T95 Allwinner H616 TV Box

Search This thread

stevendeb25

Senior Member
May 27, 2010
2,515
2,099
england
pnht.org
For owners of this device, have a look in this folder:

Code:
/data/data/com.swe.dgbluancher/files

Check to see if there's a folder named да -- If there is, your device is infected with malware. I'm investigating reports this is included in brand-new devices purchased online. If you're affected (or not) please reply here and let us know if you're on stock or flashed firmware.
Friend just bought one for me to setup for movies and tv
 
Last edited:

DesktopECHO

Senior Member
Sep 10, 2021
50
27
Hamilton, Bermuda
Ads sure, but not all the malware on the box.

You may want to check to see if this folder exists:

/data/data/com.swe.dgbluancher/files/да

Also run AVG, it will find malware (but not all of it)
 

nicktyke

New member
Aug 9, 2018
3
0
I have this box. 4/64gb model. Doing ls from terminal in the dgbluancher/files folder shows no such subfolder. However, I'd now be keen to see what it is up to. I have an Ubuntu box on the same network which is easier to work with than the crappy t95. Any danger of a walkthrough of installing pi-hole on the Ubuntu box and configuring the t95 to use the Ubuntu box as DNS, please?
 

DesktopECHO

Senior Member
Sep 10, 2021
50
27
Hamilton, Bermuda
Can you check one more thing real quick? Do you have a folder named:

Code:
/data/system/Corejava

And the file:

Code:
/data/system/shared_prefs/open_preference.xml

If so, you are infected.
 

nicktyke

New member
Aug 9, 2018
3
0
Can you check one more thing real quick? Do you have a folder named:

Code:
/data/system/Corejava

And the file:

Code:
/data/system/shared_prefs/open_preference.xml

If so, you are infected.
Both folder and file are present 😢
Struggling for time this evening. Will have a look at pi-hole tomorrow. Ideally on the Linux box with a decent screen and a hardware keyboard and point the t95 DNS settings to it. If I can't fathom that, I'll install pi-hole on the t95 per your guide. Thanks
 

DesktopECHO

Senior Member
Sep 10, 2021
50
27
Hamilton, Bermuda
Both folder and file are present 😢
Struggling for time this evening. Will have a look at pi-hole tomorrow. Ideally on the Linux box with a decent screen and a hardware keyboard and point the t95 DNS settings to it. If I can't fathom that, I'll install pi-hole on the t95 per your guide. Thanks

Help is on the way!


The script I posted to GitHub will effectively 'de-fang' the malware and clean-up your T95 as much as possible (for now, while a better solution can be found)
 

nicktyke

New member
Aug 9, 2018
3
0
Right then. Set up pi-hole and there it is 🤬
 

Attachments

  • Screenshot_2023-01-11-17-29-34-05_3aea4af51f236e4932235fdada7d1643.jpg
    Screenshot_2023-01-11-17-29-34-05_3aea4af51f236e4932235fdada7d1643.jpg
    39.7 KB · Views: 113

DesktopECHO

Senior Member
Sep 10, 2021
50
27
Hamilton, Bermuda
You will also see these after you run the remediation script:
1673458385795.png

On top of that, it tries to use 8.8.8.8 if it doesn't like the answer it's getting from default DNS.

The cleanup script I put together will prevent Stage One from being downloaded, but it will NOT (at this time) stop pinging the C2 servers.
 

PhyllisDillhole

New member
Feb 3, 2023
1
0
Bump.

Stage 1? Could you elaborate a little more? What would stage 2 do? I almost gave one of these away as a gift. Like you said, these can easily be obtained en masse from places like Alibaba and sell like hotcakes on Amazon and eBay (and it's not like the sellers on Amazon or eBay know- and perhaps not even the wholesalers) and most people just plug them in and connect all their devices, etc, without knowing anything about this or that there's a de-fanging script- etc.

