Share via

BSOD ExceptionCode: c0000005 while instalation Windows 11 caused by process Registry

Anonymous
2023-08-10T13:01:46+00:00

Hello! Recently I got some troubles with Windows, my wireless headset does not wanted to connect to my PC. I tried to delete bluetooth driver and re-install it. Problem was not solved and also I faced with some new issues such as: some apps are closing without any error, new audio devices drivers wont install properly. So I decided to re-instal Windows 11. Using Media Creation Tool I prepared usb-disk. Instalation was like regular but after first reboot (which needed for instaling) I got bsod cx0000005*.* I tried few times more but still get same msg.
Before instalation BIOS was reseted to default settings, all SSDs was formated. I have 2 pcs of RAM so I tried each one separetly. Also tried to install on different SSDs.
Here is dump file info:
************* Preparing the environment for Debugger Extensions Gallery repositories ************** ExtensionRepository : Implicit UseExperimentalFeatureForNugetShare : false AllowNugetExeUpdate : false AllowNugetMSCredentialProviderInstall : false AllowParallelInitializationOfLocalRepositories : true

-- Configuring repositories ----> Repository : LocalInstalled, Enabled: true ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.016 seconds ----> Repository : UserExtensions, Enabled: true, Packages count: 0 ----> Repository : LocalInstalled, Enabled: true, Packages count: 36

Microsoft (R) Windows Debugger Version 10.0.25877.1004 AMD64 Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\080823-2546-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv* Executable search path is: Windows 10 Kernel Version 22621 MP (32 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Edition build lab: 22621.1.amd64fre.ni_release.220506-1250 Kernel base = 0xfffff8000c200000 PsLoadedModuleList = 0xfffff8000ce13470 Debug session time: Tue Aug 8 22:00:30.871 2023 (UTC + 3:00) System Uptime: 0 days 0:00:02.548 Loading Kernel Symbols ............................................................... ............................................................ Loading User Symbols PEB address is NULL ! Loading unloaded module list ..... For analysis of this file, run !analyze -v nt!KeBugCheckEx: fffff8000c62b8f0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffff5845f095f60=000000000000007e 8: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * *******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e) This is a very common BugCheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffff8000c98ec0e, The address that the exception occurred at Arg3: fffff5845f096fc8, Exception Record Address Arg4: fffff5845f0967e0, Context Record Address

Debugging Details:

