Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.

Windows 7: Probably caused by : cng.sys ( cng!SHA512Transform+b5e )

22 Oct 2011   #1

Windows 7 Home Premium x64 Service Pack 1
Probably caused by : cng.sys ( cng!SHA512Transform+b5e )

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If kernel debugger is available get stack backtrace. Arguments: Arg1: fffff87f844f232d, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000008, value 0 = read operation, 1 = write operation Arg4: fffff87f844f232d, address which referenced memory.

Recent dump files point specifically to Cryptographic Service Provider (CSP) running Vista driver. This is where I'm stuck.
Can anyone please help me decipher this BDOD?

Computer Name: HOME-PC
BIOS Information
Vendor American Megatrends Inc.
Version 1504
Board Product ID P7P55D-E PREMIUM

Processor Information
Summary 1 Physical Processors / 4 Cores / 8 Logical Processors / 64 bits
Name Intel(R) Core(TM) i7 CPU 870 @ 2.93GHz
Vendor GenuineIntel
Original System Clock 133 MHz

Storage Device Information
Disk 0 500.1 GB WDC WD5000AAKS-00A7B0 Western Digital
Disk 1 500.1 GB WDC WD5000AAKS-00A7B0 Western Digital
Disk 2 640.1 GB WDC WD6400AAVS-00G9B1 WD
DVD Writer 0 ASUS DRW-2014L1T ATA Device (ASUS DRW-2014L1T)

Logical Disk Information
B:\ (Backup) Local Disk Size: 195.3 (GB) Free: 194.9 (GB)
C:\ Local Disk Size: 270.3 (GB) Free: 223.2 (GB)
D:\ (DATA) Local Disk Size: 465.7 (GB) Free: 294.6 (GB)
F:\ Optical Drive
G:\ (MYBOOK) Local Disk Size: 596.0 (GB) Free: 514.1 (GB)
H:\ Optical Drive

Memory Information
Slot 1 DDR3 (PC3-10700H) 2048 MBytes G.Skill
Slot 2 DDR3 (PC3-10700H) 2048 MBytes G.Skill
Slot 3 DDR3 (PC3-10700H) 2048 MBytes G.Skill
Slot 4 DDR3 (PC3-10700H) 2048 MBytes G.Skill

Display Adapter Information
NVIDIA GeForce 8800 GT 512 MBytes

Sound Adapter Information
High Definition Audio Device Microsoft

Network Adapter Information
Realtek PCIe GBE Family Controller WIRED Disconnected [100 Mbps]
Realtek PCI GBE Family Controller WIRED Connected [100 Mbps]

Operating System
Type Windows 7 Home Premium x64 Service Pack 1

My System SpecsSystem Spec
22 Oct 2011   #2

Windows 7 Home Premium x64 Service Pack 1
No replies!

Seriously, in 45 minutes no one with experience with debugging tools can decipher my BSOD issue?
My System SpecsSystem Spec
22 Oct 2011   #3

Windows 10 Pro x64

It's Saturday, and I would guess everyone here assists in their spare time. I tend to spend time with my family and friends on Saturday and Sunday, and enjoy not working - I sincerely doubt I'm in the minority.

Also, the dump file provided is corrupt (assuming dump.txt is really dump.dmp), so you might want to follow the guidelines for posting a dump file, please.
My System SpecsSystem Spec

