Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


BIOS Firmware
-------------
LENOVO 81N6
Version: AGCN24WW(V1.07)
Date: 2019-09-16
UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 483
Some the Lenovo's can get a signed KEK CA 2023, even if there's no recent BIOS update. Lenovo has been submitting them to MS.
This PC has all of the CA 2023 certs, but revocation hasn't been applied.

If your brother does nothing, Windows will handle revocation later this year.
 

My Computer

System One

  • OS
    Windows 7
Would @garlin script, Update_Uefi-CA2023.ps1, achieve the same objective?
 

My Computer

System One

  • OS
    Windows 11 Pro x64 Version V23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    i7-8700K
    Motherboard
    Asus Maximus X Code - Z370
    Memory
    G.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (2) 32GB
    Graphics Card(s)
    Intel UHD Graphics 630
    Sound Card
    Integrated ROG SupremeFX
    Monitor(s) Displays
    Asus VP279 27", Samsung BX2431 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung M.2 NVMe 960 EVO 500GB Boot,
    Samsung 840 EVO 250GB (System Copy Drive),
    Samsung 860 EVO 1TB (Primary Data Drive),
    WD Black 500GB (Data Copy Drive)
    ICY Dock 5.25 2.5/3.5 Bays MB971SP-B
    PSU
    Corsair RM 650i +Gold
    Case
    Phanteks Enthroo Primo
    Cooling
    Corsair Hydro H150i, 360mm Rad & Five Corsair 140mm Pro ML Case Fans
    Keyboard
    das Keyboard MX Brown Mechanical Switches Model DASKMKPROSIL-3G7-r1.0
    Mouse
    Logitech MX Master 3 Wireless & Bluetooth
    Internet Speed
    500Mb +
    Browser
    Chrome (Pri), Firefox (Sec)
    Antivirus
    Malwarebytes Premium, SuperAntiSpyware Pro (Licensed)
    Other Info
    Microsoft LifeCam HD,
    APC Back-UPS Pro 1500,
    Macrium (Licensed),
    Microsoft 365,
    Wise Disk Cleaner,
    Crystal Disk Info,
    Screenpresso (Licensed),
    AnyDesk (Licensed),
If I run those commands and something goes south can I just disable secure boot and at least boot?
The fallback is you can ALWAYS disable Secure Boot mode, and have Windows working again. You will have less security against rootkit attacks, but it will allow you to run check scripts, and figure out what to do next.
 

My Computer

System One

  • OS
    Windows 7
Would @garlin script, Update_Uefi-CA2023.ps1, achieve the same objective?
The update script does a best effort to update your PC.

1. If you have a supported KEK (the OEM submitted a signed copy to MS), it will download the KEK from GitHub and apply it.

2. Failing that, it will try copying the KEK certificate to your EFI partition. If your BIOS has a custom mode, and has "KEK key management", you can try importing the file (from the EFI's filesystem) and apply it.

3. Worse case, you can delete all existing certs and enter Setup Mode. The update script will recognize you're in Setup Mode and replace all the certs with a new set provided by Microsoft for this purpose. You start from option 1 and keep going if the first two options don't work for your PC. Some PC's are easier to update, depending on the age of their BIOS. Newer BIOS'es make this process easier than old ones.
 

My Computer

System One

  • OS
    Windows 7
Thank you Garlin.

So is your script or the individual powershell commands the better route to go.

In your #3 when you say enter Setup Mode, I assume you mean enter the BIOS. My machine is already reporting Option 1, Patch Tuesday didn't update anything hence I'm here.