KEY_VALUES_STRING: 1

Key  : AV.Fault
Value: Read

Key  : Analysis.CPU.mSec
Value: 546

Key  : Analysis.Elapsed.mSec
Value: 11363

Key  : Analysis.IO.Other.Mb
Value: 7

Key  : Analysis.IO.Read.Mb
Value: 0

Key  : Analysis.IO.Write.Mb
Value: 33

Key  : Analysis.Init.CPU.mSec
Value: 93

Key  : Analysis.Init.Elapsed.mSec
Value: 37265

Key  : Analysis.Memory.CommitPeak.Mb
Value: 96

Key  : Bugcheck.Code.LegacyAPI
Value: 0x1000007e

Key  : Failure.Bucket
Value: AV\_nt!HvpGetCellPaged

Key  : Failure.Hash
Value: {90e145c3-c04a-f304-4254-781be6862dc9}

Key  : Hypervisor.Enlightenments.ValueHex
Value: 1417df84

Key  : Hypervisor.Flags.AnyHypervisorPresent
Value: 1

Key  : Hypervisor.Flags.ApicEnlightened
Value: 0

Key  : Hypervisor.Flags.ApicVirtualizationAvailable
Value: 1

Key  : Hypervisor.Flags.AsyncMemoryHint
Value: 0

Key  : Hypervisor.Flags.CoreSchedulerRequested
Value: 0

Key  : Hypervisor.Flags.CpuManager
Value: 1

Key  : Hypervisor.Flags.DeprecateAutoEoi
Value: 1

Key  : Hypervisor.Flags.DynamicCpuDisabled
Value: 1

Key  : Hypervisor.Flags.Epf
Value: 0

Key  : Hypervisor.Flags.ExtendedProcessorMasks
Value: 1

Key  : Hypervisor.Flags.HardwareMbecAvailable
Value: 1

Key  : Hypervisor.Flags.MaxBankNumber
Value: 0

Key  : Hypervisor.Flags.MemoryZeroingControl
Value: 0

Key  : Hypervisor.Flags.NoExtendedRangeFlush
Value: 0

Key  : Hypervisor.Flags.NoNonArchCoreSharing
Value: 1

Key  : Hypervisor.Flags.Phase0InitDone
Value: 1

Key  : Hypervisor.Flags.PowerSchedulerQos
Value: 0

Key  : Hypervisor.Flags.RootScheduler
Value: 0

Key  : Hypervisor.Flags.SynicAvailable
Value: 1

Key  : Hypervisor.Flags.UseQpcBias
Value: 0

Key  : Hypervisor.Flags.Value
Value: 21631230

Key  : Hypervisor.Flags.ValueHex
Value: 14a10fe

Key  : Hypervisor.Flags.VpAssistPage
Value: 1

Key  : Hypervisor.Flags.VsmAvailable
Value: 1

Key  : Hypervisor.RootFlags.AccessStats
Value: 1

Key  : Hypervisor.RootFlags.CrashdumpEnlightened
Value: 1

Key  : Hypervisor.RootFlags.CreateVirtualProcessor
Value: 1

Key  : Hypervisor.RootFlags.DisableHyperthreading
Value: 0

Key  : Hypervisor.RootFlags.HostTimelineSync
Value: 1

Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
Value: 0

Key  : Hypervisor.RootFlags.IsHyperV
Value: 1

Key  : Hypervisor.RootFlags.LivedumpEnlightened
Value: 1

Key  : Hypervisor.RootFlags.MapDeviceInterrupt
Value: 1

Key  : Hypervisor.RootFlags.MceEnlightened
Value: 1

Key  : Hypervisor.RootFlags.Nested
Value: 0

Key  : Hypervisor.RootFlags.StartLogicalProcessor
Value: 1

Key  : Hypervisor.RootFlags.Value
Value: 1015

Key  : Hypervisor.RootFlags.ValueHex
Value: 3f7

Key  : WER.OS.Branch
Value: ni\_release

Key  : WER.OS.Version
Value: 10.0.22621.1

BUGCHECK_CODE: 7e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8000c98ec0e

BUGCHECK_P3: fffff5845f096fc8

BUGCHECK_P4: fffff5845f0967e0

FILE_IN_CAB: 080823-2546-01.dmp

TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b

EXCEPTION_RECORD: fffff5845f096fc8 -- (.exr 0xfffff5845f096fc8) ExceptionAddress: fffff8000c98ec0e (nt!HvpGetCellPaged+0x000000000000005e) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000000 Parameter[1]: 0000000000001ff8 Attempt to read from address 0000000000001ff8

CONTEXT: fffff5845f0967e0 -- (.cxr 0xfffff5845f0967e0) rax=0000000000000001 rbx=00000000ffffffff rcx=00000000000005fd rdx=0000000000000000 rsi=fffff5845f097260 rdi=0000000000000fff rip=fffff8000c98ec0e rsp=fffff5845f097200 rbp=fffff5845f097270 r8=00000000000003ff r9=00000000000001ff r10=ffffa50a6a536000 r11=fffff5845f097108 r12=0000000003c855f8 r13=0000000000000000 r14=0000019ba348412c r15=00000000ffffffff iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206 nt!HvpGetCellPaged+0x5e: fffff8000c98ec0e 4a8b04c2 mov rax,qword ptr [rdx+r8*8] ds:002b:0000000000001ff8=???????????????? Resetting default scope

BLACKBOXNTFS: 1 (!blackboxntfs)

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: Registry

READ_ADDRESS: fffff8000cf1c468: Unable to get MiVisibleState Unable to get NonPagedPoolStart Unable to get NonPagedPoolEnd Unable to get PagedPoolStart Unable to get PagedPoolEnd unable to get nt!MmSpecialPagesInUse 0000000000001ff8

ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p 0x%p. %s.

