When Secure Boot Fails - System Repair Broke Windows
Feb 8, 2013
I had a problem where I was running UEFI with secure boot disabled and dual booting with Linux Mint which is UEFI compliant. Mint had installed Grub, Mint's boot manager but I don't like Grub so i installed rEFInd. Unlike Grub rEFInd has support for UEFI and should have worked better as a boot manager. But it gave me problems too. So I had Grub and rEFInd both installed. I could boot to both Mint and Windows but the boot managers, both Grub or rEFInd, would not show at startup like they are supposed to.
I had to boot the PC, then hit Escape getting into my options menu built into the system, hit F9 to get a list of boot options where i could then choose to boot from hard drive, cd rom, usb etc. rEFInd was in this list. Only after choosing rEFInd from here, was I able to open rEFInd and choose Windows or Mint. This is way too many steps to boot into an OS, so i thought i'd try to use the system repair disk to repair my master boot record or the EFI data that the system uses at boot under UEFI. I forgot that i had to run some additional commands under command prompt and just ran automatic repair from Advanced instead.
At this time Windows had no trouble working at all with secure boot enabled if I really needed windows to use secure boot.
It said it found but could not fix the errors. Suddenly, Windows would not boot even with secure boot enabled. I reran the tool 3 times and it didn't work so i wiped the drive and reinstalled Windows from a clean state. I really did not have errors on the system to begin with accept that the system was trying to access my boot managers in an odd manner.. although i could get everything to work.
The automatic repair option should not have made things worse, even breaking my secure boot but it did.
My point of this is to show that the repair disk tools and how they play with the EFI boot tools is buggy and it can break your system even if there is nothing wrong with Windows and it's ability to boot under secure boot. Don't trust the Repair Disk tool folks. Don't trust UEFI. Don't trust Secure Boot. Be smart. Install a clean system under Legacy Bios mode with UEFI and secure boot disabled.
I have Windows 8 64 bit Pro Edition working fine using UEFI boot from a SSD disk. I've twice created a system repair disk on DVD but when I use boot override in the BIOS to boot from the DVD, I get the message "Non-system disk....
I have a Windows 8.1 Update 1 ISO and would like to use it to perform a clean install on a system which supports UEFI Secure Boot but has no optical drive. What would be the best way to approach this?
WIMBoot would be nice to have as well, if there's a way to do it without making things too complicated.
Windows 8.1 64 bit pc48 GB RamIntel i7 - 3960X CPUBoxxTech ComputerDrive C: SSD - 446 GB
When I first got my new personal computer in January, I created a System Image using Microsoft's utility. I typically use Acronis for my backups, but after major changes, I use both Microsoft and Acronis.
Now, I am attempting to complete a System Image Backup using Microsoft's utility so that I can fix my SecureBoot concern, knowing that I have a safety net in place. Unfortunately, I am unable to complete a backup. BoxxTech suggests that I use Microsoft's utility.
I begin with the File History in the Control Panel as shown below. Note, that I have plenty of room on my FreeAgent F Drive (standalone USB drive). Yet, Microsoft's utility believes otherwise.
Only the three items that shown to be selected are selected. In other words, there are no other drives or partitions off-screen that are selected.
Thinking that it might be a problem with my external USB hard drive, I look at using one of my internal drives, T.
I get the same error message as shown earlier.
why I am unable to back-up my personal computer using Windows 8.1?
While I was messing around with my laptop, I decided to add on a fourth operating system, Arch Linux. I suppose I was pushing my luck a bit . Anyways, during the installation, I accidentally deleted the EFI system partition from my laptop, which contained the Windows Boot Manager and necessary files to boot. Great. I only made things worse by trying to troubleshoot, and broke grub as well.
I have a Windows 8 repair disk I made using the Windows 8 built in utility, but it does not boot: the computer turns on, and just hangs at the Toshiba splash screen.
I also can obviously not access the Toshiba recovery partitions, as they are booted into just like Windows itself.
