New
#1
BSOD Error Code 7E when computer booted up.
So I just performed a windows update (i've been getting blue screens before the update as well) and I restarted my computer. When I booted it up I let my desktop load then right as I was about to touch my keyboard and mouse, my computer blue screened with the Bug Check Code of 7E, SYSTEM_THREAD_EXCEPTION_NOT_HANDLED. I'm uploading the kernal memory dump to my OneDrive right now but here's what WinDbg had to say about the BSOD
I saw it mentioned cng.sys so I am currently running System File check, sfc, right now to ensure it, as well as other files, are not corrupted.*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800030e563c, The address that the exception occurred at
Arg3: fffff88003715d98, Exception Record Address
Arg4: fffff880037155f0, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObReferenceObjectSafe+c
fffff800`030e563c 498b02 mov rax,qword ptr [r10]
EXCEPTION_RECORD: fffff88003715d98 -- (.exr 0xfffff88003715d98)
ExceptionAddress: fffff800030e563c (nt!ObReferenceObjectSafe+0x000000000000000c)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff880037155f0 -- (.cxr 0xfffff880037155f0;r)
rax=fffffa8009f7d060 rbx=d2fffa800994ca90 rcx=d2fffa800994ca90
rdx=fffff80003301c40 rsi=d2fffa800994ceb8 rdi=fffffa800972fb50
rip=fffff800030e563c rsp=fffff88003715fd0 rbp=fffff880037165c0
r8=0000000000000000 r9=fffffa8009fafb60 r10=d2fffa800994ca60
r11=0000000000000005 r12=0000000000000000 r13=fffffa8009fafe38
r14=0000000000000011 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!ObReferenceObjectSafe+0xc:
fffff800`030e563c 498b02 mov rax,qword ptr [r10] ds:002b:d2fffa80`0994ca60=????????????????
Last set context:
rax=fffffa8009f7d060 rbx=d2fffa800994ca90 rcx=d2fffa800994ca90
rdx=fffff80003301c40 rsi=d2fffa800994ceb8 rdi=fffffa800972fb50
rip=fffff800030e563c rsp=fffff88003715fd0 rbp=fffff880037165c0
r8=0000000000000000 r9=fffffa8009fafb60 r10=d2fffa800994ca60
r11=0000000000000005 r12=0000000000000000 r13=fffffa8009fafe38
r14=0000000000000011 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!ObReferenceObjectSafe+0xc:
fffff800`030e563c 498b02 mov rax,qword ptr [r10] ds:002b:d2fffa80`0994ca60=????????????????
Resetting default scope
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: ffffffffffffffff
FOLLOWUP_IP:
cng!GatherRandomKey+22c
fffff880`0181f1dc 83ff20 cmp edi,20h
BUGCHECK_STR: 0x7E
ANALYSIS_VERSION: 6.3.9600.17029 (debuggers(dbg).140219-1702) amd64fre
LAST_CONTROL_TRANSFER: from fffff80003385ff4 to fffff800030e563c
STACK_TEXT:
fffff880`03715fd0 fffff800`03385ff4 : 00000000`00000000 fffffa80`09f7d060 fffffa80`09f7d060 fffff8a0`190857e8 : nt!ObReferenceObjectSafe+0xc
fffff880`03716000 fffff800`033d5416 : fffff8a0`190690a8 fffff800`0001ff58 fffff880`03716190 00000000`00000000 : nt!ExpGetProcessInformation+0x496
fffff880`03716150 fffff800`033d5e6d : fffff8a0`190690a8 fffffa80`6365734b 00000000`00000000 fffff880`03716ae0 : nt!ExpQuerySystemInformation+0xfb4
fffff880`03716500 fffff800`030c8e53 : fffff880`037165d0 fffff800`030c7dfd 00000000`00000001 fffff8a0`19069000 : nt!NtQuerySystemInformation+0x4d
fffff880`03716540 fffff800`030c5410 : fffff880`0181f1dc fffff8a0`18f97000 fffff880`03716704 00000000`6365734b : nt!KiSystemServiceCopyEnd+0x13
fffff880`037166d8 fffff880`0181f1dc : fffff8a0`18f97000 fffff880`03716704 00000000`6365734b fffffa80`00000000 : nt!KiServiceLinkage
fffff880`037166e0 fffff880`0181f73d : fffffa80`0c8ade70 00000000`00000018 fffffa80`20206f49 0000007c`04c28a14 : cng!GatherRandomKey+0x22c
fffff880`03716aa0 fffff800`033c0cad : 00000000`00000001 00000000`00000001 fffff800`0326e0b0 fffffa80`0972fb50 : cng!scavengingWorkItemRoutine+0x3d
fffff880`03716b40 fffff800`030d3261 : fffff800`030bece0 fffffa80`0972fb01 fffffa80`0972fb00 fffffa80`0972fb50 : nt!IopProcessWorkItem+0x3d
fffff880`03716b70 fffff800`0336573a : 00000000`00000000 fffffa80`0972fb50 00000000`00000080 fffffa80`096ac840 : nt!ExpWorkerThread+0x111
fffff880`03716c00 fffff800`030ba8e6 : fffff880`033d7180 fffffa80`0972fb50 fffff880`033e1fc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`03716c40 00000000`00000000 : fffff880`03717000 fffff880`03711000 fffff880`03715920 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: cng!GatherRandomKey+22c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: cng
IMAGE_NAME: cng.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 50194fb7
STACK_COMMAND: .cxr 0xfffff880037155f0 ; kb
FAILURE_BUCKET_ID: X64_0x7E_cng!GatherRandomKey+22c
BUCKET_ID: X64_0x7E_cng!GatherRandomKey+22c
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x7e_cng!gatherrandomkey+22c
FAILURE_ID_HASH: {ee5f4d2a-987d-9a67-0c3f-7dae9915a1c5}
Followup: MachineOwner
---------
I admit by BSODs have gotten less frequent but they are still there. I will link to my Kernal Memory Dump once it finishes uploading to my OneDrive
EDIT:
Finished uploading the dump to oneDrive, here is the link
https://onedrive.live.com/redir?resi...D4F258D1%21118