• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Seize the moment! nominate yourself or a tech enthusiast you admire & join the HP Community Experts!
HP Recommended
Victus by HP 15L Gaming Desktop PC TG02-0000i (491A7AV)
Microsoft Windows 11

Hi,

Persistent Secure Boot errors on my HP Victus 15L Gaming Desktop PC TG02-0000i (491A7AV, baseboard 89B5). Running Windows 11 Home 24H2 (OS Build 26100.7171). Errors hit every boot in Event Viewer (System logs) via TPM-WMI—Windows flags the need for CA/key updates but fails to apply them. No major impacts yet, but i want to fix it proactively.


Error Details:

  • Event ID 1801: "Secure Boot CA/keys need to be updated..."
    Device Attributes: FirmwareManufacturer:AMI;FirmwareVersion:F.33;OEMModelBaseBoard:89B5;OEMManufacturerName:HP;OSArchitecture:amd64;
    Bucket ID: 764f9547ab59a5f09cf632a942a7b9f2af4d0fe3098ea7c42267eff937de7c89
Log Name:      System
Source:        Microsoft-Windows-TPM-WMI
Date:          16/11/2025 13:24:43
Event ID:      1801
Task Category: None
Level:         Error
Keywords:      
User:          SYSTEM
Computer:      VICTUS
Description:
Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: FirmwareManufacturer:AMI;FirmwareVersion:F.33;OEMModelBaseBoard:89B5;OEMManufacturerName:HP;OSArchitecture:amd64;
BucketId: 764f9547ab59a5f09cf632a942a7b9f2af4d0fe3098ea7c42267eff937de7c89
BucketConfidenceLevel: 
UpdateType: 0
HResult: The operation completed successfully.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />
    <EventID>1801</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2025-11-16T12:24:43.9816446Z" />
    <EventRecordID>2359</EventRecordID>
    <Correlation />
    <Execution ProcessID="7724" ThreadID="8020" />
    <Channel>System</Channel>
    <Computer>VICTUS</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="DeviceAttributes">FirmwareManufacturer:AMI;FirmwareVersion:F.33;OEMModelBaseBoard:89B5;OEMManufacturerName:HP;OSArchitecture:amd64;</Data>
    <Data Name="BucketId">764f9547ab59a5f09cf632a942a7b9f2af4d0fe3098ea7c42267eff937de7c89</Data>
    <Data Name="BucketConfidenceLevel">
    </Data>
    <Data Name="UpdateType">0</Data>
    <Data Name="HResult">0</Data>
  </EventData>
</Event>​
  • Event ID 1796: "The Secure Boot update failed... error Unknown HResult Error code: 0x800700c1."
    HResult: -1878589247; UpdateType: 1024
Log Name:      System
Source:        Microsoft-Windows-TPM-WMI
Date:          16/11/2025 13:24:47
Event ID:      1796
Task Category: None
Level:         Error
Keywords:      
User:          SYSTEM
Computer:      VICTUS
Description:
The Secure Boot update failed to update a Secure Boot variable with error Unknown HResult Error code: 0x800700c1. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />
    <EventID>1796</EventID>
    <Version>2</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2025-11-16T12:24:47.7992576Z" />
    <EventRecordID>2368</EventRecordID>
    <Correlation />
    <Execution ProcessID="7724" ThreadID="8020" />
    <Channel>System</Channel>
    <Computer>VICTUS</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="HResult">-1878589247</Data>
    <Data Name="UpdateType">1024</Data>
  </EventData>
</Event>​

 

Tried So Far (No Fix):

  • BIOS (F10): Disabled Secure Boot > Saved/Exited > Rebooted > Re-enabled. Errors return immediately.
  • Full CMOS Reset: Unplugged power, removed CMOS battery , reassembled/booted. Same issue.

System details:

  • Model: Victus 15L Gaming Desktop TG02-0000i (491A7AV)
  • BIOS: AMI F.33
  • OS: Windows 11 Home 24H2 (OS Build 26100.7171)
4 REPLIES 4
HP Recommended

Hi @HaniRouatbi1 

 

Welcome to the HP Support Community! We're here to help you get back up and running.

 

Thanks for sharing the full event details and your proactive steps—your clarity makes it much easier to guide you. Since you’ve already reset CMOS and toggled Secure Boot, we’ll now focus on deeper firmware and OS-level alignment.

 

The Secure Boot update failure on your HP Victus 15L (TG02-0000i) with Event IDs 1801 and 1796 is caused by a mismatch between Windows 11’s TPM-WMI update process and the system firmware’s ability to apply Secure Boot key updates. This can be resolved by refreshing the platform key structure and ensuring firmware and OS integrity.