My BIOS (UEFI) is date Sept 2021
 

My Computer

System One

  • OS
    Windows 11 Pro x64 Version V23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    i7-8700K
    Motherboard
    Asus Maximus X Code - Z370
    Memory
    G.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (2) 32GB
    Graphics Card(s)
    Intel UHD Graphics 630
    Sound Card
    Integrated ROG SupremeFX
    Monitor(s) Displays
    Asus VP279 27", Samsung BX2431 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung M.2 NVMe 960 EVO 500GB Boot,
    Samsung 840 EVO 250GB (System Copy Drive),
    Samsung 860 EVO 1TB (Primary Data Drive),
    WD Black 500GB (Data Copy Drive)
    ICY Dock 5.25 2.5/3.5 Bays MB971SP-B
    PSU
    Corsair RM 650i +Gold
    Case
    Phanteks Enthroo Primo
    Cooling
    Corsair Hydro H150i, 360mm Rad & Five Corsair 140mm Pro ML Case Fans
    Keyboard
    das Keyboard MX Brown Mechanical Switches Model DASKMKPROSIL-3G7-r1.0
    Mouse
    Logitech MX Master 3 Wireless & Bluetooth
    Internet Speed
    500Mb +
    Browser
    Chrome (Pri), Firefox (Sec)
    Antivirus
    Malwarebytes Premium, SuperAntiSpyware Pro (Licensed)
    Other Info
    Microsoft LifeCam HD,
    APC Back-UPS Pro 1500,
    Macrium (Licensed),
    Microsoft 365,
    Wise Disk Cleaner,
    Crystal Disk Info,
    Screenpresso (Licensed),
    AnyDesk (Licensed),
Thank you Garlin.

So is your script or the individual powershell commands the better route to go.

In your #3 when you say enter Setup Mode, I assume you mean enter the BIOS. My machine is already reporting Option 1, Patch Tuesday didn't update anything hence I'm here.

My BIOS (UEFI) is date Sept 2021
My Wife's ASUS Laptop just got a BIOS Update maybe on Tuesday.
 

My Computers

System One System Two

  • OS
    Windows11 Pro 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Alienware Aurora R16
    CPU
    Intel Core i9 14900F (24 -Core, 68 MB Total Cache)
    Motherboard
    Dell Alienware
    Memory
    32GB DDR5
    Graphics Card(s)
    RTX 4080 Super w/581.95
    Sound Card
    Realtec
    Monitor(s) Displays
    Corsair XENEON 32QHD165
    Screen Resolution
    2560 X 1440
    Hard Drives
    1-2TB Samsung 990 Pro PCIe NVMe M2 SSD
    1-4TB Samsung 990 Pro PCIe NVMe M2 SSD
    PSU
    1000 Watt Platinum Dell
    Case
    Alienware
    Cooling
    Liquid Closed Loop
    Keyboard
    Logitech MK270 Wireless Keyboard
    Mouse
    Logitech MK270 Wireless
    Internet Speed
    100Gb's Down-20 Up
    Browser
    Firefox 151.0.2
    Antivirus
    Defender
    Other Info
    Very Quiet And Fast
    CyberPower UPS CP1500PFCLCD
  • Operating System
    PClinuxOS Mate (2025.7)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel
    CPU
    13th Gen Inter(R) Core(TM) i3-1315U
    Motherboard
    Intel
    Memory
    64 GB DDR4 @3200 MHz.
    Graphics card(s)
    Internal
    Sound Card
    None
    Monitor(s) Displays
    Dell 2419HGCF
    Screen Resolution
    1920 X 1080
    Hard Drives
    SAMSUNG 980 PRO SSD 2TB, PCIe 4.0 M.2 2280
    PSU
    Chicony 30 Watt
    Case
    Small
    Keyboard
    Dell
    Mouse
    Razor
    Internet Speed
    1GB
    Browser
    Slimjet
My BIOS (UEFI) is date Sept 2021
Your BIOS is probably too old for factory certs. But you should check the UEFI menus, and see if there's manual key enrollment (option 2). It's the less disruptive than option 3 (Setup Mode). Every BIOS will have slightly different screens.
 

My Computer

System One

  • OS
    Windows 7

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
It might be waiting for the next reboot? Here's my conjecture on the path moving forward:
- Windows Update rolls a new boot manager and SVN file- The update adds 0x300 to AvailableUpdates- Secure Boot task does the needful, and eventually (maybe after a reboot or two), we get there
Secure Boot task is super paranoid (that's a good thing). It probably wants to replace the boot manager, reboot and confirm it used the newer file. Then apply the SVN. And reboot again to know everything was done.

