Windows 11 Blue Screen Stop Codes: How to Read Your Code and Fix CRITICAL_PROCESS_DIED, 0x124 and More

Reviewed by IT Cares technicians · Updated October 1, 2026

Windows 11 laptop on a dark desk with a blue crash screen and a notebook for writing down a stop code
A blue screen is Windows protecting your data. The stop code is the clue that tells you where to look first.

Quick fix (4 steps)

  1. Photograph the screen and write down the stop code name (for example CRITICAL_PROCESS_DIED) and any file named after it.
  2. Find the code in the lookup table and apply the first fix in its row.
  3. If Windows boots, open Windows Terminal as administrator and run sfc /scannow, then DISM /Online /Cleanup-Image /RestoreHealth.
  4. If it keeps crashing or will not start, use the hardware versus software triage and consider calling a professional.

What a Windows 11 stop code is, and why it matters

A stop code is the name and hex number Windows shows when its kernel detects a condition it cannot safely continue from, so it halts the system on purpose to protect your data. Microsoft calls this event a bug check, and the stop code is the single most useful clue you get about what failed. A blue screen is not a virus and it is rarely a sign that your PC is finished. It is the operating system choosing a controlled stop over silent corruption.

People search for "windows 11 blue screen" in the middle of a bad moment, so this page is built as a hub. It teaches you to read the code, gives you a lookup table with the usual cause and the first fix for each common code, collects every copy-paste command in one place, and shows you how to separate hardware failures from software ones. When you need the full step-by-step for a specific code, the hub points you to the matching page on this site instead of repeating it.

If your code is one of these, jump straight to the deep guide:

Stop code, error code and app error are three different things

Much of the confusion around these searches comes from mixing up three kinds of failure. A stop code (bug check) takes down the whole operating system and shows a full-screen message, for example CRITICAL_PROCESS_DIED with the value 0xEF. A Windows Update error code such as 0x800f0922 appears inside Settings and does not crash the PC. An application error such as 0xc0000142 ("the application was unable to start correctly") appears in a small dialog box when one program fails to start, while Windows itself keeps running.

The distinction matters because the fixes are different. If a single program shows 0xc0000142, you do not need a memory test; you need to repair that program or its runtime libraries, as explained in our 0xc0000142 guide. If the whole screen turns blue or black and the PC restarts, you are in stop code territory, and everything below applies.

The screen might not be blue anymore

Recent Windows 11 builds can show the crash screen in a different color, and the layout has been simplified compared with older Windows versions. Whatever the color, the information you need is the same: a stop code name, usually a percentage counter while Windows collects data, a QR code, and sometimes the name of a file such as a driver ending in .sys. If your PC shows a completely black screen with no text at all, that is a different symptom with its own causes, covered in our black screen of death guide.

Read your stop code in 60 seconds

To read a stop code in 60 seconds, capture the code name and any .sys file name, ask three quick questions (what changed, when does it crash, and is it the same code every time), and then match the code to a family: memory, driver, storage, hardware error or system process. That short routine replaces hours of random fixes, because it tells you which part of the machine to test first.

Use this routine every time. It takes about a minute, and the notes you make are valuable if you later ask a technician for help.

Step 1 (15 seconds): capture the evidence

Photograph the screen with your phone before the PC restarts. Write down three things: the stop code name in capital letters with underscores, the hex value if it appears, and the name of any file listed as "What failed" on versions that show it. If the PC restarts too fast to read, do not worry: Windows records the code, and the later sections show where to find it again.

Step 2 (20 seconds): ask the three questions

  1. What changed in the last two weeks? A new Windows update, a graphics driver, new RAM, a new SSD, a BIOS update, new antivirus or overclocking software. A crash that starts right after a change is almost always related to it.
  2. When does it crash? At boot (storage, boot files, drivers), under load such as gaming or video export (heat, power supply, graphics driver), when idle or waking from sleep (power management drivers), or at random times (often memory or storage).
  3. Is the code the same every time? A repeating code points to one cause. Different codes on each crash usually mean memory corruption, unstable power or a failing drive.

