Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


The SVN is another form of version number, which belongs to the file. It doesn't impact how Get-Volume determines what are removable (USB) drives.

Run this command as Admin:
Code:
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi "C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi"
Thanks, I'm confused as usual: C: has the bootmgfw_EX.efi then - in the Hasleo instruction you jut bootmgfw.efi which is what I have in Hasleo.
After pasting bootmgfw_EX.efi into Hasleo and running the scipt to check bootmedia check it still shows SVN 7.0. It seems something is not reading the new file or does it need a restart ? or do I have to edit out the _EX in the Hasleo file
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.8973 07/28/2026
Thanks, I'm confused as usual: C: has the bootmgfw_EX.efi then - in the Hasleo instruction you jut bootmgfw.efi which is what I have in Hasleo.
You cannot use the filename by itself, to identify the file's SVN version.

Get-SecureBootSVN -BootManagerPath C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi
Get-SecureBootSVN -BootManagerPath "C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi"

After pasting bootmgfw_EX.efi into Hasleo and running the scipt to check bootmedia check it still shows SVN 7.0. It seems something is not reading the new file or does it need a restart ? or do I have to edit out the _EX in the Hasleo file
Copying the \Windows\Boot\EFI_EX replaces the boot manager version stored in Hasleo's staging folder. So the next time you use Hasleo to create a boot drive, it will use this updated version instead of whatever was cached from before.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
2. These tests were done with the Ventoy USB only
PS C:\WINDOWS\system32> powershell -nop -ep bypass -f D:\Downloads\TestScript_A.ps1
Test Script A counts 2 drives
PS C:\WINDOWS\system32> powershell -nop -ep bypass -f D:\Downloads\TestScript_B.ps1
Test Script B counts 2 drives
PS C:\WINDOWS\system32> powershell -nop -ep bypass -f D:\Downloads\TestScript_C.ps1
Test Script C counts 2 drives
I understand the Ventoy results, it creates two distinct drive volumes. One for Ventoy, the other to hold your ISO data.

3. These 3 tests were done with both the HBS USB & a Ventoy USB (seen by Explorer as 2 drives)
PS C:\WINDOWS\system32> powershell -nop -ep bypass -f D:\Downloads\TestScript_C.ps1
Test Script C counts 3 drives
PS C:\WINDOWS\system32> powershell -nop -ep bypass -f D:\Downloads\TestScript_B.ps1
Test Script B counts 3 drives
PS C:\WINDOWS\system32> powershell -nop -ep bypass -f D:\Downloads\TestScript_A.ps1
Test Script A counts 3 drives
Just confusing.

OK. I found another drive querying script in a PS Gallery, can you try this one?
 

Attachments

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Not_smart test results:
PS C:\Windows\System32> powershell -nop -ep bypass -f C:\temp16\not_smart.ps1
Get-WmiObject : Not supported
At C:\temp16\not_smart.ps1:3 char:37
+ ... PredictData=Get-WmiObject -Class MSStorageDriver_FailurePredictData - ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (:) [Get-WmiObject], ManagementException
+ FullyQualifiedErrorId : GetWMIManagementException,Microsoft.PowerShell.Commands.GetWmiObjectCommand

Get-WmiObject : Not supported
At C:\temp16\not_smart.ps1:4 char:39
+ ... edictStatus=Get-WmiObject -Class MSStorageDriver_FailurePredictStatus ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (:) [Get-WmiObject], ManagementException
+ FullyQualifiedErrorId : GetWMIManagementException,Microsoft.PowerShell.Commands.GetWmiObjectCommand


DriveLetter Model MediaType InterfaceType
----------- ----- --------- -------------
C: WD Blue SN570 500GB Fixed hard disk media SCSI This disk is SSD
G: SanDisk Cruzer Glide USB Device Removable Media USB
E: WD My Passport 259F USB Device External hard disk media USB
HP ENVY 5530 series USB Device USB
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.8973 07/28/2026
OK. That's a start for me. Back to some refactoring of borrowed code. I have to rip out all the non-essential parts...
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
@garlin As requested:

PS C:\WINDOWS\system32> powershell -nop -ep bypass -f "D:\Downloads\NOT_SMART.ps1"

DriveLetter Model MediaType InterfaceType
----------- ----- --------- -------------
F: USB Flash Disk USB Device Removable Media USB