I found a bootx64.efi file on one of my system's recovery partitions (Toshiba seems to have some really complex system going on) and placed it in EFIootootx64.efi. According to this site, FGA: The EFI boot process., I need to place the bkpbootmgfw.efi (on my system, that was what it was called, but I suspect boot-repair (ubuntu tool) messed something up when I was first setting up grub and the ESP and the bkp stands for backup) back onto the EFI System Partition.
Where to look for in the various Windows Imaging Format .wim and .swm files I have laying around my recovery partition(s) in order to extract the necessary EFI files. Any Windows Repair iso that works.
I am attempting to repair a Dell Inspiron 5520 Laptop for a friend of mine.
He's been having issues updating it for sometime and when he called me he was having a "Windows update hasn't been able to check for new updates for 30 days" pop-up appearing every few seconds that was rendering the laptop almost unusable.
I managed to stop that by disabling automatic updates. When I attempted a manual update I got the message :
Windows could not search for new updates: Error Found Code 80070BC9
Other times it would say it needed to be restarted and would go into a restart loop that was generally Restart one - no message Restart two - configuring updates - 33%, 67%, 100% Restart three - failed to configure updates - reverting - restarting Then would go to the normal login screen
I tried SFC /Scannow which seemed to work and say a restart is needed to implement changes but then fails on restart
DISM didn't work when attempting to run it from the machine but got to 100% when I ran it from my own Windows 8 install disk but then failed and needed a restart to undo the changes.
I also tried a repair and a restore of the current Windows installation but got : Error Code: 80070490 both times
The laptop didn't come with an install disk or serial so it seems restoring it from external media may be out of the question?
I have run sfc /scannow on my system to find if there were any bad files. It comes up and says that it had found bad files and could not repair all of them. Ive run it three or four times in a row and always get the same result.
When I try to use the tutorial,I get as far as the Product Key entry.
The install was an original 8 I downloaded when it first came out.
I then installed 8.1, probably from the Store.
I recently downloaded and install 8.1 Media Center Pack.
Had a real problem with activation.MS Support finally had me go to where there was a long activation string and then he gave me a new Product Key, which is now on the machine and Activated.
When I get to the "Product Key" page and enter the Media Pack key, "This product key didn't work. ....."
You have Windows 8 or Windows 8 Pro installed on your PC. Your PC fails to boot into Windows and launches Automatic Repair to attempt to repair Windows.
Automatic Repair is unable to repair your PC and you select "Advanced options". After selecting "Troubleshoot", you choose to either "Refresh your PC" or "Reset your PC".
In this scenario, recovery may fail and you are returned back to the main WinRE screen. This issue may occur if the System or Software registry hives have become damaged or corrupted.
To attempt to resolve this issue, follow the steps below. Following these steps should only be used if you are attempting to use the "Refresh your PC" or "Reset your PC" options in Windows RE because your system is in a non-bootable state.
-After Automatic Repair fails to repair your PC, select "Advanced options" and then "Troubleshoot". -Select "Advanced options" and then select "Command Prompt". -If prompted, enter in the password for the user name. -At the Command Prompt, go to the windowssystem32config folder by typing the following command: cd %windir%system32config. -Rename the System and Software registry hives to System.001 and Software.001 by using the following commands: ren system system.001 ren software software.001
I did all that but when I tried to rename the Software.001 file the system responds: "The process cannot access the file because it is being used by another process" ...
I tried to create a Ubuntu start up usb key so that i could maybe get in and rename the file but that presented more problems.
I did the Upgrade Assistant from Win7 pro to 8 pro and this is what I was told:
Secure Boot isn't compatible with your PC
Your PC's firmware doesn't support Secure Boot so you won't be able to use it in Windows 8.
More info, I really want Secure boot, however. I have a UEFI BIOS. I am willing to upgrade or clean install, as I will never use the previous windows 7 version again. Is there a way to get Secure boot with my computer [when I upgrade to 8]?
