Unsolved

This post is more than 5 years old

1 Rookie

 • 

7 Posts

14287

April 12th, 2018 08:00

Inspiron 3656, secure boot violation

My home/personal PC “Dell Inspiron 3656” has an issue. I can’t boot!I get a black screen with a red error box. In the red error box it reads “Secure Boot Violation, Invalid Signature Detected. Check Secure Boot Policy in Setup.”I can’t get past that. I have been in/out of the bios screen and made some alterations to the boot options, but still, nada.I followed some youtube videos and came up short. Some changes worked for other people, but not myself.

I didn't make any recent changes to my PC either. Nothing.

Any help? Advice?

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 12th, 2018 10:00


@kahoolawewrote:

 

I didn't make any recent changes to my PC either. Nothing.

 


So, you didn't just swap your motherboard out-from-underneath your un-touched hard-drive (HDD or SSD)? You didn't just update your BIOS or anything major like that?

Have you been having trouble with your HDD lately?

Do you tend to have a lot of trouble with viruses or spyware lately?

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 12th, 2018 11:00

Does your Dell Inspiron 3656 have:

1. The Computrace feature in BIOS, and is it Activated with a Subscription?

2. The new SupportAssist feature in BIOS and is it Enabled?

PS. Be sure to answer questions on both of my posts.

11 Legend

 • 

47K Posts

April 13th, 2018 04:00

There are specific malware that cause "“Secure Boot Violation, Invalid Signature Detected"

Time for scorched earth erase and reinstall.

MalwareMalware

1 Rookie

 • 

7 Posts

April 13th, 2018 08:00

I am not with my PC right now, but I will be later tonight. I do remember seeing "Computrace" but I didn't touch it.

Should I alter it/setting?

SupportAssist? I don't recall seeing that, but I'll check tonight. If it's enabled, should it not be?

 

1 Rookie

 • 

7 Posts

April 13th, 2018 08:00

Ouch! I need to remove my HD and move my files over to my other PC, etc.. first?

I don't want to lose my files.

1 Rookie

 • 

7 Posts

April 13th, 2018 08:00

Nope. Nothing at all. My PC was fine and has been fine. I have a firewall, anti-virus, etc... always on/running.

I haven't made any changes at all.

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 13th, 2018 09:00


@kahoolawewrote:

1. I am not with my PC right now, but I will be later tonight. I do remember seeing "Computrace" but I didn't touch it.

2. Should I alter it/setting?

3. SupportAssist? I don't recall seeing that, but I'll check tonight. If it's enabled, should it not be?

 


1. If you were paying for a Computrace account, you would know it.

2. no

3. Computrace and SupportAssist are both authorized Boot-Kits (but not Root-Kits). You could try Disabling them.

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 13th, 2018 09:00


@kahoolawewrote:

Nope. Nothing at all. My PC was fine and has been fine. I have a firewall, anti-virus, etc... always on/running.

I haven't made any changes at all.


Then either:
1. Your hard-drive is failing, or
2. There is a good chance that your computer is infected with a Root-Kit virus.

Either way, I would suggest a full Nuke and Pave

https://www.dell.com/community/Alienware-General/fixed/td-p/5627124

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 13th, 2018 09:00


@kahoolawewrote:

Ouch! I need to remove my HD and move my files over to my other PC, etc.. first?

I don't want to lose my files.


You could try:

- Disabling SecureBoot
- Go into Windows (preferably in Safe-Mode and with Windows Defender still running)
- Backup your data files (as few as possible) to a single flash-drive.

After the machine is fixed, and SecureBoot is back on, be very cautious with this flash-drive. Scan it and these files thoroughly before trusting it/them and restoring them. You don't want to bring back the RootKit, RansomWare, or Virus.

It would have been MUCH-MUCH BETTER if your data-files would have been backed-up BEFORE all this started. In that case, you could have just formatted and nuked the whole drive away more safely.

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 13th, 2018 10:00


@speedstepwrote:

There are specific malware that cause "“Secure Boot Violation, Invalid Signature Detected"

Time for scorched earth erase and reinstall.

MalwareMalware


Yeah, I didn't want to jump to conclusions at that early stage, but this is where I was going ... definitely a possibility.

Cool you found a hosted-pic of it.

Now that I think about it, I guess it should know the difference between hard-drive failure and a true SecureBoot Violation. That just leaves:

1. An unintentional BIOS update that incorrectly revoked the Boot-Kit authorizations for Computrace or SupportAssist. This is a long-shot.

2. Or more likely, SecureBoot working as designed ... to alert the user to a Root-Kit infection. I've never seen one in "real life" but if genuine, this is one of the first documented cases I've seen (here anyway).

If this is real/genuine ... I would be very careful, cautious, and thorough cleaning it up.

 

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 13th, 2018 11:00


@kahoolawewrote:

1. I can't get to windows or safe mode.

2. Disabling Secure Boot didn't work.

3. I'm likely calling Dell tonight and paying the darn fee for their assistance.

 


1. That's unfortunate.

2. Interesting

3. I kinda doubt they will help you recover your data-files in this instance (or, if it's even possible). As for the full-wipe and clean-install (Nuke-and-Pave) ... I already posted the link, and have written other tips (in other posts) and helped many other users do it. 

But yeah, do whatever you think is appropriate.

1 Rookie

 • 

7 Posts

April 13th, 2018 11:00

And to top it all off, the Dell "system restore" thing will not work either. Can't get it to move to a USB drive.

It may think I've used my Service Tag number already or something. And I haven't.

 

1 Rookie

 • 

7 Posts

April 13th, 2018 11:00

I wish I could! I would have already move my files to my external drive.

I can't get to windows or safe mode.

Disabling Secure Boot didn't work.

I'm likely calling Dell tonight and paying the darn fee for their assistance.

 

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

April 13th, 2018 11:00


@kahoolawewrote:

And to top it all off, the Dell "system restore" thing will not work either. Can't get it to move to a USB drive.

It may think I've used my Service Tag number already or something. And I haven't.

 


Yeah ... I'm not sure what any of that means.

Stay calm. :Smile:

1 Message

June 30th, 2018 10:00

I was having the same issue... I eventually took off the disabled the secure boot... Then File Browser add boot option... then chose the HDD.. Boot... efi… boot64... then it asked to name the file and I named it boot, save and exit and my computer booted...

No Events found!

Top