Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Stop:0x0000007E sysaudio.sys


  • Please log in to reply
1 reply to this topic

#1 kochese

kochese

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 13 May 2009 - 08:08 AM

stop:0x0000007E( 0xC0000005, 0xAA4796FE, 0xF78D6B28,0xF78DD624)
sysaudio.sys address AA82C6FE base at AA826000 Datestamp 57E276C3

BSOD shows up after login, disabling plug and play in msconfig stops problem but I have no sound.
Appreciate any help, I've replaced sysaudio.sys. Problem showed up when I tried to reinstall WinTV which I have uninstalled along with Roxio 9. Problem persists.

Memory dump analysis follows:


Microsoft ® Windows Debugger Version 6.11.0001.404 X86
Copyright © Microsoft Corporation. All rights reserved.


Loading Dump File [C:\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp3_gdr.090206-1234
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0
Debug session time: Wed May 13 05:56:09.640 2009 (GMT-6)
System Uptime: 0 days 0:00:31.187
Loading Kernel Symbols
...............................................................
................................................................
........
Loading User Symbols

Loading unloaded module list
...
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 7E, {c0000005, aa3116fe, f78d6b28, f78d6824}

Probably caused by : sysaudio.sys ( sysaudio!CLogicalFilterNode::CreateAll+81 )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: aa3116fe, The address that the exception occurred at
Arg3: f78d6b28, Exception Record Address
Arg4: f78d6824, Context Record Address

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

FAULTING_IP:
sysaudio!CLogicalFilterNode::CreateAll+81
aa3116fe f3a7 repe cmps dword ptr [esi],dword ptr es:[edi]

EXCEPTION_RECORD: f78d6b28 -- (.exr 0xfffffffff78d6b28)
ExceptionAddress: aa3116fe (sysaudio!CLogicalFilterNode::CreateAll+0x00000081)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00000020
Attempt to read from address 00000020

CONTEXT: f78d6824 -- (.cxr 0xfffffffff78d6824)
eax=00000000 ebx=e28728d8 ecx=00000004 edx=00000000 esi=00000020 edi=aa30cae4
eip=aa3116fe esp=f78d6bf0 ebp=f78d6c10 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
sysaudio!CLogicalFilterNode::CreateAll+0x81:
aa3116fe f3a7 repe cmps dword ptr [esi],dword ptr es:[edi]
Resetting default scope

PROCESS_NAME: System

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

EXCEPTION_PARAMETER1: 00000000

EXCEPTION_PARAMETER2: 00000020

READ_ADDRESS: 00000020

FOLLOWUP_IP:
sysaudio!CLogicalFilterNode::CreateAll+81
aa3116fe f3a7 repe cmps dword ptr [esi],dword ptr es:[edi]

BUGCHECK_STR: 0x7E

DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE

LAST_CONTROL_TRANSFER: from aa312c53 to aa3116fe

STACK_TEXT:
f78d6c10 aa312c53 00000000 f78d6c8c 00000000 sysaudio!CLogicalFilterNode::CreateAll+0x81
f78d6c64 aa312a59 8975af90 00000000 e28cc760 sysaudio!CFilterNode::ProfileFilter+0x19c
f78d6d00 aa311a54 e28ba4a8 804e5638 89755f48 sysaudio!CFilterNode::Create+0x2d6
f78d6d3c aa312de5 e28ba4a8 00000000 f78d6d7c sysaudio!AddFilter+0xf2
f78d6d4c aa3110a6 e28ba4a8 00000000 897a5500 sysaudio!AddFilterWorker+0xf
f78d6d64 bad367ee 00000000 897a54e0 8056a5fc sysaudio!CQueueWorkListData::AsyncWorker+0x20
f78d6d7c 804e23b5 897a54e0 00000000 89ee9b30 ks!WorkerThread+0x45
f78d6dac 80575723 897a54e0 00000000 00000000 nt!ExpWorkerThread+0xef
f78d6ddc 804ec6d9 804e22f1 00000001 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: sysaudio!CLogicalFilterNode::CreateAll+81

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: sysaudio

IMAGE_NAME: sysaudio.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 47e276c3

STACK_COMMAND: .cxr 0xfffffffff78d6824 ; kb

FAILURE_BUCKET_ID: 0x7E_sysaudio!CLogicalFilterNode::CreateAll+81

BUCKET_ID: 0x7E_sysaudio!CLogicalFilterNode::CreateAll+81

Followup: MachineOwner
---------

BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 55,561 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:05:43 PM

Posted 13 May 2009 - 02:28 PM

Basic reference at http://support.microsoft.com/kb/330182

http://www.file.net/process/sysaudio.sys.html

If the file is the right size and in the right location...and you've already replaced it (removed old, installed new)...then I have no clue.

Of course, it could be malware masquerading as a legit file.

http://www.google.com/search?hl=en&q=s...mp;aq=f&oq=

Louis




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users