Secure boot requires firmware that supports UEFI v2.3.1 Errata B and has the Microsoft Windows Certification Authority in the UEFI signature database. How do I get this?
I have a new laptop (HP G7-2292NR) with Windows 8 and today I turned on the laptop for the 3rd time and I see in the bottom right corner Windows 8.1 Secure boot isn't configured correctly build 9600, what does that mean? I am so new to Window 8 that I cannot find a thing, I need specific instructions. This is a huge change given I went from XP to Windows 8.
I am running Windows 8 x64 without secure boot enabled. According to the screen shot
secure boot is "Unsupported" but my motherboard has secure boot features in it. Its just that I didn't have secure boot enabled when I installed Windows 8 so Windows is unable to use secure boot now. What are the steps for setting up my computer for installing windows in secure boot mode ?
Pc Specs-: Motherboard: Gigabyte H77m-D3H (rev 1.1)GIGABYTE - Motherboard - Socket 1155 - GA-H77M-D3H (rev. 1.1) BIOS ver: F11 (Latest) Ram:8 Gb DDR3 Corsair HardDisk-: 1) Western Digital 160 GB (boot) 2) Western Digital 1 TB.
I had mailed Gigabyte support on how to enable secure boot they told me the following-:
"We suggest you can first back up data, reset BIOS items we mentioned in first mail, format your HDD into GPT partition and then reinstall Genuine Windows 8 to test again."
So I am asking how can I format my HDD into a GPT ? Is there anything else I need to before I install Windows 8 again ?? What are the exact steps to follow.
Also, there are two things is there any app available via which I can backup my entire C drive including Program Files, all my installed apps, and all of my hotfixes and Windows updates ?? Because I don't want to reinstall everything again and again update my Windows 8.
I want to disable secure boot so i can use my new gpu but I've heard that you must disable secure boot and enable legacy boot. If I do this, can i still boot Windows 8 or do you have to reinstall windows 8?
I'm having nothing but epic failures when I try to image a Windows 8 box with Secure Boot enabled, that was installed using UEFI and has GPT partitions.
I can install using standard MBR, and disable Secure Boot and UEFI in the BIOS and I can restore that no problem.
However, I have been playing with Aomei, Macrium, EaseUs, etc to handle my image restores and not having any luck at all. Basically it's this thread that explains my issues almost perfectly.
Home user: Need Win 8 Disk Imaging solution with UEFI-compatible Startup Disks
I want to install Windows 8, using UEFI with Secure Boot, install patches, software, etc, then run sysprep, shut down, image and then deploy the image on the same make/model down the road.
The only real success thus far has been to load Windows 8, and then run imagex to capture a new wim and then install using that WIM. But that's a whole install, I'd rather just lay an image back down.
I own an Asus laptop with pre-installed Windows 8.1 and, after downloading & installing recent Windows updates (20th of September 2014, if memory serves me correctly), I am unable to access desktop because system freezes at boot sequence returning me this error: "Secure Boot Violation. Invalid signature detected. Check Secure Boot Policy in Setup" printed inside a small red box.
After googling around, someone suggested to disable "Secure Boot" from BIOS and enable "Launch CSM". I performed such operations but I got no results (BIOS menu automatically appears after every reboot). Someone else suggested to change boot sequence and start system from a Recovery CD but I got no CD supplied with my laptop as Asus stopped providing CDs from very long time AFAIK.
I am quite sure problem relies on Windows Updates because I used this Laptop very little times and no p2p or hacked programs are installed. In addition to that, as far as I read, it seems other Win users experienced the same issue after installing WinUpdates but they have different BIOS so is not easy for me to understand my BIOS accordingly to what they do in their own BIOS in order to solve issue.
What annoys me most is that I bought this Laptop in July 2014 and, just three months later, it got freezes because of official Windows Updates and not because of bad behaviour of user.
