Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 0x00000024

NTFS_FILE_SYSTEM 0x00000024 – volume corruption behind the blue screen

12 min read Updated October 5, 2026 Windows Crashes & Boot Recovery

Fix it now

0x00000024 means a problem occurred in ntfs.sys. Microsoft publishes three causes: disk corruption or bad sectors, corrupted SATA or IDE drivers, and depletion of nonpaged pool – and that last one is the reason a healthy disk sometimes gets replaced for nothing.

Run these in an elevated Command Prompt, in order

chkdsk C: /scan
sfc /scannow
  1. Check the System log for storage errors around the crash. Microsoft’s own first resolution step is to look for messages from SCSI, IDE or other disk controllers that pinpoint the device or driver.
  2. Confirm the volume has sufficient free space. Microsoft names it explicitly and suggests keeping ten to fifteen per cent free, and it is the cheapest check on the list.
  3. Disable virus scanners, backup programs and defragmenter tools that continually monitor the system, and see whether the crash stops. That is a documented step, not a folk remedy.
  4. Run chkdsk C: /f /r if the online scan reported problems. It needs the volume locked, so on the system drive it offers to run at the next restart instead.
  5. Run the storage diagnostics the system manufacturer supplies, and read the drive’s own health data.

If the machine will not start, run chkdsk /r from the recovery environment against the volume letter recovery has assigned to Windows – confirm it with diskpart and list volume first, because it is often not C.

If chkdsk repairs the volume and the machine is stable, stop here. The next section explains the nonpaged pool case and what the sibling codes actually mean.

Why it happens

ntfs.sys is the driver that reads and writes NTFS volumes, and it works from on-disk metadata – the master file table, index structures, the log. When it finds that metadata in a state that cannot legitimately exist, or when an operation it depends on fails in a way it cannot recover from, it raises an exception and the system stops. Parameter 1 encodes the source file and line number inside the driver, and parameters 2 and 3 are the exception and context records when NtfsExceptionFilter is on the stack.

Microsoft’s cause list has three entries and only two of them are about the disk. The first is corruption in the file system, or bad blocks on the drive. The second is corrupted SATA or IDE drivers, which can affect the system’s ability to read and write regardless of the drive’s condition. The third is depletion of nonpaged pool memory – and Microsoft adds that during indexing, if available nonpaged pool is very low, another kernel-mode driver that needs nonpaged pool can trigger this error too.

That third cause is the one that changes what you do. A machine that bug checks with 0x00000024 because a driver has consumed the nonpaged pool will do it again on a new disk, having lost the evidence in the rebuild. The tell is a machine that crashes under a specific sustained workload – a backup run, an indexing pass, a large replication job – on a drive that reports clean.

The sibling codes are the same structure for other file systems and they mostly share the same causes: 0x00000023 for FAT, with FatExceptionFilter; 0x0000009B for UDFS, with UdfExceptionFilter. Both list disk corruption and nonpaged pool depletion. 0x00000022 publishes nothing at all beyond its name. And 0x0000012C, exFAT, is the exception that has to be read carefully: Microsoft states that the file system raises it as a last resort when its internal accounting is in an unsupportable state, and that it never causes this bug check when the on-disk structures are corrupted, the sectors go bad, or a memory allocation fails.

The volume or the drive is genuinely damaged

You have this one if Storage errors in the System log around the crash, or a drive whose health data shows reallocated or pending sectors.

  1. Image the disk before repairing it if the drive is producing read errors.
  2. Run chkdsk C: /f /r. It needs the volume locked, so on the system drive it offers to run at the next restart, and the /r pass takes hours on a large volume.
  3. Read the drive’s own health data with the manufacturer’s tool afterwards.
  4. Replace the drive if the error counts are climbing. chkdsk maps blocks out; it does not make a failing drive healthy.

A driver has consumed the nonpaged pool

You have this one if The drive is clean, chkdsk finds nothing, and the crash follows a sustained job such as a backup, an indexing pass or a replication run.

