Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ks.sys BSOD when trying to record voice


  • Please log in to reply
5 replies to this topic

#1 Tetti

Tetti

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 08 August 2011 - 02:43 PM

I was about to try recording my voice on a website helping people learn other languages. I instantly got a BSOD citing ks.sys when I clicked on the button to record my voice.

Here is the info I received from the crash dump debugger. I'll try and provide any additional info if necessary. Thanks in advance for your help!



Microsoft ® Windows Debugger Version 6.12.0002.633 X86
Copyright © Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Documents and Settings\Kirk Rupnik\Desktop\Mini080611-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp3_gdr.101209-1647
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Sat Aug 6 16:21:22.828 2011 (UTC - 4:00)
System Uptime: 6 days 4:07:23.533
Loading Kernel Symbols
...............................................................
................................................................
....
Loading User Symbols
Loading unloaded module list
..................................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 100000BE, {b7296278, 1bb43121, b2432428, b}

Unable to load image cmdguard.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for cmdguard.sys
*** ERROR: Module load completed but symbols could not be loaded for cmdguard.sys
Probably caused by : memory_corruption

Followup: memory_corruption
---------

3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: b7296278, Virtual address for the attempted write.
Arg2: 1bb43121, PTE contents.
Arg3: b2432428, (reserved)
Arg4: 0000000b, (reserved)

Debugging Details:
------------------


CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: CODE_CORRUPTION

BUGCHECK_STR: 0xBE

PROCESS_NAME: chrome.exe

LAST_CONTROL_TRANSFER: from b7292fdb to b72a06b5

STACK_TEXT:
b2432498 b7292fdb 897a1648 894cb008 894cb008 ks!CKsFilter::DispatchCreatePin+0x5
b24324bc b72974d4 897a1648 00000000 894cb018 ks!DispatchCreate+0xc7
b24324d8 804ef19f 897a1648 894cb008 894cb008 ks!CKsDevice::DispatchCreate+0x8a
b24324e8 80583220 89959cd8 8b0a9d20 b24326b8 nt!IopfCallDriver+0x31
b24325c8 80583642 897a1648 00000000 89efd528 nt!IopParseDevice+0xa12
b2432600 805bf065 89959cd8 00000000 89efd528 nt!IopParseFile+0x46
b2432678 805bba14 80000930 b24326b8 00000240 nt!ObpLookupObjectName+0x119
b24326cc 80576057 00000000 00000000 fbb03000 nt!ObOpenObjectByName+0xea
b2432748 805769ce e5d37ec0 40000000 b24327f0 nt!IopCreateFile+0x407
b24327a4 b72934ee e5d37ec0 40000000 b24327f0 nt!IoCreateFile+0x8e
b2432820 b7292a77 80000930 b7292a80 e5dbf4a8 ks!KsiCreateObjectType+0xd6
b2432840 b27b2fdf 80000930 e5dbf4a8 40000200 ks!KsCreatePin+0x33
b2432864 b27b3726 e6230734 e334d0b8 e409de80 sysaudio!CPinNodeInstance::Create+0x6b
b24328a0 b27b2454 89a93470 e6230734 00000001 sysaudio!CConnectNodeInstance::Connect+0xd9
b24328bc b27ba851 00000000 89a933f0 89a93470 sysaudio!CStartNodeInstance::Connect+0x52
b24328f4 b27b8dd4 e242e3a8 89a933f0 89a93470 sysaudio!CStartNodeInstance::IntelligentConnect+0x79
b2432918 b27b1574 e5fea9f0 e411f618 89a933f0 sysaudio!CStartNodeInstance::Create+0xe1
b2432948 b27b21e7 c0000010 89a933f0 00000000 sysaudio!CPinInstance::PinDispatchCreateKP+0xa8
b2432964 b27b1718 8977e2e0 b27b14e6 89a933f0 sysaudio!CInstance::DispatchCreate+0x63
b2432998 b7292fdb 89b0da88 8977e2e0 8977e2f0 sysaudio!CPinInstance::PinDispatchCreate+0xc1
b24329bc 804ef19f 89b0da88 00000000 8977e2e0 ks!DispatchCreate+0xc7
b24329cc 80583220 894c4cc8 897d0338 b2432b9c nt!IopfCallDriver+0x31
b2432aac 80583642 89b0da88 00000000 89586050 nt!IopParseDevice+0xa12
b2432ae4 805bf065 894c4cc8 00000000 89586050 nt!IopParseFile+0x46
b2432b5c 805bba14 00002864 b2432b9c 00000040 nt!ObpLookupObjectName+0x119
b2432bb0 80576057 00000000 00000000 a84f8d01 nt!ObOpenObjectByName+0xea
b2432c2c 805769ce 0012ec68 80000000 0012ebe4 nt!IopCreateFile+0x407
b2432c88 805790d8 0012ec68 80000000 0012ebe4 nt!IoCreateFile+0x8e
b2432cc8 b3cb36e6 0012ec68 80000000 0012ebe4 nt!NtCreateFile+0x30
WARNING: Stack unwind information not available. Following frames may be wrong.
b2432d30 8054167c 0012ec68 80000000 0012ebe4 cmdguard+0xa6e6
b2432d30 7c90e514 0012ec68 80000000 0012ebe4 nt!KiFastCallEntry+0xfc
0012ec10 00000000 00000000 00000000 00000000 0x7c90e514


