Fix it now
0x00000178 is an early launch anti-malware driver reporting a fatal error. Parameter 1 says whether a TPM attestation could not be revoked or, far more often, the ELAM vendor’s own code raised a defined failure. ELAM drivers load before every other boot-start driver, so the machine stops seconds into boot and you need the recovery environment to get in.
bcdedit /enum
- Get into the recovery environment: hold Shift while selecting Restart from the sign-in screen, boot from installation media and choose Repair your computer, or let Windows enter it automatically after two consecutive failed start attempts.
- Go to Troubleshoot, then Advanced options, then Startup Settings, and restart. On the menu that appears, choose the option that disables early launch anti-malware protection. It applies to that boot only.
- Once Windows starts, uninstall the endpoint security agent using the vendor’s dedicated removal tool, which clears the ELAM registration as well as the product.
- Reboot normally and confirm the machine reaches the sign-in screen without the workaround.
- Install a current supported build of the agent and reboot once more to prove its ELAM driver loads cleanly.
If several machines updated at once and several are now down, hold the agent update in your management console before you start fixing them one at a time.
If the machine boots after the agent is replaced, you are done. If it does not, or if the stop code is 0x0000011D instead, the next section covers what else runs in that window.
Why it happens
ELAM drivers are boot-start drivers that declare themselves with a start type of boot-start and a load order group of Early-Launch. They load during kernel initialisation, ahead of the other boot-start drivers, and classify each of those images through a callback as known good, known bad or unknown. The kernel then applies a load policy to those classifications and decides what may initialise. The whole arrangement exists so that malware cannot win the race by loading earlier than the security product.
The price of loading first is that there is nothing underneath you. An ELAM driver runs with no user session, no full registry and no networking, and Microsoft holds it to hard limits: half a millisecond to evaluate each driver, fifty milliseconds for all of them, and 128 kB for the driver plus its configuration data. It is meant to be small, self-contained and signed for this specific role. When it faults the kernel cannot skip it, because the point of the mechanism is that boot does not proceed unvetted.
Parameter 1 is the part worth reading. A value of 0x0 means a TPM attestation could not be revoked, and parameters 2 and 3 carry the image information structure and the TPM result code. A value of 0x10000 means an ELAM-vendor defined failure, with two optional vendor-supplied values behind it. In practice the second is what you meet, and it means the agent’s own code decided it could not continue. That is a vendor defect, not a Windows one, and no amount of policy tuning will change it.
0x0000011D belongs in the same few seconds for a different reason. Modern endpoint agents rely on kernel trace sessions started at boot, and this code says the event tracing subsystem hit an unexpected fatal error, with parameter 1 naming the subtype: kernel mode registration corruption, an invalid handle on unregistration, trace buffer corruption, lost events and so on. An agent with a broken autologger configuration can take the tracing subsystem down with it, and the stop looks like a security product failure because it is one.
An agent update left a mismatched ELAM driver behind
You have this one if The machine booted normally until the endpoint product updated itself, and the first reboot after that failed.
- Boot with early launch anti-malware protection disabled from the Startup Settings menu.
- Uninstall the agent with the vendor’s removal tool, which clears the ELAM registration as well as the product.
- Reboot without the workaround and confirm Windows starts.
- Install the current supported build and reboot again.
Two security products both register early launch drivers
You have this one if A second endpoint product was installed recently and the failure began at the first reboot afterwards.
- Boot with early launch protection disabled.
- Remove the product you do not intend to keep, using its own removal utility.
- Reboot and confirm normal startup.
- Confirm in the surviving product’s console that the machine is reporting in and protected.
A restored image carries an ELAM binary from an older build
You have this one if Only machines from a particular image or an old backup fail; identical machines built fresh are fine.
- Boot with early launch protection disabled and update the agent to a current build.
- Rebuild the reference image with a current agent, or leave the agent out of the image and install it during deployment.
- If the image is old enough that Windows itself is unpatched, patch it before adding security software back.
- Reboot twice and confirm stability before capturing a new image.
The boot-start driver load policy has been tightened
You have this one if Nothing changed on the security product, but a hardening policy or template was applied recently.
- Read
DriverLoadPolicyunderHKLM\SYSTEM\CurrentControlSet\Control\EarlyLaunchand compare it against the documented values. - The default is 0x3, which initialises good, unknown and bad-but-boot-critical drivers. 0x0 initialises known good only and is the setting that turns a misclassification into a boot failure.
- Return the policy to the default and reboot.
- If the strict setting is a deliberate requirement, find which driver is being classified as bad and fix that driver rather than loosening the policy permanently.
Full reference
The documented driver load policy values
| Value | Name | Effect |
|---|---|---|
| 0x0 | PNP_INITIALIZE_DRIVERS_DEFAULT | Initialises known good drivers only |
| 0x1 | PNP_INITIALIZE_UNKNOWN_DRIVERS | Also initialises drivers classified unknown |
| 0x3 | PNP_INITIALIZE_BAD_CRITICAL_DRIVERS | The default. Also initialises drivers classified bad but boot critical |
| 0x7 | PNP_INITIALIZE_BAD_DRIVERS | Initialises drivers classified bad as well |
The policy is read from HKLM\SYSTEM\CurrentControlSet\Control\EarlyLaunch\DriverLoadPolicy. A related value in the same key, BackupPath, is where the location of a backup ELAM driver is read from. Export the key before you change anything: a wrong value here can leave the machine unable to boot, and you will be recovering it from installation media.
