Fix it now
0x8007042B is Win32 1067, ERROR_PROCESS_ABORTED: the process terminated unexpectedly. The 0x4000D tail puts it in the second boot phase while setup was migrating your data, and Microsoft Support attributes it to another process running in the background killing setup’s helper.
chkdsk C: /scan
pnputil /enum-drivers
- Uninstall third-party security software before retrying, rather than disabling it. Disabling leaves its drivers loaded, and a loaded driver is what terminates a process.
- Clean boot the machine with msconfig so that only Microsoft services and no third-party startup items run, then retry the upgrade.
- Disconnect everything you do not need: docks, hubs, card readers, external drives, printers.
- If
chkdsk C: /scanreports problems, schedule a full check and let it complete before attempting the upgrade again. - Read the crash evidence rather than guessing. Look in
$Windows.~BT\Sources\Rollbackforsetupmem.dmpand for the entry naming the process that died.
Clean boot is a diagnostic state, not a fix. Put the startup items back after the upgrade, or you will be troubleshooting missing software next week.
If the upgrade finishes you can stop here. If not, the next section explains what the second boot phase is doing and which of the codes belongs to which failure.
Why it happens
By the time you see a 0x4000D code the upgrade is nearly finished. The new build is on disk, the machine has restarted into it, and setup is doing the last and least reversible part of the job: moving accounts, profiles, settings and application state from the old installation into the new one. That is what the MIGRATE_DATA operation is, and it is the operation the 0x4000D tail names.
Migration is unusually exposed. It touches millions of files and thousands of registry keys, it runs while the new build is up and services are starting, and it has to finish for the machine to be usable. Anything that interferes with it, whether that is a security product examining every file it touches, a driver failing under load, or a disk returning errors, stops the migration and forces a rollback.
The codes divide neatly once you split them. 0x8007042B is Win32 1067, ERROR_PROCESS_ABORTED. 0x80070005 is access denied, which is what an endpoint product’s file filter produces when it refuses setup access to something. 0x8007001F is Win32 31, a device attached to the system is not functioning, published here as a general failure. 0xC1900101 with a 0x4001E tail is the same setup platform error at the PRE_OOBE operation instead. And 0xC1900405 is MOSETUP_E_UA_BOX_CRASHED: the installation process terminated unexpectedly.
Security software is terminating or blocking setup’s helper
You have this one if 0x8007042B – 0x4000D or 0x80070005 – 0x4000D, on a machine running a third-party endpoint product.
- Uninstall the product, do not disable it. Its filter driver stays loaded until the product is removed.
- Restart, confirm the product’s services are gone, and retry the upgrade.
- Reinstall from a current installer once the upgrade has completed and the machine is stable.
This is Microsoft’s own line on the 0x4000D family: setup terminated because of another process running in the background. Security software is the commonest such process.
The file system is returning errors under load
You have this one if The failure lands at a different point each attempt, and the machine has had unexplained application faults.
- Run
chkdsk C: /scanfirst, which checks online and does not require a restart. - If it reports problems, schedule a full check and let it run to completion.
- Check the disk’s health independently, because a drive that is failing will keep producing this.
- Only retry the upgrade once the volume checks clean.
A device or its driver fails while migration is running
You have this one if 0x8007001F – 0x4000D, or a machine with a dock, external storage or unusual peripherals attached.
- Disconnect every non-essential device and retry with the machine as bare as possible.
- List third-party drivers with
pnputil /enum-driversand note storage and peripheral entries. - If the upgrade then succeeds, reattach devices one at a time to identify the offender.
A user profile is damaged and migration will not complete on it
You have this one if The failure is consistent, no security product is involved, and one account on the machine has a history of profile problems.
- Sign in as a different administrator and confirm that account works normally.
- Check the profile list under
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListfor entries with a.baksuffix or no matching folder. - Where a profile is beyond repair, move its data out, remove the profile properly through system settings, and retry.
Delete profiles through the system properties user profile dialogue rather than by deleting folders, so the registry entry goes with them.
Full reference
What the second half of each code tells you
| Extend code | Phase and operation |
|---|---|
0x4000D |
Second boot phase, MIGRATE_DATA |
0x4001E |
Second boot phase, PRE_OOBE |
0x3000D |
First boot phase, MIGRATE_DATA |
0x20007 |
SafeOS phase, driver installation |
0x20009 |
Partition analysis and validation |
A 0x4001E tail is worth noticing separately. PRE_OOBE runs after migration, as the new build prepares the first sign-in experience, so a failure there usually points at something in the new build’s start-up path rather than at the migration itself. Both 0x8007042B and 0xC1900101 appear with that tail.