STACK_COMMAND: kb

CHKIMG_EXTENSION: !chkimg -lo 50 -d !ks
b72a0000-b72a002c 45 bytes - ks!CKsDevice::DispatchSystemPowerIrp+c8
[ 03 00 8b 41 60 83 e8 24:00 02 06 00 c2 06 00 00 ]
b72a002e-b72a005b 46 bytes - ks!CKsDevice::DispatchSystemPowerIrp+f6 (+0x2e)
[ 11 29 b7 32 d2 8b cf ff:72 65 6e 64 73 20 49 6e ]
b72a005f-b72a0089 43 bytes - ks!CKsDevice::DispatchDeviceSetPowerIrp+16 (+0x31)
[ 3b 46 0c 57 7e 3d 80 4e:00 00 00 06 05 06 4d 53 ]
b72a008b-b72a00cc 66 bytes - ks!CKsDevice::DispatchDeviceSetPowerIrp+42 (+0x2c)
[ c6 40 03 e0 ff 73 7c ff:00 54 6f 20 42 65 20 46 ]
b72a00ce-b72a0136 105 bytes - ks!CKsDevice::DispatchDeviceSetPowerIrp+85 (+0x43)
[ 00 8b bb 80 01 00 00 89:4e 46 37 35 30 2d 47 35 ]
b72a0138-b72a013e 7 bytes - ks!CKsDevice::DispatchDeviceSetPowerIrp+ef (+0x6a)
[ 53 ff 50 18 83 66 18:03 00 00 00 00 00 01 ]
b72a0140-b72a0203 196 bytes - ks!CKsDevice::DispatchDeviceSetPowerIrp+f7 (+0x08)
[ 56 ff 15 74 11 29 b7 fe:00 4d 53 49 00 31 2e 30 ]
b72a0205-b72a025a 86 bytes - ks!CKsDevice::DispatchPower+a1 (+0xc5)
[ 8b ce 75 07 e8 2a fd ff:20 20 20 20 20 20 20 20 ]
b72a025c-b72a02a0 69 bytes - ks!CKsFilterFactory::NonDelegatedQueryInterface+28 (+0x57)
[ 50 ff 51 04 eb 51 68 60:10 00 10 00 00 05 05 05 ]
b72a02a2-b72a02c7 38 bytes - ks!CKsFilterFactory::NonDelegatedQueryInterface+6e (+0x46)
[ 74 0e ff 75 10 8b 46 44:00 08 09 09 00 01 00 02 ]
b72a02c9-b72a02ed 37 bytes - ks!_GUID_3ef6ee43_0d41_11d2_beda_00c04f8ef457+d (+0x27)
[ 8e f4 57 90 90 90 90 90:4d 31 00 43 4f 4d 00 00 ]
b72a02ef-b72a0350 98 bytes - ks!CKsFilterFactory::Sleep+1e (+0x26)
[ 00 90 90 90 90 90 8b ff:09 0c 00 01 00 02 1f 1d ]
b72a0352-b72a0357 6 bytes - ks!CKsFilterFactory::UpdateCacheData+3a (+0x63)
[ 8b 43 24 83 65 f8:00 08 09 10 00 01 ]
b72a0359-b72a0369 17 bytes - ks!CKsFilterFactory::UpdateCacheData+41 (+0x07)
[ 89 45 fc eb 03 8b 7d ec:02 12 10 4c 41 4e 5f 55 ]
b72a036b-b72a036f 5 bytes - ks!CKsFilterFactory::UpdateCacheData+53 (+0x12)
[ 00 00 81 c7 a8:08 09 11 00 01 ]
b72a0371-b72a03e2 114 bytes - ks!CKsFilterFactory::UpdateCacheData+59 (+0x06)
