Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


OK, still learning: how do I update the BANNED file in the G: Hasleo drive

PS C:\Windows\System32> powershell -nop -ep bypass -f C:\temp17\check_bootmedia.ps1 -verbose
Windows 11 25H2 (26200.9168)

Secure Boot: ON
Virtualization Based Security: ON

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 9.0

EFI Files
---------
SkuSiPolicy.p7b is CURRENT.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
Version: 3.0.0.17

FileRule MinimumFileVersion MaximumFileVersion
-------- ------------------ ------------------
ID_FILEATTRIB_F_0044 0.0.0.0 10.0.14393.9399
ID_FILEATTRIB_F_0042 10.0.14400.0 10.0.17763.9099
ID_FILEATTRIB_F_0040 10.0.18000.0 10.0.19041.7639
ID_FILEATTRIB_F_0041 10.0.19100.0 10.0.20348.5479
ID_FILEATTRIB_F_0046 10.0.20400.0 10.0.22621.7494
ID_FILEATTRIB_F_0049 10.0.23000.0 10.0.26100.9140
ID_FILEATTRIB_F_0045 10.0.26100.32000 10.0.26100.33249
ID_FILEATTRIB_F_0048 10.0.26172.0 10.0.26172.33249
ID_FILEATTRIB_F_0047 10.0.27000.0 10.0.28000.2684
ID_FILEATTRIB_F_0043 10.0.29426.0 65535.65535.65535.65535



Hasleo 5.9.2.1
--------------
WinPE Boot Manager [Windows UEFI CA 2023] is BANNED.
C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi
File Version: 26100.30227, SVN 7.0

Bootable Media
--------------

DVD Drive E: "My Passport"

USB Drive G: "HASLEOBS"
Boot File [Windows UEFI CA 2023] is ALLOWED.
G:\EFI\Boot\bootx64.efi
File Version: 28000.352, SVN 9.0

boot.wim:1 (WinRE 26100.1)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is BANNED.
File Version: 26100.8971


PS C:\Windows\System32>
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026
OK, still learning: how do I update the BANNED file in the G: Hasleo drive
You can use Garlin's update script for the USB drive
Code:
powershell -nop -ep bypass -f C:\temp17\Update_UEFI-CA2023.ps1 -bootmedia
I don't think Garlin's script fixes the staging of Hasleo/Macrium, or at least in the version he shared so far...
So to fix the Hasleo staging you need to copy the files yourself

The following is for Macrium, can someone share the exact path for Hasleo...
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi $MacriumStagingFolder\macrium\WinREFiles\media\EFI\Boot\bootx64.efi
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi $MacriumStagingFolder\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi


Based on Garlin's post #3057, it's this command for Hasleo
Code:
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi "C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi"
 
Last edited:

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
ok, ran the bootmedia update and it stated : SUCCESS: NO UPDATES ARE REQUIRED.

but... on the end of USB I still see:

USB Drive G: "HASLEOBS"
Boot File [Windows UEFI CA 2023] is ALLOWED.
G:\EFI\Boot\bootx64.efi
File Version: 28000.352, SVN 9.0

boot.wim:1 (WinRE 26100.1)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is BANNED.
File Version: 26100.8971

That windload.efi is BANNED showing an older build ID: perhaps that's normal ? 26100 is I believe windows 24h2 does not seem right since I'm on 25H2 latest build updated just today: 26200.9168
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026
New SkuSiPolicy and WinRE, all boot media updated.

Code:
C:\Windows\System32>powershell -ep bypass -f D:\Scripts\BlockedOrNot.ps1
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b", Version 3.0.0.17

VolumeName  Filename                        FileVersion Status
----------  --------                        ----------- ------
BOOT2023PCA J:\sources\boot.wim             26100.9168  ALLOWED
MACRIUMHOME L:\sources\boot.wim             26100.9168  ALLOWED
            C:\Windows\System32\winload.efi 26100.9168  ALLOWED
            Disk 0 Partition 4 Winre.wim    26100.9168  ALLOWED

C:\Windows\System32>


Code:
EFI Files
---------
    SkuSiPolicy.p7b is CURRENT.
        \\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
        Version: 3.0.0.17

    NOT RECOMMENDED for dual-boot setups.

