Quick fix (4 steps)
- Photograph the screen and write down the stop code name (for example CRITICAL_PROCESS_DIED) and any file named after it.
- Find the code in the lookup table and apply the first fix in its row.
- If Windows boots, open Windows Terminal as administrator and run
sfc /scannow, thenDISM /Online /Cleanup-Image /RestoreHealth. - If it keeps crashing or will not start, use the hardware versus software triage and consider calling a professional.
What a Windows 11 stop code is, and why it matters
A stop code is the name and hex number Windows shows when its kernel detects a condition it cannot safely continue from, so it halts the system on purpose to protect your data. Microsoft calls this event a bug check, and the stop code is the single most useful clue you get about what failed. A blue screen is not a virus and it is rarely a sign that your PC is finished. It is the operating system choosing a controlled stop over silent corruption.
People search for "windows 11 blue screen" in the middle of a bad moment, so this page is built as a hub. It teaches you to read the code, gives you a lookup table with the usual cause and the first fix for each common code, collects every copy-paste command in one place, and shows you how to separate hardware failures from software ones. When you need the full step-by-step for a specific code, the hub points you to the matching page on this site instead of repeating it.
If your code is one of these, jump straight to the deep guide:
- CRITICAL_PROCESS_DIED (0xEF): read our CRITICAL_PROCESS_DIED guide with 10 fixes and the shorter 0x000000EF error page.
- WHEA_UNCORRECTABLE_ERROR (0x124): see the 0x00000124 page, then come back here for the hardware triage.
- PAGE_FAULT_IN_NONPAGED_AREA (0x50): 0x00000050 fixes.
- SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (0x7E): 0x0000007E fixes.
- DPC_WATCHDOG_VIOLATION (0x133): 0x00000133 fixes.
- Any other blue screen: the general how to fix the blue screen of death on Windows 11 guide.
Stop code, error code and app error are three different things
Much of the confusion around these searches comes from mixing up three kinds of failure. A stop code (bug check) takes down the whole operating system and shows a full-screen message, for example CRITICAL_PROCESS_DIED with the value 0xEF. A Windows Update error code such as 0x800f0922 appears inside Settings and does not crash the PC. An application error such as 0xc0000142 ("the application was unable to start correctly") appears in a small dialog box when one program fails to start, while Windows itself keeps running.
The distinction matters because the fixes are different. If a single program shows 0xc0000142, you do not need a memory test; you need to repair that program or its runtime libraries, as explained in our 0xc0000142 guide. If the whole screen turns blue or black and the PC restarts, you are in stop code territory, and everything below applies.
The screen might not be blue anymore
Recent Windows 11 builds can show the crash screen in a different color, and the layout has been simplified compared with older Windows versions. Whatever the color, the information you need is the same: a stop code name, usually a percentage counter while Windows collects data, a QR code, and sometimes the name of a file such as a driver ending in .sys. If your PC shows a completely black screen with no text at all, that is a different symptom with its own causes, covered in our black screen of death guide.
Read your stop code in 60 seconds
To read a stop code in 60 seconds, capture the code name and any .sys file name, ask three quick questions (what changed, when does it crash, and is it the same code every time), and then match the code to a family: memory, driver, storage, hardware error or system process. That short routine replaces hours of random fixes, because it tells you which part of the machine to test first.
Use this routine every time. It takes about a minute, and the notes you make are valuable if you later ask a technician for help.
Step 1 (15 seconds): capture the evidence
Photograph the screen with your phone before the PC restarts. Write down three things: the stop code name in capital letters with underscores, the hex value if it appears, and the name of any file listed as "What failed" on versions that show it. If the PC restarts too fast to read, do not worry: Windows records the code, and the later sections show where to find it again.
Step 2 (20 seconds): ask the three questions
- What changed in the last two weeks? A new Windows update, a graphics driver, new RAM, a new SSD, a BIOS update, new antivirus or overclocking software. A crash that starts right after a change is almost always related to it.
- When does it crash? At boot (storage, boot files, drivers), under load such as gaming or video export (heat, power supply, graphics driver), when idle or waking from sleep (power management drivers), or at random times (often memory or storage).
- Is the code the same every time? A repeating code points to one cause. Different codes on each crash usually mean memory corruption, unstable power or a failing drive.
Step 3 (25 seconds): match the code to a family
| Family | Typical stop codes | First suspect | First move |
|---|---|---|---|
| Driver or software fault | DRIVER_IRQL_NOT_LESS_OR_EQUAL (0xD1), SYSTEM_SERVICE_EXCEPTION (0x3B), SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (0x7E), IRQL_NOT_LESS_OR_EQUAL (0xA) | The driver named on screen or the last one installed | Roll back or update that driver |
| Memory | MEMORY_MANAGEMENT (0x1A), PAGE_FAULT_IN_NONPAGED_AREA (0x50) | RAM, XMP or overclock, or a driver corrupting memory | Windows Memory Diagnostic, reset memory profile |
| Storage | INACCESSIBLE_BOOT_DEVICE (0x7B), UNEXPECTED_STORE_EXCEPTION (0x154) | SSD or hard drive, cable, storage mode in BIOS | Drive health check, chkdsk, BIOS storage mode |
| Hardware error report | WHEA_UNCORRECTABLE_ERROR (0x124) | CPU, heat, power, memory or overclock | Remove overclock, check cooling, test memory |
| Integrity or process failure | CRITICAL_PROCESS_DIED (0xEF), KERNEL_SECURITY_CHECK_FAILURE (0x139) | Corrupt system files, a driver, or failing storage or memory | sfc, DISM, recent update check |
This table is a starting map, not a verdict. Drivers can cause nearly any stop code, and a hardware fault can masquerade as a software one, which is why the lookup table and the triage table later in the article give you an order of operations rather than a single answer.
