• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended

@jeobsplyr,

 

Good evening again, my friend!

 

YES — this is exactly what I wanted to see. And thank you for putting the three results together in one place. That makes the situation considerably easier to evaluate.

 

I have gone through all three results carefully, and I can now say this with confidence:

 

The BCDBoot portion of the repair was successful. 🎉

 

Your three results tell us a very consistent story.

 

1. BCDBoot successfully created the boot files:

 

You received:

 

Boot files successfully created.

 

That is the critical result.

 

The earlier "Failure when initializing library system volume" was caused by S: not being properly invoked/mounted when the first command was attempted.

 

Once S: was available, the exact same command completed successfully.

 

So we can put that earlier error behind us.

 

2. The Windows UEFI boot manager is present:

 

You verified:

 

S:\EFI\Microsoft\Boot\bootmgfw.efi

 

and Windows reports:

 

3,086,848 bytes

 

So the Microsoft Windows Boot Manager executable is physically present on the EFI System Partition.

 

3. The BCD store was successfully created:

 

You also verified:

 

S:\EFI\Microsoft\Boot\BCD

 

and the file is:

 

49,152 bytes

 

with a timestamp of:

 

08/21/2026 06:37 PM

 

That timestamp is particularly useful because it corresponds to your successful BCDBoot operation.

So we now have direct evidence that BCDBoot actually created/refreshed the BCD store on the EFI partition.

 
Here's where we stand now:
 

We can now confidently check off:

 

EFI System Partition exists:

ESP is FAT32:

ESP is identified as the System partition:

S: is accessible:

Windows Boot Manager (bootmgfw.efi) exists:

BCD store exists:

BCDBoot successfully completed:

 

That is a very significant milestone.

 

And I want to emphasize something:

 

DO NOT run BCDBoot again.

 

We have accomplished what we needed from that command.

 

Also, please do not:

 

  • format S:
  • delete anything under S:\EFI
  • run bootrec
  • delete/recreate the EFI partition
  • change partition IDs or attributes
  • start changing other BIOS settings

 

There is no reason to do any of those things now.

 
Now we get to the moment we've been working toward.
 

The original problem was not simply "Windows won't boot."

 

The important symptom was that Windows boots normally when Secure Boot is disabled, but enabling Secure Boot produces the "Invalid signature detected. Check Secure Boot Policy in Setup" error.

 

We have now repaired the Windows UEFI boot environment.

 

So the next test is extremely valuable because it will tell us whether the repaired bootloader resolves that Secure Boot failure.

 

Please do this next:

 

  1. Close Command Prompt.
  2. Restart the Pavilion.
  3. Enter BIOS/UEFI Setup.
  4. Go to the Secure Boot settings.
  5. Enable Secure Boot.
  6. Leave the other BIOS settings exactly as they are.
  7. Save the changes and exit BIOS.
  8. Let the computer attempt to boot Windows.

 

And then stop and tell me exactly what happens.

 

If Windows boots normally:

 

Fantastic — we may have solved it. 🎉

 

If you receive:

 

Invalid signature detected. Check Secure Boot Policy in Setup

 

again, do not make any further changes.

 

That result would actually be very informative.

 

It would tell us that the Windows boot environment is now properly constructed, but the firmware is still rejecting something during Secure Boot validation. At that point, we would stop working on the Windows boot files and concentrate specifically on the Secure Boot keys/signatures/policy.

 

That would be a much more narrowly defined problem.

 
And one last thing, my friend:
 

Your habit of keeping these commands and results in Notepad is excellent. Please keep doing exactly that. It gives us a chronological record and prevents us from accidentally repeating a step or losing a known-good result.

 

Your latest record gives us a very clean checkpoint:

 

BCDBoot — SUCCESSFUL

bootmgfw.efi — PRESENT
BCD — PRESENT AND RECREATED 08/21/2026 06:37 PM

 

That's the information I needed.

 

So, no more command-line work for the moment.

 

Let's see what the firmware does with the repaired UEFI boot environment.

 

Enable Secure Boot, attempt one normal boot, and tell me exactly what appears on the screen.

 

We're no longer guessing at the EFI boot files.

 

That part is now repaired and verified.

 

PEACE, my friend!

 

Kind Regards,

 

NonSequitur777


HP Recommended

Well, My Good Friend.........SUCCESS!!!!  Shut down PC, turned on, accessed BIOS, went to Secure Boot Configuration, enabled it, then save changes and exit.  Computer started up to Windows, with no error messages!  Even verified secure boot state in msconfig32, Secure Boot-ON.

I am so happy, I wish I could shake your hand!!  I don't know how to thank you for all your diligent efforts to help me solve this issue.  If you ran for President.....HEY, you'd get my vote!!  I'm going to archive this "adventure" on my external drive for future info. Hopefully, I won't run into this problem in the near future.  I would like to ask, what usually causes this to happen??  Maybe I can steer clear of the cause moving forward.  Truthfully, I have no clue why this occurred, somehow, it doesn't really matter.  IT'S FIXED!!!! I can only hope the next phase, is easier to solve.....my laptop.  You've spent quite a bit of time helping me with this.  I hope you can be available to help with my Elitebook 840 G5.  With ALL my heart, I thank you so much.  Please let me know of your availability to help me with that.  PEACE, MY GOOD FRIEND!!!

