Fix it now
0x0000007A means a page of kernel data could not be read back from the paging file. Parameter 2 is the error status the storage stack returned, and it is what decides whether you are looking at a failing disk, a loose cable, or a driver that ran the system out of nonpaged pool.
chkdsk C: /scan
wevtutil qe System /c:40 /rd:true /f:text
- Get parameter 2 from the BugCheck event in the System log or from
!analyze -von the newest dump. Do not skip this – it changes the whole answer. - 0xC000009C or 0xC000016A means bad sectors on the disk. Run
chkdsk C: /f /r. It needs to lock the volume, so on the system drive it will ask whether to run at the next restart. - 0xC000009D means defective or loose cabling or termination, or that the controller cannot see the disk. Reseat cables and the drive at both ends before anything else.
- 0xC000009A means a lack of nonpaged pool – a driver problem in the storage stack, not a disk problem. Replacing the drive will not help.
- 0xC0000185 is an I/O device error, documented as improper termination or defective cabling, or two devices trying to use the same IRQ.
- Whatever the status, back the machine up before you run repairs. A disk that fails a paging read is a disk you should be copying, not writing to.
Microsoft names virus infection among the causes of both 0x7A and 0x77, specifically infections affecting the master boot record, and its documented check is a current scanner rather than a boot record rebuild.
If the status pointed at cabling or sectors and the repair held, stop here. The next section explains the status codes and the difference between 0x7A and 0x77.
Why it happens
Windows pages kernel data out to the paging file like anything else, and reads it back when it is needed. A read that fails leaves the memory manager holding a page it cannot produce and code waiting on data that will never arrive, which is not a state it can continue from. 0x0000007A is that failure, and because it happens at the boundary between memory and storage it is misdiagnosed in both directions.
Parameter 2 removes the guesswork. It is the error status, usually an I/O status code, and Microsoft publishes a table mapping the common values to causes. 0xC000009C, STATUS_DEVICE_DATA_ERROR, is bad blocks on the disk. 0xC000016A, STATUS_DISK_OPERATION_FAILED, is also bad blocks. 0xC000009D, STATUS_DEVICE_NOT_CONNECTED, is defective or loose cabling or termination, or a controller that cannot see the drive. 0xC0000185, STATUS_IO_DEVICE_ERROR, is improper termination or defective cabling, or two devices attempting to use the same IRQ. 0xC000000E, STATUS_NO_SUCH_DEVICE, is a hardware failure or an incorrect drive configuration.
And then there is 0xC000009A, STATUS_INSUFFICIENT_RESOURCES, which is a lack of nonpaged pool – a driver error in the storage stack. It appears in the same table as the others and it means something entirely different. A reader who treats every 0x7A as a dying disk will replace a healthy drive, restore from backup, and see the crash again a fortnight later.
0x00000077 is the same failure where the page belonged to a kernel thread’s stack, but its parameters are read differently. If parameter 1 is 0, 1 or 2 it describes where the page came from and whether the stack signature was found, and Microsoft attributes values 0 and 1 to defective hardware, specifically a RAM error, rather than to the disk. Any other value of parameter 1 is itself an NTSTATUS code from the storage stack, with the I/O status in parameter 2. So on 0x77 you read parameter 1 first and parameter 2 second.
Bad sectors on the system disk
You have this one if Parameter 2 of 0xC000009C or 0xC000016A, and storage errors in the System log around the crash.
- Image the disk before repairing it. A drive producing read errors can get worse quickly.
- Run
chkdsk C: /f /r. It needs to lock the volume, so on the system drive it asks whether to check at the next restart, and the /r pass takes hours on a large disk. - Read the drive’s SMART or health data with the manufacturer’s own tool afterwards.
- Replace the drive if the reallocated or pending sector counts are climbing. chkdsk maps bad blocks out; it does not make the drive healthy.
Cabling, connectors or the controller
You have this one if Parameter 2 of 0xC000009D or 0xC0000185, or the drive appearing and disappearing in firmware setup.
- Reseat the data and power cables at both ends, or reseat the M.2 module and check its retention screw.
- Try a different port on the board and a known-good cable.
- Check the drive is detected consistently in firmware setup across several cold starts.
- On a machine with an add-in controller, reseat the card and confirm its firmware is current.
A driver exhausting nonpaged pool
You have this one if Parameter 2 of 0xC000009A. The disk is healthy and chkdsk finds nothing.
- Treat it as a driver problem in the storage stack rather than a hardware fault.
- In the debugger,
!vm 1for total pool usage and!poolused 2for nonpaged pool by tag. The tag using the most is the candidate. - Update or remove the storage, backup or endpoint driver behind that tag.
- Watch whether the crash correlates with a long-running job – backups and replication are common triggers because they hold pool for the duration.
Failing memory rather than storage
You have this one if The code is 0x00000077 with parameter 1 of 0 or 1, which Microsoft attributes to defective hardware such as a RAM error.
- Run Windows Memory Diagnostics with the extended test mix and read the result in the System log.
- Test one memory module at a time where more than one is fitted.
- Return firmware to stock settings, including memory profiles, before concluding anything.
- Check the System log for other memory-manager codes in the same period – 0x0000001A and 0x00000050 alongside this one point the same way.
