• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
Microsoft Windows 11

On booting my HP computer, I get a message: "Secure Boot Violation. Invalid signature detected. Check secure boot policy. However, if I disable secure boot in BIOS computer boots just fine. I have tried to remove security keys and restore factory defaults, but nothing seems to help.  I need to add that, prior to that, a virus visited my computer. So I ran McAfee, and as of now, all scans are clean.

 

Any suggestions?

1 REPLY 1
HP Recommended

Hi,

Since the computer boots when Secure Boot is disabled, the hardware is probably not the main problem. The issue is more likely that Secure Boot is detecting an invalid or untrusted boot component.

Because you mentioned that the computer had a virus recently, I would treat this carefully. A clean antivirus scan inside Windows is good, but it does not always prove that the boot path is clean.

Please try this order:

  1. Back up your important files first.
  2. Disconnect all external devices:
  • USB drives
  • External hard drives
  • Memory cards
  • Docks
  • Printers
  1. Enter BIOS Setup:
  • Turn on the computer and press Esc repeatedly.
  • Press F10 for BIOS Setup.
  • Load BIOS Setup Defaults.
  • Save and restart.
  1. Go back into BIOS and check:
  • OS Boot Manager is first in the boot order.
  • Secure Boot is enabled.
  • If available, restore/load the default Secure Boot keys.

HP Secure Boot information:

https://support.hp.com/us-en/document/ish_6930187-6931079-16

  1. If Windows still gives the same Secure Boot Violation, disable Secure Boot only temporarily so you can boot into Windows and run an offline security scan.

Run Microsoft Defender Offline scan:

Windows Security > Virus & threat protection > Scan options > Microsoft Defender Antivirus Offline scan

Microsoft Defender Offline scan:

https://support.microsoft.com/en-us/windows/help-protect-my-pc-with-microsoft-defender-offline-9306d...

  1. After the offline scan, run Windows repair.

Open Command Prompt as Administrator and run:

sfc /scannow

DISM /Online /Cleanup-Image /RestoreHealth

  1. If Secure Boot still fails, boot from a clean Windows 11 installation USB and choose:

Repair your computer > Troubleshoot > Advanced options > Startup Repair

Do not choose Install now unless you plan to reinstall Windows.

Microsoft Startup Repair:

https://support.microsoft.com/en-us/windows/experience/startup-boot/startup-repair

  1. If the issue started after the virus and Secure Boot still fails after restoring BIOS defaults, restoring Secure Boot keys, running an offline scan, and using Startup Repair, the safest solution may be to back up your files and perform a clean Windows installation from official Microsoft installation media.

I would not recommend leaving Secure Boot disabled permanently. Secure Boot is there to protect the boot process, and this error means something in the startup path is not trusted or not signed correctly.

Regards,
Haytham

 

Haytham Alqolaq
† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->