I don't think so, see registry after last reboot for april updates, 'Available updates' is on 0x4000, but there were some remarks
[UploadedForCurrentBootCycle]
[RestartRequiredForKeyRolling]
[RestartRequiredForVSMBFSVCAI]
[SBInstalledInCurrentBootCycle]
"SBUpdateType"=dword:00000002
But even after two reboots nothing changed but the remarks / empty keys disappeared after the first reboot already without changing anything. The dbx update error came with the march '26 updates.

1776540104232.webp

Applied dbx update and SVN revocation manually after reboot, but that didn't change the registry.

Windows 10 22H2 (19045.7184)

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) ON

BIOS Firmware
-------------
Gigabyte Technology Co. B760M DS3H DDR4
Version: F23
Date: 2025-12-02

Factory Default UEFI PK Cert
----------------------------
GIGABYTE

UEFI PK Cert
------------
GIGABYTE

Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
GIGABYTE

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
GIGABYTE

Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Windows UEFI CA 2023
GIGABYTE
GIGABYTE

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
GIGABYTE
GIGABYTE

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 430

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 8.0
EFI_CERT_SHA256_GUID Signatures: 436

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume4\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.322, SVN 8.0

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

SkuSiPolicy.p7b is CURRENT.
\\.\HarddiskVolume4\EFI\Microsoft\Boot\SkuSiPolicy.p7b
Version: 3.0.0.14

STATUS REPORT
-------------
Registry: UEFICA2023Status = Updated

SUCCESS: UPDATES ARE FINISHED. UEFI CA 2023 certs are present, PCA 2011 cert is revoked.
 

Attachments

My Computer

System One

  • OS
    W10
Your BIOS is probably too old for factory certs. But you should check the UEFI menus, and see if there's manual key enrollment (option 2). It's the less disruptive than option 3 (Setup Mode). Every BIOS will have slightly different screens.
Thanks for the info.

So even though your script reports, Option 1, Do Nothing Windows will apply the uefi updates it actual won't.

So in my BIOS I have a section for PK, KEK, DB and DBX Management. If I click on any I get an option to "Set New Key"

1776541782366.webp

I do not have a simple option to disable Secure Boot. It appears I have to clear all keys which then disables it. I'm not sure "Set New Key" is the same as Manual add key. The kill of all this, an old Asus laptop with a 2014 BISO, Windows 10, was updated.

There is also an Append Key option which sounds like I can add something.

I
 

My Computer

System One

  • OS
    Windows 11 Pro x64 Version V23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    i7-8700K
    Motherboard
    Asus Maximus X Code - Z370
    Memory
    G.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (2) 32GB
    Graphics Card(s)
    Intel UHD Graphics 630
    Sound Card
    Integrated ROG SupremeFX
    Monitor(s) Displays
    Asus VP279 27", Samsung BX2431 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung M.2 NVMe 960 EVO 500GB Boot,
    Samsung 840 EVO 250GB (System Copy Drive),
    Samsung 860 EVO 1TB (Primary Data Drive),
    WD Black 500GB (Data Copy Drive)
    ICY Dock 5.25 2.5/3.5 Bays MB971SP-B
    PSU
    Corsair RM 650i +Gold
    Case
    Phanteks Enthroo Primo
    Cooling
    Corsair Hydro H150i, 360mm Rad & Five Corsair 140mm Pro ML Case Fans
    Keyboard
    das Keyboard MX Brown Mechanical Switches Model DASKMKPROSIL-3G7-r1.0
    Mouse
    Logitech MX Master 3 Wireless & Bluetooth
    Internet Speed
    500Mb +
    Browser
    Chrome (Pri), Firefox (Sec)
    Antivirus
    Malwarebytes Premium, SuperAntiSpyware Pro (Licensed)
    Other Info
    Microsoft LifeCam HD,
    APC Back-UPS Pro 1500,
    Macrium (Licensed),
    Microsoft 365,
    Wise Disk Cleaner,
    Crystal Disk Info,
    Screenpresso (Licensed),
    AnyDesk (Licensed),
Run the update script. It should copy the KEK CA 2023 cert as both a .der and .crt file to the EFI partition.

