NTFS_FILE_SYSTEM
Code: 0x24 (36)
As HRESULT:- S: 0 (Success)
- C: 0 (Microsoft-defined)
- N: 0 (Not an NTSTATUS value)
- Facility: 0x000 (FACILITY_NULL: Default)
- Code: 0x0024 (36)
- Sev: 0 (STATUS_SEVERITY_SUCCESS)
- C: 0 (Microsoft-defined)
- Facility: 0x000 (Default)
- Code: 0x0024 (36)
Parameters
| Parameter | Description |
|---|---|
| 1 | Specifies source file and line number information. The high 16 bits (the first four hexadecimal digits after the "0x") identify the source file by its identifier number. The low 16 bits identify the source line in the file where the bug check occurred. |
| 2 | If NtfsExceptionFilter is on the stack, this parameter specifies the address of the exception record. |
| 3 | If NtfsExceptionFilter is on the stack, this parameter specifies the address of the context record. |
| 4 | Reserved |
Description
The NTFS_FILE_SYSTEM bug check has a value of 0x00000024. This indicates a problem occurred in ntfs.sys, the driver file that allows the system to read and write to NTFS drives.
Important
This article is for programmers. If you're a customer who has received a blue screen error code while using your computer, see Troubleshoot blue screen errors.
Cause
One possible cause of this bug check is disk corruption. Corruption in the NTFS file system or bad blocks (sectors) on the hard disk can induce this error. Corrupted hard drive (SATA/IDE) drivers can also adversely affect the system's ability to read and write to disk, thus causing the error.
Resolution
To debug this problem: Use the .cxr (Display Context Record) command with Parameter 3, and then use kb (Display Stack Backtrace).
To resolve a disk corruption problem:
- Check Event Viewer for error messages related to the hard drive appearing in the System Log that might help pinpoint the device or driver that is causing the error.
- Try disabling any virus scanners, backup programs, or disk defragmenter tools that continually monitor the system.
- You should also run hardware diagnostics supplied by the system manufacturer related to the storage sub system.
- Use the scan disk utility to confirm that there are no file system errors. Select and hold (or right-click) on the drive you want to scan and select Properties. Select Tools. Select the Check now button.
- Confirm that there is sufficient free space on the hard drive. The operating system and some applications require sufficient free space to create swap files and for other functions. Based on the system configuration, the exact requirement varies, but it is normally a good idea to have 10% to 15% free space available.
Use the System File Checker tool to repair missing or corrupted system files. The System File Checker is a utility in Windows that allows users to scan for corruptions in Windows system files and restore corrupted files. Use the following command to run the System File Checker tool (SFC.exe).
SFC /scannowFor more information, see Use the System File Checker tool to repair missing or corrupted system files.
Driver Verifier
Driver Verifier is a tool that runs in real time to examine the behavior of drivers. If it see errors in the execution of driver code, it proactively creates an exception to allow that part of the driver code to be further scrutinized. The driver verifier manager is built into Windows and is available on all Windows PCs. To start the driver verifier manager, type Verifier at a command prompt. You can configure which drivers you would like to verify. The code that verifies drivers adds overhead as it runs, so try and verify the smallest number of drivers as possible. For more information, see Driver Verifier.
In the past, another possible cause of this stop code is depletion of nonpaged pool memory. If the nonpaged pool memory is completely depleted, this error can stop the system. However, during the indexing process, if the amount of available nonpaged pool memory is very low, another kernel-mode driver requiring nonpaged pool memory can also trigger this error.
Article text from the Windows driver documentation (opens in a new tab), by Microsoft, under the CC BY 4.0 (opens in a new tab) licence.
Associated Modules
| Module | Code | Found in | Description |
|---|---|---|---|
| EventCreate.exe | 0x24 | 78.11011 | %1 |
| KernelBase.dll | 0x24 | 78.1 | Too many files opened for sharing. |
| NetTCPIP.dll | 0x24 | 1011 | Both IP addresses must be from the same address family. |
| VSSVC.exe | 0x24 | 1011 | Volume Shadow Copy Service error: The MSXML classes are not registered. This may be caused due to a setup failure or as a result of an application's installer or uninstaller. %1 |
| cipher.exe | 0x24 | 78.11011 | Please retype the password to confirm: |
| compact.exe | 0x24 | 1011 | The system is not in the Compact state but may become compact as needed. |
| dssec.dll | 0x24 | 78.11011 | Change domain master |
| ehepgres.dll | 0x24 | 7 | %1 |
| hvloader.dll | 0x24 | 11 | Hypervisor launch failed; the image %1 failed code integrity checks, and cannot be used. |
| hvservice.sys | 0x24 | 10 | Hypervisor launch failed; the image %1 failed code integrity checks, and cannot be used. |
| kernel32.dll | 0x24 | 78.11011 | Too many files opened for sharing. |
| microsoft-windows-kernel-processor-power-events.dll | 0x24 | 1011 | Throttle power management features on Hyper-V logical processor %2 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware. |
| msprivs.dll | 0x24 | 1011 | Obtain an impersonation token for another user in the same session |
| nslookup.exe | 0x24 | 78.11011 | server = |
| powershell.exe | 0x24 | 8.11011 | Warning: Windows PowerShell was started with CLR version "%1!ls!". This CLR version has not been tested with Windows PowerShell and might not operate properly. For more information about supported versions of the CLR, see http://go.microsoft.com/fwlink/?LinkId=215538. |
| reagentc.exe | 0x24 | 8.11011 | %1: Windows RE cannot be enabled on a volume with BitLocker Drive Encryption enabled. |
| sc.exe | 0x24 | 78.11011 | Name = %1 |
| w32time.dll | 0x24 | 1011 | The time service has not synchronized the system time for the last %1 seconds because none of the time service providers provided a usable time stamp. The time service will not update the local system time until it is able to synchronize with a time source. If the local system is configured to act as a time server for clients, it will stop advertising as a time source to clients after %2 seconds. The time service will continue to retry and sync time with its time sources. Check system event log for other W32time events for more details. Run 'w32tm /resync' to force an instant time synchronization. You can control the frequency of the time source rediscovery using ClockHoldoverPeriod W32time config setting. Modify the EventLogFlags W32time config setting if you wish to disable this message. |
| webservices.dll | 0x24 | 78.11011 | There were two or more headers present in the message when only one was expected. |
| wecutil.exe | 0x24 | 78.11011 | Root node of config file is not Subscription or in correct namespace. |
| wevtutil.exe | 0x24 | 78.11011 | LCID %1!s! cannot be found. |
| wfascim.dll | 0x24 | 1011 | RemoteAddress must be specified. |
| win32k.sys | 0x24 | 78.1 | Menu |
| win32kbase.sys | 0x24 | 1011 | Menu |
| 24 entries | |||