Bad_Pool_Header 0x0000019 BSOD tho can boot in safe mode

sunhux
sunhux used Ask the Experts™
on
The Lenovo has been working fine till around 2-3 weeks ago, it BSODed
while booting up : saw the Windows logo & shortly after it BSODed 0x0...19
Not aware of any change other than around those few days, noted an
MS update took place (from Windows "System Restore" point description.

It could boot up in Safe Mode or "Safe Mode with Networking" though.
Tried "Repair Windows" & it did not help.

https://www.experts-exchange.com/questions/26813125/Bad-Pool-Header-0x019-BSOD.html
Also tried the suggestions given in url above ie

1. boot up in Safe Mode & renamed away the file
    C:\Windows\System32\FNTCACHE.DAT & reboot

2. sfc / scannow   in Safe Mode showed no error (ie no integrity issue)

3. in Safe Mode, I used msconfig to disabled the AV TrendMicro & a few startups
    that are of unknown developer

I can attach the minidump & the screen showing the BSOD if it's useful as clue
for troubleshooting.

Running Windows 7 Profesnl
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Natty GregIn Theory (IT)

Commented:
Open up the computer take out memory, hard drive and battery, reseat the memory and hard disk and boot up the machine, then post back
RaminTechnical Advisor

Commented:
Please go to C:\Windows\Minidump\
 and attach the Minidump.dmp file to your post.
Python 3 Fundamentals

This course will teach participants about installing and configuring Python, syntax, importing, statements, types, strings, booleans, files, lists, tuples, comprehensions, functions, and classes.

Author

Commented:
Reseating the RAM, battery & HDD did not help.

As there are 2 RAM chips, used 1 chip at a time on each of the DIMM sockets but did not help.
Is the hotfix link correct?  It says it's not there anymore.

Will provide  the minidump on Monday

Author

Commented:
While in Safe mode, have 'restored' to a point that is about 1 month back (ie prior to the
Windows update that was automatically updated) : it did not help too
Top Expert 2013
Commented:
i Always start by running diags on Ram and disk - to be sure about the basics , before proceeding a repair
i use the ubcd for this :
Hardware diagnostic CD    UBCD
---------------------------------------------------
go to the download page, scroll down to the mirror section, and  click on a mirror to start the download
Download the UBCD and make the cd   <<==on a WORKING PC, and boot the problem PC from it
Here 2 links, one to the general site, and a direct link to the download

since the downloaded file is an ISO file, eg ubcd527.iso - so you need to use an ISO burning tool
if you don't have that software, install cdburnerXP : http://cdburnerxp.se/

If you want also the Ram tested - run memtest86+ at least 1 full pass,  - you should have NO errors!
 
For disk Diagnostics run the disk diag for your disk brand (eg seagate diag for seagate drive)  from the HDD section -  long or advanced diag !  (runs at least for30 minutes)

http://www.ultimatebootcd.com/      

**  you can make a bootable cd - or bootable usb stick
*** note *** for SSD drives  use the tool from the manufacturer, like intel 's toolbox :
https://downloadcenter.intel.com/download/18455/Intel-Solid-State-Drive-Toolbox

for completeness -here's how i handle disk problems : http://www.experts-exchange.com/Storage/Hard_Drives/A_3000-The-bad-hard-disk-problem.html

==>>****in order to be able to  boot from CD or usb - you may have to disable secure boot in the bios
Distinguished Expert 2018
Commented:
Did you try removing Trend Micro entirely?
RaminTechnical Advisor

Commented:
Please try CHKDSK /r in Command Prompt and let us know the result.

Author

Commented:
attached the dump : sorry it took too long.

Did not remove Trendmicro completely but can do that.
I'm worried of doing chkdsk /r  as I had in the past done
this with a Win2008 R2 tt has NTFS 55 error & it got worse
040817-160790-01.dmp

Author

Commented:
I've  run a scan while in Safe mode:  scannow / ...   but it gives no error

Author

Commented:
correction:  it's   sfc /scannow
Technical Advisor
Commented:
This is a typical software Driver bug.  More often memory corruption happens because of software errors in buggy drivers.

In your case the cause is TMUMH.sys
The TMUMH.sys is a Trend Micro driver for Anti-exploit feature.
Uninstall Trend Micro completely.
Try reinstalling latest version of Trend Micro or use alternative security software.
Distinguished Expert 2018
Commented:
I've historically known Trend Micro to be pretty problematic, hence why I suggested removing it first... I've even seen an instance of it corrupting the TCP/IP stack so bad that it had to be reinstalled (resetting didn't work). And all that was done was that Windows updates were installed.
Top Expert 2013

Commented:
note that in some case sit can also be caused ba ram or disk problems, so running a diag on them can help too

Author

Commented:
Now, we are unable to uninstall TrendMicro :
hv tried the suggestions in link below:
  http://www.compit.se/?p=3

While uninstalling in Safe mode (as can't boot
to full mode), it gave the error message:
  Uninstallation Stopped
  Unable to remove the software while in Safe Mode
Distinguished Expert 2018

Commented:
Most likely dependent on Windows Installer, which doesn't run when you're in Safe Mode. Have you tried Safe Mode with Networking? That *might* let you do some additional things.

But here's an article from Trend Micro with instructions for manual uninstall or other uninstall methods (I am assuming you are using OfficeScan): https://success.trendmicro.com/solution/1039283-uninstalling-clients-or-agents-in-officescan-osce

Author

Commented:
Yes it's Officescan.   Got it resolved:

Booted up in Safe Mode w Networking & downloaded Revo Uninstaller:
using this tool, uninstalled TrendMicro & after reboot, it doesn't BSOD anymore.

Presume the copy of TrendMicro may have been corrupted that it doesn't
allow uninstallation & had to be manually uninstalled using Revo
RaminTechnical Advisor

Commented:
I am glad you got it working, and Thanks.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial