System error 1003

By RigSir
Oct 12, 2008
  1. Okay so i just got a second BSOD and i dont know why >.<.. in the log it say System error 1003

    Im running xp sp2

    this is my hardware:
    Asus P5N-D, nForce-750i SLI, Socket-775
    Antec Performance P182 Miditower
    Corsair Powersupply 650W Black,ATX/EPS
    Intel Core? 2 Duo E8600 3,33GHz
    OCZ DDR2 PC8500 4096MB KIT, Reaper HPC
    Samsung SpinPoint F1 750GB SATA2
    Sapphire Radeon HD 4870 1GB GDDR5
    Zalman CNPS9700LED Ultra Quiet CPU

    this is what the dump file said

    Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
    Copyright (c) Microsoft Corporation. All rights reserved.

    Loading Dump File [C:\WINDOWS\Minidump\Mini101308-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: C:\WINDOWS\system;C:\WINDOWS\Symbols
    Executable search path is:
    Unable to load image ntoskrnl.exe, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for ntoskrnl.exe
    Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055c700
    Debug session time: Mon Oct 13 11:35:55.968 2008 (GMT+2)
    System Uptime: 0 days 1:00:32.700
    Unable to load image ntoskrnl.exe, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for ntoskrnl.exe
    Loading Kernel Symbols
    Loading User Symbols
    Loading unloaded module list
    * *
    * Bugcheck Analysis *
    * *

    Use !analyze -v to get detailed debugging information.

    BugCheck 10000050, {e44fc000, 0, ba11daf1, 1}

    Could not read faulting driver name
    Probably caused by : ntoskrnl.exe ( nt!RtlIpv4StringToAddressA+fd )

    Followup: MachineOwner

    1: kd> !analyze -v
    * *
    * Bugcheck Analysis *
    * *

    Invalid system memory was referenced. This cannot be protected by try-except,
    it must be protected by a Probe. Typically the address is just plain bad or it
    is pointing at freed memory.
    Arg1: e44fc000, memory referenced.
    Arg2: 00000000, value 0 = read operation, 1 = write operation.
    Arg3: ba11daf1, If non-zero, the instruction address which referenced the bad memory
    Arg4: 00000001, (reserved)

    Debugging Details:

    Could not read faulting driver name

    READ_ADDRESS: e44fc000

    ba11daf1 66833c1000 cmp word ptr [eax+edx],0




    BUGCHECK_STR: 0x50

    PROCESS_NAME: System

    LAST_CONTROL_TRANSFER: from ba11c46b to ba11daf1

    WARNING: Frame IP not in any known module. Following frames may be wrong.
    ba4fb7cc ba11c46b e44fbffe 8a433b20 8a433b08 0xba11daf1
    ba4fb7f4 ba11c7d5 8a450848 e44fbfd0 00000030 0xba11c46b
    ba4fb874 ba11c8a2 e44fbfd0 00000030 00000002 0xba11c7d5
    ba4fb8a4 8054060c ba4fb9b4 000f003f ba4fb954 0xba11c8a2
    ba4fb8b8 804ff9fd badb0d00 ba4fb930 badb0d00 nt!RtlIpv4StringToAddressA+0xfd
    ba4fb940 80589bd1 ba4fb9b4 000f003f ba4fb954 nt!RtlpStatusTable+0x795
    ba4fb96c 8058a063 ba4fb9b4 80001270 ba4fb990 nt!MmCreatePeb+0x1d2
    ba4fb9a8 8059bbc5 80001270 80000c5c 000f003f nt!NtOpenKeyedEvent+0x20
    ba4fba04 8059bd45 ba4fba34 88b622c4 8a457290 nt!MmExtendSection+0x258
    ba4fba2c 804eeeb1 00000000 88b62230 ba4fbaac nt!RtlPrefixUnicodeString+0x2e
    ba4fba68 804f6b05 8a492f10 ba4fba88 8a492eb8 nt!MiAddViewsForSection+0x38
    ba4fbab0 8058db39 00000000 8a492f10 00000001 nt!CcMapAndCopy+0x2fe
    ba4fbac8 80590f9b 8a492dd8 00000001 88beb350 nt!PfVerifyTraceBuffer+0x10b
    ba4fbd20 805913da 8a492dd8 00000001 00000000 nt!HvFreeCell+0x2b
    ba4fbd54 804f669f 00000003 8055a5c0 8056375c nt!HvpFindFreeCellInThisViewWindow+0x16
    ba4fbd7c 80537757 00000000 00000000 8a46d640 nt!CcMapAndCopy+0x3e7
    ba4fbdac 805ce794 00000000 00000000 00000000 nt!MiExtendPagingFileMaximum+0x8f
    ba4fbddc 805450ce 80537668 00000001 00000000 nt!CmpInitializeHive+0x55
    ba4fbe8c 00000000 00000000 00000000 00000000 nt!WmiTraceMessageVa+0x35


    8054060c ?? ???


    SYMBOL_NAME: nt!RtlIpv4StringToAddressA+fd

    FOLLOWUP_NAME: MachineOwner


    IMAGE_NAME: ntoskrnl.exe


    FAILURE_BUCKET_ID: 0x50_nt!RtlIpv4StringToAddressA+fd

    BUCKET_ID: 0x50_nt!RtlIpv4StringToAddressA+fd

    Followup: MachineOwner

    1: kd> lmvm nt
    start end module name
    804d7000 806e2000 nt M (pdb symbols) C:\WINDOWS\Symbols\exe\ntoskrnl.pdb
    Loaded symbol image file: ntoskrnl.exe
    Image path: ntoskrnl.exe
    Image name: ntoskrnl.exe
    Timestamp: Wed Aug 04 07:58:37 2004 (41107B0D)
    CheckSum: 001F0824
    ImageSize: 0020B000
    Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0

    Is there a way to solve this problem?
  2. BillAllen55

    BillAllen55 TS Maniac Posts: 368

    Dealing with NTOSKRNL.EXE

    I have put on the website 'SaveFile' a document that explains how to deal with the NTOSKRNL.EXE missing or corrupted issue. If you will follow this website

    That will take you directly to a page that has been uploaded with instructions on how to deal with referenced issue. You may have to log on (free) to arrive at this page.
    Please let me know how things turn out.
  3. RigSir

    RigSir TS Rookie Topic Starter

    i guess its missing, but im using a false xp and i am able to a recovery but im not able to expand it, i press R and it recovers everything, does that work too?
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...