Keep the evidence
Before you start fixing, save a photo of the screen and copy any files in C:\Windows\Minidump to a folder on your desktop. Some repair steps, and a technician later, can use those files to see the pattern across several crashes instead of just the last one.
Windows 11 stop code lookup table: code, name, usual cause, first fix
Use this table to translate a stop code into its usual cause and the first fix to try. Names and hex values come from Microsoft's bug check reference; the causes are the common ones seen in practice, so treat them as leads to test, not guarantees. Always try the first fix before the heavy options such as Reset this PC.
The first group is the eleven codes people see most. The second group lists other codes you may meet. If your code is not listed, search for the stop code name on Microsoft Learn, or open your minidump and run !analyze -v in WinDbg, explained in the minidump section.
| Hex | Stop code name | Usual cause (hedged) | First fix to try |
|---|---|---|---|
| 0xEF | CRITICAL_PROCESS_DIED | A critical system process ended; corrupt system files, a bad driver or update, sometimes failing storage or memory | sfc /scannow then DISM /Online /Cleanup-Image /RestoreHealth |
| 0x124 | WHEA_UNCORRECTABLE_ERROR | Fatal hardware error reported by the processor or platform; heat, power, failing CPU or memory, overclocking (a driver is less likely) | Disable overclock and XMP, check fans and temperatures, run mdsched.exe |
| 0x139 | KERNEL_SECURITY_CHECK_FAILURE | Kernel detected corrupted data structures; faulty drivers, memory problems or disk issues | Update or roll back recent drivers, sfc, memory test |
| 0x7B | INACCESSIBLE_BOOT_DEVICE | Windows cannot read the boot drive; storage mode changed in BIOS, failing drive, boot data or storage driver problem | Check BIOS storage mode (AHCI, RAID, VMD), reseat cables, run repair from recovery |
| 0x50 | PAGE_FAULT_IN_NONPAGED_AREA | Windows referenced memory that should exist but did not; bad RAM, a faulty driver, antivirus or file system damage | Memory test, update drivers, remove recent software |
| 0x3B | SYSTEM_SERVICE_EXCEPTION | An error during a system service call, commonly a graphics or other driver | Clean install the graphics driver, check the file named on screen |
| 0xD1 | DRIVER_IRQL_NOT_LESS_OR_EQUAL | A driver accessed memory at the wrong time or address; often network, graphics or storage drivers | Identify the .sys file, roll back or update that driver |
| 0x1A | MEMORY_MANAGEMENT | A serious memory management problem; faulty RAM, unstable memory profile or driver | Reset XMP or EXPO to default, run mdsched.exe, reseat RAM |
| 0x154 | UNEXPECTED_STORE_EXCEPTION | An unexpected error in the memory store component; often storage device or driver issues, sometimes antivirus | Check drive health, chkdsk C: /f /r, update storage and chipset drivers |
| 0xA | IRQL_NOT_LESS_OR_EQUAL | Kernel or a driver touched memory with the wrong privilege level; drivers or faulty memory | Roll back the last driver, test memory |
| 0x7E | SYSTEM_THREAD_EXCEPTION_NOT_HANDLED | A system thread raised an error nobody handled; very often a named driver | Update or remove the driver in the "What failed" line, boot to Safe Mode if needed |
Other codes you may meet
| Hex | Stop code name | Where to start |
|---|---|---|
| 0x133 | DPC_WATCHDOG_VIOLATION | Storage and other drivers that stall; update SSD firmware and storage drivers. See our 0x133 page |
| 0x1E | KMODE_EXCEPTION_NOT_HANDLED | Driver or kernel-mode code fault; identify the file named on screen |
| 0x9F | DRIVER_POWER_STATE_FAILURE | Sleep and wake problems; update chipset, network and graphics drivers, check power settings |
| 0x116 | VIDEO_TDR_FAILURE | Graphics driver stopped responding; clean install the graphics driver and check temperatures |
| 0x101 | CLOCK_WATCHDOG_TIMEOUT | A processor core stopped responding; BIOS update, remove overclock, check cooling |
| 0x7A | KERNEL_DATA_INPAGE_ERROR | Windows could not read data from disk into memory; drive, cable, or memory; run chkdsk and a drive health check |
| 0xED | UNMOUNTABLE_BOOT_VOLUME | The system volume could not be mounted; file system damage; repair from recovery with chkdsk |
| 0x109 | CRITICAL_STRUCTURE_CORRUPTION | Kernel code or data was modified; drivers or memory fault, occasionally hardware |
| 0x9C | MACHINE_CHECK_EXCEPTION | Processor reported a hardware error; treat like 0x124 and test heat, power and overclock |
| 0xC000021A | WINLOGON_FATAL_ERROR | A critical user-mode subsystem failed; system file damage or failed update; see recovery and repair steps |
How to use the table without overthinking it
Match your code, perform the first fix, and then test whether the PC survives a normal day. Do not stack five changes at once. If you update the graphics driver, roll back a Windows update, and change BIOS settings in the same hour, a stable result teaches you nothing, and a new crash cannot be traced. One change, one day of use, one note in your log. That discipline is what separates a clean diagnosis from a pile of guesses.