I purchased these because of the processor, that I could flash Batocera or whatever to it or run it off of an sd card and use it for gaming and movies. Unfortunately, I did plug it in briefly before I found this post, One thing I did notice is that an air mouse I had that was working and in perfect working order stopped working. It still works on other machines.

I don't need it to be online for what I use it for, but I guess my main question is- given the current climate, should this be of a larger security concern?

I still have one in the packaging and I have said folders and files on the one I did use. Is this something that should be brought to broader attention? These are cool, functional, and cheap- thus people turn other people onto them and they buy them for friends and family, etc.

What's Stage 2? Pegasus? lol
 

nazgul67

Senior Member
Jul 15, 2016
84
13
Anyone experienced distorted voice using Zoom Cloud Meeting app?
Any way of fixing this?

Device: T95 4gb ram
Firmware: X19
 

GarM35

New member
Feb 28, 2023
1
0
Hi! I have 2 tv boxes Allwinner t95 max with android 9 (2.1.21) and they were working perfectly. From last month or so both have started to do the same thing: playing videos (either streaming or from hard drive) suddenly the image and sound freeze a couple of seconds (making a very annoying noise), and sometimes the image freezes but the sound continues until it all fades to black and then continues synchronized. I have restored one of them to factory defaults and it keeps doing it. Do you have any idea what could have happened and how to fix it? Thank you very much!
 

spinnersp

Member
Jun 10, 2014
18
1
I have the 4/64 ver. Opened box to confirm.I cannot for the life of me get this detected with adb or even pheniox tool. Any help on drivers(which i believe pheniox tool installed. I can here windows sound when connecting. i can sometimes get this error in adb "
adb server version (39) doesn't match this client (41); killing...
* daemon started successfully" Sometimes the client and server numbers sre different.
 
Last edited:

theslydog

Member
Jan 16, 2007
20
3
I had an unused T95 and I just fired it up and sure enough it was infected.
So I hunted for some firmware and the only firmware (out of many) that would install with PhoenixSuit was T95-H616-X29.img
It says Build 10.1.X29-0621

Has anyone had a look to see if this img is infected like that of the firmware that the box comes with?

I can see
/data/system/Corejava
but not
/data/system/shared_prefs/open_preference.xml

the 'files' folder here is also not present
/data/data/com.swe.dgbluancher/files/да
 
  • Like
Reactions: DesktopECHO

spinnersp

Member
Jun 10, 2014
18
1
I hunted around for firmware for this box 4/64 dual wifi. Tried many different H616 files,couldnt get any to work unless they were T95 specific.Then I found "Vontar-X1-A29-1105",boots up with the Vontar logo. Once booted up looks just like the T95 and same as theslydog
I can see
/data/system/Corejava
but not
/data/system/shared_prefs/open_preference.xml
the 'files' folder here is also not present
/data/data/com.swe.dgbluancher/files/да
 
Last edited:
  • Like
Reactions: DesktopECHO

Top Liked Posts

  • There are no posts matching your filters.
  • 1
    I had an unused T95 and I just fired it up and sure enough it was infected.
    So I hunted for some firmware and the only firmware (out of many) that would install with PhoenixSuit was T95-H616-X29.img
    It says Build 10.1.X29-0621

    Has anyone had a look to see if this img is infected like that of the firmware that the box comes with?

    I can see
    /data/system/Corejava
    but not
    /data/system/shared_prefs/open_preference.xml

    the 'files' folder here is also not present
    /data/data/com.swe.dgbluancher/files/да
    1
    I hunted around for firmware for this box 4/64 dual wifi. Tried many different H616 files,couldnt get any to work unless they were T95 specific.Then I found "Vontar-X1-A29-1105",boots up with the Vontar logo. Once booted up looks just like the T95 and same as theslydog
    I can see
    /data/system/Corejava
    but not
    /data/system/shared_prefs/open_preference.xml
    the 'files' folder here is also not present
    /data/data/com.swe.dgbluancher/files/да
    1
    I did it now with powershell and usb a cable, can now see the box on the PC, without having switched on the internet, let your script run through. But the first thing I did was install atv launcher and delete the original one, with a tutorial from malwarebytes, one difficult birth :).Thank you again for your help and your patience.I'm not an expert in a field, try to master many things, we simply don't have enough time in our lives.Great forum, you're always helped, best regards
  • 4
    Transpeed T98-616
    If you want custom rom with root and update 2020.10.21 the room fully working :) its better then stock some memory optimization was done .
    Flash with PhoenixSuit_V1.10
    First change language from russian to english and then connect to the internet run magisk tv box will reboot
    Creators of the room bosia_angel and VPS56:

