BSOD after Acronis True Image Restore

rx8pilot

New member
Joined
Nov 25, 2016
Posts
4
Hi all - it's another BSOD party.

0xC000021a following a system restore from an Acronis True Image Backup. A cascade of failures put this PC in a precarious position. I am REALLY hoping to get it back to booting without a re-install. The software, licenses, and configuration of this workstation is nearly impossible to re-create and at minimum extremely expensive. It was had a RAID5 system disk that offered one level of redundancy followed by local and cloud images. The RAID failed faster than I could rebuild it, the local backups were not happening because of an improper configuration of Acronis or possibly a bug. That left me with a cloud backup as the only option. At least I have an option.

Stats Pre crash:
Win7 x64 Pro
Intel i7 12 core - 24GB RAM - system drive: RAID5 with 4x HDD's
Asus P6X58D
No known recent changes to the system pre-crash
This system has been rock stable since 2010

Stats post crash:
Changed sys dirve to AHCI 500GB Samsung SSD

60hrs to recover from Acronis cloud that led to a BSOD indicating it could not find the boot partition
I went through the usual suspects of checks: chkdsk, sfc, DISM, bootrec, confirmed partition arrangements etc - no improvements.
Changed the BIOS from AHCI to IDE and Windows was able to get much further in the boot process but now offers a BSOD C000021a which is some sort of security issue with winlogon or CSRSS. I had heard there may be some issues with Acronis restore dealing with a change in the HDD controller configuration so I built a new RAID config with 2 drives and have been working with that for a bit - no improvements though.

bootrec /scanos finds 0 installations of Windows. If I rename BCD and run bootrec /rebuildbcd it finds windows on the correct volume and successfully adds it, however it still reports 0 installations with /scanos. That remains true even after a reboot. The windows repair environment can no longer find windows after this.

Automatic windows repair booting from DVD and USB does nothing that I can see.

sfc /scannow /offboot=c:\ offwindir=d:\windows returns 'Windows Resource Protection could not perform the requested operation" - have not found any offline repair options for this error. I only have access to command line outside of windows.

chkdsk returns no errors

no version of safe mode is bootable - same BSOD STOP code C000021a

RAM tests are all good.

PSU tested extensively (I am a power supply designer, so that is an easy one)

Last know configuration does not help.

This has been going for quite some time - I have bee hacking on this for many hours. Most things have been tried with ever imaginable variation and multiple times. Clearly I am missing something and HOPING it is a simple thing. Grateful for any help. Donations and payments if I can find a solution for sure.
 
UPDATE: It does not appear that the BSOD dump works outside of Windows - I may be wrong. Any other options to get useful logs?
 
Hi,

WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.

usualy a antivirussoftware or in your case running acronis or both?

sometimes, in case win aborts before login you can take / try the last known good by pressing F8 before win starts and chose just last known good..

else
stop any service from acronis manual in the registry, then try again.
 
Late last night, I believe I stumbled on a smoking gun. As an experiment, I restored the registry hive from %system%\windows\system32\config\regback and it booted up. Not all of the software was working, and there are a number of odd behaviors. I reverted back to the original registry hive and swapped in each hive one at a time to see if a single file was a problem. I found that restoring the backup SOFTWARE hive was the one that allowed it to boot up. I took that one to another machine and it is unreadable when I try to load it into regedit. I left the backup SOFTWARE hive in place and used the originals of the others SYSTEM, SAM, SECURITY, etc.

It appears that all of my critical software is working (fantastic!), but Windows update is not working and it cannot make any restore points. It will not allow me to rename a folder without an error - "Could Not Find This Item". Overall it is FAR better than BSOD boot loops for sure. I will continue to run some tests to make sure it is working well enough to get work done while I chase down the remaining Gremlins.

I had been (since August) chasing down disk configurations, MBR problems, and other lower level areas looking for the problem. As it turns out Acronis True Image failed to ever make a clean backup of my system. I even went back and manually pulled 10 versions of the SOFTWARE hive going back months before and none of them are readable. Acronis support only offers Level 0 troubleshooting and they spent most of the time telling me that 'True Image is a consumer product....." Like I should have purchased the more expensive version even though the core backup/restore engine is a failure. Never again will I consider Acronis. I since started using Paragon to image and restore numerous machines and it works flawlessly. No effort, no errors. Acronis seems to spend too much time sponsoring race car teams and parties while there core tech is failing.

Not sure where to go from here, but at least the BSOD stop error is less of a mystery. Apparently that is the code if the system cannot read the SOFTWARE hive at all - an unexpected error. Wondering if it can be repaired with a binary editor - maybe just the header is corrupted and the rest (200MB) is just fine?
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top