Black screen or repeated preboot authentication prompts seen after a Windows 7 update on UEFI systems
Last Modified: 2024-01-06 08:59:26 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Black screen or repeated preboot authentication prompts seen after a Windows 7 update on UEFI systems
Technical Articles ID:
KB92286
Last Modified: 2024-01-06 08:59:26 Etc/GMT Environment
Drive Encryption (DE) 7.2.9.5 (GA) and 7.2.9.7 (Hotfix 1) and earlier versions. Microsoft Windows 10 (Unified Extensible Firmware Interface (UEFI) systems) Microsoft Windows 7 (UEFI systems) Problem
You observe the following during application of a Windows update on Windows 7 UEFI systems:
EfiBootcode Installing EFI bootcode EfiBootcode Finalizing bootcode install INFO EfiBootcode Error upgrading EFI bootcode: [0xEE000007] Error opening the service control manager ERROR PcSystem Error starting: [0xEE000007] Error opening the service control manager ERROR MfeEpePcEncryptionProviderPlugin ..\..\..\Src\EpeGenInitHandler.cpp: EPE_gen_init_handler::handle: 279: [0xEE000007] Error opening the service control manager CauseAs of DE 7.2.9.5, an issue is seen where the UEFI bootcode is upgraded on every service start. The upgrade occurs even if the bootcode doesn't require an upgrade. The issue is documented in the Known Issues article under reference MDE-5028. The solution was delivered in 7.2.9 Hotfix 2 and later. The defect by itself doesn't cause the issue pertaining to this article, but increases the chance of it occurring.
When a Windows Update is applied that requires multiple reboots, a race condition might occur between the DE service that performs a bootcode upgrade and the system shutting down. In this scenario, because the Service Control Manager is unavailable, a DE bootcode upgrade might be rendered unbootable. On an affected system that's booting, preboot authentication (PBA) appears. After authentication, instead of loading the original Microsoft bootloader, MDE tries to load another copy of itself. But, on systems with Solution 1On systems that can't boot:
IMPORTANT: Don't deactivate DE because deactivation doesn't resolve the issue. The reason is because a deactivation copies the incorrect version of
NOTE: In Step 4 above, the example uses the drive letter
The system now boots correctly after successfully authenticating at preboot.
Solution 2On systems that have not yet rebooted:
Contact Technical Support for assistance. To contact Technical Support, go to the Create a Service Request page and log on to the ServicePortal.
Affected ProductsLanguages:This article is available in the following languages: |
|