Select Append Key / Load from file...
Browse the disks, see if there's a folder view with \EFI folder. Search under that folder for "Certs" folder.
Find the the KEK CA 2023 file, and import it.

If that works fine, restart Windows. Run the update script one more time, it should now add the CA 2023 certs.
 

My Computer

System One

  • OS
    Windows 7
Looks promising.

When you say select Append Key I assume I do that under the KEK heading as that is the cert we are importing. Or should I be in a different heading.

When you say browse the disks, see if there is a folder with \efi would this be on C: or could it be on any disk / partition. My understanding is I can't search the efi partition as it has no drive letter.
 

My Computer

System One

  • OS
    Windows 11 Pro x64 Version V23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    i7-8700K
    Motherboard
    Asus Maximus X Code - Z370
    Memory
    G.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (2) 32GB
    Graphics Card(s)
    Intel UHD Graphics 630
    Sound Card
    Integrated ROG SupremeFX
    Monitor(s) Displays
    Asus VP279 27", Samsung BX2431 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung M.2 NVMe 960 EVO 500GB Boot,
    Samsung 840 EVO 250GB (System Copy Drive),
    Samsung 860 EVO 1TB (Primary Data Drive),
    WD Black 500GB (Data Copy Drive)
    ICY Dock 5.25 2.5/3.5 Bays MB971SP-B
    PSU
    Corsair RM 650i +Gold
    Case
    Phanteks Enthroo Primo
    Cooling
    Corsair Hydro H150i, 360mm Rad & Five Corsair 140mm Pro ML Case Fans
    Keyboard
    das Keyboard MX Brown Mechanical Switches Model DASKMKPROSIL-3G7-r1.0
    Mouse
    Logitech MX Master 3 Wireless & Bluetooth
    Internet Speed
    500Mb +
    Browser
    Chrome (Pri), Firefox (Sec)
    Antivirus
    Malwarebytes Premium, SuperAntiSpyware Pro (Licensed)
    Other Info
    Microsoft LifeCam HD,
    APC Back-UPS Pro 1500,
    Macrium (Licensed),
    Microsoft 365,
    Wise Disk Cleaner,
    Crystal Disk Info,
    Screenpresso (Licensed),
    AnyDesk (Licensed),
I believe suatcini54 is offline at the moment.

Would anyone else know if I run these commands and things go south will I be able to boot with secure boot off. Can't afford to lose this machine. Thank you.
Sorry. I turned off my PC. It is late into the night here. I am typing off my iPad. The script I advised you to run is harmless. If you get a true value after running the script, it means your m/b is capable of accepting the CA2023 certificates. You may continue to install other updated certificates as I did in my PC about a year ago. If you do not continue, you may continue using your PC as before. If you get a false value, it means your PC does not readily accept the new certificates. You have to try other ways.

Hope this clarifies.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-4790
    Motherboard
    Asus H97 Pro Gamer with add-on TPM1.2 module
    Memory
    Teams DDR3-1600 4x4 GB
    Graphics Card(s)
    MSI Nvidia GeForce GTX 1050Ti
    Sound Card
    Realtek ALC1150
    Monitor(s) Displays
    Dell P2425D
    Screen Resolution
    2560 by 1440 pixels
    Hard Drives
    Corsair NVMe M.2 Core XT 1000 GB (Windows 11 v.25H2); Samsung SATA Evo 870 500 GB (Windows 11 v.25H2);
    PSU
    Corsair HX850
    Case
    Gigabyte Solo 210
    Cooling
    Zalman CNPS7X Tower
    Keyboard
    Microsoft AIO Wireless (includes touchpad)
    Mouse
    HP S1000 Plus Wireless
    Internet Speed
    500 Mb fiber optic
    Browser
    Chrome; MS Edge
    Antivirus
    Windows Defender
  • Operating System
    MacOS 12 Monterey
    Computer type
    Laptop
    Manufacturer/Model
    Apple Macbook Air
    CPU
    Intel Core i5
    Memory
    8 GB
    Graphics card(s)
    Intel integrated
    Screen Resolution
    1440 by 900 pixels
    Hard Drives
    128 GB
    Keyboard
    Built-in
    Mouse
    Microsoft Wireless
    Internet Speed
    802.11 ac
    Browser
    Chrome; Safari
    Antivirus
    N/A
Looks promising.

