Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


@garlin I ran your new script in power shell and Malwarebytes picked it up as Malware

This only happens once. If I run the script again Malwarebytes ignores it until a system restart.
This happened on my laptop and desktop. There was no pop up. I saw the result when I went into Malwarebytes and was like what the heck but can say it happens exactly when the script runs. You need to open the program and go to detection history and it will be there.
@EB2XR6 reported a similar malware alert from Webroot.

I believe it's false positive triggered by the inclusion of an open source function written by security researcher Matt Graeber. The function decodes the policy version number that's embedded in the SkuSiPolicy.p7b file, since it's not an open setting that can be read from the file.

Matt is a legitimate security expert who specializes in Windows code integrity (security), and provides many analysis scripts for other researchers.

Unfortunately, I can't ask the different security companies to unblock my script, since I'm an individual with no professional reputation online. Yes, I worked for two large tech companies people have known, but I those details are not public. Security companies don't like unblocking people who don't have a long reputation as a public-facing developer with a recognized project or software app.

You can choose to use the previous version (v2024.01.18):
Releases · garlin-cant-code/SecureBoot-CA-2023-Updates

As an experiment, I'm going to create an obfuscated version of the current script (for fun) to see if the security scanners are doing what I think they shouldn't be doing.
 
Last edited:

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
OK! Success.

2. The option in bios that forced secure boot into setup mode on my X99 Godlike board (2015 era) so the update script can install the certs:

Step 0 - MANUAL management of secure boot keys (NOT standard mode)

Step 1 - DISABLE factory default option
Step 2 - DELETE all factory default keys
Step 3 - A msg box appears stating all keys will be deleted and force secure boot into setup mode.

Run the check script then update script.
Thanks for the write-up, it will help other users who might not know their BIOS menus.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
@garlin I ran your new script in power shell and Malwarebytes picked it up as Malware

Please see the screenshots.

This only happens once. If I run the script again Malwarebytes ignores it until a system restart.

View attachment 168151

View attachment 168152

View attachment 168153

This happened on my laptop and desktop. There was no pop up. I saw the result when I went into Malwarebytes and was like what the heck but can say it happens exactly when the script runs. You need to open the program and go to detection history and it will be there.

James.
Hi James & Garlin
I have sent a copy of the script to Webroot for analysis a few hours ago and have not heard anything back.
I already mentioned to Garlin that I uploaded the Script to virustotal.com and nothing was detected.
Regards EB2XR6
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 8700G64 GBOnboard
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Generic
CPU
AMD Ryzen 8700G
Motherboard
Gigabyte B650 UD AC
Memory
64 GB
Graphics Card(s)
Onboard
Sound Card
Onboard
Monitor(s) Displays
Del U2723QE
Screen Resolution
3840 x 2160
Hard Drives
Corsiar MP600 1TB
PSU
Silverstone 750 GOLD
Case
Silverstone FARA 513
Just for fun... does this trigger anyone's security product? I rewrote Matt's function to fluster automated scanning.
 

Attachments

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hi James & Garlin
I have sent a copy of the script to Webroot for analysis a few hours ago and have not heard anything back.
I already mentioned to Garlin that I uploaded the Script to virustotal.com and nothing was detected.
Regards EB2XR6

That's because the file is not the problem. I have scanned Check-UEFI with Malwarebytes, Norton 360 and HitmanPro and have received negative results. It only happens when you run the script.

There is no pop up with Malwarebytes but if you open it up you will see a entry in Detection History - Detection Overview related to the script being run.
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i5-12600K 3.7 GHz 10-Core ProcessorCorsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-...Integrated Intel UHD Graphics 770
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built PC by me.
    CPU
    Intel Core i5-12600K 3.7 GHz 10-Core Processor
    Motherboard
    Gigabyte B760M H DDR4 Micro ATX LGA1700 Motherboard
    Memory
    Corsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-3200 CL16 Memory
    Graphics Card(s)
    Integrated Intel UHD Graphics 770
    Sound Card
    Realtek
    Monitor(s) Displays
    LG
    Hard Drives
    Samsung 990 Pro 1 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    Samsung 990 Pro 2 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    PSU
    NZXT 850w ATX 3.1 Gold Fully Modular Power Supply
    Case
    Thermaltake Versa H25 ATX Mid Tower Case
    Cooling
    CPU Cooler Thermalright Assassin Spirit 120 EVO ARGB (ARGB Disabled) - Case Fans BlackThermalright TL-C12C-S X3 66.17 CFM 120 mm Fans 3-Pack (ARGB disabled)
    Internet Speed
    1 Gbps
    Other Info
    I hate ARGB.
  • At a glance

