# What type of files can't carry a computer virus

**URL:** <https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670>\
**Category:** Factual Questions\
**Created:** [April 4, 2007, 3:01am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670 "2007-04-04T03:01:43Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bang\_This](https://avatars.discourse-cdn.com/v4/letter/b/f19dbf/32.png) [@Bang\_This](https://boards.straightdope.com/u/Bang_This)\
**Post date:** [April 4, 2007, 3:01am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/1 "2007-04-04T03:01:43Z")

</div>

I opened a text file (with the .txt extention) and my MIS person where I worked said you have to be careful as all files can carry viruses.

I know certain files can carry viruses but I always thought .txt files could not. Are there any types of computer files that cannot carry computer viruses?

---

<div class="post-metadata">

**Author:** ![Hirka\_T\_Bawa](https://avatars.discourse-cdn.com/v4/letter/h/db5fbb/32.png) [@Hirka\_T\_Bawa](https://boards.straightdope.com/u/Hirka_T_Bawa)\
**Post date:** [April 4, 2007, 3:08am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/2 "2007-04-04T03:08:11Z")

</div>

Till someone more knowlegable comes along, as far as I know, every type of file can be infected with a virus, but only executable files can transmit them. So that would be exe and com files. Now, there are some exploits in some programs that allow a non-executable file to infect you, but that is done through the program. I’m mainly thinking of some problems with Microsoft Outlook awhile back.

Now, my knowledge is a little out of date, I know this was true back when, but with all the new stuff in XP and Vista, who knows.

---

<div class="post-metadata">

**Author:** ![Rysto](https://avatars.discourse-cdn.com/v4/letter/r/ecccb3/32.png) [@Rysto](https://boards.straightdope.com/u/Rysto)\
**Post date:** [April 4, 2007, 3:22am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/3 "2007-04-04T03:22:32Z")

</div>

Usually, only executable files(programs) can carry viruses. Now, Microsoft Office documents can contain programs(called macros) in them, so that’s why Office documents have been able to infect people with viruses as well. However, there have also been cases where files which never contain programs have been used to transmit viruses. That has happened by exploiting a bug in the program that displays the file and tricking it to run the file like an executable. Internet Explorer got hit with this once – someone found a way to make IE execute code embedded in a JPEG picture. This kind of virus is much more rare, though.

So, in theory, a text file could spread a virus if opened with a buggy text editor, but that’s exceedingly unlikely. Usually, you only ever need to worry about files that are programs or can contain programs.

---

<div class="post-metadata">

**Author:** ![jovan](https://avatars.discourse-cdn.com/v4/letter/j/0ea827/32.png) [@jovan](https://boards.straightdope.com/u/jovan)\
**Post date:** [April 4, 2007, 3:23am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/4 "2007-04-04T03:23:30Z")

</div>

One of the problems is that sometimes file suffixes are hidden. So, an executable file called readme.txt.exe will appear as readme.txt. It’s not a text file, but it looks like one. That’s a common distribution method for computer viruses.

---

<div class="post-metadata">

**Author:** ![Cerowyn](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Cerowyn](https://boards.straightdope.com/u/Cerowyn)\
**Post date:** [April 4, 2007, 3:25am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/5 "2007-04-04T03:25:15Z")

</div>

Virtually any type of file can exploit a bug or vulnerability. One of the more prevalent methods relies on the so-called “buffer-overflow” problem that a lot of software exhibits, where deliberately malformed data ends up causing code to execute. Note that this does not require the file to be an executable itself, nor does the application loading the data have to support scripting or add-ons; it could be something as simple as reading a data file that triggers the exploit.

---

<div class="post-metadata">

**Author:** ![crowmanyclouds](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crowmanyclouds/32/19884_2.png) [@crowmanyclouds](https://boards.straightdope.com/u/crowmanyclouds)\
**Post date:** [April 4, 2007, 3:28am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/6 "2007-04-04T03:28:19Z")