PS C:\WINDOWS\system32> powershell -nop -ep bypass -f "D:\Downloads\NOT_SMART.ps1"

DriveLetter Model MediaType InterfaceType
----------- ----- --------- -------------
F: USB Flash Disk USB Device Removable Media USB
{G:, H:} USB DISK 3.0 USB Device Removable Media USB
 

My Computer My Computer

At a glance

Windows 11 ProIntel Core Ultra16GBIntel(R) Arc Graphics
OS
Windows 11 Pro
Computer type
Laptop
Manufacturer/Model
ASUS Zenbook 14 OLED
CPU
Intel Core Ultra
Memory
16GB
Graphics Card(s)
Intel(R) Arc Graphics
Sound Card
Realtek High Definition Audio(SST)
Screen Resolution
2880 x 1800
Hard Drives
500 GB NVMe SSD
Internet Speed
1,500Mbps
Browser
Firefox, Edge
Antivirus
Windows Defender
So if you run it twice in a row, you get two different results?

I misread the reply. So the first one is with HSB, and the second one is with Ventoy?
 
Last edited:

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hey @garlin, not sure if that can be interesting or not for you, but here it is...

I use Macrium 10.
If I run your lastest Check_BootMedia.ps1 from post #3046 and I have:
  • Macrium staging in E:\boot\macrium
  • Macrium ISO mounted as drive G:
  • USB drive with Macrium ISO writen with Rufus as drive H:
If I run your script Check_BootMedia.ps1 -verbose -audit, I get: (skipping all the stuff before it get's to Macrium to reduce size or post)

Code:
Macrium v10.0.8843
------------------
    WinRE Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        E:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

Now if I change 1 line in your script to force it to scan drives G: and H: (line 2295)

Code:
#        $RemovableDrives = Get-Volume | where { $_.DriveType -in 'CD-ROM','Removable' -and $_.DriveLetter -ne $null -and $_.OperationalStatus -eq 'OK' } | sort DriveLetter
        $RemovableDrives = Get-Volume | where { $_.DriveLetter -in "H","G" -and $_.OperationalStatus -eq 'OK' } | sort DriveLetter

I now get this:

Code:
Macrium v10.0.8843
------------------
    WinRE Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        E:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

Bootable Media
--------------

DVD Drive G: "Rescue"
    Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        G:\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:1 (WinRE 26100.1)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.8875


DVD Drive H: "RESCUE"
    Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        H:\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:1 (WinRE 26100.1)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.8875

So not sure why forcing the Get-Volume to find both drives changes the result.
And I re-downloaded your script from post #3046 and compared them to make sure I had not changed anything else.
Most probably it impacts the rest of your script but not good enough to understand all your code...
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
  • Macrium staging in E:\boot\macrium
Your Macrium's staging path doesn't matter, because the script looks it up from the registry.

Now if I change 1 line in your script to force it to scan drives G: and H: (line 2295)

Code:
#        $RemovableDrives = Get-Volume | where { $_.DriveType -in 'CD-ROM','Removable' -and $_.DriveLetter -ne $null -and $_.OperationalStatus -eq 'OK' } | sort DriveLetter
        $RemovableDrives = Get-Volume | where { $_.DriveLetter -in "H","G" -and $_.OperationalStatus -eq 'OK' } | sort DriveLetter

So not sure why forcing the Get-Volume to find both drives changes the result.
Get-Volume isn't wrong, it's the selection criteria that blows up. Normally you would filter by any mounted CD/DVD device, and "Removable" drives. Typically all USB sticks fall under the "Removable" category.

If you manually select the drive letters you want to scan, then it means the filter is wrong. But in reality, PS (or Windows, or some stupid USB device implementation) is identifying some removable USB's as anything but "Removable". Now, why is it broken for some users but not the majority of every one else?
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

My Computer My Computer

At a glance

Windows 11 ProIntel Core Ultra16GBIntel(R) Arc Graphics
OS
Windows 11 Pro
Computer type
Laptop
Manufacturer/Model
ASUS Zenbook 14 OLED
CPU
Intel Core Ultra
Memory
16GB
Graphics Card(s)
Intel(R) Arc Graphics
Sound Card
Realtek High Definition Audio(SST)
Screen Resolution
2880 x 1800
Hard Drives
500 GB NVMe SSD
Internet Speed
1,500Mbps
Browser
Firefox, Edge
Antivirus
Windows Defender
Back
Top Bottom