mirror of
https://github.com/SabreTools/BinaryObjectScanner.git
synced 2026-02-04 05:35:49 +00:00
[Installer] Add PopCap Installer detection #51
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @TheRogueArchivist on GitHub (Jan 12, 2022).
Installer used by PopCap shareware games for a period of at least around 2004-2010. Files can be easily extracted using 7-zip, with two root folders ("cfg" and "files") being present. The "files" folder seems to contain the exact files as dropped into the installation directory. I haven't been able to find identifying strings in every sample I have, but some have "popcap" very early in the header, and others having "!popcapinstallersig!" somewhat later in the header. It tentatively seems that older games use "popcap" and newer ones use "!popcapinstallersig!", but this isn't for sure yet. According to 7-zip, these installers use at least 2 different compression methods, MSZip and LZX:21. I'm hoping that these should be able to be extracted by BOS, which would greatly aid in detection of PopCap DRM Protect (When added) and ActiveMARK.
@mnadareski commented on GitHub (Sep 7, 2025):
If there are any links or references for what items may contain this, please provide them.