[Guide] Unlock Insyde H2O BIOS with Checksum Control

Thanks for the guide, it seems I’m very close but no success so far :frowning:

Since I’m a new user here and can’t post files yet, I hope it’s okay to post a link to the BIOS dump (+the extracted PEI modules that need to be edited in IDA): toshiba wt8-a bios dump.zip - Google Drive

I have identified the padding area, the absolute address (FFFE0058) and the PEI modules (ChipsetSvcPei and ChipsetSvcPeiBB).

I can see the section that @B83C has posted in the tips in IDA.

However, when compared to the tutorial and his supplied MOMO.G.WI71C.MABMRBA02.ROM, instead of jz loc_FFF.... I have jns loc_FFF...., tried changing it to a jmp, but no boot. I can see similar structures, yet things are a bit different…

Does anyone have any ideas on where to look?