Dynamic Windows 11 Setup TPM Bypass

Discussion in 'Windows 11' started by AveYo, Sep 2, 2021.

  1. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,727
    60
    That's a manual, repetitive, tiresome and lame procedure I would not bother doing every new insider build. GG You! But that's exactly what the subject of this thread successfully avoids.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,647
    103,302
    450
    #182 Enthousiast, May 13, 2022
    Last edited: May 13, 2022
    And that won't work when the source ISO where the install.wim is put in is <22621.1, afaik (for ISO inplace/repair upgrades at the least).
     
  3. pm67310

    pm67310 MDL Guru

    Sep 6, 2011
    3,326
    2,507
    120
    but this script not works with 22h2 build ;)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,647
    103,302
    450
    Mine does;) And the one for WU upgrades from the OP this thread also works.
     
  5. insanwicaksana

    insanwicaksana MDL Novice

    Jul 30, 2015
    39
    8
    0
    i've just tried this but kaspersky sometimes locking out my computer because it detected a false positive in system memory (can't open any programs while disinfection in progress, trying run any command in cmd or terminal resulting ony get access denied message) until kaspersky restarting my system. Already added Skip_TPM_Check_on_Dynamic_Update.cmd to exclusions and trying upgrading my unsupported laptop from build 22000 to 22621, but setup suddenly interrupted at 65% and just closes down after kaspersky detected a false positive in memory
     
  6. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,727
    60
    #186 AveYo, May 14, 2022
    Last edited: May 14, 2022
    (OP)
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. KleineZiege

    KleineZiege MDL Expert

    Dec 11, 2018
    1,849
    2,087
    60
    lol
    the crazy ones come out now
     
  8. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,727
    60
    Holly Cow that's bad! It's a known Microsoft Windows Update temporary folder, the host process is a Microsoft signed binary, and the files it generates like in your last screenshot is an xml, so WTF
    I'm gonna write to them and ask literally WTF
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. phalk

    phalk MDL Novice

    Sep 30, 2015
    1
    1
    0
    I'm being unable to update to 22621.1 (ni_release) through Windows Update even with the TPM Check reg edits. Still giving me a "need TPM 2.0" error.

    Currently on version 22000.588 21H2.

    My processor is an old i5 3570k without any TPM support.
     
  10. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,727
    60
    ⧠ I have read 1st post and followed instructions to the letter
    ⧠ - I have run Skip_TPM_Check_on_Dynamic_Update.cmd (latest v9+) with result: INSTALLED (on green background)
    ⧠ - I have run OfflineInsiderEnroll.cmd (as Admin) and pressed 2 to Enroll to Beta Channel (for build 22621)
    ⧠ - I have rebooted the machine if asked

    ⧠ I have read the last couple posts and I am aware that some AV might interfere. My antivirus is:
    ⧠ - I have not received any antivirus alerts / threat history is clear / am not aware of it
    ⧠ - I did received alerts / threat history has relevant entries, so I tried excluding / turning it off

    ⧠ My C:\$WINDOWS.~BT\Sources\Panther\setupact.log
    ⧠ Anything else I can add that can help (screenshots, etc)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  11. tomay3000

    tomay3000 MDL Member

    Apr 16, 2010
    198
    10
    10
    This is the good stuff.
    That was really quick.
     
  12. insanwicaksana

    insanwicaksana MDL Novice

    Jul 30, 2015
    39
    8
    0
    Yep, some of them was xml file. But there were .sys file that got deleted too. Let me copied all of reports from kaspersky (447 lines, file attached below :oops:)
     

    Attached Files:

  13. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,727
    60
    Non-automated response, and in weekend. Other AV vendors don't even bother to reply with an automatic one, or even have a false positive submission form. Kaspersky still kicking, despite all the hate around it.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. Windows_Addict

    Windows_Addict MDL Expert

    Jul 19, 2018
    1,364
    4,292
    60
    AVs don't like when something tries to edit IFEO since it is kind of a sensitive area. That's the main and probably the only reason for flags.
    Code:
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  15. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,727
    60
    Obviously.
    But the error is their automatic scripts ("heuristics") ignored the fact that both the IFEO target and the replacement (a hard-link) are essentially the same file, digitally signed by Microsoft.
    And it's not a LOLBAS (exploitable binary) it's setuphost that can only do setup stuff.
    Well, you could plant something with it, but there's no reason why a smart AV would not know what launch options and locations can do that. And if you don't, don't touch it - it's as simple as that.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. Michel

    Michel MDL Expert

    Jul 29, 2009
    1,860
    262
    60
    So i followed the instructions in the first post to update my legit windows 10 to 11, switched to dev channel and yet it still downloads the Windows 11 Insider Preview 25115.1000 (rs_prerelease). Why does it not upgrade to RTM ?
     
  17. NICK@NUMBER11

    NICK@NUMBER11 MDL Expert

    Mar 23, 2010
    1,515
    719
    60
    switch to beta and windows update will offer it

    upload_2022-5-15_15-59-59.png
     
  18. Michel

    Michel MDL Expert

    Jul 29, 2009
    1,860
    262
    60
    I switched to beta channel and in Windows 10 and it still shows Insider preview as update (same as your screenshot). I assume after it's upgraded to that my machine will receive a new Windows 11 update to rtm ?
     
  19. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    49,647
    103,302
    450
    MSFT will keep calling the upgrade insider preview till it goes to the public retail channel.