Macrium v8.1.8853
-----------------
    WinRE Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        c:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

Bootable Media
--------------

USB Drive J: "BOOT2023PCA"
    Boot File [Windows UEFI CA 2023] is ALLOWED.
        J:\EFI\Boot\bootx64.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:2 (WinRE 26100.9168)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.9168

    Please wait while install SWM is analyzed.

    install.swm:1 (W11 25H2 26200.9168)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.9168

    J:\EFI\Microsoft\Boot\boot.stl [5/18/2026 07:44] is CURRENT.

USB Drive L: "MACRIUMHOME"
    Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        L:\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:1 (WinRE 26100.1)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.9168

    L:\EFI\Microsoft\Boot\boot.stl [5/18/2026 07:44] is CURRENT.


PS D:\Scripts\SecureBoot-CA-2023-Updates.v2026.08.03>
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.9168Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.9168Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.9168
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Cooler Master Hyper 212
    Mid-Tower Desktop
  • Like
Reactions: x_1
I ran :
PS C:\Windows\System32> powershell -nop -ep bypass -f C:\temp15\blockedornot.ps1
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.17

Filename FileVersion Status
-------- ----------- ------
C:\Windows\System32\winload.efi 26100.9168 ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168 ALLOWED
G:\sources\boot.wim 26100.8971 BLOCKED BY 'FILEATTRIB_F_0049'

how to fix/update boot.wim
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.9168Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.9168Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.9168
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Cooler Master Hyper 212
    Mid-Tower Desktop
Try:

.\Update_UEFI-CA2023.ps1 -bootmedia
Thanks tried that, and for fun ran it again stated : SUCCESS: NO UPDATES ARE REQUIRED.

I've done 2 restarts with no change, still flagging the wim.file

I have to leave for a couple hours. check later
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026
The update script can only handle the boot files on the USB. It will not touch any files inside a boot or install WIM. That would be unwise since it doesn't track what changes go into a specific Monthly Update, and making that change without deeper understanding isn't a good idea.

You need to find an updated source WIM to rebuild from. If you can import from your system's current WinRE, that would be ideal.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
The update script can only handle the boot files on the USB. It will not touch any files inside a boot or install WIM. That would be unwise since it doesn't track what changes go into a specific Monthly Update, and making that change without deeper understanding isn't a good idea.

You need to find an updated source WIM to rebuild from. If you can import from your system's current WinRE, that would be ideal.
woudn't this fix it for him ?
replacing X: for his USB drive letter...

Code:
copy X:\EFI\MICROSOFT\BOOT\BCD X:\EFI\MICROSOFT\BOOT\BCD.BAK
bcdboot c:\windows /f UEFI /s X: /bootex
copy X:\EFI\MICROSOFT\BOOT\BCD.BAK X:\EFI\MICROSOFT\BOOT\BCD
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
@garlin, check my post #3299, if you did not already see it
Macrium X WinRE, WinPE for your COMBINED.ps1
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
This is what i get when i ran BlockedOrNot.ps1

Already updated the SkuSiPolicy, and restarted system, unless it didn't update right for some reason

Code:
PS C:\Temp> powershell -nop -ep bypass -f "C:\Temp\BlockedOrNot.ps1"
Windows 11 25H2 (26200.9168)
VBS: ON

WARNING: \\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b has an invalid or unsupported binary CI policy format
version value: 0x0000000B. If you are sure that you are dealing with a binary code integrity policy, there is a high
likelihood that Microsoft updated the binary file format to support new schema elements and that this code will likely
need to be updated.
Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.17

Filename                                           FileVersion Status
--------                                           ----------- ------
C:\Windows\System32\winload.efi                    26100.9168  ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168  ALLOWED
E:\sources\boot.wim                                26100.8875  BLOCKED BY 'FILEATTRIB_F_0049'

let me know what i need to fix, or how to, and i will get it done
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8894AMD Ryzen 7700X32GB DDR 5 RGB 5600MhzRadeon 7800XT
    OS
    Windows 11 Pro 25H2 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    PreBuilt
    CPU
    AMD Ryzen 7700X
    Motherboard
    MSI B650 VC WIfi Rev 1.0
    Memory
    32GB DDR 5 RGB 5600Mhz
    Graphics Card(s)
    Radeon 7800XT
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 990 Pro 1TB Boot NVMe
    Samsung 990 Pro 2TB Game NVMe



