Potential embarrassment, Joudres and alternate Streams

R

Roedy Green

I have discovered a potential embarrassment to Java developers.

Microsoft Windows has a rarely used feature called alternate streams,
something like Mac file forks, that allows you to attach little
descriptive files of metadata to your files.

The SysInternals people, now bought out by Microsoft, have a utility
called STREAMS.EXE to detect and optionally delete them.
http://www.microsoft.com/technet/sysinternals/FileAndDisk/Streams.mspx

The Joudres virus exploits this and hides in the alternate stream/
fork. It attaches itself to every image file on your machine. You
can then unwittingly pass it on embedded in image files. It does not
appear to be all that harmful, but it could be embarrassing.

Neither of the three virus checkers I used are aware of it. It never
occurs to them to look in image files, or in the alternate stream.

I discovered the little beasts when I was defragging and found tiny
locked files interfering with the defrag process. You can perhaps
most quickly detect if you have the problem with a trial version of
O&O defragger http://mindprod.com/jgloss/defragger.html
and do an analyse followed by a double click on the drive and look at
the locked file report. Look for files of the form
myfile.png$joudres....
 
L

Lew

Roedy said:
I discovered the little beasts when I was defragging and found tiny
locked files interfering with the defrag process. You can perhaps
most quickly detect if you have the problem with a trial version of
O&O defragger http://mindprod.com/jgloss/defragger.html
and do an analyse followed by a double click on the drive and look at
the locked file report. Look for files of the form
myfile.png$joudres....

Ad-Aware checks alternate streams.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

Forum statistics

Threads
474,434
Messages
2,571,690
Members
48,796
Latest member
Greg L.

Latest Threads

Top