[ 00 00 8b 37 eb 14 ff 75:02 12 10 4c 41 4e 5f 55 ]
b72a03e4-b72a03e8 5 bytes - ks!CKsFilterFactory::UpdateCacheData+cc (+0x73)
[ 53 57 e8 c9 1a:17 00 01 ff 00 ]
b72a03ea-b72a03fe 21 bytes - ks!CKsFilterFactory::UpdateCacheData+d2 (+0x06)
[ 00 8b f0 83 45 fc 10 ff:ff 4a 43 49 31 00 00 08 ]
b72a0401-b72a041e 30 bytes - ks!CKsFilterFactory::UpdateCacheData+ea (+0x17)
[ c0 83 7d 08 00 74 0b 6a:08 09 19 00 01 ff 00 00 ]
b72a0420-b72a0422 3 bytes - ks!CKsFilterFactory::ItemFreeCallback+4e (+0x1f)
[ 6c 00 74:08 09 1b ]
b72a0424-b72a0426 3 bytes - ks!CKsFilterFactory::ItemFreeCallback+52 (+0x04)
[ 65 00 72:01 ff 00 ]
b72a0428-b72a042c 5 bytes - ks!CKsFilterFactory::ItemFreeCallback+56 (+0x04)
[ 44 00 61 00 74:ff 4a 46 50 32 ]
b72a042e-b72a0453 38 bytes - ks!CKsFilterFactory::ItemFreeCallback+5c (+0x06)
[ 61 00 00 00 cc cc cc cc:00 08 09 1c 00 01 17 00 ]
b72a0455-b72a04c2 110 bytes - ks!KsFilterFactorySetDeviceClassesState+18 (+0x27)
[ 90 90 90 90 90 8b ff 55:20 53 41 54 41 31 00 00 ]
b72a04c4-b72a05c9 262 bytes - ks!KsFilterFactoryAddCreateItem+2d (+0x6f)
[ 90 90 90 90 90 8b ff 55:00 13 0f 24 00 00 00 00 ]
b72a05cc-b72a05d4 9 bytes - ks!CKsFilter::NonDelegatedQueryInterface+92 (+0x108)
[ 8b d8 85 db 7d 14 83 7e:40 00 00 00 01 00 01 02 ]
b72a05d6-b72a0619 68 bytes - ks!CKsFilter::NonDelegatedQueryInterface+9c (+0x0a)
[ 74 0e ff 75 10 8b 46 44:00 00 00 03 04 05 06 00 ]
b72a061b-b72a0621 7 bytes - ks!CKsFilter::KsProperty+16 (+0x45)
[ 0c 68 03 00 2f 00 6a:6d 62 65 72 30 33 00 ]
b72a0623-b72a0626 4 bytes - ks!CKsFilter::KsProperty+1e (+0x08)
[ ff b0 48 01:7e 13 2a 00 ]
b72a0629-b72a0658 48 bytes - ks!CKsFilter::KsProperty+24 (+0x06)
[ e8 ef 24 ff ff 5d c2 18:00 00 00 00 00 00 29 00 ]
b72a065a-b72a068a 49 bytes - ks!CKsFilter::KsMethod+23 (+0x31)
[ 00 e8 bd 24 ff ff 5d c2:42 41 4e 4b 34 00 4d 61 ]
b72a068c-b72a0696 11 bytes - ks!CKsFilter::KsEvent+23 (+0x32)
[ 50 ff 75 18 ff 75 14 68:61 72 74 4e 75 6d 62 65 ]
b72a0698-b72a069f 8 bytes - ks!CKsFilter::KsEvent+2f (+0x0c)
[ 50 8b 45 08 ff b0 48 01:00 7e 13 2c 00 00 00 00 ]
b72a06a2-b72a06a9 8 bytes - ks!CKsFilter::KsEvent+39 (+0x0a)