    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB Blue
    Western Digital My Passport 2TB Red
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Seagate 1TB Portable USB 3 External Drive
    Western Digital My Book 8TB (Primary Backup drive)
    Western Digital Black 4TB In External Enclosure
    PSU
    Seasonic Focus GX 750 Watt Power Supply
    Case
    Lian Li Lan Cool 216 ARGB Airflow
    Cooling
    2 160MM Front, 1 140MM Rear Exhaust
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1100Mb/35 Upload
    Browser
    MS Edge Chromium and Bing Search
    Antivirus
    Windows Defender, Malwarebytes Premium
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium Reflect X
  • At a glance

    Windows 11 Pro 25H2 26200.8894Ryzen 7 7735HS16GB DDR 5AMD Radeon™ 680M & Radeon 7700S
    Operating System
    Windows 11 Pro 25H2 26200.8894
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF A16 Advantage Edition FA617NT.A16.R7700
    CPU
    Ryzen 7 7735HS
    Motherboard
    OEM Asus Motherboard
    Memory
    16GB DDR 5
    Graphics card(s)
    AMD Radeon™ 680M & Radeon 7700S
    Sound Card
    Onboard
    Monitor(s) Displays
    16inch FHD 165hz
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe Boot Drive
    Samsung 990 Evo Plus 1TB Game NVMe
    PSU
    Laptop PSU
    Case
    Laptop Case
    Cooling
    OEM Cooling
    Keyboard
    OEM Laptop Keyboard
    Mouse
    Touchpad & G502 Hero
    Internet Speed
    Gigabit 1100 Download/35 Upload
    Browser
    MS Edge with Bing search
    Antivirus
    Windows Defender & Malwarebytes Premium
    Other Info
    Macrium Reflect X
woudn't this fix it for him ?
replacing X: for his USB drive letter...
A bootable USB drive can contain several elements:

1. Boot file (\EFI\Boot\bootx64.efi) for WinPE-style drives, or boot manager (\EFI\Microsoft\Boot\bootmfgw.efi) for WinRE-style drives.
2. boot.wim image with a \Windows\Boot\bootmgfw.efi inside.
3. When it's a Windows setup, install.wim/esd with a \Windows\Boot\bootmgfw.efi inside.

The stars must align for Secure Boot to work. You can't just randomly swap the boot manager inside a WIM without knowing what's going on with the build number. An image isn't updated by copying new files, it's done by applying a KB update to the offline image.
 
Last edited:

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.17

Filename FileVersion Status
-------- ----------- ------
C:\Windows\System32\winload.efi 26100.9168 ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168 ALLOWED
WU installed Aug 2026, and both your Windows system and WinRE are up-to-date.

E:\sources\boot.wim 26100.8875 BLOCKED BY 'FILEATTRIB_F_0049'
This boot WIM which was created before is now invalidated. You need to rebuild this USB device, but it requires taking a source image which has been patched to Aug 2026. Typically that would be using your current WinRE image (winre.wim) as the basis for a custom WIM.

Waiting for Macrium or Hasleo to push a newer base image will take a little longer, since it's Patch Tuesday and they have to catch up.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hey Garlin with the "Check_Bootmedia" script I get this now ... ???

Code:
powershell -nop -ep bypass -f E:\Z_c2023\Check_BootMedia.ps1
Unable to connect to the remote server
Secure Boot: ON
Virtualization Based Security: ON

UEFI KEK Certs
--------------
    Microsoft Corporation KEK CA 2011
    Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
    Microsoft Corporation UEFI CA 2011
    Microsoft Windows Production PCA 2011
    Microsoft Option ROM UEFI CA 2023
    Microsoft UEFI CA 2023
    Windows UEFI CA 2023

UEFI DBX Certs
--------------
    Microsoft Windows Production PCA 2011
    Windows BootMgr SVN 9.0

EFI Files
---------
    SkuSiPolicy.p7b is CURRENT.

