NTFS_FILE_SYSTEM

Code: 0x24 (36)

As HRESULT:As NTSTATUS:

Parameters

ParameterDescription
1Specifies source file and line number information. The high 16 bits (the first four hexadecimal digits after the "0x") identify the source file by its identifier number. The low 16 bits identify the source line in the file where the bug check occurred.
2If NtfsExceptionFilter is on the stack, this parameter specifies the address of the exception record.
3If NtfsExceptionFilter is on the stack, this parameter specifies the address of the context record.
4Reserved

Description

The NTFS_FILE_SYSTEM bug check has a value of 0x00000024. This indicates a problem occurred in ntfs.sys, the driver file that allows the system to read and write to NTFS drives.

Important

This article is for programmers. If you're a customer who has received a blue screen error code while using your computer, see Troubleshoot blue screen errors.

Cause

One possible cause of this bug check is disk corruption. Corruption in the NTFS file system or bad blocks (sectors) on the hard disk can induce this error. Corrupted hard drive (SATA/IDE) drivers can also adversely affect the system's ability to read and write to disk, thus causing the error.

Resolution

To debug this problem: Use the .cxr (Display Context Record) command with Parameter 3, and then use kb (Display Stack Backtrace).

To resolve a disk corruption problem:

In the past, another possible cause of this stop code is depletion of nonpaged pool memory. If the nonpaged pool memory is completely depleted, this error can stop the system. However, during the indexing process, if the amount of available nonpaged pool memory is very low, another kernel-mode driver requiring nonpaged pool memory can also trigger this error.

Article text from the Windows driver documentation (opens in a new tab), by Microsoft, under the CC BY 4.0 (opens in a new tab) licence.

Associated Modules

ModuleCodeFound inDescription
EventCreate.exe0x2478.11011%1
KernelBase.dll0x2478.1Too many files opened for sharing.
NetTCPIP.dll0x241011Both IP addresses must be from the same address family.
VSSVC.exe0x241011Volume Shadow Copy Service error: The MSXML classes are not registered. This may be caused due to a setup failure or as a result of an application's installer or uninstaller. %1
cipher.exe0x2478.11011Please retype the password to confirm:
compact.exe0x241011The system is not in the Compact state but may become compact as needed.
dssec.dll0x2478.11011Change domain master
ehepgres.dll0x247%1
hvloader.dll0x2411Hypervisor launch failed; the image %1 failed code integrity checks, and cannot be used.
hvservice.sys0x2410Hypervisor launch failed; the image %1 failed code integrity checks, and cannot be used.
kernel32.dll0x2478.11011Too many files opened for sharing.
microsoft-windows-kernel-processor-power-events.dll0x241011Throttle power management features on Hyper-V logical processor %2 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
msprivs.dll0x241011Obtain an impersonation token for another user in the same session
nslookup.exe0x2478.11011server =
powershell.exe0x248.11011Warning: Windows PowerShell was started with CLR version "%1!ls!". This CLR version has not been tested with Windows PowerShell and might not operate properly. For more information about supported versions of the CLR, see http://go.microsoft.com/fwlink/?LinkId=215538.
reagentc.exe0x248.11011%1: Windows RE cannot be enabled on a volume with BitLocker Drive Encryption enabled.
sc.exe0x2478.11011Name = %1
w32time.dll0x241011The time service has not synchronized the system time for the last %1 seconds because none of the time service providers provided a usable time stamp. The time service will not update the local system time until it is able to synchronize with a time source. If the local system is configured to act as a time server for clients, it will stop advertising as a time source to clients after %2 seconds. The time service will continue to retry and sync time with its time sources. Check system event log for other W32time events for more details. Run 'w32tm /resync' to force an instant time synchronization. You can control the frequency of the time source rediscovery using ClockHoldoverPeriod W32time config setting. Modify the EventLogFlags W32time config setting if you wish to disable this message.
webservices.dll0x2478.11011There were two or more headers present in the message when only one was expected.
wecutil.exe0x2478.11011Root node of config file is not Subscription or in correct namespace.
wevtutil.exe0x2478.11011LCID %1!s! cannot be found.
wfascim.dll0x241011RemoteAddress must be specified.
win32k.sys0x2478.1Menu
win32kbase.sys0x241011Menu
24 entries