</div>

> [@](#):
>
> [**What can I do to avoid getting infected?**](http://www.kangarose.com/tss/FAQs.html#viruses)
> 
> The simplest answer is to not open any email attachments, and use a firewall program. However, most people would like to be able to send and receive attachments such as pictures, so the advice to not open any attachments is often too extereme. However, the list of conditions to watch out for is rather complicated. First of all, don’t open executable attachments. Up until the Melissa and Love Letter viruses came out, most people thought that this meant only files with “.exe” extensions. But it turns out that there are at several executable extensions, including:
> 
> ```
> * .exe
> * .vbs (visual basic script)
> * .reg (Windows registry file)
> * .com (a command file, not the web address extension)
> * .bat (Windows batch file)
> * .shs (Windows scrap file)
> * .pif (a program information file, not to be confused with .pdf, the Adobe Acrobat portable document file format.
> * .scr (a script file, can also be a screen saver)
> * .doc (Microsoft Word document) Normally, you wouldn't think of a document file as an executable, but MS Word documents can contain macros, which are executable. The infamous Mellisa virus was this file type. 
> 
> ```
> 
> Avoiding these files types is more complicated than not clicking on them when they appear in email. Microsoft, in its infinite wisdom ;), decided to make it possible to hide certain file extensions, so that they aren’t displayed. Malicious coders took advantage of this by giving their virus files names like AnnaKournikova.jpg.vbs. By default the Windows operating system hides extensions like “.vbs”, so a person receiving this virus would only see “AnnaKournikova.jpg” and think that it was a harmless picture file. To display all file extensions on your computer, click on My Computer, select “View” and “Folder Options”. Select the “View” tab, and under Advanced settings, uncheck the box labeled “Hide file extensions for known file types”. …

> [@](#):
>
> [**Executable file extensions**](http://antivirus.about.com/od/securitytips/a/fileextview.htm)  
> Following is a partial list of file types that should be considered suspicious when received in email and should not be opened unless you requested or expected the attachment:
> 
> ADE - Microsoft Access Project Extension  
> ADP - Microsoft Access Project  
> BAS - Visual Basic Class Module  
> BAT - Batch File  
> CHM - Compiled HTML Help File  
> CMD - Windows NT Command Script  
> COM - MS-DOS Application  
> CPL - Control Panel Extension  
> CRT - Security Certificate  
> DLL - Dynamic Link Library  
> DO\* - Word Documents and Templates  
> EXE - Application  
> HLP - Windows Help File  
> HTA - HTML Applications  
> INF - Setup Information File  
> INS - Internet Communication Settings  
> ISP - Internet Communication Settings  
> JS - JScript File  
> JSE - JScript Encoded Script File  
> LNK - Shortcut  
> MDB - Microsoft Access Application  
> MDE - Microsoft Access MDE Database  
> MSC - Microsoft Common Console Document  
> MSI - Windows Installer Package  
> MSP - Windows Installer Patch  
> MST - Visual Test Source File  
> OCX - ActiveX Objects  
> PCD - Photo CD Image  
> PIF - Shortcut to MS-DOS Program  
> POT - PowerPoint Templates  
> PPT - PowerPoint Files  
> REG - Registration Entries  
> SCR - Screen Saver  
> SCT - Windows Script Component  
> SHB - Document Shortcut File  
> SHS - Shell Scrap Object  
> SYS - System Config/Driver  
> URL - Internet Shortcut (Uniform Resource Locator)  
> VB - VBScript File  
> VBE - VBScript Encoded Script File  
> VBS - VBScript Script File  
> WSC - Windows Script Component  
> WSF - Windows Script File  
> WSH - Windows Scripting Host Settings File  
> XL\* - Excel Files and Templates

CMC fnord!

---

<div class="post-metadata">

**Author:** ![1010011010](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@1010011010](https://boards.straightdope.com/u/1010011010)\
**Post date:** [April 4, 2007, 3:29am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/7 "2007-04-04T03:29:03Z")

</div>

Most malicious code functions by taking advantage of exploits within specific applications or libraries. This means that, yes, _any_ file can contain malicious code, but the programs that process .TXT files (for example) usually aren’t complex enough to have buffer overflows or other vectors for the malicious code to be executed.

---

<div class="post-metadata">

**Author:** ![crowmanyclouds](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crowmanyclouds/32/19884_2.png) [@crowmanyclouds](https://boards.straightdope.com/u/crowmanyclouds)\
**Post date:** [April 4, 2007, 3:37am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/8 "2007-04-04T03:37:56Z")

</div>

[QUOTE=Rysto]  
… Internet Explorer got hit with this once – someone found a way to make IE execute code embedded in a JPEG picture. …  
[/QUOTE]  
M.I.C.E. Metafile Image Code Execution  
GRC’s “MouseTrap” MICE detection [utility](http://www.grc.com/wmf/wmf.htm).

CMC fnord!

---

<div class="post-metadata">

**Author:** ![Rysto](https://avatars.discourse-cdn.com/v4/letter/r/ecccb3/32.png) [@Rysto](https://boards.straightdope.com/u/Rysto)\
**Post date:** [April 4, 2007, 3:57am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/9 "2007-04-04T03:57:20Z")

</div>

That’s actually a different vulnerability. In that case, it was a picture file format that Microsoft allowed to contain programs.

I was talking about [this security hole](http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx).