Bootable Media
--------------

USB Drive F: "PHILIPSOK"
    Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

This command cannot be run due to the error: The system cannot find the file specified.
PS C:\Users\

Like what Server .... maybe Down ? / Maybe the "mockingbird" is in a bad mood LMAO
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
Ok I'll get that figured out and the Macrium Rescue USB all fixed up shortly here then
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8894AMD Ryzen 7700X32GB DDR 5 RGB 5600MhzRadeon 7800XT
    OS
    Windows 11 Pro 25H2 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    PreBuilt
    CPU
    AMD Ryzen 7700X
    Motherboard
    MSI B650 VC WIfi Rev 1.0
    Memory
    32GB DDR 5 RGB 5600Mhz
    Graphics Card(s)
    Radeon 7800XT
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 990 Pro 1TB Boot NVMe
    Samsung 990 Pro 2TB Game NVMe



    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB Blue
    Western Digital My Passport 2TB Red
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Seagate 1TB Portable USB 3 External Drive
    Western Digital My Book 8TB (Primary Backup drive)
    Western Digital Black 4TB In External Enclosure
    PSU
    Seasonic Focus GX 750 Watt Power Supply
    Case
    Lian Li Lan Cool 216 ARGB Airflow
    Cooling
    2 160MM Front, 1 140MM Rear Exhaust
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1100Mb/35 Upload
    Browser
    MS Edge Chromium and Bing Search
    Antivirus
    Windows Defender, Malwarebytes Premium
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium Reflect X
  • At a glance

    Windows 11 Pro 25H2 26200.8894Ryzen 7 7735HS16GB DDR 5AMD Radeon™ 680M & Radeon 7700S
    Operating System
    Windows 11 Pro 25H2 26200.8894
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF A16 Advantage Edition FA617NT.A16.R7700
    CPU
    Ryzen 7 7735HS
    Motherboard
    OEM Asus Motherboard
    Memory
    16GB DDR 5
    Graphics card(s)
    AMD Radeon™ 680M & Radeon 7700S
    Sound Card
    Onboard
    Monitor(s) Displays
    16inch FHD 165hz
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe Boot Drive
    Samsung 990 Evo Plus 1TB Game NVMe
    PSU
    Laptop PSU
    Case
    Laptop Case
    Cooling
    OEM Cooling
    Keyboard
    OEM Laptop Keyboard
    Mouse
    Touchpad & G502 Hero
    Internet Speed
    Gigabit 1100 Download/35 Upload
    Browser
    MS Edge with Bing search
    Antivirus
    Windows Defender & Malwarebytes Premium
    Other Info
    Macrium Reflect X
Hey Garlin with the "Check_Bootmedia" script I get this now ... ???

Code:
powershell -nop -ep bypass -f E:\Z_c2023\Check_BootMedia.ps1
Unable to connect to the remote server
The only reason to connect to a server is to download one of the missing tools (wimlib, 7z, or offlinereg). If the script runs once, those files should be left behind in your $env:TEMP folder for future re-use.

wimlib appears to be refusing service. For now, you can download the two files and save them under $env:TEMP
BatUtil/ESD2WIM-WIM2ESD/bin/bin64 at master · abbodi1406/BatUtil
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
@garlin

I'm still at SkuSiPolicy.p7b 3.0.0.16 after the latest windows update. SVN remains at 9.0.

PS C:\> cd Scripts
PS C:\Scripts> .\BlockedOrNot.ps1
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.16

Filename FileVersion Status
-------- ----------- ------
C:\Windows\System32\winload.efi 26100.9168 ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168 ALLOWED
D:\sources\boot.wim 26100.8874 ALLOWED


PS C:\Scripts>
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2AMD Ryzen 9 7940HS32 GBRadeon 780M Graphics
    OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Geekom AX7 Pro
    CPU
    AMD Ryzen 9 7940HS
    Memory
    32 GB
    Graphics Card(s)
    Radeon 780M Graphics
    Monitor(s) Displays
    Dell S2425H 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    2 TB NVMe SSD
    Internet Speed
    100 Mbs
    Browser
    Microsoft Edge / Firefox
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • At a glance