    Windows 11 Pro
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 14 G2 ITL
That's because the file is not the problem. I have scanned Check-UEFI with Malwarebytes, Norton 360 and HitmanPro and have received negative results. It only happens when you run the script.
Webroot tagged the Script and Quarantined the file when I was decompressing the Zip file.
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 8700G64 GBOnboard
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Generic
CPU
AMD Ryzen 8700G
Motherboard
Gigabyte B650 UD AC
Memory
64 GB
Graphics Card(s)
Onboard
Sound Card
Onboard
Monitor(s) Displays
Del U2723QE
Screen Resolution
3840 x 2160
Hard Drives
Corsiar MP600 1TB
PSU
Silverstone 750 GOLD
Case
Silverstone FARA 513
Webroot tagged the Script and Quarantined the file when I was decompressing the Zip file.
The new one released today?
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i5-12600K 3.7 GHz 10-Core ProcessorCorsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-...Integrated Intel UHD Graphics 770
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built PC by me.
    CPU
    Intel Core i5-12600K 3.7 GHz 10-Core Processor
    Motherboard
    Gigabyte B760M H DDR4 Micro ATX LGA1700 Motherboard
    Memory
    Corsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-3200 CL16 Memory
    Graphics Card(s)
    Integrated Intel UHD Graphics 770
    Sound Card
    Realtek
    Monitor(s) Displays
    LG
    Hard Drives
    Samsung 990 Pro 1 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    Samsung 990 Pro 2 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    PSU
    NZXT 850w ATX 3.1 Gold Fully Modular Power Supply
    Case
    Thermaltake Versa H25 ATX Mid Tower Case
    Cooling
    CPU Cooler Thermalright Assassin Spirit 120 EVO ARGB (ARGB Disabled) - Case Fans BlackThermalright TL-C12C-S X3 66.17 CFM 120 mm Fans 3-Pack (ARGB disabled)
    Internet Speed
    1 Gbps
    Other Info
    I hate ARGB.
  • At a glance

    Windows 11 Pro
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 14 G2 ITL

My Computer My Computer

At a glance

Windows 11AMD Ryzen 8700G64 GBOnboard
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Generic
CPU
AMD Ryzen 8700G
Motherboard
Gigabyte B650 UD AC
Memory
64 GB
Graphics Card(s)
Onboard
Sound Card
Onboard
Monitor(s) Displays
Del U2723QE
Screen Resolution
3840 x 2160
Hard Drives
Corsiar MP600 1TB
PSU
Silverstone 750 GOLD
Case
Silverstone FARA 513
Just for fun... does this trigger anyone's security product? I rewrote Matt's function to fluster automated scanning.
Not a peep from Webroot, Thanks Garlin.
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 8700G64 GBOnboard
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Generic
CPU
AMD Ryzen 8700G
Motherboard
Gigabyte B650 UD AC
Memory
64 GB
Graphics Card(s)
Onboard
Sound Card
Onboard
Monitor(s) Displays
Del U2723QE
Screen Resolution
3840 x 2160
Hard Drives
Corsiar MP600 1TB
PSU
Silverstone 750 GOLD
Case
Silverstone FARA 513
I've written a few scripts to override default Windows file security settings (some posted to Ten/ElevenForum). They use well known methods. And believe me Defender loves to flag my scripts over and over, when they're sitting idle in my projects folder.

