STOP c000021a winlogon ONLY with Administrator

borhani

Honorable
Apr 7, 2013
26
0
10,540
I've recently reinstalled XP SP3; all patches up to date. About 10 days ago, I started getting the dreaded "STOP c000021a winlogon.exe terminated" blue screen. The "minidumps", unlike regular BSOD minidumps, seem almost completely uninformative (though if anyone knows how to extract useful info from them, *please* let me know!).

I've tried going back to two different system restore points saved *before* this started happening: no luck.

The STOP error is:
1. Apparently random. I can go for hours or even a day without it happening, but then it might happen 3 times in a row, in the course of 5 minutes.
2. Most often occurs directly upon logging in (e.g., having typed part, but not all, of the password, even!!), or within seconds or a minute very soon after the profile is loaded and XP is populating my desktop icons.
3. Happens regardless of my being directly connected (keyboard & mouse) to the computer, or coming in via RDP (I mention this only because of my last post, which involved RDPDR.SYS playing poorly with Avast!, now fixed!).
4. Strangely, seems to happen ONLY for the "Administrator" user. I'm not 100% sure about this, given that I can go hours without a STOP error, but I think this is the case.

I have tried rolling back to earlier, supposedly good, system restore points. Doesn't help. I don't believe I have any unusual drivers, etc. I do have Avast! antivirus and Carbonite, but I uninstalled Carbonite, and I was still getting STOP errors.

Is it possible that it is the Administrator profile that is somehow ruined? Can I delete it, so that XP will create a new one (in a new "administrator.domainname" folder)?

Thanks!!
 
Recently did memtest: OK. Clean XP installation, i.e. all drivers "updated".

If it *is* a driver, how can I figure out which one? When I had the rdpdr.sys error the minidump clearly said "It's rdpdr.sys that is causing me to die". Here, all I get is that winlogon.exe didn't like *something*, and shut down (for my own protection ;-) ). But what is that *something*?
 
Not sure of the relevance of that link. I recreated the Administrator profile:

1. Logged in as another user with (temporary) admin privileges, renamed Administrator's ntuser.dat to ntuser.dat.foobar
2. Logged in as Administrator (which created a fresh profile)
3. As other user, copied D:\D&S\Administrator.domainname\ntuser.* to D:\D&S\Administrator; edited registry to replace the two occurrences of "Administrator.domainname" by "Administrator"
4. Logged in (successfully) as Administrator, with the fresh profile; deleted D:\D&S\Administrator.domainname, and took ownership of D:\D&S\Administrator\ntuser.*

For now, this seems to have fixed the problem (worked for several hours after this, without any BSOD's). But, given the intermittent nature, I'll have to see what the long-term results are.




 

TRENDING THREADS