When you say select Append Key I assume I do that under the KEK heading as that is the cert we are importing. Or should I be in a different heading.

When you say browse the disks, see if there is a folder with \efi would this be on C: or could it be on any disk / partition. My understanding is I can't search the efi partition as it has no drive letter.
1. First run the update script, it will create a new \EFI\Certs folder on the EFI partition.

2. Shutdown Windows.

3. In the BIOS menu, open KEK Management / Append Key

4. There are no drive letters. You will be presented with a random list of disk devices. Search each of them one at time until you see an \EFI folder. If you don't have one, it's the wrong drive. Keep going until you see it. Then drill down until you reach \EFI -> \Certs folder. Load any of the files you see in there as the Key.
 

My Computer

System One

  • OS
    Windows 7
For those folks having trouble with Macrium boot media, I have managed to get things working on my two systems.

Update_UEFI-CA2023.ps1 -BootMedia did not work, although it gave a "success" message.

I had to use a short script from elsewhere to copy the boot file. BUT, while Check-UEFI gave a successful result, the USB would NOT boot to Macrium.

The solution on both machines was to rebuild the WinRE boot media in Macrium. This reverted to the older boot file. Running the short script again copied the boot file. Now both machines boot properly into Macrium from the respective USB drives.

I don't know why @garlin's Update script does not work with the recent updates. This is the .bat file that worked. Change the .txt to .bat.
 

Attachments

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P16s Workstation
    CPU
    Intel i7-1260P 12th Gen 4.7GHz
    Memory
    32GB DDR4-3200
    Graphics Card(s)
    NVIDIA T550 Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    16" Laptop Display
    Screen Resolution
    2560x1600
    Hard Drives
    2TB Samsung M.2 2280 SSD PCIe 4.0 x 4 NVMe
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast
  • Operating System
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P50 Workstation
    CPU
    i7-6820HQ 6th Gen 3.6 GHz
    Memory
    32GB DDR4-2133
    Graphics card(s)
    NVIDIA Quadro M2000M Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    15.6" Laptop Display
    Screen Resolution
    1920x1080
    Hard Drives
    2 x 1TB Samsung M.2 2280 SSD PCIe 3.0 x 4 NVMe
    Cooling
    Dual Fan System
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast
Thanks guys, Garlin while I was waiting for response I popped into my BIOS to see how append would present data.

If just gives a mass of data, something you likely can read but I can't. Pic attached. Are these the lines I should be clicking on to search for efi folder?

Sorry. I thank you for your patience.


1776544556713.webp
 

My Computer

System One

  • OS
    Windows 11 Pro x64 Version V23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    i7-8700K
    Motherboard
    Asus Maximus X Code - Z370
    Memory
    G.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (2) 32GB
    Graphics Card(s)
    Intel UHD Graphics 630
    Sound Card
    Integrated ROG SupremeFX
    Monitor(s) Displays
    Asus VP279 27", Samsung BX2431 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung M.2 NVMe 960 EVO 500GB Boot,
    Samsung 840 EVO 250GB (System Copy Drive),
    Samsung 860 EVO 1TB (Primary Data Drive),
    WD Black 500GB (Data Copy Drive)
    ICY Dock 5.25 2.5/3.5 Bays MB971SP-B
    PSU
    Corsair RM 650i +Gold
    Case
    Phanteks Enthroo Primo
    Cooling
    Corsair Hydro H150i, 360mm Rad & Five Corsair 140mm Pro ML Case Fans
    Keyboard
    das Keyboard MX Brown Mechanical Switches Model DASKMKPROSIL-3G7-r1.0
    Mouse
    Logitech MX Master 3 Wireless & Bluetooth
    Internet Speed
    500Mb +
    Browser
    Chrome (Pri), Firefox (Sec)
    Antivirus
    Malwarebytes Premium, SuperAntiSpyware Pro (Licensed)
    Other Info
    Microsoft LifeCam HD,
    APC Back-UPS Pro 1500,
    Macrium (Licensed),
    Microsoft 365,
    Wise Disk Cleaner,
    Crystal Disk Info,
    Screenpresso (Licensed),
    AnyDesk (Licensed),
I don't know why @garlin's Update script does not work with the recent updates. This is the .bat file that worked. Change the .txt to .bat.
Thanks for the report.