Step 3 (25 seconds): match the code to a family

FamilyTypical stop codesFirst suspectFirst move
Driver or software faultDRIVER_IRQL_NOT_LESS_OR_EQUAL (0xD1), SYSTEM_SERVICE_EXCEPTION (0x3B), SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (0x7E), IRQL_NOT_LESS_OR_EQUAL (0xA)The driver named on screen or the last one installedRoll back or update that driver
MemoryMEMORY_MANAGEMENT (0x1A), PAGE_FAULT_IN_NONPAGED_AREA (0x50)RAM, XMP or overclock, or a driver corrupting memoryWindows Memory Diagnostic, reset memory profile
StorageINACCESSIBLE_BOOT_DEVICE (0x7B), UNEXPECTED_STORE_EXCEPTION (0x154)SSD or hard drive, cable, storage mode in BIOSDrive health check, chkdsk, BIOS storage mode
Hardware error reportWHEA_UNCORRECTABLE_ERROR (0x124)CPU, heat, power, memory or overclockRemove overclock, check cooling, test memory
Integrity or process failureCRITICAL_PROCESS_DIED (0xEF), KERNEL_SECURITY_CHECK_FAILURE (0x139)Corrupt system files, a driver, or failing storage or memorysfc, DISM, recent update check

This table is a starting map, not a verdict. Drivers can cause nearly any stop code, and a hardware fault can masquerade as a software one, which is why the lookup table and the triage table later in the article give you an order of operations rather than a single answer.

Keep the evidence

Before you start fixing, save a photo of the screen and copy any files in C:\Windows\Minidump to a folder on your desktop. Some repair steps, and a technician later, can use those files to see the pattern across several crashes instead of just the last one.

Windows 11 stop code lookup table: code, name, usual cause, first fix

Use this table to translate a stop code into its usual cause and the first fix to try. Names and hex values come from Microsoft's bug check reference; the causes are the common ones seen in practice, so treat them as leads to test, not guarantees. Always try the first fix before the heavy options such as Reset this PC.

The first group is the eleven codes people see most. The second group lists other codes you may meet. If your code is not listed, search for the stop code name on Microsoft Learn, or open your minidump and run !analyze -v in WinDbg, explained in the minidump section.

HexStop code nameUsual cause (hedged)First fix to try
0xEFCRITICAL_PROCESS_DIEDA critical system process ended; corrupt system files, a bad driver or update, sometimes failing storage or memorysfc /scannow then DISM /Online /Cleanup-Image /RestoreHealth
0x124WHEA_UNCORRECTABLE_ERRORFatal hardware error reported by the processor or platform; heat, power, failing CPU or memory, overclocking (a driver is less likely)Disable overclock and XMP, check fans and temperatures, run mdsched.exe
0x139KERNEL_SECURITY_CHECK_FAILUREKernel detected corrupted data structures; faulty drivers, memory problems or disk issuesUpdate or roll back recent drivers, sfc, memory test
0x7BINACCESSIBLE_BOOT_DEVICEWindows cannot read the boot drive; storage mode changed in BIOS, failing drive, boot data or storage driver problemCheck BIOS storage mode (AHCI, RAID, VMD), reseat cables, run repair from recovery
0x50PAGE_FAULT_IN_NONPAGED_AREAWindows referenced memory that should exist but did not; bad RAM, a faulty driver, antivirus or file system damageMemory test, update drivers, remove recent software
0x3BSYSTEM_SERVICE_EXCEPTIONAn error during a system service call, commonly a graphics or other driverClean install the graphics driver, check the file named on screen
0xD1DRIVER_IRQL_NOT_LESS_OR_EQUALA driver accessed memory at the wrong time or address; often network, graphics or storage driversIdentify the .sys file, roll back or update that driver
0x1AMEMORY_MANAGEMENTA serious memory management problem; faulty RAM, unstable memory profile or driverReset XMP or EXPO to default, run mdsched.exe, reseat RAM
0x154UNEXPECTED_STORE_EXCEPTIONAn unexpected error in the memory store component; often storage device or driver issues, sometimes antivirusCheck drive health, chkdsk C: /f /r, update storage and chipset drivers
0xAIRQL_NOT_LESS_OR_EQUALKernel or a driver touched memory with the wrong privilege level; drivers or faulty memoryRoll back the last driver, test memory
0x7ESYSTEM_THREAD_EXCEPTION_NOT_HANDLEDA system thread raised an error nobody handled; very often a named driverUpdate or remove the driver in the "What failed" line, boot to Safe Mode if needed

