How to Keep Flagged Malware Files in Unrar

This article explains how to prevent unrar and Windows Defender from deleting files flagged as malicious during archive extraction. It covers the specific unrar command-line switch used to retain interrupted files, alongside the required Windows Defender exclusion settings to stop real-time protection from automatically quarantining the extracted contents.

Use the -kb Switch in Unrar

By default, when unrar encounters a write error—such as when Windows Defender locks or blocks a file mid-extraction—the utility automatically deletes the incomplete or failed output file.

To override this behavior, use the -kb (Keep Broken) switch. This instructs unrar to retain whatever was written to disk despite any error triggered by the antivirus interception.

Run the extraction using the following syntax:

unrar x -kb archive.rar C:\TargetFolder\
  • x: Extracts files with full paths.
  • -kb: Keeps broken, damaged, or interrupted extracted files.

Configure Windows Defender Exclusions

The -kb flag prevents unrar from cleaning up the file, but Windows Defender's real-time protection operates at the operating system level and will still attempt to quarantine or delete the file once written. To ensure the file remains intact, you must set an exclusion before extracting:

  1. Open Windows Security from the Start menu.
  2. Navigate to Virus & threat protection.
  3. Under Virus & threat protection settings, click Manage settings.
  4. Scroll down to the Exclusions section and select Add or remove exclusions.
  5. Click Add an exclusion and choose Folder.
  6. Select the target directory where you intend to extract the files (e.g., C:\TargetFolder\).

Alternatively, you can set the exclusion via PowerShell running as Administrator:

Add-MpPreference -ExclusionPath "C:\TargetFolder\"

Once the exclusion is active and the -kb switch is applied, unrar will write the file to the designated directory without Windows Defender intercepting or deleting it.