EXCEPTION_CODE_STR: c0000005

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000000001ff8

EXCEPTION_STR: 0xc0000005

STACK_TEXT:
fffff5845f097200 fffff8000cc1974e : 0000000003c83128 ffffa50a6a536000 0000019ba348412c ffffa50a6a536000 : nt!HvpGetCellPaged+0x5e fffff5845f097230 fffff8000caf3eab : ffffa50a6d6af064 000000000000000d 0000000003c855f8 00000000ffffffff : nt!CmpRemoveSubKeyCellNoCellRef+0xa2 fffff5845f0972b0 fffff8000c883700 : 00000000ffffffff fffff5845f097398 fffff5845f097420 fffff58400000001 : nt!CmpCheckRegistry2+0x168bfb fffff5845f097350 fffff8000c97e38c : 0000000000000000 fffff58401590001 0000000000000000 ffffa50a00010000 : nt!CmCheckRegistry+0x178 fffff5845f097420 fffff8000c8d1a25 : fffff8000ce028b8 0000000000000001 ffff838401590001 fffff5845f0976f4 : nt!CmpCreateHive+0x474 fffff5845f097680 fffff8000ca3aae7 : ffff8384e709f540 0000000000000000 000000000000010f ffff8384e709f540 : nt!CmpInitHiveFromFile+0x229 fffff5845f097850 fffff8000c40dc67 : ffff8384f369a5c0 ffff8384f369a5c0 fffff8000ca3a9c0 0000000000000002 : nt!CmpLoadHiveThread+0x127 fffff5845f097b30 fffff8000c630854 : ffffe18157bd1180 ffff8384f369a5c0 fffff8000c40dc10 95cf95ce95cd95cc : nt!PspSystemThreadStartup+0x57 fffff5845f097b80 0000000000000000 : fffff5845f098000 fffff5845f091000 0000000000000000 0000000000000000 : nt!KiStartSystemThread+0x34

SYMBOL_NAME: nt!HvpGetCellPaged+5e

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.22621.1702

STACK_COMMAND: .cxr 0xfffff5845f0967e0 ; kb

BUCKET_ID_FUNC_OFFSET: 5e

FAILURE_BUCKET_ID: AV_nt!HvpGetCellPaged

OS_VERSION: 10.0.22621.1

BUILDLAB_STR: ni_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {90e145c3-c04a-f304-4254-781be6862dc9}

Followup: MachineOwner

Windows for home | Windows 11 | Install and upgrade

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

6 answers

Sort by: Most helpful
  1. David-M 113.6K Reputation points Independent Advisor
    2023-08-11T12:41:53+00:00

    This minidump also doesn't mention any drivers.

    You are right. The problem may be with the hardware. However, minidumps usually do not mention faulty hardware. Physical analysis of the equipment is necessary in this situation as some free tools that promise to identify problems are not 100% reliable.

    But before checking your hardware, I suggest doing one more test using the Driver Verifier utility to make sure it's not a driver causing this.

    The Driver Verifier utility is used to force the system to show the driver causing the problem.

    Before turning on Driver Verifier, I like to create a restore point just in case. I suggest doing the same.

    https://support.microsoft.com/en-us/windows/cre...

    Turn on Driver Verifier, let the system crash 3 times, then turn off Driver Verifier. Send the minidumps that the crashes created.

    See the article below for instructions.

    https://answers.microsoft.com/en-us/windows/for...

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-08-10T23:22:10+00:00

    Hi again! I updated bios to latest version and double check XMP its turned off. Just tried to update windows, after first reboot I got this BSOD again, then it rebooted again and update instalation continues and finaly its updated. Maybe its a problem of motherboard multi controller. When Windows trying to reach data its failing. I also checked RAM by MemTest and its okay, SSD`s are okay also. So I dont have any idea beside motherboard (asus rog strix b660-g gaming wifi). Here is new dump.zip
    Thank you for your help!

    Was this answer helpful?

    0 comments No comments
  3. David-M 113.6K Reputation points Independent Advisor
    2023-08-10T17:13:23+00:00

    Your minidumps do not mention any driver as causing the crashes.

    I suggest doing the following:

    • Go to the motherboard BIOS and check if you have any XMP/DOCP profile configured. Disable it, leave it as default.
    • Go to the support area of the Asus website, and search for the model of your motherboard. Then, download the latest chipset drivers, and install them.
    • I noticed that the motherboard BIOS is outdated. I suggest you update it by following Asus's instructions.

    Then see if the system will work stable.

    Let me know if the system will still behave weirdly even if it works stably. Maybe you will need to do another procedure.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-08-10T14:47:10+00:00

    Hello David. After many attemps of instalation I am managed to instal it but it isnt work properly apps closing and I cant install updates it going to this BSOD while updating so here is dump files ( on new clean windows )
    DUMP.zip

    Thank you in advance.

    Was this answer helpful?

    0 comments No comments
  5. David-M 113.6K Reputation points Independent Advisor
    2023-08-10T13:36:24+00:00

    Hi. I'm David, and I'm happy to help you.

    Send the minidump files.

    These files are in "C:\Windows\Minidump".

    Copy any files you have to your desktop and store them in a ZIP file. Then upload the ZIP file to the cloud (OneDrive, Google Drive, Dropbox, etc...), choose to share it, and get the link.

    Post the link to the ZIP file here so I can have a look.

    Was this answer helpful?

    0 comments No comments