Other codes you may meet

HexStop code nameWhere to start
0x133DPC_WATCHDOG_VIOLATIONStorage and other drivers that stall; update SSD firmware and storage drivers. See our 0x133 page
0x1EKMODE_EXCEPTION_NOT_HANDLEDDriver or kernel-mode code fault; identify the file named on screen
0x9FDRIVER_POWER_STATE_FAILURESleep and wake problems; update chipset, network and graphics drivers, check power settings
0x116VIDEO_TDR_FAILUREGraphics driver stopped responding; clean install the graphics driver and check temperatures
0x101CLOCK_WATCHDOG_TIMEOUTA processor core stopped responding; BIOS update, remove overclock, check cooling
0x7AKERNEL_DATA_INPAGE_ERRORWindows could not read data from disk into memory; drive, cable, or memory; run chkdsk and a drive health check
0xEDUNMOUNTABLE_BOOT_VOLUMEThe system volume could not be mounted; file system damage; repair from recovery with chkdsk
0x109CRITICAL_STRUCTURE_CORRUPTIONKernel code or data was modified; drivers or memory fault, occasionally hardware
0x9CMACHINE_CHECK_EXCEPTIONProcessor reported a hardware error; treat like 0x124 and test heat, power and overclock
0xC000021AWINLOGON_FATAL_ERRORA critical user-mode subsystem failed; system file damage or failed update; see recovery and repair steps

How to use the table without overthinking it

Match your code, perform the first fix, and then test whether the PC survives a normal day. Do not stack five changes at once. If you update the graphics driver, roll back a Windows update, and change BIOS settings in the same hour, a stable result teaches you nothing, and a new crash cannot be traced. One change, one day of use, one note in your log. That discipline is what separates a clean diagnosis from a pile of guesses.

If the first fix does not help, the next best step is the hardware versus software triage table, which tells you what to test in what order. If the PC cannot start at all, jump to what to do when Windows will not boot.

Patterns that point to a family of causes

Illustration of a laptop connected to icons for memory, storage drive, processor and drivers, representing blue screen triage

The copy-paste command toolkit for blue screens

Six repair tools solve most software-side blue screens: sfc for system files, DISM for the component store, chkdsk for the disk, mdsched for memory, a driver rollback for a recent device change, and uninstalling the latest update. Run them in this order, one at a time, and note the result of each. All commands below are standard Windows tools and none of them deletes your personal files.

Open Windows Terminal (Admin) by right-clicking the Start button and choosing it. If Windows will not start normally, boot to Safe Mode or to the recovery command prompt first; see our Windows 11 Safe Mode guide for every way to get there, including when it is stuck.

1. System File Checker (sfc)

SFC scans protected system files and replaces damaged ones from a cached copy. It is the first command for CRITICAL_PROCESS_DIED, KERNEL_SECURITY_CHECK_FAILURE and any unexplained crash.

sfc /scannow

Wait for the scan to reach 100 percent, which can take 10 to 20 minutes. The result says one of three things: no integrity violations, found and repaired corrupt files, or found corrupt files it could not fix. The third answer means you need DISM first, then sfc again.

2. DISM (repair the component store)

DISM repairs the source that sfc copies from. Run it when sfc cannot repair files, or even before sfc on a machine that has had update problems.

DISM /Online /Cleanup-Image /CheckHealth
DISM /Online /Cleanup-Image /ScanHealth
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow

RestoreHealth needs an internet connection because it may download replacement files from Windows Update. A progress bar can sit at 20 percent or 62.3 percent for a long time without being stuck. Give it at least 30 minutes before you worry. Then run sfc once more.

3. Check Disk (chkdsk)

Chkdsk finds and repairs file system errors and flags bad sectors. It is the right tool for UNEXPECTED_STORE_EXCEPTION, KERNEL_DATA_INPAGE_ERROR, UNMOUNTABLE_BOOT_VOLUME and any crash that coincides with slow file access.

chkdsk C: /f /r

Windows will say it cannot lock the drive and offer to run at the next restart; type Y and restart. The /r option reads every sector, so on a 1 TB drive the scan can take one to several hours. Do not interrupt it. If chkdsk reports bad sectors on a drive that keeps growing them, the drive is failing. Stop repairing and copy your data off first, then replace it.

Failing drive warning

Clicking sounds, a drive that disappears from the file explorer, SMART warnings, or chkdsk finding more bad sectors each run are all signs to back up immediately. Heavy repair scans on a dying drive can make recovery harder. Our guide to hard drive data recovery explains what is possible and what to avoid.

