How to Keep Flagged Malware Files in Unrar
This article explains how to prevent unrar and Windows
Defender from deleting files flagged as malicious during archive
extraction. It covers the specific unrar command-line
switch used to retain interrupted files, alongside the required Windows
Defender exclusion settings to stop real-time protection from
automatically quarantining the extracted contents.
Use the -kb Switch in
Unrar
By default, when unrar encounters a write error—such as
when Windows Defender locks or blocks a file mid-extraction—the utility
automatically deletes the incomplete or failed output file.
To override this behavior, use the -kb (Keep Broken)
switch. This instructs unrar to retain whatever was written
to disk despite any error triggered by the antivirus interception.
Run the extraction using the following syntax:
unrar x -kb archive.rar C:\TargetFolder\x: Extracts files with full paths.-kb: Keeps broken, damaged, or interrupted extracted files.
Configure Windows Defender Exclusions
The -kb flag prevents unrar from cleaning
up the file, but Windows Defender's real-time protection operates at the
operating system level and will still attempt to quarantine or delete
the file once written. To ensure the file remains intact, you must set
an exclusion before extracting:
- Open Windows Security from the Start menu.
- Navigate to Virus & threat protection.
- Under Virus & threat protection settings, click Manage settings.
- Scroll down to the Exclusions section and select Add or remove exclusions.
- Click Add an exclusion and choose Folder.
- Select the target directory where you intend to extract the files
(e.g.,
C:\TargetFolder\).
Alternatively, you can set the exclusion via PowerShell running as Administrator:
Add-MpPreference -ExclusionPath "C:\TargetFolder\"Once the exclusion is active and the -kb switch is
applied, unrar will write the file to the designated
directory without Windows Defender intercepting or deleting it.