  1. In the debugger, !vm 1 for total pool usage and !poolused 2 for nonpaged pool by tag. The tag consuming the most is the candidate.
  2. Identify the driver behind that tag and update or remove it.
  3. Where the workload is a backup or replication agent, check the vendor supports that build on your Windows version.
  4. Microsoft’s own published remedy for pool depletion on the related file system codes is to add physical memory, which raises the nonpaged pool available to the kernel – but find the consumer first.

A storage driver rather than the disk

You have this one if The System log names a controller, or the machine has a vendor storage driver installed over an inbox one.

  1. Confirm which storage mode the firmware is presenting and install only the matching driver.
  2. Update the storage controller driver and the drive firmware from their own vendors.
  3. Remove caching or acceleration software that duplicates what the controller already does.
  4. Re-test with a sustained file copy, which exercises the path that crashed.

A file system filter in the path

You have this one if fltmc lists filters from more than one product doing the same job, or one belonging to software that is no longer installed.

  1. Microsoft’s documented step is to disable virus scanners, backup programs and defragmenter tools that continually monitor the system, and confirm whether the error stops.
  2. Remove leftover filters with the original vendor’s removal utility and confirm with fltmc.
  3. fltmc unload <name> takes one filter out of the path for a clean test without a reboot.
  4. Where two products genuinely have to coexist, apply each vendor’s documented exclusions for the other.

Full reference

The file system bug checks, side by side

Code File system Documented causes
0x00000024 NTFS Disk corruption or bad sectors, corrupted SATA/IDE drivers, nonpaged pool depletion
0x00000023 FAT Disk corruption and nonpaged pool depletion
0x0000009B UDFS Disk corruption and nonpaged pool depletion
0x0000012C exFAT Internal accounting in an unsupportable state. Explicitly not on-disk corruption, bad sectors or a failed allocation
0x00000022 Generic FILE_SYSTEM Nothing published

All of them share a parameter structure. Parameter 1 encodes the source file identifier in its high 16 bits and the source line in its low 16 bits. Parameters 2 and 3 are the exception record and the context record when the file system’s exception filter is on the stack – NtfsExceptionFilter, FatExceptionFilter, UdfExceptionFilter, FppExceptionFilter for exFAT. In the debugger, .cxr on parameter 3 followed by kb gets you a usable stack.

Microsoft’s own resolution list for 0x00000024

  1. Check Event Viewer for hard drive messages in the System log that might pinpoint the device or driver.
  2. Disable any virus scanners, backup programs or disk defragmenter tools that continually monitor the system.
  3. Run the hardware diagnostics the system manufacturer supplies for the storage subsystem.
  4. Use the scan disk utility to confirm there are no file system errors – right-click the drive, Properties, Tools, Check.
  5. Confirm sufficient free space; Microsoft suggests ten to fifteen per cent as a general figure.
  6. Run SFC /scannow to repair missing or corrupted system files.
  7. Use Driver Verifier against a small number of suspect drivers, on a machine you can afford to crash.

Commands for the volume

Command What it does
chkdsk C: /scan Scans an NTFS volume online, without a restart
chkdsk C: /f /r Fixes errors and locates bad sectors. /r includes /f and needs the volume locked, so on the system drive it offers to run at the next restart
Repair-Volume -DriveLetter C -OfflineScanAndFix Documented as the equivalent of chkdsk /f
diskpart then list volume Confirms the volume letters, which differ inside the recovery environment
fltmc Lists the loaded file system minifilters
fltmc unload <name> Takes one filter out of the path for a test

Repair-Volume -OfflineScanAndFix is documented as the equivalent of chkdsk /f, not of chkdsk /f /r. If you want the bad-sector pass, run chkdsk with /r.

0x0000012C is the one people get backwards

It is easy to read EXFAT_FILE_SYSTEM as the exFAT version of a corruption bug check, but Microsoft says the opposite in as many words: the file system never causes this bug check when the on-disk structures are corrupted, the disk sectors go bad, or a memory allocation fails. It is raised as a last resort when the file system’s own internal accounting has reached a state where continuing risks large data loss. So the answer is not chkdsk on the removable drive – it is the dump, .cxr on parameter 3, and kb.

