Paginas

07 September 2016

Windows 10 Anniversary Update vs Bitlocker. Error 0xc00000bd

 


Yesterday I decided to make some Updates and one of them was the Windows 10 Anniversary Update. I heard that there are many problems, but I decided to risk. Basically the news of this Update are these: https://www.microsoft.com/en-us/windows/features


The installation went smoothly and the Windows version went from 1511 to 1607. Only one reboot ahead... oh.. did I said that my computar had bitlocker configured? So, after restart it I put my bitlocker PIN and then, for the first time, I had to enter the Bitlocker Recovery key (yes, that key that we must save in the USB stick or print. If you have Bitlocker, please keep in mind that this key is very important and should always be present. I have mine in a Cloud service. I think it is a good option).

Then, after I entered the numerical key, a BSOD appeared (Blue Screen of Death) with 0xc00000bd.
Something like this:

Recovery
         Your PC/Device needs to be repaired
         A required device isn't connected or can't be accessed.
         Error code: 0xc00000bd
         You'll need to use recovery tools. If you don't have any installation media (like a disc or USB
         device), contact your PC administrator or PC/Device manufacturer.
         Press Enter to try again         Press F8 for Startup Settings

In short, I lost access to my disk drive and Windows could not start up. I could not put a DVD to repair, because the system could  not recognize the Drive. Let's see how to solve this situation without loosing data.



First I checked what this error code mean:


It doesn't make any sense. Let's move on.

I can go to the Repair Options, but I can't do anything to resolve this situation. Safe Mode and Last Good Known Configuration don't work even after I put the Bitlocker Key.


So, it seems that the Update broke the TPM/Bitlocker. At this time I thought that I was going to lose some data and reinstall Windows. But I tried something else that worked. Here are the steps:
 
  1. Move the disk to another PC/Laptop with Windows 7 or newer;
  2. After Windows recognize the disk, I entered this in a Administrator Command Prompt (Letter D is the drive that I want to recover). That way I could see all the files and folders:
    • manage-bde -unlock D: -recoverypassword "Bitlocker_KEY"
  3. Disable Bitlocker in that Drive. The Drive will be decrypting after that:
    • manage-bde -off D:
  4. See the status of the decrypting. It can take a coulpe of hours:
    • manage-bde -status
  5. Insert the Drive decrypted in the source PC/Laptop.
  6. Verify that Windows boot up and everything is OK.
  7. Encrypt again with bitlocker in the new Windows version and keep the Key safe.
The steps are very easy and simple, but when you are in this sitation its a little bit scare and frustrating. Well done Microsoft!

4 comments:

  1. Thanks very much! This helped one of my users out a jam. Once we decrypted his drives we were OK.

    ReplyDelete
  2. How can i do it without another pc cuz i only have one and a phone

    ReplyDelete
  3. Hi,
    As far as I know, you need another PC with Windows 7 or higher to put your disk and decrypt it. You can use any PC, because you will not destroy anything. It will only be used as an intermediary.

    ReplyDelete