HP Recommended

Just thought I'd give you a brief explanation of what is the issue with my Elitebook 840 G5. I tried to manually install the 2023 secure boot certificates, after perusing some methods on the Net. I found one I thought would be pretty easy. Well, the install didn't go well and I tried reverting bios changes I made for the install. When rebooting, got the f30 error with secure boot enabled. So I disabled both legacy and secure boot supports. I can boot into windows. Need to correct the error. Let me know when you're available. PEACE!!

HP Recommended

@jeobsplyr,

 

MY GOOD FRIEND.............WE DID IT!!! 🎉🎉🎉

 

Now THAT is the result I was hoping to see!

 

You shut the machine down, enabled Secure Boot, saved the BIOS settings, and Windows came right up -with no "Invalid signature detected" message whatsoever.

 

And then you independently verified:

 

Secure Boot State: ON

 

in System Information.

 

That's a complete success.

 

And believe me, you can absolutely shake my hand virtually! 😂

 

After all the twists and turns this Pavilion put us through, I think we've earned the right to enjoy this one.

 
So...what actually happened?
 

This is an excellent question, and I want to make one distinction very clear:

 

We know exactly what fixed it.

 

We do not know with absolute certainty what originally caused it.

 

Those are two different things.

 

What we established during the troubleshooting was that the Pavilion's EFI System Partition existed and was healthy, but the Windows UEFI boot environment on that partition needed to be rebuilt.

 

The decisive repair was:

 

bcdboot C:\Windows /s S: /f UEFI

 

Once S: was properly mounted, BCDBoot successfully recreated the Windows boot environment.

 

We then verified that:

 

S:\EFI\Microsoft\Boot\bootmgfw.efi

 

was present,

 

and that:

 

S:\EFI\Microsoft\Boot\BCD

 

had been recreated.

 

And then, when you enabled Secure Boot, the firmware accepted the Windows boot chain and Windows started normally.

 

That sequence is extremely strong evidence that the problem was in the Windows UEFI boot environment/BCD on the EFI System Partition, rather than a bad Windows installation, bad SSD, or defective motherboard.

 
What can cause something like this?
 

Unfortunately, there isn't one single culprit.

 

An EFI boot environment can become inconsistent or damaged for several reasons, including:

 

  • A Windows update or upgrade that modifies boot files.
  • An interrupted Windows update or unexpected shutdown while boot files are being serviced.
  • A failed or interrupted boot-repair operation.
  • Disk/partition-management software modifying the EFI System Partition.
  • Cloning or migrating Windows to another drive.
  • Restoring an old system image.
  • Third-party backup/recovery software modifying the boot environment.
  • Multiple Windows installations or boot managers being installed/removed.
  • Occasionally, filesystem corruption affecting the EFI partition or BCD.

 

And sometimes...

 

Windows simply does something we don't get a satisfactory explanation for. 😂

 

I don't want to tell you that one particular event caused your problem because we don't have evidence proving that.

 

What we can say with confidence is that the EFI boot environment wasn't in a state that your firmware could successfully validate with Secure Boot enabled.

 

Rebuilding it with BCDBoot restored the proper Microsoft UEFI boot files, and the firmware subsequently accepted them.

 
One important lesson from this adventure:
 

You asked how to steer clear of this happening again.

 

The best advice is actually pretty simple:

 

Don't routinely modify the EFI System Partition.

 

If Windows is working, leave the EFI partition alone.

 

Don't manually delete EFI folders.

 

Don't format the ESP.

 

Don't use bootrec or BCDBoot just because a website recommends it as a generic "boot repair".

 

And if Windows is functioning normally, don't change Secure Boot keys or firmware security settings unless there is a specific reason to do so.

 

If you ever encounter another Secure Boot problem, remember what we learned here:

 

Diagnose first. Modify second.

 

That principle probably saved us from making this Pavilion problem considerably worse.

 
And please archive this adventure!
 

I actually think that's a great idea.

 

Keep the successful command and the resulting information in your archive:

 

bcdboot C:\Windows /s S: /f UEFI

 

and note that it successfully rebuilt the boot environment on the 260-MB FAT32 EFI System Partition.

 

Also keep the DiskPart information showing that Volume 3 was:

 

SYSTEM — FAT32 — 260 MB — Healthy — System

 

That gives you a very useful reference if anything similar ever happens again.

 

Kind Regards,

 

NonSequitur777


HP Recommended

@jeobsplyr,

 

I created a new discussion thread for your HP EliteDesk 840 G5 here: Fixing an HP EliteBook 840 G5 - HP Support Community - 9697547 -so, let's continue that discussion in that new link!

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good Evening my friend! DITTO on everything you said! I'm ecstatic. I have so much more knowledge, most importantly, confidence in solving my pc issues. Hopefully, after the next one, I'll be good for a very long time, with your expertise, of course. I'll hit you up on the thread you created, ASAP! PEACE AND BLESSINGS, MY FRIEND!!!

HP Recommended

@jeobsplyr,

 

Looking forward to our new adventure!

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->