 

Step-by-step actions to resolve Secure Boot update failures (0x800700c1)

 

1. Reflash BIOS with latest version—even if already on F.33
Reinstalling the same BIOS version can reinitialize Secure Boot variables:

  • Visit the official HP support page for your model:
    HP Victus 15L TG02-0000i Drivers
  • Download the BIOS update utility for Windows
  • Run the installer and follow on-screen instructions
  • After reboot, enter BIOS (F10) and confirm Secure Boot is enabled

 

2. Reset Secure Boot keys from BIOS
This clears and regenerates platform keys:

  • Enter BIOS Setup (F10 at startup)
  • Navigate to Security > Secure Boot Configuration
  • Select Reset Secure Boot Keys to Factory Defaults
  • Save and exit BIOS
  • Boot into Windows and check Event Viewer again

 

3. Run Windows integrity checks
Ensure OS components can apply Secure Boot updates:

  • Open Command Prompt as Administrator
  • Run:sfc /scannow dism /online /cleanup-image /restorehealth
  • Restart after completion

 

4. Confirm TPM and Secure Boot status in Windows

  • Open Settings > Privacy & Security > Device Security
  • Confirm Secure Boot and TPM are listed as active
  • If TPM is not initialized, open tpm.msc and click Prepare TPM

 

5. Optional: Clear Secure Boot pending updates
If the error persists, you can clear pending Secure Boot updates using PowerShell:

  • Open PowerShell as Administrator
  • Run:Confirm-SecureBootUEFI
  • If it returns True, Secure Boot is active
  • Then run:Get-SecureBootPolicy | Remove-SecureBootPolicy
  • Reboot and check Event Viewer

 

Let me know how the system responds after these steps. You’re doing everything right by addressing this early, and I’ll be here to guide you further if needed. This issue is solvable with firmware and OS alignment, and your system is well-positioned for a clean fix.

 

 

If my response helped, please mark it as an Accepted Solution It helps others and spreads support. 💙 Also, tapping "Yes" on "Was this reply helpful?" makes a big difference! Thanks! 😊

 

Take care, and have an amazing day!

 

Regards, 

Hawks_Eye

I am an HP Employee.
HP Recommended

Hi @Hawks_Eye, thank you for the detailed steps.

Before I reflash the BIOS, I need clarification on the correct file to use.
On the HP support page for my system, there are two different BIOS packages listed:

  1. HP Consumer Desktop PC BIOS (ROM Family 89B5)

  2. HP Consumer Desktop PC BIOS (ROM Family SSID 89B5)

Could you please confirm which one is appropriate for my Victus 15L TG02-0000i (491A7AV) 

Also, what is the functional difference between the ROM Family 89B5 package and the ROM Family SSID 89B5 package? I want to ensure I flash the correct firmware to avoid compatibility issues.

Thank you!

HP Recommended

You are very welcome @HaniRouatbi1 

 

For your HP Victus 15L TG02-0000i (491A7AV), the correct BIOS package is the one labeled “HP Consumer Desktop PC BIOS (ROM Family SSID 89B5).” This matches your system’s specific SSID and ensures compatibility with your motherboard configuration.

 

Understanding the difference: ROM Family vs. ROM Family SSID

  • ROM Family 89B5 refers to a broader firmware family shared across multiple HP desktop models that use similar chipsets or board layouts.
     
  • ROM Family SSID 89B5 is more specific—it includes the System SKU ID (SSID), which directly maps to your system’s exact hardware configuration (in your case, 491A7AV).
     

Using the SSID-specific BIOS ensures that the firmware aligns precisely with your system board’s embedded controller, thermal tables, and Secure Boot key structure. This is especially important when resolving Secure Boot update failures like Event 1801/1796.

 

What to do next

  1. Visit the HP Victus 15L TG02-0000i driver page
     
  2. Under BIOS, download the package labeled:
    • HP Consumer Desktop PC BIOS (ROM Family SSID 89B5)
       
  3. Run the installer in Windows and follow the on-screen instructions
     
  4. After reboot, enter BIOS (F10) and confirm Secure Boot is enabled
     

This reflash will help reinitialize Secure Boot variables and align firmware with Windows 11’s TPM-WMI update process.

 

Let me know how the system behaves after the update—we’ll continue refining from there if needed. You’re doing everything right by verifying before flashing.

 

 

If my response helped, please mark it as an Accepted Solution It helps others and spreads support. 💙 Also, tapping "Yes" on "Was this reply helpful?" makes a big difference! Thanks! 😊

 

Take care, and have an amazing day!

 

Regards, 

Hawks_Eye

I am an HP Employee.
HP Recommended

Hi @Hawks_Eye, thanks for the clarification.

I have one important detail to add:

My current BIOS version F.33 was delivered through Windows Update (WU).
On the HP support page, the SSID BIOS shows version F.30, which is older than the F.33 installed by WU.

Before I proceed, could you please confirm: Is it safe to downgrade from the WU-delivered F.33 to the SSID F.30?

Thanks again for your help — just want to double-check before flashing.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.