Check BIOS ROM for changes/corruption

derChronostat

New member
Local time
1:44 PM
Messages
22
Hi,
i hope its ok to post a BIOS-related question. My PC works fine, but out of curiosity I wanted to check my BIOS for changes/corruption via checksum (SHA1).
I got the fresh and identical BIOS version from manufacturer website and checked the hash.
I went to BIOS and saved a backup and checked the hash. Result - hashes are not identical


I checked byte-size of both files - identical
I tried different things (save-changes or not, filenames, several backups within one session, etc) and boiled it down to the situation that apparently every distinct BIOS-session I start, is causing a change to the BIOS ROM. I started several sessions, saved a backup each session and checked the hash. Every single ROM is different, except when I did the backup twice within ONE session.

If every indivdual session yields a different BIOS ROM how can I track BIOS integrity/changes?


Any ideas?


Thanks, Chris
 

My Computer My Computer

At a glance

Windows 7 Prof. 64bit SP1i7 2600K4x2GB Kingston 1333onboard
Computer type
PC/Desktop
OS
Windows 7 Prof. 64bit SP1
CPU
i7 2600K
Motherboard
Asus P8Z68-V Pro Gen3
Memory
4x2GB Kingston 1333
Graphics Card(s)
onboard
Sound Card
onboard
Monitor(s) Displays
LG 27"
Screen Resolution
1920x1080
Hard Drives
Samsung 840 EVO 256GB
WD Green 2TB
PSU
Corsair TX850W
Case
open air
Cooling
Intel
Internet Speed
10Mbit
Antivirus
Avira
Browser
Firefox
Other Info
WIFI router: TP-Link TL-WR1043ND Ver:1.8
Hi derChronostat

I am not too sure that both files contain the same information.

The BIOS that you are able to download from the manufacturer's website is the complete Firmware of the motherboard.

However, the file that you are able to save from within BIOS, only contains the custom configuration settings of that BIOS. Therefore, this second file will be different to the first file, so I am not sure as how you got them to be the same size.
 

My Computer My Computer

At a glance

Windows 7 x64, Vista x64, 8.1 smartphoneIntel E8400 65W 64-bitDDR2 2 x 2GB, 1GB x 2XFX Radeon HD5750
Computer type
PC/Desktop
OS
Windows 7 x64, Vista x64, 8.1 smartphone
CPU
Intel E8400 65W 64-bit
Motherboard
Gigabyte EP45-UD3LR
Memory
DDR2 2 x 2GB, 1GB x 2
Graphics Card(s)
XFX Radeon HD5750
Sound Card
AMD High Definition Audio; Realtek High Definition Audio
Monitor(s) Displays
iiyama prolite X2377HDS
Screen Resolution
1920 x 1080
Hard Drives
500GB 7200 rpm Seagate ST3500413AS 16MB, 500GB 5400 rpm Toshiba MQ02ABF050H 32MB, 200GB 7200 rpm Seagate ST3200820AS 8MB, 2TB 7200 rpm Western Digital WD20EZRX 64MB
PSU
Enermax Liberty Modular
Case
Antec P193 Midi Tower
Keyboard
Mionix ZIBAL 60
Mouse
Razer USB 2.0 Diamondback Mouse or Huion Graphics Tablet
Browser
Internet Explorer, Lunascape, Firefox, Opera, Avast Safezone
The BIOS that you are able to download from the manufacturer's website is the complete Firmware of the motherboard.

However, the file that you are able to save from within BIOS, only contains the custom configuration settings of that BIOS. Therefore, this second file will be different to the first file . . .
:thumbsup:
 

My Computer My Computer

At a glance

Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux...Intel(R) Pentium(R) CPU P6200 @ 2.13GHz4.00 GBIntel(R) Graphics Media Accelerator HD
Computer type
Laptop
Computer Manufacturer/Model Number
Fujitsu LIFEBOOK
OS
Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
CPU
Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Motherboard
FUJITSU FJNBB06
Memory
4.00 GB
Graphics Card(s)
Intel(R) Graphics Media Accelerator HD
Sound Card
[1] Realtek High Definition Audio [2] Intel(R) Display Audio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
TOSHIBA MK5076GSX
Antivirus
AVG FREE
I just used the ASUS EZ Flash 2 Utility within the BIOS to do a backup. That yielded a file with the expected size, identical to the ROM downloadable from the manufacturer website. In the meantime I used UEFITool to compare the content of downloaded and backed up BIOS. The files show obvious differences in the Regions but the BIOS region of both files contain exactly the same Volumes and File-content. I extracted several Volumes and compared the checksums and found that some volumes are identical between the two ROMs and some volumes differ.


I could understand that the EZ Flash Utility is doing some proprietary stuff that results in a slightly different ROM-image than the original but what I do not understand is why it is changing from BIOS-session to BIOS-session.
From my understanding an image of a ROM-chip which is 'read only', hence no custom configuration should be in it.
If there is, I would expect that if I do not change custom config I should at least get identical backups and should be able to compare the backups with each other. Which is not the case



Ok, I was hoping that this would be a relatively straight forward thing but whatever ASUS is doing, it hinders tracking BIOS integrity.
 

My Computer My Computer

At a glance

Windows 7 Prof. 64bit SP1i7 2600K4x2GB Kingston 1333onboard
Computer type
PC/Desktop
OS
Windows 7 Prof. 64bit SP1
CPU
i7 2600K
Motherboard
Asus P8Z68-V Pro Gen3
Memory
4x2GB Kingston 1333
Graphics Card(s)
onboard
Sound Card
onboard
Monitor(s) Displays
LG 27"
Screen Resolution
1920x1080
Hard Drives
Samsung 840 EVO 256GB
WD Green 2TB
PSU
Corsair TX850W
Case
open air
Cooling
Intel
Internet Speed
10Mbit
Antivirus
Avira
Browser
Firefox
Other Info
WIFI router: TP-Link TL-WR1043ND Ver:1.8
Back
Top