Vault7: CIA Hacking Tools Revealed
Navigation: » Directory » RoidRage » RoidRage
Uninstalling
There are several modes of installing RoidRage and the process of uninstalling can vary depending on what mode it was installed in.
Rild Install Mode
The rild install is used on older devices and is not preferred on SELinux enabled devices.
- remount the system partition
- decrypt the backup copy of debuggerd from /system/usr/.cfg_r to /system/bin/rild using the AQCipher
- set the file permissions on /system/bin/rild
- chmod 755 /system/bin/debuggerd
- chown root.shell /system/bin/debuggerd
- chcon u:object_r:rild_exec:s0 /system/bin/rild
- remove /system/usr/.cfg
- rm -f /system/usr/.cfg
- remove /efs/.nv_files (if it exists)
- rm -r -f /efs/.nv_files
Debuggerd Install Mode
The debuggerd install is used for devices which have 4.3+, but less than 5.0.
To uninstall:
- decrypt the backup copy of debuggerd from /efs/.nv_files/.d.cfg to /system/bin/debuggerd using the AQCipher
- set the file permissions on /system/bin/debuggerd
- chmod 755 /system/bin/debuggerd
- chown root.shell /system/bin/debuggerd
- chcon u:object_r:debuggerd_exec:s0 /system/bin/debuggerd
- remove /efs/.nv_files
- rm -r -f /efs/.nv_files
Sysmon Install Mode
The sysmon install is used for newer devices such as the Note 4 or 5.0+.
To uninstall on a Note 4, you will need to run "copper", which is a flashlock bypass technique.
After this, remount the system partition and remove the following files:
- /system/bin/sysmon
- /efs/.nv_files/*
- /efs/.nv_files
Data Files
RoidRage will use data files in the following paths:
- /data/app-private/.d
- /data/app-private/.p
- /data/app-private/.i
- /data/app-private/.o
- /dev/.1324536