# Is there a self-extracting file archive format that isn't .exe?

**URL:** <https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783>\
**Category:** Factual Questions\
**Created:** [May 7, 2005, 3:25am UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783 "2005-05-07T03:25:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cagey\_Drifter](https://avatars.discourse-cdn.com/v4/letter/c/b2d939/32.png) [@Cagey\_Drifter](https://boards.straightdope.com/u/Cagey_Drifter)\
**Post date:** [May 7, 2005, 3:25am UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/1 "2005-05-07T03:25:28Z")

</div>

Nobody wants to run an .exe file they downloaded off the internet. That’s obviously very risky.

Nonetheless, I want to make a self-extracting file available. But for the above reason, it can’t be an .exe file. Is there a non-proprietary self-extracting file format that won’t cause a user to immediately consider the risk factor of getting viruses (the way .exe might)?

---

<div class="post-metadata">

**Author:** ![Kamino\_Neko](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kamino_neko/32/34_2.png) [@Kamino\_Neko](https://boards.straightdope.com/u/Kamino_Neko)\
**Post date:** [May 7, 2005, 3:32am UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/2 "2005-05-07T03:32:46Z")

</div>

A self-extracting file needs to be a format that can run.

Which means, anything self-extractable is also a potential virus vector.

---

<div class="post-metadata">

**Author:** ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)\
**Post date:** [May 7, 2005, 4:08am UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/3 "2005-05-07T04:08:55Z")

</div>

On the Mac, the names of Self-Extracting Archives often end in “sea”. I suppose you could use [Stuffit](http://www.stuffit.com/win/index.html) to make an SEA, then instruct your recipients to extract them inside their Macs or Mac emulators… 🙂

---

<div class="post-metadata">

**Author:** ![Sage\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sage_rat/32/399_2.png) [@Sage\_Rat](https://boards.straightdope.com/u/Sage_Rat)\
**Post date:** [May 7, 2005, 9:22am UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/4 "2005-05-07T09:22:49Z")

</div>

Self-installation packages are .msi and .msp files. But I don’t know how one makes these.

---

<div class="post-metadata">

**Author:** ![Derleth](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@Derleth](https://boards.straightdope.com/u/Derleth)\
**Post date:** [May 7, 2005, 9:52am UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/5 "2005-05-07T09:52:17Z")

</div>

You can play games with extensions, but that won’t placate the more intelligent of your audience: By their very nature, self-extracting files have to contain executable code, and _all executable code is a potential vector_. Going from .exe to .sea or .msp or .foo won’t change that fact.

It comes down to trust: Do your patrons trust you? They obviously don’t trust their OS to protect them, so do they trust your files to do what you say they’ll do and nothing more? Unless that trust is there, the problem remains.

This is a _social_ problem, not a technical one.

---

<div class="post-metadata">

**Author:** ![Cagey\_Drifter](https://avatars.discourse-cdn.com/v4/letter/c/b2d939/32.png) [@Cagey\_Drifter](https://boards.straightdope.com/u/Cagey_Drifter)\
**Post date:** [May 8, 2005, 5:33pm UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/6 "2005-05-08T17:33:36Z")

</div>

hm. that’s disappointing. well, thanks!

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [May 8, 2005, 7:45pm UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/7 "2005-05-08T19:45:09Z")

</div>

Your other option is to not make it self-extracting. You could, for instance, distribute a zip file. While a zip file can contain a virus (heck, it can contain anything), it won’t automatically run the virus when you open it. The downside is that your users must already have a program to open zip files. But this shouldn’t be too big a deal: Recent computers are almost guaranteed to already have a program on them for dealing with zip files, possibly even built into the operating system.

---

<div class="post-metadata">

**Author:** ![ouryL](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ouryl/32/6067_2.png) [@ouryL](https://boards.straightdope.com/u/ouryL)\
**Post date:** [May 9, 2005, 1:36am UTC](https://boards.straightdope.com/t/is-there-a-self-extracting-file-archive-format-that-isnt-exe/302783/8 "2005-05-09T01:36:10Z")

</div>

> [@Chronos](#):
>
> Your other option is to not make it self-extracting. You could, for instance, distribute a zip file. While a zip file can contain a virus (heck, it can contain anything), it won’t automatically run the virus when you open it. The downside is that your users must already have a program to open zip files. But this shouldn’t be too big a deal: Recent computers are almost guaranteed to already have a program on them for dealing with zip files, possibly even built into the operating system.

Yes, any good virus program can scan a zip before opening it.