If the first fix does not help, the next best step is the hardware versus software triage table, which tells you what to test in what order. If the PC cannot start at all, jump to what to do when Windows will not boot.
Patterns that point to a family of causes
- The same driver file keeps appearing across crashes: a driver issue. Update, roll back or remove the software that installed it.
- Different codes each time, random moments: memory, power supply or storage. Test memory first, because it is cheap and fast.
- Crashes only under load (games, video export, heavy spreadsheets): heat, power supply or graphics driver.
- Crashes at startup only: boot configuration, storage mode, storage drivers or a failing system drive.
- Crash began right after an update: uninstall the update or roll back the driver it brought, then pause updates while you watch for stability.

The copy-paste command toolkit for blue screens
Six repair tools solve most software-side blue screens: sfc for system files, DISM for the component store, chkdsk for the disk, mdsched for memory, a driver rollback for a recent device change, and uninstalling the latest update. Run them in this order, one at a time, and note the result of each. All commands below are standard Windows tools and none of them deletes your personal files.
Open Windows Terminal (Admin) by right-clicking the Start button and choosing it. If Windows will not start normally, boot to Safe Mode or to the recovery command prompt first; see our Windows 11 Safe Mode guide for every way to get there, including when it is stuck.
1. System File Checker (sfc)
SFC scans protected system files and replaces damaged ones from a cached copy. It is the first command for CRITICAL_PROCESS_DIED, KERNEL_SECURITY_CHECK_FAILURE and any unexplained crash.
sfc /scannow
Wait for the scan to reach 100 percent, which can take 10 to 20 minutes. The result says one of three things: no integrity violations, found and repaired corrupt files, or found corrupt files it could not fix. The third answer means you need DISM first, then sfc again.
2. DISM (repair the component store)
DISM repairs the source that sfc copies from. Run it when sfc cannot repair files, or even before sfc on a machine that has had update problems.
DISM /Online /Cleanup-Image /CheckHealth
DISM /Online /Cleanup-Image /ScanHealth
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow
RestoreHealth needs an internet connection because it may download replacement files from Windows Update. A progress bar can sit at 20 percent or 62.3 percent for a long time without being stuck. Give it at least 30 minutes before you worry. Then run sfc once more.
3. Check Disk (chkdsk)
Chkdsk finds and repairs file system errors and flags bad sectors. It is the right tool for UNEXPECTED_STORE_EXCEPTION, KERNEL_DATA_INPAGE_ERROR, UNMOUNTABLE_BOOT_VOLUME and any crash that coincides with slow file access.
chkdsk C: /f /r
Windows will say it cannot lock the drive and offer to run at the next restart; type Y and restart. The /r option reads every sector, so on a 1 TB drive the scan can take one to several hours. Do not interrupt it. If chkdsk reports bad sectors on a drive that keeps growing them, the drive is failing. Stop repairing and copy your data off first, then replace it.
Failing drive warning
Clicking sounds, a drive that disappears from the file explorer, SMART warnings, or chkdsk finding more bad sectors each run are all signs to back up immediately. Heavy repair scans on a dying drive can make recovery harder. Our guide to hard drive data recovery explains what is possible and what to avoid.
4. Windows Memory Diagnostic (mdsched)
Memory faults cause the most confusing, random stop codes. The built-in test is quick and free.
mdsched.exe
Choose "Restart now and check for problems." The PC reboots into a blue test screen, runs a standard pass in about 10 to 20 minutes and restarts into Windows. The result appears as a notification, or in Event Viewer under Windows Logs, System, from the source MemoryDiagnostics-Results. One error in a pass is enough to suspect a bad stick. A clean pass does not prove the RAM is perfect, because subtle faults can need many hours with a longer test such as MemTest86 (a separate free download that runs from a USB drive).
Before blaming a stick, reset the memory profile. If the BIOS has XMP, EXPO or a manual overclock on, set it back to default and test again. Many "bad RAM" cases turn out to be a profile that the CPU's memory controller cannot hold stable.
5. Driver rollback or removal
If the crash started after a driver change, use Device Manager. Right-click Start, choose Device Manager, expand the category (Display adapters, Network adapters, Storage controllers), double-click the device, choose the Driver tab, and select Roll Back Driver if the button is available. If it is grey, use Uninstall Device, tick "Attempt to remove the driver for this device" when offered, restart and let Windows reinstall a default version.
To list the drivers installed on the machine, which helps match a .sys name from a crash screen to a vendor:
driverquery /v /fo table
pnputil /enum-drivers
Download replacements only from the PC maker, the component maker (Intel, AMD, NVIDIA, Realtek) or Windows Update. For a step-by-step approach, read how to update drivers safely. If your crash is graphics specific, our GPU driver crashed guide covers a clean install.
6. Uninstall the latest update
If the first crash followed a Windows update, go to Settings, Windows Update, Update history, then Uninstall updates (at the bottom under Related settings). Pick the most recent entry, uninstall it, restart, and pause updates for a few days. This is a diagnostic step as much as a fix: if the crashes stop, you have found the trigger, and you can look for an updated driver from the manufacturer before letting the update return. If the PC is stuck in a loop before you can get to Settings, see the Automatic Repair loop guide.
