A
A
arseniylebedev2018-06-23 12:18:52
Malware
arseniylebedev, 2018-06-23 12:18:52

Can a virus packed in a rar archive with a password be launched after unpacking?

If you just unpack a password-protected rar archive with an exe virus, can it start during the unpacking process? Or only if, after unpacking, run the exe itself.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
R
Roman Mirilaczvili, 2018-06-23
@arseniylebedev

RAR archive (not SFX) is a non-executable data format. And .EXE files themselves are not called. There is something that motivates them to perform. That "something" is a decompressor program that tries to extract data from an archive by reading data from it.
After all, just .exe files with viruses lying on the disk are not harmful in themselves until something causes them.
On the other hand, specially created archives can exploit flaws in unpacking programs and exploit their vulnerabilities.
In total, if there are no vulnerabilities in the program that reads the archive, then everything is safe even if the virus is inside the archive until some process starts it.
If I am wrong, I will be glad to receive new information.

A
Alexander, 2018-06-23
@NeiroNx

Purely theoretically - yes it can - an archive file can itself be a virus that penetrates through a vulnerability in the archiver program.
But in practice, the probability is less than 1 percent, so you can extract.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question