---

<div class="post-metadata">

**Author:** ![crowmanyclouds](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crowmanyclouds/32/19884_2.png) [@crowmanyclouds](https://boards.straightdope.com/u/crowmanyclouds)\
**Post date:** [April 4, 2007, 4:02am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/10 "2007-04-04T04:02:50Z")

</div>

There’s just too many to keep track of!

CMC fnord!

---

<div class="post-metadata">

**Author:** ![si\_blakely](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@si\_blakely](https://boards.straightdope.com/u/si_blakely)\
**Post date:** [April 4, 2007, 12:41pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/11 "2007-04-04T12:41:03Z")

</div>

[QUOTE=1010011010]  
Most malicious code functions by taking advantage of exploits within specific applications or libraries. This means that, yes, _any_ file can contain malicious code, but the programs that process .TXT files (for example) usually aren’t complex enough to have buffer overflows or other vectors for the malicious code to be executed.  
[/QUOTE]  
You have never used EMACS, have you 😃  
Si

---

<div class="post-metadata">

**Author:** ![El\_Zagna](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@El\_Zagna](https://boards.straightdope.com/u/El_Zagna)\
**Post date:** [April 4, 2007, 2:22pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/12 "2007-04-04T14:22:48Z")

</div>

[QUOTE=jovan]  
One of the problems is that sometimes file suffixes are hidden. So, an executable file called readme.txt.exe will appear as readme.txt. It’s not a text file, but it looks like one. That’s a common distribution method for computer viruses.  
[/QUOTE]  
In fact MS chose this to be the \*default \*setting in Explorer, although I don’t know why anyone would \*not \*want to see the extensions.

If you can’t see your file extensions, open up Explorer and go to Tools…/Folder Options and click on the View tab. Find the setting “Hide extensions for known file types”, and uncheck that sucker.

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [April 4, 2007, 2:49pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/13 "2007-04-04T14:49:37Z")

</div>

Thanks to NTFS any file can carry a virus. You see NTFS supports things called [Streams](http://www.diamondcs.com.au/index.php?page=archive&id=ntfs-streams). See also [here](http://www.ntfs.com/ntfs-multiple.htm) and [here](http://www.securiteam.com/windowsntfocus/5OP021FIUC.html).

---

<div class="post-metadata">

**Author:** ![si\_blakely](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@si\_blakely](https://boards.straightdope.com/u/si_blakely)\
**Post date:** [April 4, 2007, 3:36pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/14 "2007-04-04T15:36:08Z")

</div>

[QUOTE=Quartz]  
Thanks to NTFS any file can carry a virus. You see NTFS supports things called [Streams](http://www.diamondcs.com.au/index.php?page=archive&id=ntfs-streams). See also [here](http://www.ntfs.com/ntfs-multiple.htm) and [here](http://www.securiteam.com/windowsntfocus/5OP021FIUC.html).  
[/QUOTE]

While any NTFS file can carry a virus tucked into a stream (a concept taken from the Mac filesystem - known as a resource fork) the fact that very few applications actually _look_ at the streams means that there are limited avenues of infection.

Streams could have been useful - once upon a time. Now, they are generally considered irrelevant as there are no real uses for them. The were intended for Metadata (tags etc) and things like thumbnails on image files. Metadata generally gets tucked into extensible file formats (IPTC/EXIF for photos, ID3 for MP3s) so that they can be used across OSes, and MS did not implement stream-based thumbnailing, sticking with the stupid Thumbnails.db scheme.

Streams can be used to **hide** malware, and it has been a failing of the AV industry that stream scanning has not been implemented. Then again, streams have not actually been used by malware authors, in spite of the fact that the proof of concept has been about since 2000.

Si

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [April 4, 2007, 6:01pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/15 "2007-04-04T18:01:30Z")

</div>

1. Back in the old days…

One problem with text files was that many people used an ansi (or VT100) screen driver to get extra speed and functionality in a text screen. One “feature” of ansi screen coding was keyboard remapping. So you read a text file that contains the code to remap a key to something bad, you press the key, bad command gets executed.

Not really a problem now since it’s all old hat.

1. Even if you have MS-Windows set to show file extensions, not all are properly handled. The most awful one is the “.url” extension. If you have a file that looks safe but has the “.url” extension hidden, then IE opens and takes you to the linked web site. Which can then infect your computer with everything imaginable.

Thank you Bill Gates. Brilliant security planning there.

