Unsolved

1 Message

5041

January 16th, 2021 09:00

XPS Secure boot violation, invalid signature detected

My XPS computer, Windows 10, is now showing "Secure boot violation - invalid signture detected".  Everything I have read suggests doing factory reboot. 

I have files backed up.

I did not set up a system restore

Can I go into BIOS setup and use F9 "default settings" to reset this to factory settings and get rid of any potential malware?

Thanks

 

 

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

January 16th, 2021 10:00

It sounds like your machine has a serious:

- Malware and/or RootKit infection
- Hardware malfunction (including main drive and/or motherboard).

No, that is not how you do it. Since you are asking like this, and the general tone of your post...

I suggest you seek-out professional assistance.

6 Operator

 • 

3.2K Posts

January 16th, 2021 10:00

@Xpsindy21 I suggest you Google search "Secure boot violation - invalid signature detected". You should find several articles about the problem and potential solutions. Here is one such article: https://appuals.com/how-to-fix-the-secure-boot-violation-invalid-signature-detected-problem-on-windows/

 

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

January 16th, 2021 12:00

@Xpsindy21 - Always include exact PC model number in your posts.

If recently upgraded to a new video card or installed another add-in card, that would explain this error so Secure Boot in BIOS setup would be the likely cause and has to be disabled...

Community Manager

 • 

56.9K Posts

 • 

232.1K Points

January 18th, 2021 15:00

It's the XPS 8930.

11 Legend

 • 

47K Posts

January 18th, 2021 16:00

Thank you for clarifying. Let's try to performing the steps below and check if you can boot normally after applying the said procedure:

1. Enter the bios UEFI and navigate to Advanced Menu->Boot->Secure Boot

Secure Boot stands out as one of the most important causes. Secure Boot needs to be disabled in your computer’s BIOS settings if you want to get rid of this problem.


2. Change “OS type” to “Other OS”
3. Press F10 to Save and reboot
4. Check the UEFI Advanced Menu->Boot->Secure Boot, and confirm the “Platform Key (PK) State” is changed to be unloaded.
5. Exit the UEFI, and the system will now boot normally.

If this does not work

it would be best to contact Dell to check and provide other possible workarounds to resolve  said issue.

When the KB3084905 update was released for Windows Server 2012 and Windows 8.1, Microsoft has announced that the update may cause problems regarding secure boot on computers connected to the same domain controller. The easiest way to resolve this is to simply uninstall this update from your computer

DO NOT

Disable Digital Driver Signature Enforcement

This would allow Malware from a driver or app to do bad things..

I would also recommend offline scan

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download

 

The only Other suggestion I have is to make a USB2.0 flash drive installer

Boot it in diagnostic mode

Run diskpart and select the drive

Clean the drive with diskpart

Reinstall windows from scratch with SATA operation set to AHCI and Secure boot OFF so that you can F12 boot from the USB 2.0 flash drive.

There are no soft fixes for corrupted or physically bad drives.
Yuo will need to use a USB2 16 or 32 gig flash drive to create an F12 windows 10 installer for a new drive

Once you buy that

Use Media creation tool to create USB2 installer.  This is the 20H2 link
https://go.microsoft.com/fwlink/?LinkId=691209

https://www.bestbuy.com/site/sandisk-cruzer-32gb-usb-2-0-flash-drive-black/9288807.p?skuId=9288807

These are not expensive but EBAY and other sites often have these counterfeited

Retail buying of this will guarantee you dont get a fake drive.

SanDisk - Cruzer 32GB USB 2.0 Flash Drive - Black
Model:SDCZ60-032G-A46
SKU:9288807

 

No Events found!

Top