I'm finding that I am unable to disable secure boot. I can change the boot mode from UEFI to Legacy BIOS and that disables secure boot, but in Legacy mode I can't do what I'm trying to. I can't select the Secure Boot menu in the BIOS options--it's always greyed out. I've done some research and some sources said to hold shift while shutting down "to ensure you're really stopping Windows before trying to enter the BIOS" and hitting F2 on startup. I tried that but it made no difference. I've tried fiddling around with getting to the BIOS in other ways (forgotten how, now) and of course that made no difference.
I'm running Windows 8.1 on a Acer Aspire V-3551 that came with Windows 8 preinstalled.
I got this 3F0 Error and i am 100% Sure that my HDD is in good shape. I formatted yesterday, I try to enable UEFi [Disables Legacy Boot] and the 3F0 Error Pops out.
If i switch back to Legacy Boot [Disables UEFI and Secure Boot] then the PC starts normally.
For those of us who have a PC capable of SecureBoot, but where we have chosen knowingly and intentionally to enable Legacy Boot, there has to be a way to get rid of the watermark. So, how to do it? Using the Group Policy editor to enable/disable "Use enhanced Boot Configuration Data validation profile" had no effect on my Samsung laptop.
I have been playing around with the Secure Boot feature to see if I could tell what properties it might show. Currently, to enable the full Secure Boot feature, I have to use the on board graphics, since my Graphics card does not have a UEFI Op Rom.
So far, I know Windows 7 will not boot on my machine when the Windows 8 Secure Boot bios settings are enabled, which means disabling the CSM (Compatibility Support Module). When the Windows 8 Secure Boot is on and I try to Boot Windows 7, I am returned to the Bios with a notification that some settings have been reset for compatibility. Windows 7 boots fine after that.
Because many systems will have devices that will not meet the Windows 8 standards, like Graphic Cards, the secure boot may really only be fully available on new systems.
But the CSM seems to be a way to bridge the gap by ignoring certain non-UEFI Op Rom devices during boot. Msinfo32.exe shows Secure Boot ON with the module enabled and certain options being set. I am thinking that would stop Root Kits, but have not found anything to confirm that it would.
I suppose I need to go find a really bad Root Kit somewhere to test !!
I'm attempting to follow the instructions here, to do a system image of my Dell Windows 8 machine:
Using Windows 8′s “hidden” backup to clone and recover your whole PC | Ars Technica
As I go through the wizard, I arrive at this screen:
I don't have the option to deselect any of these "drives". I proceed with the backup - it chugs along, and then consistently fails here:
"One of the critical volumes is not having enough free space." It doesn't tell me which - but, it's certainly not the OS drive, this is a virgin system.
I had an image of my disk and I tried to boot it up from my VM workstation but it failed. I added in the line firmware = "efi". I used to be able to boot up without a problem in VM with my disk images before I changed to a new Win 8 laptop. So I was wondering does the secure boot somehow affects it?
i have a Lenovo Ideapad Z585 running Windows 8, secure boot, gpt paritioning and UEFI bios.The laptop comes with a factory shipped 1TB Sata drive which i want to replace with a Kingston V300 SDD 120GB drive.
I have followed this guide How to Migrate OS to new Hard disk.Ive run this in another desktop, it completes and i shut down, remove the destination and insert it into the laptop - power up and it blue screens with There has been an unexpected error message. Trying to access the recovery partition says it is damaged but looks like its almost going to load. Looking at the drive in EaseUS paritition master the paritions look a perfect copy apart from the proportional sizing.
AHCI is enabled in bios - i've tried EaseUS Backup clone, task was successfull but again blue screens but this time with a attached device cant be found.
One thing i wasnt sure about, the PC i done the cloning in has a RAID stripe setup but not sure if this effects it.Any one had success in cloning a GPT drive over to a SSD?
I cant do a fresh installation of windows 8 as i dont have recovery discs, nor does the onekey recovery software allow me to do so and id like to keep the recovery parition in tact really.
