Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] Lenovo G710 BIOS Whitelist Rem...
Last Post: Ritter-Dussel
Today 03:43 PM
» Replies: 499
» Views: 265998
[REQUEST] Medion Deputy P40 unlock / dis...
Last Post: haavod
Today 01:17 PM
» Replies: 2
» Views: 167
[REQUEST] Lenovo P580 (5ECNxxWW) Whiteli...
Last Post: Amazing333
Today 04:51 AM
» Replies: 172
» Views: 86248
[REQUEST] Lenovo B50-70 (9DCNxxWW) BIOS ...
Last Post: Dudu2002
Today 02:04 AM
» Replies: 74
» Views: 52546
HP P5BW-LA : All 1066 Quad Core Support ...
Last Post: Pepetruen0
Today 12:05 AM
» Replies: 4
» Views: 6820
[REQUEST] HP Compaq 6730b Whitelist Remo...
Last Post: Rapadura
Yesterday 06:38 PM
» Replies: 10
» Views: 6042
Asrock b660m steel legend, Help Add supp...
Last Post: ffrog911
Yesterday 11:29 AM
» Replies: 2
» Views: 222
GA-H81M-DS2 rev. 2.1 Above 4g Decode
Last Post: NoobMaster2699
Yesterday 06:59 AM
» Replies: 0
» Views: 109
[REQUEST] Lenovo helix 1 type 3xxx 's bi...
Last Post: maestropen
Yesterday 05:53 AM
» Replies: 0
» Views: 139
[REQUEST] Lenovo ThinkPad T510 (6METxxWW...
Last Post: deepTeNk
12-06-2025 04:21 AM
» Replies: 59
» Views: 44383
[Request] Acer Aspire TC-281 B350 Ryzen ...
Last Post: Blagg2
12-05-2025 05:31 PM
» Replies: 0
» Views: 171
[Request] Fujitsu Celcius H770 Whitelist...
Last Post: kalu
12-05-2025 11:24 AM
» Replies: 0
» Views: 131
Compaq Presario R3000, HP Pavilion zv500...
Last Post: DeathBringer
12-04-2025 01:13 PM
» Replies: 28
» Views: 1328
hp 14-dq6002na raised power limits wante...
Last Post: Idkwhatimdoing
12-04-2025 01:02 AM
» Replies: 0
» Views: 177
[REQUEST] Toshiba Satellite C855-1QF-PSC...
Last Post: DeathBringer
12-03-2025 08:53 AM
» Replies: 1
» Views: 259
[REQUEST] Lenovo G50-70 (9ACNxxWW) White...
Last Post: rayz5
12-03-2025 06:14 AM
» Replies: 246
» Views: 136242
[REQUEST] Acer Nitro 5 AN515-58 BIOS Unl...
Last Post: Dudu2002
12-03-2025 03:07 AM
» Replies: 45
» Views: 62511
Enabling VT-d/VT-x on MSI Cubi 2 Bios
Last Post: janlugt
12-02-2025 07:12 PM
» Replies: 5
» Views: 383
BIOS for HP 250 G1 F45 Unlocked working ...
Last Post: Schibeki
12-02-2025 03:23 PM
» Replies: 0
» Views: 199
Can i cross-flash my...
Last Post: fr4nk1sh
12-02-2025 03:19 AM
» Replies: 2
» Views: 257

Extracting boot logo & other stuff from a UEFI Tiano/Insyde .FD image
#1
Lightbulb 
There are essentially two ways to extract graphics from an .FD UEFI BIOS image:

(1) Look for capsules with specific GUIDs known to contain it, such as:

Code:
E5BBF7BE-2417-499B-97DB-39F4896391BC,SplashLogoPackage
1FFF93C2-8C76-49E4-8AB3-43D92F5445EF,LogoJpg
6F0CF054-AE6A-418C-A7CE-3C7A7CD74EC0,LogoPcx

(2) Search for magic strings associated with particular image formats, for example:
  • BMP: "BM" string
  • GIF: "GIF89a" string
  • JPEG: "JFIF" string
  • PCX: hexadecimal 0A 05 01 08
The .FD image can be decompressed with a number of tools, in particular: Phoenix Tool, UEFI Tool, or simply binwalk. The last two also include search capabilities. Otherwise, files can be searched with grepWin once decompressed.

I've succesfully extracted boot logos and other graphics from a number of Lenovo laptop BIOSes using the above methods, all of which yield the same results. Here's an example of what can be found once decompressed:

Code:
# <GUID>
[<LaptopModel>_<BiosVersion>] <File>

# 1FFF93C2-8C76-49E4-8AB3-43D92F5445EF,LogoJpg
[B460_1DCN26WW_4FCNAWW] 1024x768 JPEG: Boot logo (40,693 bytes; inside CRC32 GUID: FC1BCDB0-7D31-49AA-936A-A4600D9DD083)

# 6F0CF054-AE6A-418C-A7CE-3C7A7CD74EC0,LogoPcx
[Y700_CDCN53WW] 1024x768 PCX, 8-bit: All black (27,068 bytes)

# 771F77D1-13AF-48BF-2584-773D389E33CA
[Y700_CDCN53WW] 360x360 JPEG: "Invalid Public Key for Secure Flash" (17,656 bytes)

# 931F00D1-10FE-48BF-AB72-773D389E3FDA
[Y700_CDCN53WW] 208x157 BMP, 8-bit: Intel logo (33,236 bytes)

# 931F77D1-10FE-48BF-AB72-773D389E3FAA
[Y700_CDCN53WW] 300x300 BMP, 24-bit: Insyde logo (270,056 bytes)

# 156A8FFE-62DB-4FF3-82AD-2EBD8A3E3DF7
[Y520_4KCN24WW] [Y900_D0CN34WW] 768x432 GIF89a: Boot logo, animated (128,090 bytes)

# 1F56B2F9-6E6D-4014-BFD4-37C9E5D398F1
[Y520_4KCN24WW] 1536x864 GIF89a: Boot logo, animated (406,313 bytes)

# E5BBF7BE-2417-499B-97DB-39F4896391BC,SplashLogoPackage
[110_1QCN20WW] 548x308 JPEG: Boot logo (17,169 bytes; followed by a GIF w/icons)
[110_1QCN31WW] 548x308 JPEG: Boot logo (53,046 bytes; followed by a GIF w/icons)
[700_E5CN58WW] 548x308 JPEG: Boot logo (49,368 bytes; followed by several GIFs w/icons)

However, none of the above methods manage to locate the boot logo in Lenovo Y700 images such as CDCN37WW.fd and CDCN53WW.fd (attached), although it is clearly somewhere there. Can anyone tell me what I am missing?

Possibly the logo is in a format other than BMP/GIF/JPG/PCX. The BIOS images have a "TgaDecoderDxe" module inside. Could there be any TGA (Targa) images there? If so, how to find them? Or is it something else altogether? Like obfuscation with XOR or something more sophisticated? Suggestions appreciated.


Attached Files
.zip   CDCN53WW.fd.zip (Size: 4.02 MB / Downloads: 29)
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)