Link to home
Start Free TrialLog in
Avatar of jana
janaFlag for United States of America

asked on

Can an Image files, like JPG, be malicious and if so, how can I detect & clean it

Yesterday I downloaded a series of images to be used in different Windows desktop as background.  In the office I was told that some image files like JPEG or JPG can have malicious code and even worse, just by visiting a website where the browser automatically download theses files, can download these infected image files.

So, help please Experts on,
Is this true, images files can be infected with virus, malware, etc.?
Is it true, that just by visiting a website where their image file be infected, just by visiting, my browser will download them without me knowing?
Can my regular antivirus software detected and clean it up?
If not, then what antivirus apps can help with detecting these malicious image files?

Any other info or advice would be great!


ASKER CERTIFIED SOLUTION
Avatar of David Favor
David Favor
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jana

ASKER

Hi guys! From I gather from both of u, this is true and very possible!

David,

I read your entry but to further understand, I am really interested, can you explain a bit more the part  “Easy test is to create a .jpg file which is 100% PHP, then scan it, see if your scanner catches the file extension + file content mismatch.”?

Ste5an,

In your answer of my “visiting a website”, I thought that every browser does an automatic download of data from every web site.  Can u explain the “automatic download”? Do u mean any image as per visiting>? Or other image files not seen?

Also, I use Edge, how can I disable third-party content and JavaScript?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jana

ASKER

Hi Arana,

Didn’t see your entry before.  Thank u for that info about mybeautifulsong2020.mp3.  I just made sure my extension are not hidden.


Hi John,

So is it safe to say, apart from Arana comment, that JPEG files that has malicious code in them only get activated if using specific apps in order to execute its instructions?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jana

ASKER

Thanx Dave, great info!

In order to close the question, can u answer the related questions I place to the other Expert, like:


I asked Ste5an,

In your answer of my “visiting a website”, I thought that every browser does an automatic download of data from every web site.  Can u explain the “automatic download”? Do u mean any image as per visiting>? Or other image files not seen?


I asked John,

So is it safe to say, apart from Arana comment, that JPEG files that has malicious code in them only get activated if using specific apps in order to execute its instructions?

(if u can, thanx!)
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jana

ASKER

Hi, didn't see my entry... don't close it, let me review and award accordingly