Malware on SD cards, can I save the files?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lauracaryl, Oct 12, 2011.

  1. lauracaryl

    lauracaryl Private E-2

    Hi,
    I recently went travelling and picked up some viruses on my SD cards. While in the camera the photos can be viewed as normal but on viewing the card on the desktop only shortcuts appear, none of which can be opened. I have scanned with Kaspersky which has detected various trojans and other malware. It states that these cannot be removed due to the disk being 'write protected'.

    Other advice suggests backing up the files before reformatting the disk, which is fine except I can't access them. Is there anyway to retrieve the files or is it a lost cause only goods for formatting?

    (Ironically I picked up the virus trying to back them up so I have no back up).

    Hope someone can help!
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    To eliminate the obvious - is the SD card's switch in the "Unlocked" position? Is the card in a built-in multicard reader or a USB cardreader ---> tried changing the device used to read it?

    Also try the below:
    Step 1:
    Please have all your removable storage devices ready for disinfection.
    Download Flash Disinfector by sUBs and save it to your desktop.
    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

    Step 2:
    The following assumes that your SD Card drive letter is G - change it to the correct letter assignment if needed.
    • Click on "Start" -->Run --> type cmd and click on OK.
    • Enter this command.

      Code:
      [b]attrib -h -r -s /s /d [color=darkgreen]g[/color]:\*.* [/b]
    • NOTE:You can copy the above command --> Right-click in the Command Prompt and paste it.
    • Press Enter

    Are your files now visible on the SD Card? If so, please do this:

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes, you could use a flash drive too, but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
     
    Last edited: Oct 12, 2011
  3. lauracaryl

    lauracaryl Private E-2

    Hi, thanks for replying.

    I have checked the cards, both are unlocked. I am currently using my camera to read the cards as I don't have a card reader to hand, I have however had the same problem when I used a USB card reader.

    I downloaded the flash disinfector but so far there seems to be a problem with it, I get as far as 'allowing it to make changes', but Windows then asks if it has been downloaded correctly. I have tried re-downloading and running it anyway, but nothing happened. I'm running Windows 7 if that makes a difference? Either way I still only have inaccessible shortcuts on the cards.

    Sorry, seems I'm more rubbish at this than i thought :p.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then continue on and skip the flash disinfector step and follow the rest of the instructions that Dr Moriarty gave you.
     
  5. lauracaryl

    lauracaryl Private E-2

    Ok, I have tried the Run sequence Dr. Moriarty suggested.

    It tells me the disk is write protected and cannot be formatted. I have checked the slide lock on on the side and all the permissions, all are correct and set to allow.

    I assume that this is a virus related problem?
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Things seem to be pointing in that direction - I now need to review the logs created from running the tools listed in the READ & RUN ME FIRST. Malware Removal Guide.

    Please complete the steps and attach the requested logs.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds