How 7-Zip Handles Temporary Decrypted Files

When viewing or previewing encrypted files inside 7-Zip, the software temporarily extracts the unencrypted payload to the local storage drive so an associated viewer or editor can open it. This article explains how 7-Zip manages this decryption process, where the temporary files are stored, how cleanup is executed, and the security implications of this behavior.

Decryption and Storage Location

When a user double-clicks an encrypted file or opens it via the built-in viewer (F3) within an encrypted archive (.7z, .zip, etc.), 7-Zip prompts for the archive password. Once authenticated, 7-Zip cannot stream the file directly from memory into external applications; instead, it writes the uncompressed, decrypted file to the local disk.

These decrypted files are created within the current user's temporary folder, typically located at:

C:\Users\<Username>\AppData\Local\Temp\

Inside this directory, 7-Zip creates a uniquely named subfolder (such as 7zOXXXX.tmp or 7zXXXXX.tmp) to contain the extracted plaintext file.

Process Tracking and Cleanup

7-Zip manages the lifecycle of these files based on how they are accessed:

  • External Viewers and Associated Applications: When an external program (such as Notepad, an image viewer, or a PDF reader) opens the preview, 7-Zip monitors the spawned process handle. 7-Zip waits for the associated application window or process to close. Once the application exits, 7-Zip attempts to delete the temporary file and its parent folder. If the 7-Zip File Manager is closed before the viewer application exits, 7-Zip defers the deletion check until the main window closes or attempts cleanup upon its own shutdown.
  • Internal Viewer: If the internal text/hex viewer is used, 7-Zip holds the file open for reading and deletes it immediately once the internal viewer window is dismissed.

File Deletion Mechanism and Residual Risks

The deletion method used by 7-Zip has several critical security limitations:

  • Standard File Deletion: 7-Zip uses standard Windows API calls (such as DeleteFile) to remove temporary files. It does not perform secure data erasure (wiping, shredding, or overwriting with zeros/random bytes). Consequently, the decrypted plaintext data remains in unallocated disk space and can often be recovered using standard file carving or forensic data recovery tools.
  • Application and System Crashes: If 7-Zip, the viewing application, or the operating system terminates unexpectedly (e.g., system crash, force-close via Task Manager, or sudden power loss), the cleanup routine fails to execute. The fully decrypted plaintext file remains permanently in %TEMP% until manually deleted.
  • Secondary Artifacts: Opening certain decrypted files may trigger third-party applications or Windows components to generate their own traces elsewhere on the system, including thumbnail caches, recent file lists (MRU), and volume shadow copies.

To prevent sensitive data from lingering on unencrypted drives, files inside sensitive archives should either be opened within encrypted containers (such as BitLocker or VeraCrypt volumes) or mounted inside a secure RAM disk where temporary files do not touch non-volatile storage.