Reading the rollback evidence
| Location | What to look for |
|---|---|
$Windows.~BT\Sources\Rollback |
setupmem.dmp after a crash, and the entry naming the process that terminated |
$Windows.~BT\Sources\Panther\setuperr.log |
The short list of errors, which is the quickest place to start |
$Windows.~BT\Sources\Panther\setupact.log |
The full narrative, including what was being migrated at the time |
%WinDir%\Panther |
Where those logs end up once setup has finished |
Search setuperr.log for the hex code and read the lines above the hit. In a migration failure that context usually names the file, key or profile being processed when it stopped, which turns a generic rollback into something specific enough to act on.
Working through it methodically
- Remove third-party security software completely, then restart.
- Disconnect all non-essential hardware.
- Run
chkdsk C: /scanand deal with anything it reports. - Clean boot the machine so no third-party services or startup items run.
- Retry the upgrade and let it run without interruption.
- If it fails again, read the rollback folder before changing anything else.
When it still fails
- Try the upgrade from mounted media rather than through Windows Update, so the payload is local and fixed for the whole run.
- Free real space on the system volume. Migration writes both the new state and the rollback data, and a volume that was adequate at the start can be full by this phase.
- Sign out every other account, and reboot, so migration is not competing with a session it also has to move.
- Consider whether a clean install is now cheaper than continuing. Migration failures are the ones where that calculation most often tips, because the work you are protecting is the profile data you can back up in an hour.
- Where the machine is managed, check whether a policy applies at first sign-in that might be failing during PRE_OOBE.
When a licence is the actual fix
Nothing here is a licensing failure, and buying a licence will not stop a process being terminated. Work through the causes first: they are free and they resolve most of these. The licence question only arrives if you conclude that migrating this installation is not worth any more attempts, and a clean install of a supported build is the better use of the time. Arco supplies Windows 11 Pro upgrade licences for that case, and would rather confirm your existing entitlement covers the rebuild than sell you a second one.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x8007042B - 0x4000D |
Win32 1067 ERROR_PROCESS_ABORTED during the second boot phase at MIGRATE_DATA. Microsoft Support attributes it to another background process terminating setup | Microsoft Learn |
0x8007042B - 0x4001E |
The same process termination, during the second boot phase at the PRE_OOBE operation | Microsoft Learn |
0x8007001F - 0x4000D |
General failure: a device attached to the system is not functioning | Microsoft Learn |
0x80070005 - 0x4000D |
Access was denied while attempting to migrate data in the second boot phase | Microsoft Learn |
0xC1900101 - 0x4001E |
Installation failed in the second boot phase with an error during the PRE_OOBE operation | Microsoft Learn |
0xC1900405 |
MOSETUP_E_UA_BOX_CRASHED: the installation process terminated unexpectedly | Microsoft Learn |
Confirm the fix worked
- The machine reaches the sign-in screen on the new build and
winverconfirms the version. - Your profile, applications and settings are present rather than a fresh profile having been created.
- The security software you removed is reinstalled and reporting as protected.
- msconfig is back to a normal start-up rather than left in the diagnostic state.
Questions people ask about this
Why does disabling my antivirus not help?
Because disabling stops the interface and the scheduled work, not the filter driver. That driver sits between applications and the file system and it stays loaded until the product is uninstalled. If a filter is refusing setup access to files it needs during migration, only removing the product takes it out of the path.
Is 0x8007042B always security software?
No, but it is the first thing to rule out because it is the most common and the easiest to test. The code itself only says a process terminated unexpectedly. A failing disk, a driver crashing under load and a damaged profile all produce it too, which is why the article works through those in order rather than stopping at the first suspect.
What is PRE_OOBE?
The operation that runs after migration, while the new build prepares the first sign-in experience. A failure with a 0x4001E tail happened there rather than during migration, which shifts attention to what runs at start-up on the new build, including any policy that applies at first sign-in on a managed machine.
Should I run chkdsk with /f?
Start with /scan, which checks the volume online and tells you whether there is anything to fix without taking the machine away from you. If it reports problems, then schedule the repair and let it complete. Running a full repair speculatively on a healthy volume costs time and tells you nothing.