[ e8 76 24 ff ff 5d c2 18:00 00 00 2b 00 24 00 01 ]
b72a06ab-b72a070a 96 bytes - ks!CKsFilter::KsEvent+42 (+0x09)
[ 90 90 90 90 90 8b ff 55:00 00 00 20 14 2d 00 00 ]
b72a070e-b72a0716 9 bytes - ks!CKsFilter::DispatchCreatePin+5e (+0x63)
[ 8b 10 3b 51 3c 72 07 bf:00 00 00 00 00 00 00 00 ]
b72a0719-b72a071f 7 bytes - ks!CKsFilter::DispatchCreatePin+69 (+0x0b)
[ c0 eb 2b 50 ff b6 9c:00 00 00 00 00 00 00 ]
b72a0723-b72a0728 6 bytes - ks!CKsFilter::DispatchCreatePin+73 (+0x0a)
[ 83 c0 08 ff b6 98:00 00 00 00 00 00 ]
b72a072c-b72a0742 23 bytes - ks!CKsFilter::DispatchCreatePin+7c (+0x09)
[ ff 70 08 51 8b 4d f8 83:00 00 00 00 00 00 00 00 ]
b72a0745-b72a0748 4 bytes - ks!CKsFilter::DispatchCreatePin+95 (+0x19)
[ 8b f8 5b 6a:00 00 00 00 ]
b72a074a-b72a074c 3 bytes - ks!CKsFilter::DispatchCreatePin+9a (+0x05)
[ 81 c6 a8:00 00 00 ]
b72a0750-b72a075a 11 bytes - ks!CKsFilter::DispatchCreatePin+a0 (+0x06)
[ 56 ff 15 3c 11 29 b7 81:00 00 00 00 00 00 00 00 ]
b72a075d-b72a0773 23 bytes - ks!CKsFilter::DispatchCreatePin+ad (+0x0d)
[ 74 0e 8b 4d 0c 32 d2 89:00 00 00 00 00 00 00 00 ]
b72a0775-b72a078e 26 bytes - ks!CKsFilter::DispatchCreatePin+c5 (+0x18)
[ 90 90 90 90 90 8b ff 55:00 00 00 00 00 00 00 00 ]
b72a0792-b72a0796 5 bytes - ks!CKsFilter::DispatchCreateNode+18 (+0x1d)
[ 52 ff 70 7c 6a:00 00 00 00 00 ]
b72a0798-b72a07a2 11 bytes - ks!CKsFilter::DispatchCreateNode+1e (+0x06)
[ 56 50 ff 51 14 8b f8 81:00 00 00 00 00 00 00 00 ]
b72a07a5-b72a07ba 22 bytes - ks!CKsFilter::DispatchCreateNode+2b (+0x0d)
[ 74 0d 32 d2 8b ce 89 7e:00 00 00 00 00 00 00 00 ]
b72a07bc-b72a07d8 29 bytes - ks!CKsFilter::DispatchCreateNode+42 (+0x17)
[ 90 90 90 90 90 8b ff 55:00 00 00 00 00 00 00 00 ]
b72a07dc-b72a07eb 16 bytes - ks!CKsFilter::CreateNode+1b (+0x20)
[ ff 75 0c e8 f7 df ff ff:00 00 00 00 00 00 00 00 ]
b72a07ee-b72a07ef 2 bytes - ks!CKsFilter::CreateNode+2d (+0x12)
[ c0 6a:00 00 ]
WARNING: !chkimg output was truncated to 50 lines. Invoke !chkimg without '-lo [num_lines]' to view entire output.
3878 errors : !ks (b72a0000-b72a0fff)