RestoreGamesExplorer.ps1 is a classic case. It uses a common ACL technique to gain control of a file

Once someone has taught a security scanner this pattern is "bad", it thinks everything with that pattern is a threat. If I remove it from the quarantine, it'll get randomly flagged again sitting in my folder.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I am not at all worried with the false positive as I understand what garlin wrote in his previous post #1061 Just a heads up for Malwarebytes Users.
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i5-12600K 3.7 GHz 10-Core ProcessorCorsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-...Integrated Intel UHD Graphics 770
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built PC by me.
    CPU
    Intel Core i5-12600K 3.7 GHz 10-Core Processor
    Motherboard
    Gigabyte B760M H DDR4 Micro ATX LGA1700 Motherboard
    Memory
    Corsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-3200 CL16 Memory
    Graphics Card(s)
    Integrated Intel UHD Graphics 770
    Sound Card
    Realtek
    Monitor(s) Displays
    LG
    Hard Drives
    Samsung 990 Pro 1 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    Samsung 990 Pro 2 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    PSU
    NZXT 850w ATX 3.1 Gold Fully Modular Power Supply
    Case
    Thermaltake Versa H25 ATX Mid Tower Case
    Cooling
    CPU Cooler Thermalright Assassin Spirit 120 EVO ARGB (ARGB Disabled) - Case Fans BlackThermalright TL-C12C-S X3 66.17 CFM 120 mm Fans 3-Pack (ARGB disabled)
    Internet Speed
    1 Gbps
    Other Info
    I hate ARGB.
  • At a glance

    Windows 11 Pro
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 14 G2 ITL
I got this today in Windows Security...

1775712874964.webp
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.8737Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.8737
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI BIOS 4505 11/29/25
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe 25H2 DEV/Games
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.8737Intel Core i7-11700F64 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.8737
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i7-11700F
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.8737
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Mid-Tower Desktop
Hey Garlin I ran the new script again and noticed some new entries from the old script.

Under UEFI DB Certs I have
Compal_Test
F8V350-ITL

Any idea what this is about?

For reference I do have
secure.webp



PS C:\V2> powershell -nop -ep bypass -f .\Check_UEFI-CA2023.ps1 -audit -verbose
Windows 11 25H2 (26200.8037)

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

BIOS Firmware
-------------
LENOVO 20VD
Version: F8CN59WW(V2.22)
Date: 2024-06-14

Factory Default UEFI PK Cert
----------------------------
Ideapad Products

UEFI PK Cert
------------
Ideapad Products

Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Compal_Test
F8V350-ITL

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Compal_Test
F8V350-ITL

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 33

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 7.0
EFI_CERT_SHA256_GUID Signatures: 437

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 26100.30227, SVN 7.0

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

SkuSiPolicy.p7b is CURRENT.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
Version: 3.0.0.13


AUDIT REPORT
============


STATUS REPORT
-------------
Registry: UEFICA2023Status = Updated

SUCCESS: UPDATES ARE FINISHED. UEFI CA 2023 certs are present, PCA 2011 cert is revoked.

PS C:\V2>


Thank you Garlin :)
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i5-12600K 3.7 GHz 10-Core ProcessorCorsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-...Integrated Intel UHD Graphics 770
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built PC by me.
    CPU
    Intel Core i5-12600K 3.7 GHz 10-Core Processor
    Motherboard
    Gigabyte B760M H DDR4 Micro ATX LGA1700 Motherboard
    Memory
    Corsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-3200 CL16 Memory
    Graphics Card(s)
    Integrated Intel UHD Graphics 770
    Sound Card
    Realtek
    Monitor(s) Displays
    LG
    Hard Drives
    Samsung 990 Pro 1 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    Samsung 990 Pro 2 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    PSU
    NZXT 850w ATX 3.1 Gold Fully Modular Power Supply
    Case
    Thermaltake Versa H25 ATX Mid Tower Case
    Cooling
    CPU Cooler Thermalright Assassin Spirit 120 EVO ARGB (ARGB Disabled) - Case Fans BlackThermalright TL-C12C-S X3 66.17 CFM 120 mm Fans 3-Pack (ARGB disabled)
    Internet Speed
    1 Gbps
    Other Info
    I hate ARGB.
  • At a glance

    Windows 11 Pro
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 14 G2 ITL
Hey Garlin I ran the new script again and noticed some new entries from the old script.