---

<div class="post-metadata">

**Author:** ![si\_blakely](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@si\_blakely](https://boards.straightdope.com/u/si_blakely)\
**Post date:** [April 4, 2007, 6:24pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/16 "2007-04-04T18:24:37Z")

</div>

[QUOTE=ftg]

1. Back in the old days…

One problem with text files was that many people used an ansi (or VT100) screen driver to get extra speed and functionality in a text screen. One “feature” of ansi screen coding was keyboard remapping. So you read a text file that contains the code to remap a key to something bad, you press the key, bad command gets executed.  
[/QUOTE]  
ANSI command string bombs - that takes me back. You could send a DEC Mail that changed the charset on the terminal, or inverted the screen colours or any one of a number of other pranks. Now all I do is rotate peoples display.

[QUOTE=ftg]  
2. Even if you have MS-Windows set to show file extensions, not all are properly handled. The most awful one is the “.url” extension. If you have a file that looks safe but has the “.url” extension hidden, then IE opens and takes you to the linked web site. Which can then infect your computer with everything imaginable.  
[/QUOTE]  
Not if you set Firefox as your default browser. And don’t run as administrator. 😃

Si

---

<div class="post-metadata">

**Author:** ![Bang\_This](https://avatars.discourse-cdn.com/v4/letter/b/f19dbf/32.png) [@Bang\_This](https://boards.straightdope.com/u/Bang_This)\
**Post date:** [April 4, 2007, 9:13pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/17 "2007-04-04T21:13:47Z")

</div>

I know about the Windows function to make sure it is displaying file extentions, because if they are not showing extentions a .ext file wouldn’t show. Then someone could disguise a file as example.txt when it’s really example.txt.exe - because you failed to turn on ext. I wonder why it’s off by default?

Anyway I guess what I mean is could you get a file mearly by opening a TXT file?

Let’s say I got a file that was in a notepad as TXT and I just click to open it. Could something really run from it?

---

<div class="post-metadata">

**Author:** ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)\
**Post date:** [April 4, 2007, 9:57pm UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/18 "2007-04-04T21:57:36Z")

</div>

[QUOTE=Bang This]  
Let’s say I got a file that was in a notepad as TXT and I just click to open it. Could something really run from it?  
[/QUOTE]

It depends on how you open it. It’s impossible to say that a file type is safe because the programs that are used to view files are so complex. Did you receive it through Outlook? What is running on your machine?

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [April 5, 2007, 5:22am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/19 "2007-04-05T05:22:48Z")

</div>

[QUOTE=Bang This]  
Anyway I guess what I mean is could you get a file mearly by opening a TXT file?

Let’s say I got a file that was in a notepad as TXT and I just click to open it. Could something really run from it?  
[/QUOTE]

It’s theoretically possible (other posts in this thread have discussed possible attacks), but it’s a relatively minor risk compared with other things that people usually do on a computer.

The thing to keep in mind is that there are always risks, both discovered and undiscovered, when you use a computer. You should do what you can to decrease the risks, but you can’t really get rid of them completely unless you just never use the computer. The real challenge is _balancing_ security versus usability.

Straying a bit into IMHO territory to explain this further: If you never double-click on another .TXT file again, you might (for example) reduce the risk of encountering a Notepad exploit from 1 in 50,000 to 1 in 100,000, but you would also (presumably) never read .TXT files again.

Is it a worthwhile trade-off? That’s ultimately up to you to decide, but I would say probably not because there are other things you can do like switch browsers, install firewalls or anti-virus programs, switch operating systems, etc. that will reduce a lot more risks without adversely affecting usability as much.

---

<div class="post-metadata">

**Author:** ![si\_blakely](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@si\_blakely](https://boards.straightdope.com/u/si_blakely)\
**Post date:** [April 5, 2007, 8:40am UTC](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670/20 "2007-04-05T08:40:44Z")

</div>

[QUOTE=Bang This]  
I know about the Windows function to make sure it is displaying file extentions, because if they are not showing extentions a .ext file wouldn’t show. Then someone could disguise a file as example.txt when it’s really example.txt.exe - because you failed to turn on ext. I wonder why it’s off by default?

Anyway I guess what I mean is could you get a file mearly by opening a TXT file?

Let’s say I got a file that was in a notepad as TXT and I just click to open it. Could something really run from it?  
[/QUOTE]  
Notepad (in the past) could actually be riskier than a proper text editor. It used to just open the file and dump the contents into a Windows API TextEdit control (which was why it could only handle files up to 64K on Win95/98) and it wasn’t fussy what it loaded. Can you say **Buffer Overflow**.

Real text editors are far more careful about data handling - using multiple buffers and suchlike. But such complexity has risks of its own.

I don’t know of any exploits based around text files, but always ensure that you display extensions before launching. And notepad now is a better app than it was, but I always use Notepad++

Si

[Next page](https://boards.straightdope.com/t/what-type-of-files-cant-carry-a-computer-virus/398670.md?page=2)
