> Source: [sk115432](https://support.checkpoint.com/results/sk/sk115432)

# sk115432 - Anti-Virus blade identifies Microsoft Office extension files (xlsx,docx,pptx) as zip files and treats them according to its policy

| Property | Value |
|----------|-------|
| Solution ID | sk115432 |
| Date Created | 2017-01-11 |
| Last Modified | 2020-07-01 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Anti-Virus blade identifies Microsoft Office extension files (xlsx,docx,pptx) as zip files and handle them according to the policy chosen.
* Anti-Virus blade - Engine Settings is set on "Process specific file types families, and the action 'Block' is chosen for 'zip' extension.
* Even if a new extension for (xlsx,docx,pptx) is created with 'Scan' action, the file is still being recognized as ZIP and hence blocked according to the ZIP file setting chosen.

## Cause

Enforcement is working according to the current design of Anti-Virus blade.

Anti-Virus checks the extension and the files '[magic-number](https://en.wikipedia.org/wiki/Magic_number_(programming))', but the file classification is done according to the magic-number (unless the extension is considered as not weak and the extension enforcement was block).  
Hence in the mentioned scenario Anti-Virus continues and checks the xlsx/docx/pptx, and as it has the same magic-number as ZIP file, it classifies them as ZIP.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115432/d11701110648.jpg)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115432/z11701110649.jpg)

## Solution

Anti-Virus recognizing xlsx/docx/pptx files as ZIP files is an expected behavior.   

For information how to add file types to Anti-Virus scans in R75.40 and above (not in R80.x), refer to [sk92575](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92575)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