4. Windows Memory Diagnostic (mdsched)

Memory faults cause the most confusing, random stop codes. The built-in test is quick and free.

mdsched.exe

Choose "Restart now and check for problems." The PC reboots into a blue test screen, runs a standard pass in about 10 to 20 minutes and restarts into Windows. The result appears as a notification, or in Event Viewer under Windows Logs, System, from the source MemoryDiagnostics-Results. One error in a pass is enough to suspect a bad stick. A clean pass does not prove the RAM is perfect, because subtle faults can need many hours with a longer test such as MemTest86 (a separate free download that runs from a USB drive).

Before blaming a stick, reset the memory profile. If the BIOS has XMP, EXPO or a manual overclock on, set it back to default and test again. Many "bad RAM" cases turn out to be a profile that the CPU's memory controller cannot hold stable.

5. Driver rollback or removal

If the crash started after a driver change, use Device Manager. Right-click Start, choose Device Manager, expand the category (Display adapters, Network adapters, Storage controllers), double-click the device, choose the Driver tab, and select Roll Back Driver if the button is available. If it is grey, use Uninstall Device, tick "Attempt to remove the driver for this device" when offered, restart and let Windows reinstall a default version.

To list the drivers installed on the machine, which helps match a .sys name from a crash screen to a vendor:

driverquery /v /fo table
pnputil /enum-drivers

Download replacements only from the PC maker, the component maker (Intel, AMD, NVIDIA, Realtek) or Windows Update. For a step-by-step approach, read how to update drivers safely. If your crash is graphics specific, our GPU driver crashed guide covers a clean install.

6. Uninstall the latest update

If the first crash followed a Windows update, go to Settings, Windows Update, Update history, then Uninstall updates (at the bottom under Related settings). Pick the most recent entry, uninstall it, restart, and pause updates for a few days. This is a diagnostic step as much as a fix: if the crashes stop, you have found the trigger, and you can look for an updated driver from the manufacturer before letting the update return. If the PC is stuck in a loop before you can get to Settings, see the Automatic Repair loop guide.

7. Turn off Fast Startup while you test

Fast Startup keeps parts of the kernel state between shutdowns, which can carry a bad driver state forward. For a clean test, run:

powercfg /h off

This disables hibernation and Fast Startup. You can turn it back on later with powercfg /h on. A full shutdown followed by a cold start is a clean test of whether a driver state is the culprit.

A sensible order, as a short list

  1. Photograph the code and note recent changes.
  2. Run sfc /scannow, then DISM, then sfc again if needed.
  3. Roll back the most recently changed driver or uninstall the latest update.
  4. Run mdsched.exe and reset any memory overclock.
  5. Run chkdsk C: /f /r and check drive health.
  6. Read the minidump to see which driver repeats.
  7. If crashes continue, move to the triage table and consider help.

Do not run these when the screen is black and nothing responds

If the PC will not reach the desktop or Safe Mode, use the recovery environment steps in the next sections. Repeatedly forcing power-offs risks file system damage, so give the system a few minutes before you hold the power button.

Find and read the minidump: BlueScreenView and WinDbg basics

Every blue screen can leave a small crash file called a minidump in C:\Windows\Minidump, and reading it shows the stop code and the drivers that were loaded when the crash happened. If the same driver shows up in several dumps, you have your best lead. You do not need to be a developer to read the basics, and the free tools below do the heavy lifting.

Where the crash files live

The Minidump folder is protected, so copy the files to your desktop before opening them, rather than changing permissions. If the folder is empty, dump writing may be off, the page file may be disabled, or a cleanup tool may have removed old dumps.

Make sure Windows is saving dumps

Press Windows + R, type sysdm.cpl and press Enter. Open the Advanced tab, choose Settings under Startup and Recovery, and check the following:

  1. Under "Write debugging information," choose Automatic memory dump or Small memory dump (256 KB). Either one produces a file the tools below can read.
  2. Untick Automatically restart while you troubleshoot, so the screen stays long enough to photograph. Tick it again afterward if you prefer.
  3. Leave the page file on (Advanced, Performance Settings, Advanced, Virtual memory), because crash dump creation depends on it.

BlueScreenView: the fast way to read dumps

BlueScreenView is a small free utility by NirSoft that reads the minidump folder and lists each crash in a table. Download it only from NirSoft's own site, because look-alike downloads exist. Open it and you will see a row per crash with the date, stop code, the parameters, and a likely culprit "caused by driver" column. The lower pane highlights drivers found on the crash stack in red.

How to use what you see:

The tool's guess is a hint, not a diagnosis. A driver can be flagged because it was on the stack while memory was corrupted by something else. Treat a repeated flag across several crashes as meaningful, and a one-off flag as weak.