I have an acer laptop that came preloaded with windows 8 64bit. I am unable to turn on test mode. It says "Setting is protected by secure boot" or something similar.
An option in the boot settings (accessed by holding shift key while restarting) is there to turn off driver signing restrictions but it isn't working for me at all.
I did it on my desktop with windows 8.1 (not preloaded) in order to set my mouse USB port to a higher frequency with a non-digitally signed driver.
I had a bit of a problem with Malware which led me to reinstall windows 8. I had also at the time been trying to install Linux to dual boot beside it. However, upon reinstalling I got the annoying watermark saying "Secureboot isn't configured correctly." Having decided I would rather remove the watermark and having gone back into the BIOS (with a reinstall) and trying to enable secure boot I get a message - "CSM is Loaded! Disable the CSM via Setup and repeat operation after Restart".
However there is, as far a I can see no option to disable the CSM in my bios - I've tried disabling anything related to Legacy and reinstalling both Ubuntu and Windows 8 as well as wiping the drive and jumping the CMOS as well as updating the BIOS.
I've tried every permutation in the BIOS. Could possibly be an incompatibility with graphics card, but wouldn't know where to start on that end if it is.
1. Does secure boot need to be disabled to boot to the Macrium Reflect Free boot disk? I've got a friend I am working remotely and she has been unable to get the disk to boot in order to restore an image I made for her a while back. I assume secure boot is enabled on her Win 8 machine.
2. From what I've read, the pay version of Macrium Reflect seems able to allow you to open the application in Windows, set up the restore, and then it reboots automatically into the Macrium recovery environment. Would secure boot interfere with that operation?
I'm having a problem with Windows System Image Backup just when I try to do a image backup it will say that it has failed and suggest to do a disk check. I've searched and some users say to use third party backup programs should I run the disk check first or just go with a different backup tool.
I can't seem to get Secure Boot enabled on my laptop, the secure boot option is greyed out and I can't change it to enabled, my computer came with windows 8 on it automatically so I thought it would've been enabled by default.
I built a new PC running 8.1, GPT, UEFI secure boot mode, everything. I'm now at the point where I'm ready to start migrating my data to it, but before I do that, I need to get some backup software that offers me the option to boot from a recovery CD and restore from an image file backup stored elsewhere. Until I've wiped this install & restored successfully, I don't consider it a usable machine. I already have this setup working on my Win7, but for some reason that software is not working with 8.1.
So I'm looking around for something new, and I'm on a trial of Paragon Backup and Recovery Home 12. It says I can create a WinPE disk (and I must use this, since I'm using Intel firmware-based RAID) that will allow me to do a bare-metal restore. The takes me to a link on their website for something called the "Paragon Boot Media Builder." And there's documentation on it, but I can't find out how to download it. If I Google downloading that, a bunch of pirate websites show up & not much else.
I have a paid for version of Acronis True Image Home 2010 that I have used for years with my Windows 7 box and it's been good.
I've also used Macrium Reflect Free, and today I tend to use AOMEI ddata backuper as it's free for personal and commercial use.
I have a new Dell laptop (with Windows 8), and thus far I have disabled the UEFI boot options and Secure Boot and use a classic setup. However, if I wanted to have a play with these other options to see what impact they would have on system performance, which of these drive imaging software packages would work?
I also have a desktop at work with all of these options (and that's likely where I will experiment). On that box, it's simple to drop in a test hard drive and whack away until I get it working. My laptop has an msata drive and I don't have any spares of these drives lying around.
After owning MSI GS70 for about less than a month I have noticed that sometimes my MSI wont boot up into Windows 8. It would get stuck on the MSI logo page without the little loading circle appearing. It would just stuck at the logo page. I had to force restart it. Sometimes after I force restart it would boot in the normal title page, but the Desktop Title would not be responsive. I then had to restart using the task manager restart button. (each shutdown I would usually unplug the power source and I would plug it back in before turning on the laptop.