Windows Test Mode: Enabled after Factory Recovery

Modifyinc

New member
Local time
10:23 AM
Messages
38
I noticed today my Windows 7 Pro x64 version of windows is running in Test Mode. Not sure how long it has been in this mode and I just didn't notice it, because I had a shortcut icon sitting in the bottom right corner that pretty much made it impossible to see. Well today I moved that icon and noticed it. I googled it and discovered its purpose and why someone might want to use it. Unfortunately, none of the reasons explained why it would be enabled on a system without the user explicitly enabling it, and on a 64bit OS.

Also, none of the results made any reference to it as something to be concerned about. If it's enabled they tell you how to disable it. I'm sorry, but I'm concerned how a Windows 7 64bit system can enable Test Mode on its own. I'm thinking a rootkit or some other type of malware has possibly compromised my system. I had just removed Cryptwall 3.0 from my system, so you can understand why I was concerned when I seen my system was in Test Mode. How do I know whether or not the Test Mode allowed the malware into my system. If I didn't enable it, then I'm thinking the malware did.

So to be extra safe, I restored my system to factory settings and chose NOT to restore any of my personal files. Guess what I noticed after the factory restore in the bottom right corner of my screen: Test Mode.

Can someone please explain how this is possible? Is the setting saved in the boot configuration data or something? If so, is this not restored during a factory restore? Could malware have compromised the manufacturer's Recovery process?

Mike
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7
CPU
AMD Athlon 64 X2 Dual Core Processor 5000 2.6 Ghz
Motherboard
Gigabyte MA78GM
Memory
4GB
Graphics Card(s)
Radeon 3200
Sound Card
RealTek HD
Monitor(s) Displays
Samsung LCD
Hard Drives
1TB WD
600GB WD
320GB WD
320GB WD
admin cmd prompt:

bcdedit /set TESTSIGNING OFF
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
admin cmd prompt:

bcdedit /set TESTSIGNING OFF

This did not address any part of my question, but only reinforced my prior statement that people seem only want to offer how to disable it. Page after page explains how to disable it, but not one page explains how it might have become enabled without user interaction. I'm beginning to think the reason is because no one truly knows anything else about it.

I know how to disable it, what I don't know is how it became enabled in the first place and can stay enabled after a Factory reset.

Mike
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7
CPU
AMD Athlon 64 X2 Dual Core Processor 5000 2.6 Ghz
Motherboard
Gigabyte MA78GM
Memory
4GB
Graphics Card(s)
Radeon 3200
Sound Card
RealTek HD
Monitor(s) Displays
Samsung LCD
Hard Drives
1TB WD
600GB WD
320GB WD
320GB WD
I had to run in test mode for a couple of years in my previous install due to enabling SLI on a non-supported motherboard. Never had an issue with malware. You can however scan with Malwarebytes Anti-Malware free (enable rootkit scanning in settings - detection). I would guess recovery partition not affected by a malware.

Unfortunately I don't know why test mode persisted after a recovery.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Ultimate x64 SP1
CPU
AMD Phenom 2 1090T
Motherboard
Gigabyte GA-890FXA-UD5
Memory
2x8GB Kingston HyperX Fury Black 1600Mhz Unganged
Graphics Card(s)
MSI GTX 970 Gaming 4G
Sound Card
Realtek On-Board HD 7.1 Audio / Logitech G35
Monitor(s) Displays
3xAcer GD245HQ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro 512GB SSD - OS /
WD Caviar Black SATA 3 - 1 TBx2 - Dynamic RAID 0 /
WD Caviar Green SATA 2 - 640GBx2 - Dynamic RAID 0 /
WD Caviar Green SATA 2 - 640GB - Internal Backup /
Seagate Barracude SATA 3 - 3TB - External Backup/ Sync
PSU
HighPower 1000W
Case
Cooler Master HAF 932
Cooling
Noctua NH-D14
Keyboard
Logitech G19
Mouse
Logitech G500
Internet Speed
100/4 Mbit Cable (100GB quota)
Antivirus
ZoneAlarm Extreme Security / MBAM Pro / MBAE Free / SAS Free
Browser
IE 11 - Firefox - Chrome
Other Info
Logitech F710/ G27/ G940/ Z5500 // TrackIR 5 // Nvidia 3D Surround Vision
As your rig is a custom build i'd be more concerned about where you got your OS from, especially if you bought it online.

I would suggest you follow the advice in the Windows Update/Activation Sub forum, and post the results for analysis.

Roy

Note looking back at your earlier problems is this an upgrade install?

This was also an indication of rootkit necurs.a
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Read this tutorial. Good information that might be helpful.

http://www.sevenforums.com/tutorial...ws-7-build-7601-watermark-remove-desktop.html


According to Microsoft, the test mode watermark can appear if the test signing mode is started on the computer. This test mode may occur if an application whose drivers are not digitally signed by Microsoft is installed and still in the test phase. Microsoft added test mode to Windows so that users can test programs without having to provide an authentication certificate.

The TESTSIGNING boot configuration option determines whether Windows Vista and later versions of Windows will load any type of test-signed kernel-mode code. This option is not set by default, which means test-signed kernel-mode drivers will not load by default on 64-bit versions of Windows Vista and later versions of Windows.