WinDbg basics: the three commands that matter

WinDbg is Microsoft's official debugger, available free from the Microsoft Store and described in Microsoft's debugging documentation. For a home or small office case you only need a few steps:

  1. Open WinDbg, choose File, then Open dump file, and select a copied .dmp file.
  2. Set the symbol path so Windows can translate addresses into names: .symfix then .reload.
  3. Run the analysis: !analyze -v.
.symfix
.reload
!analyze -v
lmvm nvlddmkm

The analysis prints the bug check name and number, its parameters, a line such as MODULE_NAME or IMAGE_NAME that names the probable module, and a FAILURE_BUCKET_ID that groups similar crashes. The last command, lmvm followed by a module name (nvlddmkm is only an example), prints that driver's version and date, which helps you decide whether an update exists. Microsoft also documents the command !analyze -show followed by a bug check code to display information about the code itself.

Analysis can take a minute the first time while symbols download. If the output says the probable cause is "memory corruption," treat that as a signal to test RAM, remove overclocks and consider enabling Driver Verifier only with expert guidance, because Driver Verifier deliberately stresses drivers and can cause boot loops on a healthy but sensitive system.

What to write down from a dump

Stop code name and hex value. Parameter 1 (it sometimes explains the type of failure). The module or driver named. The date and what you were doing. Keep a simple log: date, code, driver, what you changed. Five lines are enough to see a pattern, and a technician can use them to save an hour.

When Windows will not start: recovery, Safe Mode and bcdedit

If a blue screen loop keeps you out of Windows, force the Windows Recovery Environment by interrupting startup three times, then use Troubleshoot, Advanced options to run Startup Repair, uninstall updates, enter Safe Mode or open a command prompt. Write down your BitLocker recovery key before you start because recovery tools may ask for it. Do this calmly: each forced power-off carries a small risk to the file system, so make each attempt count.

Reach the recovery environment

Turn the PC on, and as soon as the manufacturer logo or spinning dots appear, hold the power button to turn it off. Repeat twice more. On the next start, Windows should open the recovery screen ("Preparing Automatic Repair" and then "Choose an option"). Some PCs do this on their own after two failed boots. If you reach a repair loop that never ends, our guide on the Automatic Repair loop covers the escape routes.

The useful options, in order

Option (Troubleshoot, Advanced options)Use it forNotes
Startup RepairBoot configuration damage, 0x7B or 0xED style failuresHarmless to try first
Uninstall UpdatesCrashes that began after a quality or feature updateTry the latest quality update first
Startup Settings, Safe ModeDriver faults, to remove or roll back a driverPress 4 or F4 for Safe Mode, 5 or F5 with networking
System RestoreReturn to a restore point before the problemOnly works if restore points exist
Command Promptchkdsk, sfc offline, bcdedit, copying files offDrive letters may differ here, so check with dir

Offline repair commands from the recovery command prompt

In recovery, the Windows drive often appears as D: instead of C:. Confirm with dir D:\ and look for the Windows folder, then run (replace D: if yours differs):

chkdsk D: /f /r
sfc /scannow /offbootdir=D:\ /offwindir=D:\Windows
DISM /Image:D:\ /Cleanup-Image /RestoreHealth

The DISM offline repair may need a source image if the component store itself is damaged; do not guess at this one, and stop if errors repeat.

Boot configuration with bcdedit and bootrec

These commands inspect and repair how Windows starts. View the current entries first, and change only what you understand:

bcdedit /enum
bootrec /scanos
bootrec /rebuildbcd
bcdedit /set {default} bootmenupolicy legacy

The last line brings back the classic F8 boot menu on a Windows 11 PC, which makes Safe Mode easier to reach if you expect repeated crashes. To force Safe Mode on the next boot, use bcdedit /set {default} safeboot minimal, and remember to undo it afterward with bcdedit /deletevalue {default} safeboot, or the PC will keep starting in Safe Mode. On UEFI systems with a damaged EFI partition, bootrec /fixboot may return "access denied," which is a signal to stop and get help rather than experiment with partition tools.

BitLocker and the recovery key

Changing BIOS settings, swapping hardware or a failed update can make a BitLocker-protected drive ask for its recovery key. If that screen appears, do not guess; find the key from the Microsoft account or the other places explained in our BitLocker recovery key guide. Without the key, repairs that touch the drive may be blocked, and a reset deletes the data for good.

