Previous in Forum: Loading Linux on an iMac   Next in Forum: Downgrading to Windows 7
Close
Close
Close
11 comments
Rate Comments: Nested
Guru
Hobbies - CNC - New Member Popular Science - Biology - New Member Hobbies - Musician - New Member

Join Date: Dec 2008
Location: Canada
Posts: 3523
Good Answers: 146

SD Card Invaders?

04/15/2010 12:18 PM

A funny thing happened after I downloaded some photos from SD card last night. Apparently while I was online, some download got through my defenses and put permanent read only files and executable files (mostly in chinese) on the SD.

Damn nuisance since I don't want to even bother trying to use it for photos now and risking reloading something into my computer with the pix.

Is this becoming a common target for spyware etc? I mean to seek out media like SD and leave a cache of their gear on it, ready to hike off to some other device or computer and "pass it on"?

__________________
incus opella
Register to Reply
Interested in this topic? By joining CR4 you can "subscribe" to
this discussion and receive notification when new comments are added.

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
Guru
United States - Member - New Member Hobbies - Automotive Performance - New Member

Join Date: May 2008
Posts: 845
Good Answers: 8
#1

Re: SD Card Invaders?

04/15/2010 12:49 PM

I haven't heard of this happening before. I'd say before any red flags are raised I'd make sure that those files aren't from your camera or software you use to upload photo's. If you have another SD card follow the same steps you did and see if the camera drops files onto it (besides the folder it creates per album). Then go to upload and see if it's software related.

I'm interested either way, obviously millions of people upload photo's everyday and if precautions need to be taken it would be a wonderful article to publish on CR4.

Register to Reply
Guru
Hobbies - CNC - New Member Popular Science - Biology - New Member Hobbies - Musician - New Member

Join Date: Dec 2008
Location: Canada
Posts: 3523
Good Answers: 146
#2
In reply to #1

Re: SD Card Invaders?

04/15/2010 3:08 PM

They definitely were not from the camera nor from my computer. I've been using this camera for some time now, and yes I have seen something like this once before on an SD card (that's once out of maybe hundreds of download operations) which had been shared with someone else, so I wasn't sure where it came from; and I have seen it once on my computer, now that I think of it, may have been in a file with photos.

These were .exe type programs (not used on a linux system). The one that caught my eye with an english name had "matlab" in the title. Not my software, and definitely nothing to do with my photo processing. The dates on these files were all between 1980 and 1983, and almost all labeled in Chinese or similar.

Wierd old stuff.

__________________
incus opella
Register to Reply
Guru
Hobbies - CNC - New Member Popular Science - Biology - New Member Hobbies - Musician - New Member

Join Date: Dec 2008
Location: Canada
Posts: 3523
Good Answers: 146
#3

Re: SD Card Invaders?

04/15/2010 4:39 PM

Well I went looking to see if I could find something about this. I haven't seen this story exactly, but I did find

(A) malware has been known to camo as a matlab.exe. http://www.file.net/process/matlab.exe.html That matches the product.

(b) I found a report of malware (circa 2005) that "redirects the execution using Image File execution" http://vil.nai.com/vil/content/v_135238.htm

So maybe there is malware around that already has an affinity for subverting image file processes, so when it gets in it goes looking for image files to hide with? I'm just guessing.

__________________
incus opella
Register to Reply
Guru
Safety - Hazmat - New Member Safety - ESD - New Member Engineering Fields - Transportation Engineering - New Member Popular Science - Evolution - New Member Technical Fields - Procurement - New Member Hobbies - Target Shooting - New Member Popular Science - Cosmology - New Member Engineering Fields - Architectural Engineering - New Member Technical Fields - Marketing/Advertising - New Member Engineering Fields - Food Process Engineering - New Member

Join Date: Dec 2005
Location: Mariposa Ca
Posts: 5800
Good Answers: 114
#6
In reply to #3

Re: SD Card Invaders?

04/16/2010 11:26 AM

Why not use the usb cable to transfer pictures?

it goes through the usual virus checks, I use picasa, for most things, gimp for more detailed editing.

After having a card [XD] popout & land in a heater register, I never removed one again other than to install a larger capacity....

Register to Reply
Guru
Hobbies - CNC - New Member Popular Science - Biology - New Member Hobbies - Musician - New Member

Join Date: Dec 2008
Location: Canada
Posts: 3523
Good Answers: 146
#7
In reply to #6

Re: SD Card Invaders?

04/16/2010 11:40 AM

I find the cables more of a hassle. Go find the right cable.. Whereas the card is very handy (haven't toasted one yet..).

I think the junk on the SD card probably can't affect me in Ubuntu - .exe programs don't usually run under linux unless you are set up to do so. But it is bothersome that it got through my firewall, anyway. And of course, the card is now junk!

__________________
incus opella
Register to Reply
Anonymous Poster
#4

Re: SD Card Invaders?

04/16/2010 4:16 AM

I guess this is just a variation of a past scam. Last year a friend purchased a flash drive (made in China) that was infected. Edmund

Register to Reply
Anonymous Poster
#5

Re: SD Card Invaders?

04/16/2010 9:28 AM

There have been incidents where malware was placed on SD cards and other removable devices in the last few years. I recommend having your spyware/anti-virus program scan the cards first.

The programs will probably track what you do on the computer - that is the info I got from my anti-virus provider.

Al

Register to Reply
Guru

Join Date: Feb 2006
Posts: 1758
Good Answers: 6
#8

Re: SD Card Invaders?

04/16/2010 9:37 PM

Are you using Maxthon as browser.

This happened to me also.

It also changed default site in chinese

Register to Reply
Guru
Hobbies - CNC - New Member Popular Science - Biology - New Member Hobbies - Musician - New Member

Join Date: Dec 2008
Location: Canada
Posts: 3523
Good Answers: 146
#9
In reply to #8

Re: SD Card Invaders?

04/16/2010 9:51 PM

no, not Maxthon.

I did some checking at one point on the origins of attempts that were caught by my firewall - a majority were Chinese in origin. So I guess it's no surprise!

__________________
incus opella
Register to Reply
Associate

Join Date: Jul 2007
Location: Spokane Wa. USA
Posts: 29
Good Answers: 2
#10

Re: SD Card Invaders?

04/19/2010 7:22 PM

SD cards pre-loaded with malware are now showing up all over. They all seem to be of Chinese origin. I seem to remember an article about this on the Kim Commando web site (very useful computer info source). Panda has an anti-malware program specifically for devices like thumb drives and SD cards. You are smart to be running Linux because, so far at least, the stuff all seems to be aimed at windows. In the mean time the best thing to do is to turn off the auto run function on computers running windows. If a thumb drive or SD card is in the computer when it is booted up the malware will run before the anti-virus program can kick in.

Register to Reply Score 1 for Good Answer
Guru
Hobbies - CNC - New Member Popular Science - Biology - New Member Hobbies - Musician - New Member

Join Date: Dec 2008
Location: Canada
Posts: 3523
Good Answers: 146
#11
In reply to #10

Re: SD Card Invaders?

04/19/2010 7:40 PM

That's good practical advice: don't boot up with thumb drive or SD engaged.

I got a clean SD for my photos, and since the trouble seemed to get in over the internet, I'm now doing my photo transfers while offline, and removing the card before I go online.

__________________
incus opella
Register to Reply
Register to Reply 11 comments

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
Copy to Clipboard

Users who posted comments:

Anonymous Poster (2); artsmith (5); Baxter (1); Garthh (1); Haajee (1); Zamaron (1)

Previous in Forum: Loading Linux on an iMac   Next in Forum: Downgrading to Windows 7

Advertisement