For 64-bit versions of Windows Vista and later versions of Windows, the kernel-mode code signing policy requires that all kernel-mode code have a digital signature. However, in most cases, an unsigned driver can be installed and loaded on 32-bit versions of Windows Vista and later versions of Windows.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Test mode was introduced for the testing stages of W7 and included in Vista updates, somewhat like the current upgrade path to W10, see my last line in previous post certainly looking more likely

Roy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
As your rig is a custom build i'd be more concerned about where you got your OS from, especially if you bought it online.

I would suggest you follow the advice in the Windows Update/Activation Sub forum, and post the results for analysis.

Roy

Note looking back at your earlier problems is this an upgrade install?

This was also an indication of rootkit necurs.a

What made you think my PC was custom built, I never mentioned that? It's a Dell All-in-One that was shipped directly from Dell, so I'm not too concerned about where the OS came from. Test Mode was not enabled when I received it a year or so ago. It was just recently I noticed it, and it was a coincidence I noticed it after only finding out I had CryptWall 3.0 ransomware on my computer. I never enabled Test Mode, so I figured my system at some point became compromised and the Test Mode was enabled by malicious code or similar. I mean how else could it? It doesn't enable by itself; Microsoft clearly states on 64bit machines it is not enabled by default.

I mentioned I did a Factory restore in my post, so no upgrade install. The system came preinstalled with W7 Pro x64 w/ SP1. All I did was perform a Factory restore and noticed the Test Mode was still enabled when it completed the Factory restore. Of course I disabled it immediately, but I'm still questioning why it persisted across a Factory reinstall.

Mike
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7
CPU
AMD Athlon 64 X2 Dual Core Processor 5000 2.6 Ghz
Motherboard
Gigabyte MA78GM
Memory
4GB
Graphics Card(s)
Radeon 3200
Sound Card
RealTek HD
Monitor(s) Displays
Samsung LCD
Hard Drives
1TB WD
600GB WD
320GB WD
320GB WD
Read this tutorial. Good information that might be helpful.

http://www.sevenforums.com/tutorial...ws-7-build-7601-watermark-remove-desktop.html


According to Microsoft, the test mode watermark can appear if the test signing mode is started on the computer. This test mode may occur if an application whose drivers are not digitally signed by Microsoft is installed and still in the test phase. Microsoft added test mode to Windows so that users can test programs without having to provide an authentication certificate.

The TESTSIGNING boot configuration option determines whether Windows Vista and later versions of Windows will load any type of test-signed kernel-mode code. This option is not set by default, which means test-signed kernel-mode drivers will not load by default on 64-bit versions of Windows Vista and later versions of Windows.

For 64-bit versions of Windows Vista and later versions of Windows, the kernel-mode code signing policy requires that all kernel-mode code have a digital signature. However, in most cases, an unsigned driver can be installed and loaded on 32-bit versions of Windows Vista and later versions of Windows.

Thank you, but I have already read that piece, and honestly, it's why I'm so concerned with it being enabled on my system.

The first statement says, "According to Microsoft, the test mode watermark can appear if the test signing mode is started on the computer."

It doesn't directly address how the mode can be started other than mentioning the user. So one is left to assume, if he/she didn't enable it, then malicious code on a compromised system must be the culprit. And to top it off, it is persistent across a Factory reinstall. Can someone can confirm if this is by design?

Seriously, how else could one see this?

Mike
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7
CPU
AMD Athlon 64 X2 Dual Core Processor 5000 2.6 Ghz
Motherboard
Gigabyte MA78GM
Memory
4GB
Graphics Card(s)
Radeon 3200
Sound Card
RealTek HD
Monitor(s) Displays
Samsung LCD
Hard Drives
1TB WD
600GB WD
320GB WD
320GB WD
Seriously, Factory install is the worst possible install of Win7 one can have, as bad as being badly infected. Avoid this and all other problems by doing a perfect Clean Reinstall Windows 7 which will stay that way as long as you stick with only the steps, tools and methods given. Over 1.5 million consumers have used the tutorial without a single complaint. They have the best installs of WIn7 in the world. You have the worst. Next will come the locusts.
 
I did read your complete post and that includes the last line.

From the tutorial.
This test mode may occur if an application whose drivers are not digitally signed by Microsoft is installed and still in the test phase.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
What made you think my PC was custom built, I never mentioned that? It's a Dell All-in-One that was shipped directly from Dell, so I'm not too concerned about where the OS came from.
Perhaps the information you entered in your System Specs??

CustBild.jpg
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo IdeaCenter 450
OS
Windows 10 Pro X64
CPU
Intel Quad Core i7-4770 @ 3.4Ghz
Memory
16.0GB PC3-12800 DDR3 SDRAM 1600 MHz
Graphics Card(s)
Intel Integrated HD Graphics
Sound Card
Realtek HD Audio
Monitor(s) Displays
HP 22" LCD
Screen Resolution
1680 x 1050
Hard Drives
250GB Samsung EVO SATA-3 SSD
2TB Seagate ST2000DM001 SATA-2
1.5TB Seagate ST3150041AS SATA
Keyboard
Dell USB
Mouse
Lenovo USB
Internet Speed
Cable via Road Runner 3MB Upload, 30MB Download
Antivirus
Windows Defender, MBAM Pro, MBAE
Browser
Seamonkey
Other Info
UEFI/GPT
PLDS DVD-RW DH16AERSH
change your cp

I thought it was a custom build as thats what you've got on your CP

So You were hacked, Im pretty sure you've still got remnants, thats why your still getting Test mode

Go to the security subforum and repost with ALL the info you have.

Roy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Back
Top