I downloaded five RAR archives that were supposed to contain MP4 videos. I opened them with WinRAR, checked the contents, and only saw video files. I also opened one through the viewer to confirm it appeared to be a legitimate video. NOD32 scanned the archives and reported no threats, but I'm still worried about ransomware or another hidden infection. Is there anything else I should do, and how risky is it to open these files?
4 Answers
Maliciously crafted video files can theoretically exploit a vulnerability in the program used to play them, but that’s much less common than someone disguising an executable as a video. Use a current version of your media player, scan the extracted files as well as the archive, and don’t use a player or codec pack downloaded from an unfamiliar source.
If the antivirus scan was clean, the files have normal .mp4 extensions, and you haven’t launched anything suspicious, there’s no clear sign that you have ransomware. You can run a second-opinion scan with a reputable on-demand scanner and check for unusual processes, pop-ups, encrypted files, or ransom notes. Make sure you have current backups, preferably one that isn’t permanently connected to the computer.
Compressed downloads are often used to hide unwanted files from basic filters, so it’s reasonable to be cautious. Before opening anything, enable file-extension visibility in the file manager and inspect the archive contents carefully. Delete the files if they came from an untrusted source or if the archive contains anything besides the expected videos.
A RAR file is only a container, similar to a ZIP or 7z archive. The archive itself generally isn’t ransomware, but it could contain malicious files. If the contents really are only MP4 files and you didn’t run any executable or installer, the risk is relatively low. Keep your operating system, media player, archive utility, and antivirus software fully updated, and avoid opening anything with extensions like .exe, .scr, .bat, or .cmd.

The exact player matters because the vulnerability would usually target the software decoding the file, such as a media player or its underlying libraries. Keeping that software patched is the main protection.