How 7-Zip Extracts Resources from PE Files
7-Zip can open Windows Portable Executable (PE) files—such as
.exe, .dll, and .sys—as standard
archives, allowing users to inspect and extract embedded resources.
Rather than executing the binary, 7-Zip treats the file as a structured
container. By parsing the PE headers, locating the .rsrc
(resource) section, traversing the hierarchical resource tree, and
converting raw byte streams into standalone file formats, 7-Zip exposes
icons, bitmaps, strings, manifests, and packaged secondary payloads
directly to the user.
Parsing the PE Header and Sections
Every 32-bit and 64-bit Windows binary adheres to the Portable Executable format. When 7-Zip opens an executable, it bypasses code execution and inspects the binary data directly:
- DOS and PE Headers: 7-Zip reads the initial
IMAGE_DOS_HEADERto find thee_lfanewpointer, which leads to theIMAGE_NT_HEADERS. - Optional Header Data Directories: Within the NT
headers, 7-Zip reads the Data Directory array. Index 2 points
specifically to the Resource Table
(
IMAGE_DIRECTORY_ENTRY_RESOURCE), providing its Relative Virtual Address (RVA) and size. - Section Mapping: Executables are divided into
sections (such as
.text,.data, and.rsrc). 7-Zip maps the RVA of the resource table to a physical raw file offset by referencing theIMAGE_SECTION_HEADERfor the.rsrcsection.
Traversing the Resource Directory Tree
Windows organizes the .rsrc section as a multi-level
tree structure represented by IMAGE_RESOURCE_DIRECTORY
tables. 7-Zip parses this structure down through three standard
levels:
- Level 1 (Type): Defines the category of the
resource. Standard types are defined by integer IDs or strings (e.g.,
RT_ICON[3],RT_BITMAP[2],RT_DIALOG[5],RT_MANIFEST[24],RT_RCDATA[10]). 7-Zip uses these types to categorize items or map them into subfolders. - Level 2 (Name/ID): Identifies specific resource
instances within a type (e.g., Resource ID
101or a custom string name). - Level 3 (Language): Accommodates localization,
designating the language and sublanguage (e.g., US English:
0x0409).
At the leaf of each branch sits an
IMAGE_RESOURCE_DATA_ENTRY. This structure holds the RVA of
the raw data, the exact byte size of the resource, and the code
page.
Resolving Offsets and Synthesizing File Headers
Once 7-Zip navigates to a leaf node, it converts the resource RVA into a physical file offset and extracts the raw bytes. However, PE resources often lack the file headers required to exist as valid standalone files on disk. 7-Zip bridges this gap programmatically:
- Icons and Cursors: In a PE file, icon groups
(
RT_GROUP_ICON) store directory information, while the actual icon frames (RT_ICON) are stored separately without standard.icofile headers. 7-Zip reads the group descriptor, gathers the corresponding image frames, constructs a valid 6-byteICONDIRheader andICONDIRENTRYstructures, and bundles them with the raw bitmap or PNG data to output a fully functional.icofile. - Bitmaps (
RT_BITMAP): Windows stores bitmaps internally without the standard 14-byteBITMAPFILEHEADER. 7-Zip synthesizes this header, calculates the correct file offsets, and prepends it to the embeddedBITMAPINFOHEADERand pixel data to produce standard.bmpfiles. - Manifests and Raw Data (
RT_MANIFEST,RT_RCDATA): Manifests are saved as standard.xmlor.manifesttext files, while arbitrary binary resources (RT_RCDATA) are extracted as generic binary streams.
Handling Installer Payloads and Overlays
In addition to standard Windows API resources, many executables act as setup wrappers (such as NSIS, Inno Setup, or custom self-extracting zip archives).
7-Zip includes dedicated parsers for known installer formats. If an
installer embeds a compressed archive within RT_RCDATA, or
if data is appended to the very end of the PE file as an "overlay"
(bytes located past the declared end of all PE sections), 7-Zip scans
for signature headers. Upon detecting an embedded container format, it
unpacks the payload as an inner archive rather than displaying merely
the compiled Windows interface resources.