22 Oct 2011   #4

Windows 10 Pro x64

Unfortunately, it's a little hard to say - it looks like a hardware (CPU or RAM) issue, but I can't give it a 100% backing as a hardware problem either:
// This should call loopne on that cng function and offset, which would
// decrement ECX over and over and test for 0 until it got there:
2: kd> u fffff880`014f232d
fffff880`014f232d e00f loopne cng!SHA512Transform+0xb6f (fffff880`014f233e)
fffff880`014f232f 4c8b04c4 mov r8,qword ptr [rsp+rax*8]
fffff880`014f2333 418d45fe lea eax,[r13-2]
fffff880`014f2337 83e00f and eax,0Fh
fffff880`014f233a 488b0cc4 mov rcx,qword ptr [rsp+rax*8]
fffff880`014f233e 488bd1 mov rdx,rcx
fffff880`014f2341 488bc1 mov rax,rcx
fffff880`014f2344 48c1e906 shr rcx,6
// The stack indeed does appear to go into ECX (and then crash, of course):
2: kd> kn
  *** Stack trace for last set context - .thread/.cxr resets it
 # Child-SP          RetAddr           Call Site
00 fffff880`08ed5f98 fffff880`014f232d 0xfffff87f`844f232d
01 fffff880`08ed5fa0 fffff880`014f169c cng!SHA512Transform+0xb5e
02 fffff880`08ed6080 fffff880`014f155f cng!SHA512Update+0x6c
03 fffff880`08ed60c0 fffff880`014f7b03 cng!SHA512Final+0xc5
04 fffff880`08ed61a0 fffff880`014f79ec cng!GetHashInterface+0xffffffff`fffffd93
05 fffff880`08ed6310 fffff880`014f7994 cng!GetHashInterface+0xffffffff`fffffefc
06 fffff880`08ed6350 fffff880`014ffe09 cng!GetHashInterface+0xffffffff`ffffffd4
07 fffff880`08ed6390 fffff880`015198d9 cng! ?? ::FNODOBFM::`string'+0x212a
08 fffff880`08ed6460 fffff880`015005c9 cng!CngEncryptMemoryInitialize+0x29
09 fffff880`08ed64d0 fffff880`014f5ce5 cng! ?? ::FNODOBFM::`string'+0x2939
0a fffff880`08ed6880 fffff880`012121bb cng!CngDeviceControl+0x405
0b fffff880`08ed6980 fffff880`012120aa ksecdd!KsecDeviceControl+0x5b
0c fffff880`08ed69d0 fffff800`01fa6a97 ksecdd!KsecDispatch+0x9a
0d fffff880`08ed6a10 fffff800`01fa72f6 nt!IopXxxControlFile+0x607
0e fffff880`08ed6b40 fffff800`01c8aed3 nt!NtDeviceIoControlFile+0x56
0f fffff880`08ed6bb0 00000000`00000000 nt!KiSystemServiceCopyEnd+0x13
// The registers we're talking about do match:
2: kd> r
Last set context:
rax=0000000000000017 rbx=0000000000000000 rcx=291926708afbbdb0
rdx=9227d4e6ce53e9f6 rsi=0000000000000000 rdi=0000000000000000
rip=fffff87f844f232d rsp=fffff88008ed5f98 rbp=0a85a6e821f555d2
 r8=00f01927fa685b46  r9=0000000000000007 r10=fffff88008ed62a0
r11=dcc12238842347df r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=5870  es=01bc  fs=f880  gs=ffff             efl=00010246
fffff87f`844f232d ??              ???
// We can easily see the value that will show up in ECX when looking at
// the rcx register, the 64bit version of this register:
2: kd> r @ecx
Last set context:
// Is this really an invalid address?  Given it's a minidump I can't say for
// certain, but since it's listed as an invalid address in !analyze -v and as
// the reason for the crash, it would at least seem to be true:
2: kd> dc 8afbbdb0 L1
ffffffff`8afbbdb0  ????????                             ????
I would suggest making a few changes, even if these aren't related entirely. First, you have the Asus ASCAPI.sys from March 2005 on your system, which is well known to cause all kinds of oddball corruption and BSOD's (see here for instructions on what to do to update it). Second, it's probably worth putting your hardware (both CPU and RAM) through some hardware testing to see what you come up with, to make sure it's not a hardware issue. Otherwise, the binaries check out OK, and other than making sure you test without PowerISO or SmartDefrag installed (and perhaps Avast as well, as all 3 appear to use filter drivers at the kernel level), there's not much else I can say at this point.
My System SpecsSystem Spec

 Probably caused by : cng.sys ( cng!SHA512Transform+b5e )

Thread Tools

Similar help and support threads
Thread Forum
BSOD Caused By Driver:nwifi.sys Caused By Address:nwifi.sys+34026
Hello! Lately I often have a BSOD, and since I'm not an expert I turn to you for help. The .txt files are from BlueScreenView. Thank you in advance Nikolay
BSOD Help and Support
what has caused this?
hello mydocument folder is not working, can any one help sort this out please?
Don' know what caused BSOD
What could have caused my bsod? Only has happened one time (i hope) and concerned because this is a new laptop. Could you help me find out what caused this? Thanks. Windows 7 Home Premium 64 bit OEM version with Lenovo Y570 laptop bought the laptop just last April 2012 P.S. All I was doing...
BSOD Help and Support
Help, what's caused this ?
I have just installed Windows 7 professional on my new built machine. This morning I have been copying over files and documents from my old OS (win XP on a different drive), to my current OS. I have another version of windows 7 professional on another hard drive in this machine, but decided to...
Performance & Maintenance
BSOD was caused by ?
Event log shows Event ID 41, Task 63, .....Kernel Power. I had no music players on, no videos, no scans. Just surfing while protected in Sandboxie. Other security is NIS 2010 and Prev 3 w/SafeOnline and Keyscrambler. No other security or extra programs were running. I have Windows 7 Pro x64,...
BSOD Help and Support

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 12:03.
Twitter Facebook Google+ Seven Forums iOS App Seven Forums Android App