7. Turn off Fast Startup while you test
Fast Startup keeps parts of the kernel state between shutdowns, which can carry a bad driver state forward. For a clean test, run:
powercfg /h off
This disables hibernation and Fast Startup. You can turn it back on later with powercfg /h on. A full shutdown followed by a cold start is a clean test of whether a driver state is the culprit.
A sensible order, as a short list
- Photograph the code and note recent changes.
- Run
sfc /scannow, then DISM, then sfc again if needed. - Roll back the most recently changed driver or uninstall the latest update.
- Run
mdsched.exeand reset any memory overclock. - Run
chkdsk C: /f /rand check drive health. - Read the minidump to see which driver repeats.
- If crashes continue, move to the triage table and consider help.
Do not run these when the screen is black and nothing responds
If the PC will not reach the desktop or Safe Mode, use the recovery environment steps in the next sections. Repeatedly forcing power-offs risks file system damage, so give the system a few minutes before you hold the power button.
Find and read the minidump: BlueScreenView and WinDbg basics
Every blue screen can leave a small crash file called a minidump in C:\Windows\Minidump, and reading it shows the stop code and the drivers that were loaded when the crash happened. If the same driver shows up in several dumps, you have your best lead. You do not need to be a developer to read the basics, and the free tools below do the heavy lifting.
Where the crash files live
- Minidumps:
C:\Windows\Minidump, one small .dmp file per crash, named by date. - Full or kernel dump:
C:\Windows\MEMORY.DMP, a single larger file that is overwritten by default. - Event Viewer: Windows Logs, System, filter for source BugCheck (event ID 1001) to see the stop code and the dump file path after each crash. Event ID 41 from Kernel-Power records an unexpected restart, which also happens with power cuts and forced shutdowns.
The Minidump folder is protected, so copy the files to your desktop before opening them, rather than changing permissions. If the folder is empty, dump writing may be off, the page file may be disabled, or a cleanup tool may have removed old dumps.
Make sure Windows is saving dumps
Press Windows + R, type sysdm.cpl and press Enter. Open the Advanced tab, choose Settings under Startup and Recovery, and check the following:
- Under "Write debugging information," choose Automatic memory dump or Small memory dump (256 KB). Either one produces a file the tools below can read.
- Untick Automatically restart while you troubleshoot, so the screen stays long enough to photograph. Tick it again afterward if you prefer.
- Leave the page file on (Advanced, Performance Settings, Advanced, Virtual memory), because crash dump creation depends on it.
BlueScreenView: the fast way to read dumps
BlueScreenView is a small free utility by NirSoft that reads the minidump folder and lists each crash in a table. Download it only from NirSoft's own site, because look-alike downloads exist. Open it and you will see a row per crash with the date, stop code, the parameters, and a likely culprit "caused by driver" column. The lower pane highlights drivers found on the crash stack in red.
How to use what you see:
- Sort by date and check whether the first crash lines up with a change you made.
- Look for repetition: if the same .sys file is flagged in four of five dumps, research that file name. Names that start with nv or amd often relate to graphics, rt to Realtek, iaStor or stor to storage and Intel components.
- Be careful with core files: ntoskrnl.exe appears in many dumps simply because it is the kernel that detected the problem. It is rarely the true culprit, so look at the third-party drivers listed with it.
The tool's guess is a hint, not a diagnosis. A driver can be flagged because it was on the stack while memory was corrupted by something else. Treat a repeated flag across several crashes as meaningful, and a one-off flag as weak.
WinDbg basics: the three commands that matter
WinDbg is Microsoft's official debugger, available free from the Microsoft Store and described in Microsoft's debugging documentation. For a home or small office case you only need a few steps:
- Open WinDbg, choose File, then Open dump file, and select a copied .dmp file.
- Set the symbol path so Windows can translate addresses into names:
.symfixthen.reload. - Run the analysis:
!analyze -v.
.symfix
.reload
!analyze -v
lmvm nvlddmkm
The analysis prints the bug check name and number, its parameters, a line such as MODULE_NAME or IMAGE_NAME that names the probable module, and a FAILURE_BUCKET_ID that groups similar crashes. The last command, lmvm followed by a module name (nvlddmkm is only an example), prints that driver's version and date, which helps you decide whether an update exists. Microsoft also documents the command !analyze -show followed by a bug check code to display information about the code itself.
Analysis can take a minute the first time while symbols download. If the output says the probable cause is "memory corruption," treat that as a signal to test RAM, remove overclocks and consider enabling Driver Verifier only with expert guidance, because Driver Verifier deliberately stresses drivers and can cause boot loops on a healthy but sensitive system.
What to write down from a dump
Stop code name and hex value. Parameter 1 (it sometimes explains the type of failure). The module or driver named. The date and what you were doing. Keep a simple log: date, code, driver, what you changed. Five lines are enough to see a pattern, and a technician can use them to save an hour.
When Windows will not start: recovery, Safe Mode and bcdedit
If a blue screen loop keeps you out of Windows, force the Windows Recovery Environment by interrupting startup three times, then use Troubleshoot, Advanced options to run Startup Repair, uninstall updates, enter Safe Mode or open a command prompt. Write down your BitLocker recovery key before you start because recovery tools may ask for it. Do this calmly: each forced power-off carries a small risk to the file system, so make each attempt count.