Why the boot override cannot be made permanent
There is a boot configuration datatype for this, disableelamdrivers, and it is documented. What is also documented is that it does not survive: the operating system loader removes the entry for security reasons, the option can only be triggered from the boot menu, and someone has to be physically present at the machine to trigger it. Microsoft’s own note says it should only be used for debugging.
So if a repair needs several reboots, plan for the person doing the repair to select the option at each boot, or do the work from the recovery environment or Safe Mode instead. Writing the value into the boot store and walking away will not do what you want, and a machine running permanently without its early launch driver has lost a real defence in any case.
bcdedit /enum
Telling the variants apart
| What you see | What it usually means |
|---|---|
| Stop on every boot; disabling early launch protection lets you in | The registered ELAM driver is faulty or mismatched |
| Stop began right after the agent updated | A regression in the new build, or an interrupted update |
| Parameter 1 is 0x10000 | An ELAM vendor defined failure. The agent’s own code stopped the machine |
| Parameter 1 is 0x0 | A TPM attestation could not be revoked; parameter 3 carries the TPM result code |
| Stop code 0x0000011D instead | A boot trace session the agent configures is broken. Parameter 1 names the tracing subtype |
| Stop after installing a second security product | Two products competing for the early launch slot |
Reaching the recovery environment
- From the sign-in screen, select Shutdown and then hold Shift while selecting Restart.
- From recovery media, choose Repair your computer at the Install Windows screen.
- Automatically, after two consecutive failed attempts to start Windows, two consecutive unexpected shutdowns within two minutes of boot completing, or two consecutive reboots within two minutes of boot completing.
- From a hardware recovery button or button combination where the manufacturer has configured one.
If Safe Mode is quicker
Safe Mode loads a minimal driver set, so an agent that fails a normal boot often does not start at all there. If Safe Mode reaches a desktop, do the uninstall from it. It is usually faster than the Startup Settings route and it leaves nothing to clean up in the boot store afterwards.
Removing an endpoint agent from the recovery environment or Safe Mode leaves the machine unprotected until you finish. Do the work on a network you control, and confirm the replacement is running before the machine goes back to a user.
When a licence is the actual fix
If the failing agent is out of support, or was never licensed for this class of machine, replacing it is the honest fix. Windows already includes Microsoft Defender Antivirus with its own early launch driver, so removing the failing product does not leave the machine unprotected and costs nothing. Where the problem is that a bad agent update reached a whole fleet before anyone could stop it, what you are actually buying is the ability to hold an update back centrally rather than repair machines one at a time. Sophos Intercept X Advanced is one supported option with a managed console; we can supply the licence and confirm which tier covers servers as well as workstations.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x00000178 |
ELAM_DRIVER_DETECTED_FATAL_ERROR: the early launch anti-malware driver reported a fatal error; parameter 1 is 0x0 for a TPM attestation that could not be revoked or 0x10000 for a vendor defined failure | Microsoft Learn |
0x00000029 |
SECURITY_SYSTEM. Microsoft publishes the name and value and says it appears very infrequently, but publishes no cause, parameters or resolution | Microsoft Learn (name only) |
0x00000028 |
CORRUPT_ACCESS_TOKEN. As above: the name and value are published, described as appearing very infrequently, with no cause or parameters given | Microsoft Learn (name only) |
0x0000011D |
EVENT_TRACING_FATAL_ERROR: the event tracing subsystem hit an unexpected fatal error; parameter 1 names the subtype, from registration corruption to trace buffer corruption | Microsoft Learn |
Confirm the fix worked
- Reboot normally, without the Startup Settings workaround, and confirm the machine reaches the sign-in screen.
- Run
bcdedit /enumand confirm no early launch override has been left set. - Check the System log for boot-time errors from the security product.
- Confirm
DriverLoadPolicyis at the value you intended, and that you have a record of any change. - Confirm the endpoint agent reports itself running and up to date in its own console.
Questions people ask about this
Is it safe to run with early launch protection disabled?
For the length of a repair, yes. Permanently, no, and Windows will not let you anyway: the loader removes the boot setting that would make it persist, and the option can only be selected from the boot menu by someone physically at the machine.
What does parameter 1 tell me?
Which half of the mechanism failed. 0x0 means a TPM attestation could not be revoked, with the TPM result code in parameter 3. 0x10000 means the ELAM vendor’s own code raised a defined failure, which points the case at the security vendor rather than at Windows or the TPM.
Will Safe Mode work instead?
Often, and it is worth trying because it is quicker to reach. Safe Mode loads a minimal driver set, so an agent that fails a normal boot may not start at all. If Safe Mode gets you to a desktop, do the uninstall there.
What do 0x00000029 and 0x00000028 mean?
Microsoft publishes their names, SECURITY_SYSTEM and CORRUPT_ACCESS_TOKEN, and says both appear very infrequently. No cause, parameters or resolution are published for either, so treat them as a pointer to collect a dump rather than as a diagnosis, and do not trust a source that assigns them a confident meaning.
Can I keep the product but stop it registering as an ELAM driver?
There is no supported switch for that. The registration is part of how the product installs, declared in its INF with a boot-start type and the Early-Launch load order group. If the driver is faulty the answer is a fixed build from the vendor, not a partial installation.