Under UEFI DB Certs I have
Compal_Test
F8V350-ITL

Any idea what this is about?
OEM's are allowed to create their own set of KEK and DB certs for internal reasons. Some of these certs support UEFI-based remote monitoring or management features (ie. Dell or HP).

Compal is a major Taiwanese ODM (Original Design Manufacturer) that builds PC's on behalf of large brands like Lenovo. Lenovo designs the PC's, and Compal has responsibility for following manufacturing them to Lenovo's specs. For quality control at the factory, someone doesn't boot your copy of Windows and fiddles with the PC for a few minutes. Instead there are custom automation tools which boot and run a series of HW tests.

If your system has Secure Boot enabled (from the factory) then it can't boot a custom factory app unless that app is correctly signed by a registered cert in the UEFI DB. Should they clean that up before it appears in your hands? Sure. But as long as Lenovo doesn't mind...

Why do you see these certs when it was hidden before?

You remember when your Gigabyte-based PC wasn't correctly reporting certs as "Gigabyte"? In order to handle your case, I had to remove any filtering on the cert's identity. When the script was first written, I only listed the Microsoft certs because Windows is only concerned with MS-issued certs. Following that rule, you would never see Gigabyte at all.

The non-MS certs are now displayed in Verbose mode, but always filtered out on the default report for simplicity. I have no idea what "F8V350-ITL" stands for.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Just for fun... does this trigger anyone's security product? I rewrote Matt's function to fluster automated scanning.
I just ran that script and Malware bytes or Windows Security didn't say a word. I checked the history and no mention of issues with it.

1775744955692.webp
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.8737Intel Core i5 1450064GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.8737
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.8655Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)
I just ran that script and Malware bytes or Windows Security didn't say a word. I checked the history and no mention of issues with it.
Thanks. A human can still defeat a badly sourced AI (or heuristic engine) for now. As I suspected, they're feeding the scanner a steady diet of scripts from known Windows security experts so it cries wolf when it sees certain keywords.

The modded script works the same as before. All I've done is taken the "targeted words" and substituted other variable names in their place, and changed the script's formatting in that section. A really smart security engine would watch what actions the script is taking, before flagging it.

That way, you can't just fool it.

It's like having the authorities ban a book because it contains a recipe in English for "french fries", but it's not illegal if they're called "chips" or "frittes" or translating the recipe to a non-English language.
 
Last edited:

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
It's actually a little bit concerning that it's that easy to fool the security applications! 🤨
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.8737Intel Core i5 1450064GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.8737
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.8655Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)
So,
Thanks for the reply. This is what my BIOS looks like:
View attachment 168102
Is it the option "Erase all Secure Boot setting"?
The "Select an UEFI file as trusted for executing" option only accepts the efi files and not the certs (I checked that the 2023 certs are present in the EFI partition". How do I solve this?
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel Core i7-11800H16GB (2x8 GB)RTX 3060 Laptop GPU
OS
Windows 11 Pro 25H2
Computer type
Laptop
Manufacturer/Model
Acer Predator Helios 300 PH314-54-72ZJ
CPU
Intel Core i7-11800H
Motherboard
TGL
Memory
16GB (2x8 GB)
Graphics Card(s)
RTX 3060 Laptop GPU
Sound Card
Realtek ALC295
Monitor(s) Displays
1
Screen Resolution
2560 x 1440 @ 165Hz
Hard Drives
1TB NVMe SSD, 512GB NVMe SSD, 1TB 7200 RPM HDD
Cooling
Aeroblade 5th Gen 3D fan
Keyboard
RGB Laptop keyboard
Mouse
Logitech Lightsync G203
Internet Speed
175 Mbps up/175 Mbps down
Browser
Firefox with uBlock Origin and YouTube enhancing extensions..
Antivirus
Windows Security with Core Isolation on
Different BIOS'es can accept certain types of EFI files, and they don't all agree on the supported formats.