When the volume checks out and it still crashes

  • Watch nonpaged pool under the workload that triggers it, and identify the tag consuming it.
  • Check whether the crash correlates with a scheduled job rather than with user activity.
  • Confirm the drive firmware is current, particularly on SSDs where storage-path bugs have been fixed in firmware.
  • Test the same workload against a different volume on a different controller to separate the file system from the hardware path.
  • Compare several dumps. A stable parameter 1 means the same code path in ntfs.sys every time, which is worth taking to support with the dump attached.

When a licence is the actual fix

Where the crash trail ends at a security agent that is out of support on the Windows build it is running, or one left half-removed by a failed uninstall, the fix is either full removal or a supported build. Microsoft Defender is included with Windows, costs nothing and adds no third-party minifilter to the path, which makes it the right answer for a machine that does not need central management. Where you need managed policy, device control and reporting across a fleet, a current licence restores update delivery so the file system filter tracks the Windows builds you are running. Arco supplies Bitdefender GravityZone Business Security and can check which seat count and term suits the estate you actually run.

Every code this article covers

Code What it points at Source
0x00000024 NTFS_FILE_SYSTEM: a problem occurred in ntfs.sys. Parameter 1 encodes the source file identifier and line number, and parameters 2 and 3 are the exception and context records when NtfsExceptionFilter is on the stack. Documented causes: disk corruption or bad sectors, corrupted SATA or IDE drivers, and depletion of nonpaged pool Microsoft Learn
0x00000022 FILE_SYSTEM: Microsoft publishes the symbolic name and the statement that this bug check appears very infrequently, with !analyze as the only step. No description, parameters or cause is given not published by the vendor
0x00000023 FAT_FILE_SYSTEM: a problem occurred in the FAT file system. Same parameter structure as 0x00000024 with FatExceptionFilter, and the same documented causes of disk corruption and nonpaged pool depletion Microsoft Learn
0x0000012C EXFAT_FILE_SYSTEM: raised by the file system as a last resort when its internal accounting is in an unsupportable state. Microsoft states explicitly that the file system never causes this bug check when the on-disk structures are corrupted, the disk sectors go bad, or a memory allocation fails Microsoft Learn
0x0000009B UDFS_FILE_SYSTEM: a problem occurred in the UDF file system. Same parameter structure with UdfExceptionFilter, and the same documented causes as 0x00000024 and 0x00000023 Microsoft Learn

Confirm the fix worked

  1. chkdsk C: /scan reports no problems, or the problems it found have been repaired by a /f /r pass.
  2. The drive’s health data shows no growth in reallocated or pending sectors.
  3. The volume has comfortable free space, not a few hundred megabytes.
  4. fltmc lists only filters belonging to installed, supported products.
  5. The workload that used to crash the machine – the backup, the indexing pass – completes twice without a new dump.

Questions people ask about this

Does 0x00000024 always mean the disk is failing?

No. Microsoft publishes three causes and one of them is depletion of nonpaged pool, which is a driver problem on a healthy drive. Check the volume, but check pool usage too before you order hardware.

Should I run chkdsk /f /r straight away?

Run chkdsk C: /scan first – it works online and tells you whether there is anything to repair. Go to /f /r if it reports problems, and image the disk first if the drive is already producing read errors.

Is disabling antivirus really a documented step?

Yes. Microsoft’s resolution list for this code says to disable virus scanners, backup programs and disk defragmenter tools that continually monitor the system. It is a diagnostic – turn them back on once you know the answer.

I have 0x0000012C on a machine with an exFAT memory card. Do I run chkdsk on the card?

Not for this code. Microsoft states the exFAT driver never raises it for corrupt on-disk structures, bad sectors or a failed allocation. It means the driver’s internal accounting reached an unsupportable state, so the dump is where the answer is.

Will more RAM fix the pool case?

It raises the nonpaged pool available to the kernel, which is Microsoft’s published remedy for pool depletion on the related file system codes. But a driver that leaks pool will exhaust a larger pool too, so find the consumer first.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error RESOURCE_OWNER_POINTER_INVALID 0x00000132 and lock ownership crashes Free Fix Windows RE update fails with 0x80070643 – recovery partition too small Free Fix ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY 0x000000FC and DEP blue screens License Error IRQL_GT_ZERO_AT_SYSTEM_SERVICE 0x0000004A and kernel stack exhaustion on hosts
โ† Back to Knowledge Base