c change the machine SID
to the original one. We do the following and
here: hklm\sam\sam\domains\account\v. From hklm\software\microsoft\windows
nt\currentversion\profilelist\ export the key,
describing the car number with the suffix of
user numbers, change to
original numbers and import them back.
Copy the folders with keys to c:\documents and
settings\%username%\application data\microsoft\, reboot...
and everything should work.

In the next part we will look at the situation
in which there are no key files.

A smartphone without connection to an operator, what could be worse? Without communication, we just get a player with the function of playing music, video and other little things. Communication is the soul of a smartphone; that’s what it was created for. There may be several reasons for the lack of communication with the operator: problems on the part of the operator, the SIM card needs to be replaced, a hardware defect in the smartphone, etc.

But there is another reason when the phone does not catch the network - the lack of your phone IMEI(International Mobile Equipment Identity). IMEI and cellular communication are closely intertwined and therefore the vast majority of phones from major manufacturers have IMEI. There are Chinese phones for two/three/ten SIM cards that somehow work without IMEI, but if you have a smartphone from a large manufacturer, it will not register on the network without the correct IMEI.

If we talk in simple language, then losing IMEI is your smartphone's worst nightmare. And as practice shows, this happens with Samsung phones much more often than with other manufacturers. In fact, the IMEI of Galaxy series smartphones is stored in a separate section - EFS in the root of the flash memory. Sometimes, for a variety of reasons, this partition is erased or the data in it is damaged. As a result, your phone does not have an IMEI and cannot register on the network.

Reasons for missing IMEI:

  1. Firmware update via OTA or other method
  2. Installation official firmware(yes, yes, official)
  3. Installing third-party firmware
These are the three most common reasons for the disappearance of IMEI or damage to the EFS partition on smartphones of the series Samsung Galaxy. Many custom firmwares already include a script for backing up the EFS partition to external media during firmware installation. But this is all good only if you have root access. What if he is not there?
Saving IMEI on Samsung Galaxy series phones
  1. You must have access to phoneutil menu. The default is *#7284# . If this code does not fit, then you need to find the appropriate one for your model. All necessary drivers for the phone must also be installed.
  2. Download NV-Items_Reader_Writer_Tool.zip - 2.43 MB
  3. Enable USB debugging on your phone.
  4. We are recruiting *#7284# .
  5. Let's go to Qualcomm USB Settings and choose RMNET + DM + MODEM.
  6. Now we connect the phone to the computer, run NV-items_reader_writer.exe as administrator.
  7. Save the block Range (Dec) 550-550. The block must be preserved 00550 . This will be yours IMEI.
  8. We are recruiting *#7284# . Let's go to Qualcomm USB Settings and choose MTP+ADB.
  9. Ready:)
Repairing IMEI on Samsung Galaxy series phones
  1. Find IMEI your phone, for example by battery.
  2. Create a backup block with IMEI according to the instructions above, even if it is damaged. And open it with the editor NotePad++.
  3. Divide your name into blocks of two numbers, leaving the first number separately. For example 35516705558781901 divide by 3 55 16 70 55 58 78 19 01
  4. Adding Latin A after the first digit, and swap all the rest. Add 08 to the beginning IMEI. We get the following 08 3A 55 61 07 55 85 87 91 10
  5. Now in text editor NotePad++(we already opened this file earlier) replace the first nine blocks with our correct one IMEI, which we received in the last step.
  6. Let's write it down IMEI back to phone button Write V NV-items_reader_writer.
  7. Reboot the phone.

Today we will talk about an application developed by the guys from XDA. It can be installed on any phone Samsung. Thus, creating a backup copy for the folder EFS will not be difficult, which will allow you to install custom ROM and recovery images to your smartphone without worrying about the presence or absence of network access. Folder EFS contains important information about your phone, for example, IMEI number. Additionally, every time you decide to update your Android Samsung device with new custom or beta firmware, it can be destroyed, which in turn leads to loss of network connection, and the smartphone becomes useless. For this reason, we strongly recommend that you do backup copy EFS along with other important data stored on your device. A backup is always installed without problems, so don’t be shy about making it before making any changes to your gadget.

Now, as we already noted earlier, to make a backup EFS for anyone Samsung you will need to download, install and use the device special application - EFS Pro. But to use it you need root access(and the OS Android). Before proceeding to download, make sure that you have root access, if it is missing, then work on getting it. And do not forget that this always leads to loss of warranty. You can return it only by restoring stock ROM or installation official updates from Samsung. If lost EFS you can follow the same steps to restore.

To carry out this operation you will need a PC (Windows XP, Vista, 7), your Samsung device and USB cable. Let us remind you once again that your smartphone must have root access. Must be installed on the computer Microsoft. NET Framework 4.0 , otherwise EFS Pro won't work. After downloading the file, unzip it and install it on your PC. Then connect your device to your computer. Now you can make a backup for EFS using the application EFS Pro. For more details go to THIS link (you can also download it there) EFS Pro app).

That's all, now you know how to do it EFS backup for your Samsung device, but do not forget that there are other methods, and the one indicated in the article is the easiest.

How to restore EFS for any Android Samsung device:
rating 80 out of 80 based on 80 ratings.
There are 80 reviews in total.

We have already looked at how it is possible. I said there that by default only the given user. I also said there that the private key, which is used to decrypt encrypted EFS files, is stored in the personal certificate store. But what happens if the user loses access to his private key? How then to recover files encrypted using EFS?

EFS Recovery Agent

EFS Recovery Agent is an Administrator account local computer or domain administrator, depending on where you are. The administrator account can decrypt files encrypted by other users and return them to the owner. But to do this, you need to create an EFS Recovery Agent certificate and allow it access to all newly encrypted files. I hope you remember how in the previous article we allowed another user to access encrypted files. This is exactly what happens with the recovery agent, only it's all done automatically.

How to create an EFS recovery agent?

In this article, I will not cover creating an EFS recovery agent within a domain. Let's consider only creating the Encrypting File System recovery agent on the local machine. To do this, use the default administrator account to run the following command in a command prompt window:

cipher /r:recoveryagent

In response to this command will create two files:

  1. recoveryagent.cer
  2. Recoveryagent.pfx

They will both be located in the root folder of the computer administrator. The next step is to make it clear operating system that the EFS Recovery Agent has just been created. To do this you need to open Local editor group policy and go to node Computer Configuration/Windows Configuration/Security Settings/Public Key Policies/Encryption file system and find the item Add data recovery agent. By opening this policy, you must point to the certificate recoveryagent.cer. Then save the changes and .

How to recover EFS encrypted files?

After creating an EFS recovery agent, all newly encrypted files can be recovered via account administrator. To do this, the computer administrator needs to find and run the file Recoveryagent.pfx. After launching, you need to go through all the newly opened windows in hamster mode, after which the computer administrator will be able to access all encrypted files. And he will also be able to remove encryption from them and return them to the user. This is how EFS recovery is possible.

Share