Full reference
The I/O status codes, and what each one means
| Status | Name | Published meaning |
|---|---|---|
0xC000009A |
STATUS_INSUFFICIENT_RESOURCES | A lack of nonpaged pool resources – a driver error in the storage stack |
0xC000009C |
STATUS_DEVICE_DATA_ERROR | Bad blocks (sectors) on the hard disk |
0xC000009D |
STATUS_DEVICE_NOT_CONNECTED | Defective or loose cabling or termination, or the controller cannot see the disk |
0xC000016A |
STATUS_DISK_OPERATION_FAILED | Bad blocks (sectors) on the hard disk |
0xC0000185 |
STATUS_IO_DEVICE_ERROR | Improper termination or defective cabling on SCSI devices, or two devices using the same IRQ |
0xC000000E |
STATUS_NO_SUCH_DEVICE | A hardware failure or an incorrect drive configuration |
How the parameters differ between the two codes
| Code | Parameter 1 | Parameter 2 |
|---|---|---|
0x0000007A |
The lock type held, or the address of the page table entry | The error status, usually an I/O status code |
0x00000077 |
0, 1 or 2: where the page came from and the stack signature check. Any other value: an NTSTATUS from the storage stack | The value found where the signature should be, or the I/O status code |
On 0x00000077, parameter 1 of 0 means the page came from page cache and 1 means it came from a disk; in both cases the stack signature was not found, which Microsoft attributes to defective hardware such as a RAM error. Parameter 1 of 2 means the storage stack returned success but the information count was not a page, which is an inconsistent status from the driver stack.
Microsoft’s own resolution list
- For bad blocks, run
Chkdsk /f /ron the system partition, orChkdsk /rfrom the recovery environment if the machine will not start. - For failing RAM, run the hardware diagnostics the system manufacturer supplies, particularly the memory scanner.
- For defective hardware, check disk cabling and termination, read the System log for related errors, make sure Windows is up to date, and run whatever diagnostic software you have.
- For virus infection, use current commercial scanning software, particularly against the master boot record.
- Generally, confirm adapter cards are properly seated and their contacts clean, and look for physical damage to the board.
0x0000002F, and being honest about it
INSTRUCTION_BUS_ERROR appears in lists alongside these codes and it has no published meaning. Microsoft gives the symbolic name, a note that it appears very infrequently, and !analyze as the only step. Descriptions of it as an instruction fetch failing on the bus are readings of the name, not documentation. If you have one, take the dump and work from the stack.
Getting data off first
- Image the disk before running
chkdsk /f /ron it. The repair writes to a device that has already failed a read. - If the machine will not start, take the disk out and image it from another machine rather than repairing it in place.
- Solid state drives can behave differently from mechanical ones as they degrade, which is a reason to image early rather than a rule about how they fail.
- Check whether the pagefile is on the same disk as the crash. Moving it does not fix a failing drive, but it does change which reads fail.
- Confirm free space on the volume. A system with no room for its pagefile produces its own set of problems.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x0000007A |
KERNEL_DATA_INPAGE_ERROR: the requested page of kernel data could not be read into memory from the paging file. Parameter 2 is the error status, usually an I/O status code, and Microsoft publishes a table mapping those statuses to causes | Microsoft Learn |
0x00000077 |
KERNEL_STACK_INPAGE_ERROR: the same published description, but the parameters are read differently. Parameter 1 values 0 and 1 mean the kernel stack signature was not found, which Microsoft attributes to defective hardware such as a RAM error; any other value is itself an NTSTATUS from the storage stack | Microsoft Learn |
0x0000002F |
INSTRUCTION_BUS_ERROR: Microsoft publishes the symbolic name and the statement that this bug check appears very infrequently, with !analyze as the only step. No description, parameters or cause is given | not published by the vendor |
0xC000009C |
STATUS_DEVICE_DATA_ERROR: typically indicates bad blocks (sectors) on the hard disk. Microsoft’s remedy for this status is chkdsk /f /r on the system partition | Microsoft Learn |
0xC000009D |
STATUS_DEVICE_NOT_CONNECTED: defective or loose cabling or termination, or the controller cannot see the hard disk | Microsoft Learn |
Confirm the fix worked
chkdsk C: /f /rcompletes and reports no unrecoverable bad sectors.- The drive’s own health tool reports no growth in reallocated or pending sector counts.
- The storage sources in the System log record no new errors over several days.
- The machine survives a full backup run, which exercises the whole read path.
- If parameter 2 was 0xC000009A, nonpaged pool usage by tag is stable under the workload that used to crash it.
Questions people ask about this
Do I need to replace the disk?
Read parameter 2 first. 0xC000009C and 0xC000016A do mean bad sectors, and a drive with a growing reallocated sector count should be replaced. 0xC000009D is cabling and 0xC000009A is a driver running the system out of nonpaged pool – neither is fixed by a new disk.
Will chkdsk fix it?
It repairs the file system and maps out bad blocks, which is Microsoft’s documented remedy for the bad-sector statuses. It does not make failing hardware healthy, so read the drive’s health data afterwards and plan a replacement if the counts are moving.
Why does Microsoft mention viruses for a disk error?
Because master boot record infections are a documented cause of both 0x7A and 0x77, and the published remedy is a current commercial scanner that examines the MBR. It is a cheap thing to rule out before you replace hardware.
The status is 0xC000009A. What now?
That is STATUS_INSUFFICIENT_RESOURCES – a lack of nonpaged pool, which is a driver error in the storage stack. Use !vm 1 and !poolused 2 to find the tag consuming the pool, then update or remove the driver behind it.
Should I move the pagefile to another drive?
Only as a diagnostic. It changes which device the failing reads go to, which can tell you something, but it does not repair a drive and it does not free nonpaged pool.
