When rebooting the client after uninstalling SEP, the following error shows on the Client screen:
Windows failed to start. A recent hardware or software change might be the cause.
Info: The operating system couldn’t be loaded because a critical system driver is missing or contains errors.
Status: 0xc000000f
File:\windows\system32\Drivers\SEP\xxxxxxxx\xxxx.xxx\x64\SymELAM.sys
Release : SEP 14.x
The SymELAM (Early Launch Anti-Malware) drivers got removed from the uninstall process but the service failed to unload which cause the reboot failure.
Solution 1: Disable SymELAM service in the Registry
From the Windows Recovery screen Go to Troubleshoot > Advanced options > Command Prompt
6. Close and reboot
Solution 2: Copy the content of the folder x64 from a working system
Option 1:
Option 2:
First need to create a Temp folder ..load the hive and then make the changes on the registry and then unload the hive to make this resolution work.
Please see the screenshot as mentioned below
You can run the command
reg load HKLM\temp
reg unload HKLM\temp