- A pre-signed X509 certificate file with a .der or .crt file extension
- A signed binary file with a .bin extension
- A signed binary file with an .auth extension

Your BIOS might take one of those options, however the script can only copy the .der & .crt files to the EFI. If those options don't work, you may have to Delete All Keys and enter Setup mode, so the update script can load the .bin files from Windows.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Here are my results with the "updated script", I don't get the "Windows Hello PIN" part. I guess that is because I don't have that activated on my computer. 🤷‍♂️


Screenshot 2026-04-09 125223.webp
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Ar...SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non...Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (i...
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Tower Plus EBT2250, DOB: 06/15/2025
    CPU
    Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Arrow Lake)
    Motherboard
    Dell Inc. 02D3NT A00 (U3E1)
    Memory
    SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non-ECC PC5-5600B
    Graphics Card(s)
    Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (iGPU) Integrated Intel® UHD Graphics
    Sound Card
    Chipset Realtek High-Definition Audio with Dolby Atmos
    Monitor(s) Displays
    Dell Ultra Sharp U2515H 25-Inch Screen LED-Lit
    Screen Resolution
    2560 X 1440
    Hard Drives
    Samsung (NVMe PM9C1a 1024GB) M.2 PCIe NVMe Solid State Drive (OS), with Samsung Piccolo (S4LY022) 6-Core 4 Channel Controller.

    Samsung T7 500GB SSD, USB-C External Drive
    PSU
    Dell 460W
    Case
    Dell Tower Plus EBT 2250
    Cooling
    Fan
    Keyboard
    Dell Wired Keyboard - KB216
    Mouse
    Logitech M510
    Internet Speed
    Intel Killer E3100G 2.5 Gigabit Ethernet Controller
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    The Samsung NVMe PM9C1a 1024GB SSD does not use a Phison NAND controller. Instead, it uses Samsung's in-house developed Piccolo (S4LY022) 6-Core 4 Channel Controller. The PM9C1a utilizes a controller built using Samsung's 5-nanometer process and seventh-generation V-NAND technology. 🤔
  • At a glance

    Windows 11 Pro 25H2 26200.865510th Generation Intel Core i7-10510U Processo...16GB DDR4 RAMNVIDIA® GeForce® MX250 with 2GB GDDR5 graphic...
    Operating System
    Windows 11 Pro 25H2 26200.8655
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 15 7000 (7591) 2-in-1, DOB: 11/30/2019
    CPU
    10th Generation Intel Core i7-10510U Processor (8MB Cache, up to 4.9 GHz) Comet Lake
    Motherboard
    Dell 0NNW5N
    Memory
    16GB DDR4 RAM
    Graphics card(s)
    NVIDIA® GeForce® MX250 with 2GB GDDR5 graphics memory
    Sound Card
    Chipset Realtek ALC3254 🤔🤣
    Monitor(s) Displays
    Dell 15.6-inch UHD Truelife Touch Narrow Border WVA Display with Active Pen support
    Screen Resolution
    3840 x 2160
    Hard Drives
    Intel NVME 512GB SSD with 32GB Intel Optane Memory, M.2 80mm PCIe 3.0 RAID

    SanDisk 256GB Extreme microSDXC UHS-I Memory Card
    PSU
    Dell 4-Cell Battery, 68 Whr (Integrated), 90 Watt AC Adapter
    Case
    Dell Inspiron 15 7000 2-in-1 (7591)
    Cooling
    Standard Dell Case Fan & Havit HV-F2056 USB Powered (3 Fans) Laptop Cooling Pad.
    Keyboard
    Dell
    Mouse
    Logitech Wireless Mouse M650L
    Internet Speed
    Wireless/Wired connectivity (WiFi 6 - 802.11 ax)
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    From Dell: 512GB NVME Solid State Drive accelerated by 32GB Intel Optane Memory are the fastest as compared to NAND SSDs. Intel Optane H10 with SSD offers speedy storage and accelerates opening your programs.
Back
Top Bottom