How to Scan a ZIP File for Viruses

Archives such as ZIP, RAR and 7z are one of the most common ways malware is delivered, because they hide the real file type and can slip past email filters. Here is how to check one safely.

1. Check the archive itself

Drag the .zip onto the iMalware scanner. This checks whether the exact archive is a known malware sample, without uploading it and with no size limit. It is a quick first test, especially for archives circulated in phishing campaigns.

Important: a hash check looks at the archive as a whole. It does not open the ZIP and check each file inside. A clean result for the archive does not mean every file inside is clean, so also do step 2.

2. Scan the files inside

On Windows: right-click the ZIP and choose Scan with Microsoft Defender. Defender scans inside common archive formats. You can also extract the archive to a new folder — extracting does not run anything — and then scan the folder. Do not double-click any file until the scan is done.

On a Mac or Linux: extract to a folder and scan it with ClamAV (clamscan -r folder/), or drop individual files onto the iMalware scanner.

Online: multi-engine upload scanners generally unpack archives and scan the contents, within their upload size limit. Don't upload archives containing private documents. See our comparison of online scanners.

Password-protected ZIP files

No scanner can see inside an encrypted archive without the password, which is exactly why attackers use them: phishing emails often include a ZIP plus a password in the message body. If you didn't expect a password-protected archive, treat it as suspicious. If you trust the sender, extract it with the password into a folder and scan the extracted files before opening any of them.

Red flags inside an archive

  • A single executable or script: .exe, .scr, .js, .vbs, .bat, .hta, .lnk.
  • Double extensions such as Invoice.pdf.exe.
  • An archive inside an archive inside an archive, or a disk image (.iso, .img) inside a ZIP.
  • A tiny archive that claims to expand to an enormous size (a "zip bomb"), designed to crash or overwhelm scanners.
  • Office documents that ask you to "Enable Content" or "Enable Macros".

Large archives and backups

Online upload scanners refuse multi-gigabyte archives, and Google Drive warns that large files are "too large to scan for viruses". iMalware hashes the file in your browser in chunks, so size is not a problem. See how to virus-scan large files.

Frequently Asked Questions

Can a ZIP file contain a virus?

Yes. A ZIP is just a container, and it can hold any file, including malicious executables, scripts or macro-enabled documents. The archive itself does nothing until you open a file inside it.

Is it safe to extract a ZIP file to check it?

Extracting copies files out of the archive but does not run them, so it is generally safe. Just don't open any extracted file until you have scanned it.

Why can't my antivirus scan a password-protected ZIP?

The contents are encrypted, so a scanner can't read them without the password. Extract the archive with the password and scan the extracted files instead.

Does iMalware scan the files inside a ZIP?

No. iMalware checks the hash of the file you drop, so for a ZIP it checks the archive as a whole. Drop the extracted files individually to check each one.