The BIOS can't see F. This is why you need NKPatcher or PBL to see an F drive.
They can't be hashing, or checking saves, because thats an invasion of privacy and due to the Action Replay existing its a stupid idea and would probably get innocent people banned.
MS has, and still is, banning anyone running a modified BIOS. This could be avoided by simply rebooting the system with an original disc, avoiding running the exploit and modifying the BIOS.
Most likely there checking the hash of the dashboard XBE (xboxdash.xbe) and then banning the HD serial number or the DVD serial number, because the DVD and the HD serial number are pretty much the only unchangeable codes in the XBox (Live ID's, MAC addresses, etc, can all be swapped with an EEPROM change and this has been proven not to work).
MS could be banning IP's but then our dynamically IP'ed friends could just grab another and get back on, or get their entire ISP banned which is also a stupid thing for MS to do.
So, for now, please let anyone you know running an exploit know.
Connect to Live like this and your probably getting in some serious new shit.
As for MS employees that will probably read this, bravo. Your finally proving some competence in your ability to secure people off your network. Too bad you suddenly decided to up and fuck exploiters over though.