Backup efs using samsung tool. Restoring IMEI on Android after flashing. Recovery on Explay smartphones

EFS on Qualcomm devices, backup, recovery

You can share your experience or ask a question at.
This instruction is dedicated to how to use the program " QFIL"implement backup "EFS"on PC, as well as the process of restoring a backup copy" EFS" to device: " Lenovo based on Qualcomm".

Preparation

  • Follow the instructions: .
  • Open the folder of the installed software package" QPST", and run " QFIL.exe".

  • Make sure that the program has detected the device in the mode: " Lenovo HS-USB Diagnostics".

  • In the top menu of the program " QFIL" choose " Tools" -> "QCN Backup Restore".

Creating an EFS Backup

Backup QCN" and wait for the backup process to complete. By default, the backup is (file 00000000.qcn) will be saved in the folder " C:\temp\", it is better not to change the save location and name of the backup copy. If the device is dual-SIM, then check the "Enable Multi-SIM" option. Backup " EFS"It is advisable to copy it to a couple of safe places.

Log of a successfully created backup:

Process Index:0 Start Download QCN COM Port number:7 Checking if phone is connected... IsPhoneConnected: Passed. Phone is connected Sent SPC code to the phone successfully Downloading QCN file: C:\temp\00000000.qcn Done downloading the qcn file: C:\temp\00000000.qcn Finish Backup QCN

Restoring EFS from a backup

In the window that opens, click on the button " Browse", specify the path to the file " 00000000.qcn" and press " Open". If the device is dual-SIM, then check the "Enable Multi-SIM" option.
Click on the " Restore QCN" and wait for the recovery process to complete.

Log of a successfully restored backup

Process Index:0 Start Restore QCN COM Port number:7 Uploading QCN file: C:\temp\00000000.qcn Checking if phone is connected... Done uploading the QCN file: C:\temp\00000000.qcn Finish Restore QCN

Every time you decide to update Samsung Galaxy S3 custom firmware, you can end up losing data that is stored in internal memory. Unfortunately, not only regular data such as contacts, messages, call logs or applications can be destroyed, but also Internet settings or the EFS folder can be erased too. So, to avoid any unpleasant situations, we will teach you how to do EFS backup and restore on Samsung Galaxy S3 using the one-click method. As usual, it's all explained in a simple step-by-step guide, so let's get started.

Why should you do it? backup copy EFS? EFS stores the IMEI and allows the phone to establish an internet connection, so in case this folder is erased, the phone will no longer be able to use the internet connection. So, if you recently updated your Galaxy S3 and can't log in... world wide web, then the EFS folder may have been destroyed. That's why you need to do it in advance so that you can easily restore it if necessary. For those who cannot do this, the only solution is to install stock firmware or apply official update, released by Samsung, suitable for S3.

There are many ways to learn how to make an EFS backup, today we will explain the one-click tool option. To do this you will need a computer with Windows control and a USB cable for your phone, since you will need to connect the S3 to your PC. In addition, this procedure requires root access on the smartphone. If they are not there, then first you need to root the device and remove factory restrictions. Please note that rooting automatically voids the warranty. We recommend that you search through our Guides section for a suitable step by step guide, where you can find everything you need to know about the root access operation. Then come back here and continue with the rest of the guide.

Remember that it is recommended to back up all data on your Galaxy S3 (before upgrading or making system changes), not just the EFS folder. It is important to save your personal information as it will likely be destroyed. For a complete backup, you can download SMS Backup & Restore for Android, Call Logs Backup & Restore, sync with Google to save contacts, or use a custom recovery image (such as CWM) to backup your current system.

Before performing all the steps, you must disable security tools on your computer and phone, as these programs can interrupt the backup operation by stopping the one-click tool. Next, enable the USB debugging option on the Galaxy S3 (this requirement is present in the steps below) and charge the smartphone battery so that it does not turn off in the middle of the process.

Please note that this guide can and should only be applied to Samsung Galaxy S3 and not to any other android device. This method was first developed and tested by XDA Developers, so we have to thank them for this opportunity. Now, finally, you can follow the appropriate steps. Read everything carefully. The process is simple and will only take a couple of minutes to complete, so let's get started.

How to Make an EFS Backup on Samsung Galaxy S3 Using One-Click Method

  • First of all, download Samsung Kies to your computer to install the appropriate drivers for the Samsung Galaxy S3.
  • Then download the EFS backup and restore application from here (search for download).
  • You must have a file with the extension .rar.
  • Unpack the archive.
  • The USB debugging option must be enabled on the Galaxy S3. Go to Settings -> Developer and make sure the USB debugging option is checked.
  • Now, connect your device to your computer using a USB cable.
  • Once the phone is connected, go to the folder where you extracted the downloaded file and click on executable file Backup EFS.
  • Follow all steps.
  • EFS will be saved to the same folder in .img format.
  • If you need to restore EFS, then you need to run Restore_EFS and go through all the steps again.

