Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.

Windows 7: Probably caused by : cng.sys ( cng!SHA512Transform+b5e )

22 Oct 2011   #1

Windows 7 Home Premium x64 Service Pack 1
Probably caused by : cng.sys ( cng!SHA512Transform+b5e )

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If kernel debugger is available get stack backtrace. Arguments: Arg1: fffff87f844f232d, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000008, value 0 = read operation, 1 = write operation Arg4: fffff87f844f232d, address which referenced memory.

Recent dump files point specifically to Cryptographic Service Provider (CSP) running Vista driver. This is where I'm stuck.
Can anyone please help me decipher this BDOD?

Computer Name: HOME-PC
BIOS Information
Vendor American Megatrends Inc.
Version 1504
Board Product ID P7P55D-E PREMIUM

Processor Information
Summary 1 Physical Processors / 4 Cores / 8 Logical Processors / 64 bits
Name Intel(R) Core(TM) i7 CPU 870 @ 2.93GHz
Vendor GenuineIntel
Original System Clock 133 MHz

Storage Device Information
Disk 0 500.1 GB WDC WD5000AAKS-00A7B0 Western Digital
Disk 1 500.1 GB WDC WD5000AAKS-00A7B0 Western Digital
Disk 2 640.1 GB WDC WD6400AAVS-00G9B1 WD
DVD Writer 0 ASUS DRW-2014L1T ATA Device (ASUS DRW-2014L1T)

Logical Disk Information
B:\ (Backup) Local Disk Size: 195.3 (GB) Free: 194.9 (GB)
C:\ Local Disk Size: 270.3 (GB) Free: 223.2 (GB)
D:\ (DATA) Local Disk Size: 465.7 (GB) Free: 294.6 (GB)
F:\ Optical Drive
G:\ (MYBOOK) Local Disk Size: 596.0 (GB) Free: 514.1 (GB)
H:\ Optical Drive

Memory Information
Slot 1 DDR3 (PC3-10700H) 2048 MBytes G.Skill
Slot 2 DDR3 (PC3-10700H) 2048 MBytes G.Skill
Slot 3 DDR3 (PC3-10700H) 2048 MBytes G.Skill
Slot 4 DDR3 (PC3-10700H) 2048 MBytes G.Skill

Display Adapter Information
NVIDIA GeForce 8800 GT 512 MBytes

Sound Adapter Information
High Definition Audio Device Microsoft

Network Adapter Information
Realtek PCIe GBE Family Controller WIRED Disconnected [100 Mbps]
Realtek PCI GBE Family Controller WIRED Connected [100 Mbps]

Operating System
Type Windows 7 Home Premium x64 Service Pack 1

My System SpecsSystem Spec
22 Oct 2011   #2

Windows 7 Home Premium x64 Service Pack 1
No replies!

Seriously, in 45 minutes no one with experience with debugging tools can decipher my BSOD issue?
My System SpecsSystem Spec
22 Oct 2011   #3

Windows 10 Pro x64

It's Saturday, and I would guess everyone here assists in their spare time. I tend to spend time with my family and friends on Saturday and Sunday, and enjoy not working - I sincerely doubt I'm in the minority.

Also, the dump file provided is corrupt (assuming dump.txt is really dump.dmp), so you might want to follow the guidelines for posting a dump file, please.
My System SpecsSystem Spec