Reach the recovery environment
Turn the PC on, and as soon as the manufacturer logo or spinning dots appear, hold the power button to turn it off. Repeat twice more. On the next start, Windows should open the recovery screen ("Preparing Automatic Repair" and then "Choose an option"). Some PCs do this on their own after two failed boots. If you reach a repair loop that never ends, our guide on the Automatic Repair loop covers the escape routes.
The useful options, in order
| Option (Troubleshoot, Advanced options) | Use it for | Notes |
|---|---|---|
| Startup Repair | Boot configuration damage, 0x7B or 0xED style failures | Harmless to try first |
| Uninstall Updates | Crashes that began after a quality or feature update | Try the latest quality update first |
| Startup Settings, Safe Mode | Driver faults, to remove or roll back a driver | Press 4 or F4 for Safe Mode, 5 or F5 with networking |
| System Restore | Return to a restore point before the problem | Only works if restore points exist |
| Command Prompt | chkdsk, sfc offline, bcdedit, copying files off | Drive letters may differ here, so check with dir |
Offline repair commands from the recovery command prompt
In recovery, the Windows drive often appears as D: instead of C:. Confirm with dir D:\ and look for the Windows folder, then run (replace D: if yours differs):
chkdsk D: /f /r
sfc /scannow /offbootdir=D:\ /offwindir=D:\Windows
DISM /Image:D:\ /Cleanup-Image /RestoreHealth
The DISM offline repair may need a source image if the component store itself is damaged; do not guess at this one, and stop if errors repeat.
Boot configuration with bcdedit and bootrec
These commands inspect and repair how Windows starts. View the current entries first, and change only what you understand:
bcdedit /enum
bootrec /scanos
bootrec /rebuildbcd
bcdedit /set {default} bootmenupolicy legacy
The last line brings back the classic F8 boot menu on a Windows 11 PC, which makes Safe Mode easier to reach if you expect repeated crashes. To force Safe Mode on the next boot, use bcdedit /set {default} safeboot minimal, and remember to undo it afterward with bcdedit /deletevalue {default} safeboot, or the PC will keep starting in Safe Mode. On UEFI systems with a damaged EFI partition, bootrec /fixboot may return "access denied," which is a signal to stop and get help rather than experiment with partition tools.
BitLocker and the recovery key
Changing BIOS settings, swapping hardware or a failed update can make a BitLocker-protected drive ask for its recovery key. If that screen appears, do not guess; find the key from the Microsoft account or the other places explained in our BitLocker recovery key guide. Without the key, repairs that touch the drive may be blocked, and a reset deletes the data for good.
Code by code: what each common Windows 11 stop code usually means
Each stop code has a typical pattern: CRITICAL_PROCESS_DIED points to system integrity, WHEA_UNCORRECTABLE_ERROR to hardware, KERNEL_SECURITY_CHECK_FAILURE to corruption, INACCESSIBLE_BOOT_DEVICE to storage at boot, and PAGE_FAULT_IN_NONPAGED_AREA to memory or drivers. The sections below add the context that a one-line table cannot, and link to the full guides where they exist. Causes are described as common patterns; any code can have an unusual cause.
CRITICAL_PROCESS_DIED (0xEF)
This stop code means a process that Windows cannot run without ended unexpectedly, so the kernel stopped the system. In practice, the trigger is often damaged system files, a faulty driver, a bad update, or storage and memory problems that corrupt a process while it runs.
The reliable sequence is: boot normally if you can, run sfc and DISM, roll back the last driver, uninstall the last update, then test memory and the drive. The dedicated guide, CRITICAL_PROCESS_DIED: 10 fixes for Windows 11, walks through ten methods in order, including Safe Mode, clean boot, disabling Fast Startup and resetting Windows. The shorter 0x000000EF page is the quick reference. If you see it only at startup and the PC then runs fine, suspect a driver loading at boot or Fast Startup; if it comes back during use, add storage and memory to your list.
- Clue: crashes right after an update or after installing a security or "optimizer" tool.
- Do not: run registry cleaners or random "fix all" tools, which often make this one worse.
WHEA_UNCORRECTABLE_ERROR (0x124)
Microsoft documents this stop code as a fatal hardware error, typically related to physical hardware failures: heat, defective hardware, memory, or a processor that is beginning to fail or has failed. A driver causing it is described as less likely but possible. The name comes from the Windows Hardware Error Architecture, which records errors reported by the processor and platform.
Because the hardware itself reported the problem, repair commands are rarely the answer. Work through these in order:
- Remove overclocking. Reset the BIOS to defaults, and disable XMP, EXPO, Precision Boost overrides, manual voltages or undervolting.
- Check heat. Clean vents and heatsinks, confirm fans spin, and watch CPU and graphics temperatures under load with a monitoring tool. Sustained temperatures near 90 degrees Celsius or above are a warning on most chips; the exact limit varies by model.
- Test memory with
mdsched.exeand, for stubborn cases, a longer MemTest86 run. - Inspect power. A weak or aging power supply, a loose power connector, a failing laptop battery or charger can all produce hardware error reports. Desktop users can try a known-good supply.
- Update BIOS and chipset drivers from the manufacturer, because some WHEA crashes are tied to firmware bugs on specific boards.