MODULE_NAME: memory_corruption

IMAGE_NAME: memory_corruption

FOLLOWUP_NAME: memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP: 0

MEMORY_CORRUPTOR: LARGE_4096

FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE_4096

BUCKET_ID: MEMORY_CORRUPTION_LARGE_4096

Followup: memory_corruption
---------

BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 55,726 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:03:43 PM

Posted 08 August 2011 - 03:53 PM

What is the website?

Exact wording of the onscreen error message?

Louis

#3 abauw

abauw

  • Members
  • 951 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kebun Kelapa
  • Local time:03:43 AM

Posted 08 August 2011 - 04:00 PM

Does that BSOD happen every time you want to record voice in Windows? try using Windows Sound Recorder and see does that BSOD happen again or not?

:guitar: Take me to a place where time is frozen
You don't have to close your eyes to dream :busy:
You can find escape inside this moment :smash:
And I will follow  :whistle:


#4 Tetti

Tetti
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 08 August 2011 - 04:44 PM

What is the website?

Exact wording of the onscreen error message?

Louis

The website is livemocha.com
(specifically http://www.livemocha.com/submissions/review/22457280?source=sub_review_request_email&utm_term=rev_submssn_reqet&utm_content=en&require_login=true&utm_medium=email&utm_campaign=Aug8-2011&utm_source=livemocha) but you probably won't be able to see the button without an account, etc.

This is what I C/P from BlueScreenView from the crashdump file.


==================================================
Dump File : Mini080611-01.dmp
Crash Time : 8/6/2011 4:22:40 PM
Bug Check String : ATTEMPTED_WRITE_TO_READONLY_MEMORY
Bug Check Code : 0x100000be
Parameter 1 : 0xb7296278
Parameter 2 : 0x1bb43121
Parameter 3 : 0xb2432428
Parameter 4 : 0x0000000b
Caused By Driver : ks.sys
Caused By Address : ks.sys+176b5
File Description : Kernel CSA Library
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.3.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Crash Address : ks.sys+176b5
Stack Address 1 : ks.sys+e4d4
Stack Address 2 : ntoskrnl.exe+1819f
Stack Address 3 : ntoskrnl.exe+ac642
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini080611-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 2600
Dump File Size : 98,304
==================================================

#5 Tetti

Tetti
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 08 August 2011 - 05:03 PM

Does that BSOD happen every time you want to record voice in Windows? try using Windows Sound Recorder and see does that BSOD happen again or not?


I tried doing the action again and it worked without problem this time. I thought this incident might be a systemic problem I have with this computer since I sometimes get other crashes pointing to ks.sys, usually on startup. My other searches seemed to point to a bad driver somewhere and I hoped this problem might help ferret it out.

#6 abauw

abauw

  • Members
  • 951 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kebun Kelapa
  • Local time:03:43 AM

Posted 09 August 2011 - 05:12 AM

Does only one crashdump file that shown up on BlueScreenView?
If yes, maybe it's only a random error.
If not, please write it on your next post.

:guitar: Take me to a place where time is frozen
You don't have to close your eyes to dream :busy:
You can find escape inside this moment :smash:
And I will follow  :whistle:





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users