The error in the screenshot matches a Secure Boot certificate trust problem: “Secure Boot Violation – Invalid signature detected.” Since Windows starts when Secure Boot is disabled, the practical recovery path is:
- Disable Secure Boot temporarily in BIOS/UEFI so Windows can boot.
- If the BIOS has it, reset Secure Boot settings / restore factory defaults for Secure Boot.
- After Windows starts, check the PC or motherboard manufacturer’s support site for a BIOS/UEFI firmware update and install it before turning Secure Boot back on.
- Then re-enter BIOS/UEFI and enable Secure Boot again.
If the problem started after resetting Secure Boot to firmware defaults, the firmware may have removed the certificate needed to trust the current Windows boot manager. In that case, use the Secure Boot recovery utility:
- On a second Windows PC with the July 2024 or newer Windows update installed, copy
SecureBootRecovery.efifromC:\Windows\Boot\EFI\. - Put it on a FAT32 USB drive in
\EFI\BOOT\. - Rename the file to
bootx64.efi. - Boot the affected PC from that USB drive and let the recovery utility run.
- After restart, try enabling Secure Boot again.
Important: BIOS/UEFI reset and Secure Boot changes can make the PC unbootable until the certificate trust is restored. If the device still fails after resetting Secure Boot settings, recovery likely requires OEM-specific guidance from the PC or motherboard manufacturer.