- Look in Event Viewer for WHEA-Logger entries (System log), which describe the component that reported the error, such as the processor core or a PCI Express device.
Read the general page for 0x00000124 too. If the crashes vanish when you remove an overclock, you have your answer. If they continue at stock settings and temperatures are fine, the CPU, motherboard, memory or power supply is the likely cause, and replacement parts are a technician's call. Do not reinstall Windows to fix this code; it will return.
KERNEL_SECURITY_CHECK_FAILURE (0x139)
This stop code means the kernel's integrity check found that a critical data structure was corrupted or inconsistent, so it stopped before the damage could spread. The name suggests a security attack, but it is usually an ordinary fault: a buggy driver, bad memory or disk problems that damaged data in memory.
Start with the cheapest tests. Update or roll back the drivers you changed most recently (graphics, network, storage and anything that installs a filter driver, such as VPN, antivirus or virtualization tools). Then run sfc and DISM, and test memory. This code is a classic partner of memory faults and unstable overclocks, so undo any tuning. If dumps show a third-party driver repeatedly, remove the software that installed it and install a current version from the vendor. For general background, the Windows 11 blue screen guide covers the broader fix order.
INACCESSIBLE_BOOT_DEVICE (0x7B)
This stop code appears during startup when Windows loses access to the drive that holds the operating system, so it cannot continue loading. The usual triggers are a storage mode change in the BIOS, a failing or disconnected drive, corrupted boot data, a storage controller driver problem after an update, or a recent hardware swap.
The key question is whether anything changed just before the first crash. Check these in order:
- BIOS storage mode: if the setting changed between AHCI, RAID and Intel VMD (names vary by maker), Windows may no longer find its drive. Switching it back often fixes the problem instantly. Do not change it to "fix" a working machine.
- Is the drive detected? Look in the BIOS for the drive model. If the drive is missing, check cables (desktop) or reseat the M.2 SSD, and suspect a failing drive.
- Recovery tools: run Startup Repair, then the offline chkdsk and bootrec steps in the can't boot section.
- Uninstall the latest update from the recovery environment if the crash began after updating.
- BitLocker: have the recovery key ready, as explained in our BitLocker guide.
If the drive is not detected or is clicking, copy data off first, because a reinstall would not help and would risk the files. See hard drive data recovery for realistic expectations.
PAGE_FAULT_IN_NONPAGED_AREA (0x50)
This stop code means Windows tried to use memory that should have been valid and available but was not. The common causes are faulty RAM, a buggy driver, antivirus or disk-filter software, and sometimes file system damage. Because the pattern is "memory that is not what the system expected," memory and drivers deserve the first two tests.
Run mdsched.exe, reset memory overclocking, and check whether the crash dump or screen names a driver. Remove or update third-party security suites, disk encryption or "cleaning" tools you recently installed. Run chkdsk C: /f /r and sfc. If you recently added RAM, remove the new stick and test each stick alone, because mixing different kits is a classic cause. The fuller walkthrough is on our 0x00000050 page.
SYSTEM_SERVICE_EXCEPTION (0x3B)
This stop code means an exception occurred while Windows was transitioning from user-mode code to kernel code to perform a system service, and nothing handled it. It is very often a driver problem, with graphics drivers the most frequent suspect. It can also follow antivirus or overlay software that hooks deeply into the system.
Check the screen or dump for a file name. If it names a graphics driver, do a clean install: download the current driver from the maker, use the vendor's clean installation option, and restart. If it names a security or VPN driver, update or remove that product. If no file is named, run sfc, DISM and a memory test. After the fix, keep the crash log for a week to confirm stability.
DRIVER_IRQL_NOT_LESS_OR_EQUAL (0xD1)
This stop code means a kernel-mode driver tried to access pageable memory at a process level that does not allow it, which is almost always a driver bug. The named file on the screen is usually the best clue you will get. Network drivers (Wi-Fi and Ethernet), graphics drivers, storage drivers and virtualization or VPN drivers appear often.
Match the name to its owner, boot into Safe Mode if the crash prevents normal use, and update, roll back or uninstall that driver. Wireless adapters are frequent offenders after a Windows update; the maker's own driver is often newer than the one Windows offers. If the dump names several unrelated drivers, suspect memory corruption and test RAM. For the general method, see how to update drivers safely.
MEMORY_MANAGEMENT (0x1A)
This stop code reports a severe memory management error, with parameter 1 identifying the exact kind of failure. Faulty RAM, an unstable memory profile, a failing drive used as a page file, or a driver that corrupts memory are the typical causes.
Reset XMP or EXPO to defaults in the BIOS, then run mdsched.exe. If the test passes but the crashes continue, remove all but one stick and test each stick in each slot. A stick that fails in every slot is bad, and a slot that fails with every stick suggests a motherboard problem. Laptops with soldered memory cannot be swapped this way and are a case for professional diagnosis. In WinDbg, parameter 1 from !analyze -v can narrow the cause; look it up on Microsoft's bug check 0x1A page.
UNEXPECTED_STORE_EXCEPTION (0x154)
This stop code means the store component, which manages memory compression and paging, hit an unexpected exception. In practice it often points to a storage device or storage driver problem, and sometimes to antivirus software interfering. It is a favorite on laptops with aging drives or SSDs with outdated firmware.
