Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[Request] Acer Predator Helios 18 (PH18-...
Last Post: the_vulture90
Today 08:34 AM
» Replies: 0
» Views: 146
Samsung Chronos NP770 NP870 disable disc...
Last Post: faeterov
Today 07:07 AM
» Replies: 6
» Views: 1063
Gigabyte GA-6RX: Tualatin Support
Last Post: dm-
Today 04:01 AM
» Replies: 0
» Views: 130
[REQUEST] Lenovo ThinkPad Edge E420 & E5...
Last Post: gianluca220
Yesterday 06:47 PM
» Replies: 92
» Views: 66543
[REQUEST] Acer Aspire 5738(G,Z) BIOS Unl...
Last Post: endyacer
Yesterday 05:22 PM
» Replies: 7
» Views: 8371
[REQUEST] Lenovo IdeaPad P400, P500, Z40...
Last Post: Dudu2002
Yesterday 02:45 PM
» Replies: 685
» Views: 347780
[REQUEST] Lenovo Legion Y9000X (16IRX9) ...
Last Post: pahgom
01-04-2026 04:00 PM
» Replies: 0
» Views: 190
Fatality Asrock 990fx killer/3.1 TPM 2.0...
Last Post: Menace57
01-04-2026 01:38 PM
» Replies: 0
» Views: 138
Geforce7050M-M V2.0 with Phenom II x4 95...
Last Post: Vlad94
01-04-2026 09:07 AM
» Replies: 14
» Views: 2904
[REQUEST] GIGABYTE G5 MF BIOS Unlock
Last Post: tcp
01-04-2026 08:11 AM
» Replies: 4
» Views: 212
Asus Rog G531GW Unlocked BIOS
Last Post: Thanathos
01-03-2026 01:55 PM
» Replies: 24
» Views: 12100
BIOS for IBASE Mainboard MB995VF-0
Last Post: alex1023
01-03-2026 10:33 AM
» Replies: 0
» Views: 177
[REQUEST] Lenovo G480 (5ECNxxWW) Whiteli...
Last Post: ajrrjerauser
01-02-2026 01:48 PM
» Replies: 103
» Views: 73881
[REQUEST]Whitelist removal DELL XPS 9570...
Last Post: koda.shojix
01-02-2026 11:05 AM
» Replies: 0
» Views: 194
GMKtec K6 (AMI Aptio V BIOS) – User pass...
Last Post: Halo
01-02-2026 04:16 AM
» Replies: 0
» Views: 217
[Request] Dell 17R Inspiron 5720-6709
Last Post: FrostyDay
01-01-2026 02:21 PM
» Replies: 1
» Views: 225
[REQUEST] Lenovo Z410 & Z510 (8DCNxxWW) ...
Last Post: Dudu2002
01-01-2026 01:21 PM
» Replies: 504
» Views: 260717
OptiPlex 360 380 760 780 960 Xeon LGA 77...
Last Post: bpm199
01-01-2026 12:31 PM
» Replies: 266
» Views: 365099
[REQUEST] Acer PT715-51 (Triton 700) ins...
Last Post: Dudu2002
01-01-2026 11:12 AM
» Replies: 29
» Views: 20221
[REQUEST] Lenovo G50-30 (A7CNxxWW) White...
Last Post: mazi54
01-01-2026 05:28 AM
» Replies: 76
» Views: 42313

Extracting boot logo & other stuff from a UEFI Tiano/Insyde .FD image
#1
Lightbulb 
There are essentially two ways to extract graphics from an .FD UEFI BIOS image:

(1) Look for capsules with specific GUIDs known to contain it, such as:

Code:
E5BBF7BE-2417-499B-97DB-39F4896391BC,SplashLogoPackage
1FFF93C2-8C76-49E4-8AB3-43D92F5445EF,LogoJpg
6F0CF054-AE6A-418C-A7CE-3C7A7CD74EC0,LogoPcx

(2) Search for magic strings associated with particular image formats, for example:
  • BMP: "BM" string
  • GIF: "GIF89a" string
  • JPEG: "JFIF" string
  • PCX: hexadecimal 0A 05 01 08
The .FD image can be decompressed with a number of tools, in particular: Phoenix Tool, UEFI Tool, or simply binwalk. The last two also include search capabilities. Otherwise, files can be searched with grepWin once decompressed.

I've succesfully extracted boot logos and other graphics from a number of Lenovo laptop BIOSes using the above methods, all of which yield the same results. Here's an example of what can be found once decompressed:

Code:
# <GUID>
[<LaptopModel>_<BiosVersion>] <File>

# 1FFF93C2-8C76-49E4-8AB3-43D92F5445EF,LogoJpg
[B460_1DCN26WW_4FCNAWW] 1024x768 JPEG: Boot logo (40,693 bytes; inside CRC32 GUID: FC1BCDB0-7D31-49AA-936A-A4600D9DD083)

# 6F0CF054-AE6A-418C-A7CE-3C7A7CD74EC0,LogoPcx
[Y700_CDCN53WW] 1024x768 PCX, 8-bit: All black (27,068 bytes)

# 771F77D1-13AF-48BF-2584-773D389E33CA
[Y700_CDCN53WW] 360x360 JPEG: "Invalid Public Key for Secure Flash" (17,656 bytes)

# 931F00D1-10FE-48BF-AB72-773D389E3FDA
[Y700_CDCN53WW] 208x157 BMP, 8-bit: Intel logo (33,236 bytes)

# 931F77D1-10FE-48BF-AB72-773D389E3FAA
[Y700_CDCN53WW] 300x300 BMP, 24-bit: Insyde logo (270,056 bytes)

# 156A8FFE-62DB-4FF3-82AD-2EBD8A3E3DF7
[Y520_4KCN24WW] [Y900_D0CN34WW] 768x432 GIF89a: Boot logo, animated (128,090 bytes)

# 1F56B2F9-6E6D-4014-BFD4-37C9E5D398F1
[Y520_4KCN24WW] 1536x864 GIF89a: Boot logo, animated (406,313 bytes)

# E5BBF7BE-2417-499B-97DB-39F4896391BC,SplashLogoPackage
[110_1QCN20WW] 548x308 JPEG: Boot logo (17,169 bytes; followed by a GIF w/icons)
[110_1QCN31WW] 548x308 JPEG: Boot logo (53,046 bytes; followed by a GIF w/icons)
[700_E5CN58WW] 548x308 JPEG: Boot logo (49,368 bytes; followed by several GIFs w/icons)

However, none of the above methods manage to locate the boot logo in Lenovo Y700 images such as CDCN37WW.fd and CDCN53WW.fd (attached), although it is clearly somewhere there. Can anyone tell me what I am missing?

Possibly the logo is in a format other than BMP/GIF/JPG/PCX. The BIOS images have a "TgaDecoderDxe" module inside. Could there be any TGA (Targa) images there? If so, how to find them? Or is it something else altogether? Like obfuscation with XOR or something more sophisticated? Suggestions appreciated.


Attached Files
.zip   CDCN53WW.fd.zip (Size: 4.02 MB / Downloads: 29)
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)