This was a one-click method that can be used to easily perform EFS backup and restore on Samsung Galaxy S3. Now you can calmly think about upgrading your phone with custom firmware, since your data and EFS are in good hands.

This article is about recovery
encrypted file system (efs) performance, import
keys from the old user profile in
new system for gaining access to
encrypted information. To start
Let's decide what you can do first
try a number of existing utilities for
this work, the work performed in the article
requires certain knowledge and skills.

  • Our favorite elcomsoft offers advanced
    efs data recovery for 2K/XP for $99 with
    available demo version.
  • Our beloved Microsoft also has in its
    arsenal recovery program
    reccerts.exe, which can be obtained via
    paid support service.
  • Well, Passware unknown to us offers efskey,
    which is said to be slower
    aefsdr, but costs exactly the same - 95 conventional
    raccoons

Let's return to our sheep. By default names
efs in XP are colored green. If everything fails
keys are naturally lost, and when opened
file creates a blank document with
description of the error. For example:

  • notepad: cannot open the c:\documents and settings\foo\my
    documents\report.txt
  • file: make sure a disk is in the drive you specified.
  • wordpad: access to c:\docume~1\foo\mydocu~1\report.txt was denied.

This error usually appears
indicates that for everyone
users who had access to the file,
The wrong encryption key is being used.
There may be several reasons for this -
the most common is reinstallation
systems.

Everyone is recommended before the first
using efs to export
public and private keys, and
preferably on another medium (cipher /?) - these
keys are randomly generated upon creation and
when reinstalling the system
naturally do not repeat. Surprisingly,
maybe on purpose, at the first
no warnings when using efs
valiant Microsoft does not give out and there is a real
completely forget about the danger.

In 2K and XP, data on efs is here:

c:\documents and settings\user\application data\microsoft\crypto\ —
private key
c:\documents and settings\user\application data\microsoft\protect\ —
password entry to the private key
c:\documents and settings\user\application data\microsoft\systemcertificates\ —
public key. In general, not so
important.

Let's say the files have been saved and you need them
use. To work with file
the system requires the same account with the same
computer number, which was originally.
You can find this data here:

c:\documents and settings\%username%\application data\microsoft\crypto\rsa\s-1-5-21-1078081533-
1606980848-854245398-1003

Computer number: 1078081533-1606980848-854245398
User number: 1003

In hex, respectively: fd374240 f094c85f 16c0ea32 and 3eb.

Go to hklm\sam\sam\domains\account\users\%usernumbers% and
check if there is an account with the same number in
system. If there is, then you need to find the name
user and create a profile with
original password. If it doesn’t exist, we create it,
having previously changed hklm\sam\sam\domains\account\f to
offset 48 to the required number, and add
him to the admin group. Next: in
hklm\sam\sam\domains\builtin\aliases\00000220\c change the machine SID
to the original one. We do the following and
here: hklm\sam\sam\domains\account\v. From hklm\software\microsoft\windows
nt\currentversion\profilelist\ export the key,
describing the car number with the suffix of
user numbers, change to
original numbers and import them back.
Copy the folders with keys to c:\documents and
settings\%username%\application data\microsoft\, reboot...
and everything should work.

In the next part we will look at the situation
in which there are no key files.

IMEI sometimes “flies” when flashing the gadget, after which the latter stops working correctly, losing the ability to make calls and go online. Note that some Chinese devices can operate without an identification number, but such devices are in the minority. Therefore, we will tell you how to restore IMEI on Android, as well as how to change it if necessary.

To make sure that it is the lost identifier that is causing problems with the gadget, enter the characters *#06# in the dialing field. If the code of your device does not appear on the display after this, then the problem has been identified correctly - you need to restore the IMEI. Keep in mind that a phone with two SIM cards must also have two IDs.

Let's describe how to restore IMEI on Android after flashing using Samsung as an example:

  1. Remove the SIM card from the device.
  2. , for which in the field for entering the number write the combination *#*#4636#*# or *#*#8255#*# if the first code is incorrect.
  3. Open the “CDS Information” section, then “Radio Information” and go to the “Phone 1” subsection.
  4. In the top line where it says “AT+”, enter the command EGMR=1.7. Next, in quotation marks, we write the fifteen-digit code corresponding to your IMEI.

Please note that the codes for entering the engineering menu differ on different devices. For Samsung they are already given above. Therefore, before changing IMEI, check this information. For other gadgets they may be as follows:

  • *#*#2846579#*# - for Huawei gadgets;
  • *#*#3646633#*# - for Alcatel devices, Philips and Fly;
  • *#*#8255#*#, *#*#3424#*# - for HTC;
  • *#*#7378423#*# - for Sony.

