How 7-Zip Extracts NSIS Executable Installers

This article explains how 7-Zip unpacks Nullsoft Scriptable Install System (NSIS) executables into their raw constituent files and scripts without executing the installer. The process relies on identifying the underlying Portable Executable (PE) overlay, parsing internal NSIS metadata headers, decompressing the embedded data stream using supported decompression algorithms, and translating compiled bytecode back into a human-readable installer script.

1. Identifying the PE Overlay and NSIS Signature

An NSIS installer is a standard Windows Portable Executable (PE) file containing a stub loader, followed by appended data known as an overlay. The stub is responsible for executing the installation logic when run by the operating system.

When opened in 7-Zip, the utility does not execute the binary. Instead, it parses the PE headers to determine the exact byte offset where the legitimate executable code ends. It then scans the trailing overlay for specific NSIS "magic signatures" (historically markers like 0xDEADBEEF or the string signature NullsoftInst). Once detected, 7-Zip switches from standard PE parsing to its dedicated NSIS archive handler.

2. Reading the NSIS Header and Block Structures

Immediately following the signature is the NSIS header structure. 7-Zip reads this block to retrieve critical metadata about the installer package, which includes:

  • Flags and Options: Target architecture, CRC check settings, and compression types.
  • Block Offlines and Sizes: The locations of the instruction records, string tables, language tables, and data blocks.
  • String Table: The repository of plain-text file paths, registry keys, and directory targets referenced throughout the installation.

3. Decompressing the Internal Stream

NSIS packages compress their payload using one of three primary algorithms: LZMA, BZip2, or zlib (Deflate). NSIS can pack files either individually or in a solid compression stream where all files are concatenated before compression.

7-Zip identifies the compression method designated in the NSIS header and applies its native decoders:

  • In non-solid archives, 7-Zip decompresses individual file streams on demand.
  • In solid archives, 7-Zip streams the entire compressed payload into memory or temporary buffers, indexing the offset boundaries corresponding to individual files based on the installer's internal entries.

4. Reconstructing Files and Folder Paths

To present a readable archive structure, 7-Zip cross-references the extracted raw data with the instruction list in the NSIS header. In an NSIS script, file extraction is defined by specific opcodes (such as File or ExtractFile) paired with destination paths defined in the string table.

7-Zip iterates through these instructions to determine:

  • The original file names.
  • The directory hierarchy inside the installer.
  • The exact compressed offset and decompressed size for each file.

It then writes the payload out to matching folders, stripping away installer-specific runtime variables (like $INSTDIR or $PROGRAMFILES) and converting them into relative folder paths.

5. Decompiling the Installer Script ([NSIS].nsi)

Beyond raw files, 7-Zip extracts the installation logic itself by parsing the compiled NSIS opcodes. The NSIS compiler converts text scripts into intermediate bytecode for variables, conditional checks, registry modifications, and execution commands.

7-Zip reverse-engineers this instruction array, translating the bytecodes back into approximate NSIS script syntax. It outputs this parsed logic into a virtual file named [NSIS].nsi. This enables users to inspect registry edits, command-line arguments, dependency installations, and execution hooks that would have run during a standard installation.