Check drive health first: run chkdsk C: /f /r, use the SSD maker's health tool, and read SMART data. Update the SSD firmware and the storage and chipset drivers from the PC maker. If you use third-party antivirus, temporarily switch to Microsoft Defender as a test. Disable Fast Startup with powercfg /h off for a clean test. If the drive reports reallocated or pending sectors, plan replacement and back up now. Our SSD vs HDD upgrade and repair cost guide helps you weigh a replacement.
IRQL_NOT_LESS_OR_EQUAL (0xA)
This stop code means kernel-mode code tried to access memory with an interrupt level that was too high for that memory. The causes are similar to 0xD1: a faulty driver, faulty memory, or software that hooks into the kernel. It is one of the oldest codes on Windows, so many guides about it are outdated.
Start with what changed. Remove new hardware, roll back the latest driver, and run the memory test. If the crash happens when using a specific device (a USB dock, a Bluetooth adapter, a webcam), unplug it and test. If it only happens after sleep or wake, update chipset and power management drivers and compare. If you cannot trace it after the driver and memory steps, treat it as a candidate for expert help.
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (0x7E)
This stop code means a system thread generated an exception that the error handler did not catch, and the screen frequently names the driver file responsible, for example one ending in .sys. That name is the single most valuable detail, so photograph it.
Search for the file name to find which driver or software owns it. Then update or roll back that component. If the PC crashes before you can log in, use Safe Mode or recovery, where problem drivers do not load. A graphics driver is the most common owner on desktops; network and storage drivers are the usual ones on laptops. The fuller guide is on the 0x0000007E page.
What about 0xc0000142?
The error 0xc0000142 is not a blue screen stop code. It is an application error that appears when one program cannot start correctly, usually because of damaged runtime libraries, a blocked DLL or a mismatched installation. Windows keeps running when it appears. Because many people search for it alongside blue screen terms, it deserves a clear boundary: if only one program fails, follow our 0xc0000142 guide; if the whole PC halts, use this page.
Hardware versus software triage: a table you can follow
To separate hardware from software, change one thing at a time in order of cost: repair software first (sfc, DISM, drivers, updates), then test the cheap hardware (memory, drive, temperatures, power), then isolate parts by removing or swapping them. If the crashes stop in a clean environment, the cause is software; if they continue, it is hardware.
| Step | What you do | If crashes stop | If crashes continue |
|---|---|---|---|
| 1. Repair | sfc, DISM, chkdsk | Corrupted files were the cause | Go to step 2 |
| 2. Roll back changes | Roll back driver, uninstall latest update, remove new software | Driver or update conflict; wait for a fixed version | Go to step 3 |
| 3. Safe Mode test | Use the PC in Safe Mode for a day or the same task that crashes | A third-party driver or program causes it; use clean boot to find which | Hardware or a core driver; go to step 4 |
| 4. Reset firmware settings | BIOS defaults, no XMP or overclock, update BIOS | Unstable tuning or firmware bug | Go to step 5 |
| 5. Memory test | mdsched, then MemTest86; test sticks individually | A stick or slot was faulty; replace it | Go to step 6 |
| 6. Drive test | Vendor tool, SMART, chkdsk, cable check; try another drive | Failing drive; clone and replace | Go to step 7 |
| 7. Heat and power | Clean dust, watch temperatures, try another power supply or charger | Cooling or power was the cause | Go to step 8 |
| 8. Clean Windows test | Back up, then try a fresh Windows install or boot another OS from USB | Windows installation was damaged | CPU, motherboard or other component; get a pro |
A key idea in this table is the clean test in step 8: if a freshly installed Windows crashes with the same stop code, no amount of software repair will help. Only do it after a verified backup, and prefer a technician if you do not have one. Our guide on data recovery versus data backup explains why a tested backup is the safest foundation for any repair.
Three realistic scenarios (illustrative)
These examples are illustrative composites, not real client cases. They show how the stop code, the timing and one change at a time lead to a fix, and how long each path typically takes. Costs and times are rough estimates for planning.
Scenario 1: CRITICAL_PROCESS_DIED after a graphics driver update
A freelancer with a three-year-old laptop installs a new graphics driver on Monday evening. On Tuesday morning the laptop shows CRITICAL_PROCESS_DIED twice within an hour. The timing points to the driver. She boots to Safe Mode by interrupting startup, opens Device Manager, rolls back the display driver, restarts, and runs sfc /scannow and DISM. No crashes appear over the next week. Total time: about 50 minutes, cost: nothing. She waits two weeks before trying the newer driver, then installs the maker's clean version.
Scenario 2: Random codes on a gaming desktop
A desktop shows MEMORY_MANAGEMENT on Friday, PAGE_FAULT_IN_NONPAGED_AREA on Saturday and KERNEL_SECURITY_CHECK_FAILURE on Sunday. Three codes in three days is the memory or power signature. The owner resets the BIOS to defaults, which removes the XMP profile, and the crashes stop for four days, then return. A mdsched.exe pass reports errors. Testing the two sticks one at a time shows that one fails in both slots. A replacement 16 GB kit costs roughly 60 to 120 CAD depending on the market and speed, and the crashes end. Total time: a weekend, mostly waiting on tests.
