efi file is to look for the signature 4D5A in the beginning, PE pointer in 0x3C-0x3F and PE signature at that pointer.

The simplest way to determine if you have an. efi file is an executable with a PE header and structure, it can be opened with any PE tool for inspection. The reason for this is that the ffs is a container for sections and has the header where you can see that GUID, while the PE section (or any section) can only make sense in a ffs and has a small header on its own, with size and extra data on a few special sections.

efi file, or you replace the entire GUID with a. When you use UEFITool, you either replace the body of PE section with an.