You are here

Found a file stream in FileZilla paf

7 posts / 0 new
Last post
plethora
Offline
Last seen: 13 years 8 months ago
Joined: 2011-04-14 22:51
Found a file stream in FileZilla paf

Is this not where malware can hide?

Simeon
Simeon's picture
Offline
Last seen: 10 years 4 months ago
DeveloperTranslator
Joined: 2006-09-25 15:15
Could you elaborate a bit?

What is a file stream?

"What about Love?" - "Overrated. Biochemically no different than eating large quantities of chocolate." - Al Pacino in The Devils Advocate

plethora
Offline
Last seen: 13 years 8 months ago
Joined: 2011-04-14 22:51
Well I'm not an engineer but

Well I'm not an engineer but my understanding is once you remove an alternate data stream from a file it (the file) may no longer work so it's probably best if they don't exist at all particularly for this kind of get up.

John T. Haller
John T. Haller's picture
Offline
Last seen: 3 hours 23 min ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
No Streams

Files you download from the web don't have streams in them. Streams can only be created within NTFS once a program has been run. If there is a stream in the installer itself, that means something else on your system may have infected it.

Sometimes, the impossible can become possible, if you're awesome!

romulous
Offline
Last seen: 7 years 7 months ago
Joined: 2009-10-23 03:58
Browsers

Both IE and Firefox support the Internet Zones of Windows. What this means is that by default (you can disable it in Firefox but not in IE), both browsers will add an alternate data stream to a downloaded executable. This stream is responsible for the 'this file has come from another computer, are you sure you want to run it' message that you see when you try and run a file after downloading it.

You can see if this is the particular stream that you have in your file by right clicking the file in Explorer, going into Properties and checking if the 'unblock' button is active. If so, click it and if that stream is the one you are seeing, it should be removed from the file once you click Ok to exit from Properties. If the button is not active, or the button is (but the stream is still present after you click unblock), then the file has another stream.

I used to have a sig...until one of the mods ate it

depp.jones
Offline
Last seen: 2 hours 22 min ago
DeveloperTranslator
Joined: 2010-06-05 17:19
Thanks for that enlightenment!

I was not aware of that. Checking with AlternateStreamView brought some further clarity on that (alternate stream name is :Zone.Identifier:$DATA for all downloaded pafs so no problem here).
I'd never even thought of that, but it explains something I didn't even question for years... Wink

romulous
Offline
Last seen: 7 years 7 months ago
Joined: 2009-10-23 03:58
Yep, that is the one...

Thanks - I had forgotten the name of the ADS added by the browsers, but the :Zone.Identifier:$DATA that you mention is in fact the name of it. A utility like AlternateStreamView will also remove that particular ADS if you prefer not to have to click the 'unblock' button on multiple downloaded files.

Not all browsers respect the Zone settings, but I think (please don't quote me on this) Chrome does as well. IE and Firefox most certainly do as I mentioned above. Opera - I don't believe it does (99% sure). The other major browser (Safari) I don't know about.

I used to have a sig...until one of the mods ate it

Log in or register to post comments