Unsolved
1 Message
0
5041
January 16th, 2021 09:00
XPS Secure boot violation, invalid signature detected
My XPS computer, Windows 10, is now showing "Secure boot violation - invalid signture detected". Everything I have read suggests doing factory reboot.
I have files backed up.
I did not set up a system restore
Can I go into BIOS setup and use F9 "default settings" to reset this to factory settings and get rid of any potential malware?
Thanks
No Events found!


Tesla1856
10 Wizard
•
17.9K Posts
•
71.4K Points
0
January 16th, 2021 10:00
It sounds like your machine has a serious:
- Malware and/or RootKit infection
- Hardware malfunction (including main drive and/or motherboard).
No, that is not how you do it. Since you are asking like this, and the general tone of your post...
I suggest you seek-out professional assistance.
Vic384
6 Operator
•
3.2K Posts
0
January 16th, 2021 10:00
@Xpsindy21 I suggest you Google search "Secure boot violation - invalid signature detected". You should find several articles about the problem and potential solutions. Here is one such article: https://appuals.com/how-to-fix-the-secure-boot-violation-invalid-signature-detected-problem-on-windows/
RoHe
12 Elder
•
45.2K Posts
•
172.6K Points
0
January 16th, 2021 12:00
@Xpsindy21 - Always include exact PC model number in your posts.
If recently upgraded to a new video card or installed another add-in card, that would explain this error so Secure Boot in BIOS setup would be the likely cause and has to be disabled...
DELL-Chris M
Community Manager
•
56.9K Posts
•
232.1K Points
0
January 18th, 2021 15:00
It's the XPS 8930.
speedstep
11 Legend
•
47K Posts
0
January 18th, 2021 16:00
Thank you for clarifying. Let's try to performing the steps below and check if you can boot normally after applying the said procedure:
1. Enter the bios UEFI and navigate to Advanced Menu->Boot->Secure Boot
Secure Boot stands out as one of the most important causes. Secure Boot needs to be disabled in your computer’s BIOS settings if you want to get rid of this problem.
2. Change “OS type” to “Other OS”
3. Press F10 to Save and reboot
4. Check the UEFI Advanced Menu->Boot->Secure Boot, and confirm the “Platform Key (PK) State” is changed to be unloaded.
5. Exit the UEFI, and the system will now boot normally.
If this does not work
it would be best to contact Dell to check and provide other possible workarounds to resolve said issue.
When the KB3084905 update was released for Windows Server 2012 and Windows 8.1, Microsoft has announced that the update may cause problems regarding secure boot on computers connected to the same domain controller. The easiest way to resolve this is to simply uninstall this update from your computer
DO NOT
Disable Digital Driver Signature Enforcement
This would allow Malware from a driver or app to do bad things..
I would also recommend offline scan
https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download
The only Other suggestion I have is to make a USB2.0 flash drive installer
Boot it in diagnostic mode
Run diskpart and select the drive
Clean the drive with diskpart
Reinstall windows from scratch with SATA operation set to AHCI and Secure boot OFF so that you can F12 boot from the USB 2.0 flash drive.
There are no soft fixes for corrupted or physically bad drives.
Yuo will need to use a USB2 16 or 32 gig flash drive to create an F12 windows 10 installer for a new drive
Once you buy that
Use Media creation tool to create USB2 installer. This is the 20H2 link
https://go.microsoft.com/fwlink/?LinkId=691209
https://www.bestbuy.com/site/sandisk-cruzer-32gb-usb-2-0-flash-drive-black/9288807.p?skuId=9288807
These are not expensive but EBAY and other sites often have these counterfeited
Retail buying of this will guarantee you dont get a fake drive.
SanDisk - Cruzer 32GB USB 2.0 Flash Drive - Black
Model:SDCZ60-032G-A46
SKU:9288807