Scenario 3: INACCESSIBLE_BOOT_DEVICE after a BIOS update
A small office PC shows INACCESSIBLE_BOOT_DEVICE right after a BIOS update. The update reset the storage mode from AHCI to RAID, so Windows no longer finds its drive. The user opens the BIOS, sets the storage mode back, saves and boots into Windows. Because the drive is encrypted, the BitLocker recovery key screen appears once; the key is retrieved from the company Microsoft account. Total time: 30 minutes. The lesson is to note the storage setting and have the key at hand before changing firmware.
What blue screen fixes cost in CAD: DIY versus a technician
Software-side fixes (sfc, DISM, driver rollback, update removal) cost nothing but time. Hardware fixes depend on the part: memory is often the cheapest, an SSD is moderate, and a motherboard or processor is the most expensive. Prices vary by market and model, so treat these as planning ranges.
| Cause found | DIY cost (CAD, rough) | Time | When a technician saves money |
|---|---|---|---|
| Corrupt files or bad driver | 0 | 1 to 2 hours | When you are unsure which driver or are locked out of Windows |
| Faulty RAM | About 60 to 150 for a replacement kit | 1 hour plus tests | On laptops with soldered or hard-to-reach memory |
| Failing SSD or hard drive | About 80 to 250 for a replacement drive | 2 to 4 hours with cloning | When the drive holds data you must save |
| Overheating | 0 to 30 for compressed air or thermal paste | 1 hour | On laptops that need disassembly |
| Power supply or charger | About 80 to 200 | 1 hour | When you cannot test with a known-good unit |
| Motherboard or CPU | Often several hundred | Varies | Always get a diagnosis before buying |
The IT Cares Expert Consultation is a single 60 minute session at 119.99$ CAD. For a blue screen, a session usually covers reading your dumps, running the repair sequence together with you, and telling you whether a hardware part is likely at fault so you do not buy the wrong one. It is often cheaper than replacing a component by guesswork. For large drives that need cloning or a possible recovery, the cost of data recovery varies by case; the page on hard drive data recovery explains what affects it.
Prevent repeat blue screens
The best prevention is a short routine: keep a tested backup, create a restore point before big changes, get drivers only from trusted sources, avoid overclocking on a work machine, and keep dust and heat under control. These habits take minutes and turn a blue screen from a crisis into an inconvenience.
Blue screen checklist (screenshot or print this)
- I photographed the screen and wrote down the stop code name and any .sys file.
- I noted what changed in the last two weeks (update, driver, hardware, BIOS, software).
- My important files exist in two places, and I opened the second copy to check.
- I know where my BitLocker recovery key is saved.
- I ran
sfc /scannowandDISM /Online /Cleanup-Image /RestoreHealth. - I rolled back the most recently changed driver or uninstalled the latest update.
- I ran
mdsched.exeand reset any memory overclock or XMP profile. - I ran
chkdsk C: /f /rand checked drive health. - I copied C:\Windows\Minidump to my desktop and looked for a repeating driver.
- I checked temperatures and cleaned dust from vents and fans.
- I stopped when the PC would not boot or the drive showed warning signs, and asked for help.
Habits that keep stop codes away
- Update drivers deliberately: from the PC or component maker, one at a time, not with a bulk updater.
- Delay optional preview updates on work machines and let others find the problems first.
- Keep free disk space of at least 15 percent on the system drive, since a full drive causes odd behavior and failed updates.
- Do not stack security suites. One antivirus is enough; two can clash at the driver level.
- Avoid pulling the plug during updates, and use a surge protector or UPS where the power is unreliable.
- Review drive health a few times a year with the maker's tool.
Official resources
Microsoft's own documents are the authority on the meaning of each stop code. This guide's names and hex values were checked against the Microsoft Learn bug check reference, and the description of 0x124 against its dedicated Microsoft page. For deeper work, Microsoft Learn also documents WinDbg, crash dump analysis and per-code pages for every bug check listed above, and the Windows support site has a consumer-oriented guide to resolving blue screen errors. The links at the end of this article list the pages that were opened for verification.
When to stop and call a professional
Call a technician if the PC will not boot, if crashes continue after the repair, driver and memory steps, if you hear clicking from a drive, if there is a burning smell or severe heat, or if the machine holds data you cannot afford to lose and has no backup. Stopping early is cheaper than repeated forced restarts, which can damage the file system and turn a repairable problem into a recovery job.
IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. A remote session lets a technician connect to your PC while you watch, read the dumps, run the repair sequence, and explain which part is likely failing. If the computer cannot start at all, an on-site visit in Quebec or a lab diagnosis may be the right path. To talk to someone now, call 1 (888) 711-9428 or book a remote session. Mention the stop code and when it started; it helps us prepare.
Still stuck? Get a technician on it now
Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.
Frequently asked questions
Related guides
- CRITICAL_PROCESS_DIED: 10 fixes for Windows 11
- Fix Windows error 0x000000EF
- How to fix the blue screen of death on Windows 11
- Fix Windows error 0x00000124 (WHEA)
- Fix Windows error 0x00000050 (page fault)
- Fix Windows error 0x0000007E
- Fix Windows error 0x00000133 (DPC watchdog)
- Fix application error 0xc0000142
- Black screen of death: how to fix it
- Windows 11 Safe Mode: start, exit and fix when stuck
- Windows 11 Automatic Repair loop and stuck updates
- BitLocker recovery key after a Windows update
- How to update drivers safely
- Hard drive data recovery
Sources and official references
Last verified: October 1, 2026