    Download here
    3
    Just google "Allwiner update guide"
    Best with Allwinner PhoenixUSB Pro V4.0.0 tool (You need a usb-A to usb-A cable)
    2
    Just thought I would post regarding this box. Not much information on it.
    I bought on a whim without realising the one thing I wanted was missing (Bluetooth). However the box has grown on me.
    Its powered by the new Allwinner H616 Chip. However its performance sucks. For some reason they have forced CPU to 1.4GHz all the time. No point in my opinion, it just causes it to heat up for no reason.

    Anyways, it comes fully rooted. I did try and install SuperSU, ended up killing root. So I reflashed it using usb flasher. There is also a new firmware update, which shows when doing wireless update.
    Firmware released is 10.1.12, update takes it up to 10.1.14. So I did update and then factory reset to start fresh. The only problem is, rom is such a mess. App folders every where and system is filled to 100%. I deleted bloat in /system/pre-install folder.

    I stopped rooting stuff years ago, so Magisk is newish to me. I thought I would try Magisk manager. Worked great, was able to install Magisk. From then on all root apps worked as I was able to set root access, which is something I could not do before. I also installed kernel auditor and set read ahead on and tweaked the build.prop. This helped speed it up, now stuff like Emulators no longer jerk and stutter.

    One downside, Prime video does not work, you have to use Amazon Video (which is their browser alternative).

    So hope this helps anyone with the same box.
    2
    Here is the latest firmware with working Wifi

    T95-H616-A24


    Well I don't or can not explain where got this you know after about 20 tries of different methods using other roms ect I ran across this. T95-H616-A25.img and i said what the hell stuck inthe old tooth pick and it completed which was a shock. So all i did was toggle Root switch and installed a X-plore file manager and sure enough I get into root. Now I am tired i can not tell you if all of BT dual wifi ect works I can say for sure it does load up with usb 4.0 and you do get root.

    T95-H616-A25.img = https://mega.nz/file/K8423QyD#0hO5-fR8gm5RUIoENVxwuzYVZv46paOOowFKZVaarKE

    I take it back I looked through web history and I found it here "https://www.turewell.com/pages/tvbox-document"
    Can you confirm that the A24 is a chipset version? Because the firmware has different letters and numbers (X18, X19, A21, A24, etc.) and the names Pixel2/MBOX.

    This firmware "T95-H616-A24" is 10.1.A24_20210315-1615 and is designed for 2GB/16GB. I don't have 5G WiFi, so I can't confirm if it's for the Dual WiFi version. Version A21 does not work on my device. I have 4GB/64GB with Dual Wifi and firmware was 10.1.A24_20210315-2036 MBOX. This "1615" have slower WiFi speed on 2,4Ghz.

    Has anyone tried to investigate where the update system will connect? So you can download the latest original firmware from the manufacturer? How do I identify the device manufacturer if it is not displayed on it? I need original firmware for my device.
    2
    I have this box on magisk 20.4 direct install T95 h616-10.01.14. X18

    Have had it for while now it works well with all the apps gms store etc using magisk hide. I will dig out the firmware and post for anyone who wants it. Decent firmware with build.prop tweaks etc applied.


    Originally posted by @3mel here is an updated link to T95 MBOX 06.24.20.X18 ROM With Magisk 20.4 just update manager app if need be.


    I've found this to be the best firmware for this box, there is a root switch in settings>about menu
    Leave this be as magisk will work with things like adaway because it has system less root.