That's the same process used by my script, I'll have to check if it's not detecting the difference between a boot file and boot folder.
Code:
if (Test-Path $EFI_BootMgr) {
    $EFI_BootMgr_Hash = (Get-FileHash -LiteralPath $EFI_BootMgr).Hash

    if ($EFI_BootMgr_Hash -ne $BootMgrEX_File_Hash) {
        $BCD = "${DriveLetter}:\EFI\Microsoft\Boot\BCD"
        $Backup_BCD = "$env:TEMP\BCD.BAK"

        try {
            Copy-Item $BCD $Backup_BCD -Force
            Start-Process 'bcdboot' -ArgumentList "$env:SystemRoot /s $EFI_DriveLetter /f UEFI /bootex" -NoNewWindow -Wait
            Copy-Item $Backup_BCD $BCD -Force
            Remove-Item $Backup_BCD -Force
        }
        catch {
            $_.Exception.Message
            exit 1
        }
    }
}
 

My Computer

System One

  • OS
    Windows 7
Thanks guys, Garlin while I was waiting for response I popped into my BIOS to see how append would present data.

If just gives a mass of data, something you likely can read but I can't. Pic attached. Are these the lines I should be clicking on to search for efi folder?

Sorry. I thank you for your patience.
Pick the ones that say "HD(Part 1)" or partition 1. It should list any folders or files present. If you don't see any files, then it was the wrong disk. And try a different one until you find it.

Remember there will be no files unless you ran the update script ONCE, and it said it copied files for you.
 

My Computer

System One

  • OS
    Windows 7
Got it. and thanks for the quick response. I went out and booted to BIOS and saw exactly what you are talking about.

My EFI partition on my boot disk is in Partition 2. ( I checked out Disk Management)

Very clear I need to run script once.

I'm getting some funny looks from better half. Computer time is over apparently.

Again thank you and I will be back

Real support is hard to find, you have been very helpful
 

My Computer

System One

  • OS
    Windows 11 Pro x64 Version V23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    i7-8700K
    Motherboard
    Asus Maximus X Code - Z370
    Memory
    G.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (2) 32GB
    Graphics Card(s)
    Intel UHD Graphics 630
    Sound Card
    Integrated ROG SupremeFX
    Monitor(s) Displays
    Asus VP279 27", Samsung BX2431 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung M.2 NVMe 960 EVO 500GB Boot,
    Samsung 840 EVO 250GB (System Copy Drive),
    Samsung 860 EVO 1TB (Primary Data Drive),
    WD Black 500GB (Data Copy Drive)
    ICY Dock 5.25 2.5/3.5 Bays MB971SP-B
    PSU
    Corsair RM 650i +Gold
    Case
    Phanteks Enthroo Primo
    Cooling
    Corsair Hydro H150i, 360mm Rad & Five Corsair 140mm Pro ML Case Fans
    Keyboard
    das Keyboard MX Brown Mechanical Switches Model DASKMKPROSIL-3G7-r1.0
    Mouse
    Logitech MX Master 3 Wireless & Bluetooth
    Internet Speed
    500Mb +
    Browser
    Chrome (Pri), Firefox (Sec)
    Antivirus
    Malwarebytes Premium, SuperAntiSpyware Pro (Licensed)
    Other Info
    Microsoft LifeCam HD,
    APC Back-UPS Pro 1500,
    Macrium (Licensed),
    Microsoft 365,
    Wise Disk Cleaner,
    Crystal Disk Info,
    Screenpresso (Licensed),
    AnyDesk (Licensed),
Back
Top Bottom