You can restore the ID not only manually, but also using various utilities that allow you to enter the engineering menu without entering a code. For this, for example, the MTK Engineering Mode program can be used, available even in Google Play. True, it only works with MediaTek processors.

Let us immediately note that changing the device identifier is not legal, since it will be very difficult to find a lost or stolen gadget using IMEI. Let's describe how the Android IMEI is changed if, for example, you find someone else's device:

After this, all you have to do is dial *#06# to make sure that the identifier has really changed. If you want to return your old imei and don’t know how to find the fifteen-digit code, then if you have the device itself, it’s very easy to do. The codes are located on the box and in the gadget itself on a sticker under the battery.

Mobile Uncle is another small utility that can be used to change IMEI if you have Root rights. It is available on Google Play and has a long name there “Launch engineering menu MTK".

From the name it is clear that the application works correctly only with MTK processors. We will describe how to restore IMEI on Android using this utility if the installer did not enter the code correctly:

Note that these methods describe how to restore IMEI on Android after flashing, that is, if it was lost after unsuccessful user actions. It is required to register a new one only in cases of an attempt to conceal illegal actions with the gadget. Moreover, there is a very high probability that if you change the “native” identifier to a changed one, the smartphone will turn into “ ”, losing the ability to access the Internet, make calls, send messages, etc.

But even if you cannot find out the IMEI, for example, in the event of a gadget theft, it is easy to obtain it in your Google account to transfer information to law enforcement agencies. This method works if the device is connected to a Google account. All smartphone data is automatically saved on the server, and to get it, you need to go to the Google account settings section in the subsection " Personal Area» or directly follow the link

When working with operating rooms Windows systems XP/Vista/7 and recovering passwords for mail and Internet sites. The next task that we often have to deal with when investigating incidents is recovering passwords for archives, email clients and EFS (Encrypting File System). About this and we'll talk in this article.


EFS Key Recovery

In fact, the best thing to do in this situation is to recover the user's password. Then decrypting EFS will be much easier, we will return to this later. However, you need to understand that even if you do not have a password, you can still try to decrypt the corresponding files and folders. This is what Advanced EFS Data Recovery software is designed for.

In this software For the convenience of the user, a corresponding Advanced EFS Data Recovery wizard has been created, with which you can go through the entire decryption process step by step. Or you can use "Expert Mode" to perform the actions yourself.

In my opinion, if a person using Advanced EFS Data Recovery does not feel confident, it is much more convenient to use the Advanced EFS Data Recovery Wizard. Let's look at this mode in more detail.

At the first stage of the Advanced EFS Data wizard Recovery system will ask for the personal certificate used for EFS.

Let's assume you have such a certificate (the situation is extremely rare, because for some reason users either neglect to export certificates or simply forget where they exported it). In this case, everything is quite simple. You are required to select the certificate file and enter the certificate password. Next, a search is made for all folders and files encrypted with its help on local partitions. You receive a list of files encrypted with this certificate that you can decrypt. Naturally, if you examine your computer, you will have to decrypt it to another hard drive or external storage device so as not to damage anything.

But what if you don't have a certificate? In this case, the Advanced EFS Data Recovery wizard will prompt you to search for it on your hard drive. Please note that you can search for a certificate not only among existing files, but also among deleted ones. But to do this, you need to enable the "Scan sector by sector" checkbox. It is recommended to enable this mode when rescanning if you did not find the required certificates on the first pass.

Next, it will take you some time to find the keys. As a result of the search, a wizard window will be displayed. If the keys are not found, you must enter the username (EFS owner) and his password or, as a last resort, a HEX code. How to obtain a user password was described in the previous article.

If you know the user's password, you enter the name of the corresponding account and her password and press the "Forward" button. Next, the found folders and files encrypted using EFS are decrypted. As you can see, even if you reinstalled operating system, this does not mean that you have lost data encrypted with EFS.

Don't forget that if you know the name and password of the account under which encryption was carried out, the decryption process will take much less time. Otherwise, you can try to decrypt using expert mode. Although we must admit that the probability positive result in this case it is noticeably lower. You will be prompted to add a password from the dictionary. Naturally, it is assumed that you have the dictionary files.

I would like to note the following. As we can see, today there are quite powerful tools for recovering (cracking) passwords. Therefore, to ensure their durability we have three options:

  1. Further increase in length and complexity (in my opinion, the path is a dead end, because sooner or later users begin to get confused, forget passwords, use the same one for all occasions, etc.).
  2. Use of biometric authentication tools.
  3. Use of multi-factor authentication and certificates. This path, again, in my opinion, is much more promising, but it is worth considering that the proposed solutions, of course, cost money, and sometimes quite a lot.

The choice, of course, is yours.

Vladimir BEZMALY




Top