22 Oct 2011   #4

Windows 10 Pro x64

Unfortunately, it's a little hard to say - it looks like a hardware (CPU or RAM) issue, but I can't give it a 100% backing as a hardware problem either:
// This should call loopne on that cng function and offset, which would
// decrement ECX over and over and test for 0 until it got there:
2: kd> u fffff880`014f232d
fffff880`014f232d e00f loopne cng!SHA512Transform+0xb6f (fffff880`014f233e)
fffff880`014f232f 4c8b04c4 mov r8,qword ptr [rsp+rax*8]
fffff880`014f2333 418d45fe lea eax,[r13-2]
fffff880`014f2337 83e00f and eax,0Fh
fffff880`014f233a 488b0cc4 mov rcx,qword ptr [rsp+rax*8]
fffff880`014f233e 488bd1 mov rdx,rcx
fffff880`014f2341 488bc1 mov rax,rcx
fffff880`014f2344 48c1e906 shr rcx,6
// The stack indeed does appear to go into ECX (and then crash, of course):
2: kd> kn
  *** Stack trace for last set context - .thread/.cxr resets it
 # Child-SP          RetAddr           Call Site
00 fffff880`08ed5f98 fffff880`014f232d 0xfffff87f`844f232d
01 fffff880`08ed5fa0 fffff880`014f169c cng!SHA512Transform+0xb5e
02 fffff880`08ed6080 fffff880`014f155f cng!SHA512Update+0x6c
03 fffff880`08ed60c0 fffff880`014f7b03 cng!SHA512Final+0xc5
04 fffff880`08ed61a0 fffff880`014f79ec cng!GetHashInterface+0xffffffff`fffffd93
05 fffff880`08ed6310 fffff880`014f7994 cng!GetHashInterface+0xffffffff`fffffefc
06 fffff880`08ed6350 fffff880`014ffe09 cng!GetHashInterface+0xffffffff`ffffffd4
07 fffff880`08ed6390 fffff880`015198d9 cng! ?? ::FNODOBFM::`string'+0x212a
08 fffff880`08ed6460 fffff880`015005c9 cng!CngEncryptMemoryInitialize+0x29
09 fffff880`08ed64d0 fffff880`014f5ce5 cng! ?? ::FNODOBFM::`string'+0x2939
0a fffff880`08ed6880 fffff880`012121bb cng!CngDeviceControl+0x405
0b fffff880`08ed6980 fffff880`012120aa ksecdd!KsecDeviceControl+0x5b
0c fffff880`08ed69d0 fffff800`01fa6a97 ksecdd!KsecDispatch+0x9a
0d fffff880`08ed6a10 fffff800`01fa72f6 nt!IopXxxControlFile+0x607
0e fffff880`08ed6b40 fffff800`01c8aed3 nt!NtDeviceIoControlFile+0x56
0f fffff880`08ed6bb0 00000000`00000000 nt!KiSystemServiceCopyEnd+0x13
// The registers we're talking about do match:
2: kd> r
Last set context:
rax=0000000000000017 rbx=0000000000000000 rcx=291926708afbbdb0
rdx=9227d4e6ce53e9f6 rsi=0000000000000000 rdi=0000000000000000
rip=fffff87f844f232d rsp=fffff88008ed5f98 rbp=0a85a6e821f555d2
 r8=00f01927fa685b46  r9=0000000000000007 r10=fffff88008ed62a0
r11=dcc12238842347df r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=5870  es=01bc  fs=f880  gs=ffff             efl=00010246
fffff87f`844f232d ??              ???
// We can easily see the value that will show up in ECX when looking at
// the rcx register, the 64bit version of this register:
2: kd> r @ecx
Last set context:
// Is this really an invalid address?  Given it's a minidump I can't say for
// certain, but since it's listed as an invalid address in !analyze -v and as
// the reason for the crash, it would at least seem to be true:
2: kd> dc 8afbbdb0 L1
ffffffff`8afbbdb0  ????????                             ????
I would suggest making a few changes, even if these aren't related entirely. First, you have the Asus ASCAPI.sys from March 2005 on your system, which is well known to cause all kinds of oddball corruption and BSOD's (see here for instructions on what to do to update it). Second, it's probably worth putting your hardware (both CPU and RAM) through some hardware testing to see what you come up with, to make sure it's not a hardware issue. Otherwise, the binaries check out OK, and other than making sure you test without PowerISO or SmartDefrag installed (and perhaps Avast as well, as all 3 appear to use filter drivers at the kernel level), there's not much else I can say at this point.
My System SpecsSystem Spec

 Probably caused by : cng.sys ( cng!SHA512Transform+b5e )

Thread Tools

Similar help and support threads
Thread Forum
what has caused this?
hello mydocument folder is not working, can any one help sort this out please?
Don't know what caused this BSOD
I've uploaded a .dmp file that probably contains info about error... So I do hope you guys gonna help me resolve it... :p P.S. And one thing is weird: It occurs every 2nd time when I use pro version of Advanced System Care 6.1 for some clean-up, I don't know why...
BSOD Help and Support
BSOD Can anyone tell me what caused it??
I've attached the zip file, the DMP file located in C:/windows/minidump. I believe that is what's needed. If anyone could tell me what caused this it would be very appreciated. It just happened on it own I had youtube on pause in another tab and was on facebook on another. I was talking to my...
BSOD Help and Support
Don't know what caused this BSOD
I don't know whats this BSOD about plz analyze and then tell me what to do....:(
BSOD Help and Support
Help, what's caused this ?
I have just installed Windows 7 professional on my new built machine. This morning I have been copying over files and documents from my old OS (win XP on a different drive), to my current OS. I have another version of windows 7 professional on another hard drive in this machine, but decided to...
Performance & Maintenance
BSOD was caused by ?
Event log shows Event ID 41, Task 63, .....Kernel Power. I had no music players on, no videos, no scans. Just surfing while protected in Sandboxie. Other security is NIS 2010 and Prev 3 w/SafeOnline and Keyscrambler. No other security or extra programs were running. I have Windows 7 Pro x64,...
BSOD Help and Support

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 14:57.
Twitter Facebook Google+ Seven Forums iOS App Seven Forums Android App