How 7-Zip Handles Temporary Decrypted Files
When viewing or previewing encrypted files inside 7-Zip, the software temporarily extracts the unencrypted payload to the local storage drive so an associated viewer or editor can open it. This article explains how 7-Zip manages this decryption process, where the temporary files are stored, how cleanup is executed, and the security implications of this behavior.
Decryption and Storage Location
When a user double-clicks an encrypted file or opens it via the
built-in viewer (F3) within an encrypted archive (.7z,
.zip, etc.), 7-Zip prompts for the archive password. Once
authenticated, 7-Zip cannot stream the file directly from memory into
external applications; instead, it writes the uncompressed, decrypted
file to the local disk.
These decrypted files are created within the current user's temporary folder, typically located at:
C:\Users\<Username>\AppData\Local\Temp\
Inside this directory, 7-Zip creates a uniquely named subfolder (such
as 7zOXXXX.tmp or 7zXXXXX.tmp) to contain the
extracted plaintext file.
Process Tracking and Cleanup
7-Zip manages the lifecycle of these files based on how they are accessed:
- External Viewers and Associated Applications: When an external program (such as Notepad, an image viewer, or a PDF reader) opens the preview, 7-Zip monitors the spawned process handle. 7-Zip waits for the associated application window or process to close. Once the application exits, 7-Zip attempts to delete the temporary file and its parent folder. If the 7-Zip File Manager is closed before the viewer application exits, 7-Zip defers the deletion check until the main window closes or attempts cleanup upon its own shutdown.
- Internal Viewer: If the internal text/hex viewer is used, 7-Zip holds the file open for reading and deletes it immediately once the internal viewer window is dismissed.
File Deletion Mechanism and Residual Risks
The deletion method used by 7-Zip has several critical security limitations:
- Standard File Deletion: 7-Zip uses standard Windows
API calls (such as
DeleteFile) to remove temporary files. It does not perform secure data erasure (wiping, shredding, or overwriting with zeros/random bytes). Consequently, the decrypted plaintext data remains in unallocated disk space and can often be recovered using standard file carving or forensic data recovery tools. - Application and System Crashes: If 7-Zip, the
viewing application, or the operating system terminates unexpectedly
(e.g., system crash, force-close via Task Manager, or sudden power
loss), the cleanup routine fails to execute. The fully decrypted
plaintext file remains permanently in
%TEMP%until manually deleted. - Secondary Artifacts: Opening certain decrypted files may trigger third-party applications or Windows components to generate their own traces elsewhere on the system, including thumbnail caches, recent file lists (MRU), and volume shadow copies.
To prevent sensitive data from lingering on unencrypted drives, files inside sensitive archives should either be opened within encrypted containers (such as BitLocker or VeraCrypt volumes) or mounted inside a secure RAM disk where temporary files do not touch non-volatile storage.