BIOS malware is even worse. This is the serious stuff.
Persistent "obfuscation-ware"-type behavior of a machine, weirdness that goes on from one OS to another,,,all symptoms
I bring this up b/c I scan regularly (AVG) and watch the processes. I use sandboxes when I can.
So I thought simple rootkit. BUT--this morning my machine auto-flashed the BIOS from the second ROM BIOS after having issues starting, dealing with I/O, etc. It said the flash BIOS was corrupted.
Why did this not get found before?! This behavior has gone on longer than just today.
What is the check that's performed? Is it CRC or something that the malware gets around with junk chars? Why did it get found now?
Anyone know of a way to dump the BIOS chip data? It would also be useful to (1000x) a day check the pristine dump from the ROM chip against the flashable chip, if your (physical) system has two BIOS chips.