    Windows 11 Pro 25H212th Gen Intel Core i7-12700 processor (12-Co...16 GBIntel(R) UHD Graphics 770 with shared graphic...
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Inspiron 3910
    CPU
    12th Gen Intel Core i7-12700 processor (12-Core, 25M Cache, 2.1GHz to 4.8GHz)
    Motherboard
    Dell 0KHP4K
    Memory
    16 GB
    Graphics card(s)
    Intel(R) UHD Graphics 770 with shared graphics memory
    Monitor(s) Displays
    Dell 27" Monitor S2721DS,
    Screen Resolution
    QHD 2560 x 1440 @ 75 Hz
    Hard Drives
    1TB M.2, PCIe NVMe, SSD
    Internet Speed
    100 Mbps
    Browser
    Edge
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • HP Laptop 15-fd0xxx
    OS: Windows 11 Home 25H2
    Processor: 13th Gen Intel(R) Core(TM) i7-1355U (1.70 GHz), 10 Cores, 12 Logical Processors
    BIOS Version: AMI F.26 4/22/2026
    RAM: 16 GB
    SSD: 1 TB
    Screen Resolution: 1920 x 1080
    All secure boot certificates updated to CA 2023 by factory.

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
@garlin

I'm still at SkuSiPolicy.p7b 3.0.0.16 after the latest windows update. SVN remains at 9.0.

PS C:\> cd Scripts
PS C:\Scripts> .\BlockedOrNot.ps1
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.16

Filename FileVersion Status
-------- ----------- ------
C:\Windows\System32\winload.efi 26100.9168 ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168 ALLOWED
D:\sources\boot.wim 26100.8874 ALLOWED


PS C:\Scripts>
SVN seems to have stayed at 9.0
For the SKuSiPolicy.p7b, you might need to update it with the new copy you should have gotten today from WU
C:\WINDOWS\System32\SecureBootUpdates\SkuSiPolicy.p7b...
I'm not enforcing it but here is my output...
Code:
PS E:\Tmp> powershell -nop -ep bypass -f E:\tmp\BlockedOrNot.ps1 -verbose
Windows 11 25H2 (26200.9168)
VBS: ON

WARNING: C:\WINDOWS\System32\SecureBootUpdates\SkuSiPolicy.p7b has an invalid or unsupported binary CI policy format version value: 0x0000000B. If you are sure that you are
dealing with a binary code integrity policy, there is a high likelihood that Microsoft updated the binary file format to support new schema elements and that this code will likely
 need to be updated.
Policy File: "C:\WINDOWS\System32\SecureBootUpdates\SkuSiPolicy.p7b" is NOT ENFORCED
Version: 3.0.0.17

As for the invalid format, Garlin is already aware, it started back in july if I remember correctly
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
I go all the way :p

Code:
powershell -nop -ep bypass -f E:\Z_c2023\BlockedOrNot.ps1
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.17

Filename                                           FileVersion Status
--------                                           ----------- ------
C:\Windows\System32\winload.efi                    26100.9168  ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168  ALLOWED


PS C:\Users\jwdav> powershell -nop -ep bypass -f E:\Z_c2023\BlockedOrNot.ps1 -verbose
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.17

RULE ID            MinimumVersion MaximumVersion
-------            -------------- --------------
FILEATTRIB_F_0044  0.0            14393.9399
FILEATTRIB_F_0042  14400.0        17763.9099
FILEATTRIB_F_0040  18000.0        19041.7639
FILEATTRIB_F_0041  19100.0        20348.5479
FILEATTRIB_F_0046  20400.0        22621.7494
FILEATTRIB_F_0049  23000.0        26100.9140
FILEATTRIB_F_0045  26100.32000    26100.33249
FILEATTRIB_F_0048  26172.0        26172.33249
FILEATTRIB_F_0047  27000.0        28000.2684
FILEATTRIB_F_0043  29426.0        65535.65535

Filename                                           FileVersion Status
--------                                           ----------- ------
C:\Windows\System32\winload.efi                    26100.9168  ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168  ALLOWED


PS C:\Users\
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.

Latest Support Threads

Back
Top Bottom