Code by code: what each common Windows 11 stop code usually means

Each stop code has a typical pattern: CRITICAL_PROCESS_DIED points to system integrity, WHEA_UNCORRECTABLE_ERROR to hardware, KERNEL_SECURITY_CHECK_FAILURE to corruption, INACCESSIBLE_BOOT_DEVICE to storage at boot, and PAGE_FAULT_IN_NONPAGED_AREA to memory or drivers. The sections below add the context that a one-line table cannot, and link to the full guides where they exist. Causes are described as common patterns; any code can have an unusual cause.

CRITICAL_PROCESS_DIED (0xEF)

This stop code means a process that Windows cannot run without ended unexpectedly, so the kernel stopped the system. In practice, the trigger is often damaged system files, a faulty driver, a bad update, or storage and memory problems that corrupt a process while it runs.

The reliable sequence is: boot normally if you can, run sfc and DISM, roll back the last driver, uninstall the last update, then test memory and the drive. The dedicated guide, CRITICAL_PROCESS_DIED: 10 fixes for Windows 11, walks through ten methods in order, including Safe Mode, clean boot, disabling Fast Startup and resetting Windows. The shorter 0x000000EF page is the quick reference. If you see it only at startup and the PC then runs fine, suspect a driver loading at boot or Fast Startup; if it comes back during use, add storage and memory to your list.

WHEA_UNCORRECTABLE_ERROR (0x124)

Microsoft documents this stop code as a fatal hardware error, typically related to physical hardware failures: heat, defective hardware, memory, or a processor that is beginning to fail or has failed. A driver causing it is described as less likely but possible. The name comes from the Windows Hardware Error Architecture, which records errors reported by the processor and platform.

Because the hardware itself reported the problem, repair commands are rarely the answer. Work through these in order:

  1. Remove overclocking. Reset the BIOS to defaults, and disable XMP, EXPO, Precision Boost overrides, manual voltages or undervolting.
  2. Check heat. Clean vents and heatsinks, confirm fans spin, and watch CPU and graphics temperatures under load with a monitoring tool. Sustained temperatures near 90 degrees Celsius or above are a warning on most chips; the exact limit varies by model.
  3. Test memory with mdsched.exe and, for stubborn cases, a longer MemTest86 run.
  4. Inspect power. A weak or aging power supply, a loose power connector, a failing laptop battery or charger can all produce hardware error reports. Desktop users can try a known-good supply.
  5. Update BIOS and chipset drivers from the manufacturer, because some WHEA crashes are tied to firmware bugs on specific boards.
  6. Look in Event Viewer for WHEA-Logger entries (System log), which describe the component that reported the error, such as the processor core or a PCI Express device.

Read the general page for 0x00000124 too. If the crashes vanish when you remove an overclock, you have your answer. If they continue at stock settings and temperatures are fine, the CPU, motherboard, memory or power supply is the likely cause, and replacement parts are a technician's call. Do not reinstall Windows to fix this code; it will return.

KERNEL_SECURITY_CHECK_FAILURE (0x139)

This stop code means the kernel's integrity check found that a critical data structure was corrupted or inconsistent, so it stopped before the damage could spread. The name suggests a security attack, but it is usually an ordinary fault: a buggy driver, bad memory or disk problems that damaged data in memory.

Start with the cheapest tests. Update or roll back the drivers you changed most recently (graphics, network, storage and anything that installs a filter driver, such as VPN, antivirus or virtualization tools). Then run sfc and DISM, and test memory. This code is a classic partner of memory faults and unstable overclocks, so undo any tuning. If dumps show a third-party driver repeatedly, remove the software that installed it and install a current version from the vendor. For general background, the Windows 11 blue screen guide covers the broader fix order.

INACCESSIBLE_BOOT_DEVICE (0x7B)

This stop code appears during startup when Windows loses access to the drive that holds the operating system, so it cannot continue loading. The usual triggers are a storage mode change in the BIOS, a failing or disconnected drive, corrupted boot data, a storage controller driver problem after an update, or a recent hardware swap.

The key question is whether anything changed just before the first crash. Check these in order:

If the drive is not detected or is clicking, copy data off first, because a reinstall would not help and would risk the files. See hard drive data recovery for realistic expectations.

PAGE_FAULT_IN_NONPAGED_AREA (0x50)

This stop code means Windows tried to use memory that should have been valid and available but was not. The common causes are faulty RAM, a buggy driver, antivirus or disk-filter software, and sometimes file system damage. Because the pattern is "memory that is not what the system expected," memory and drivers deserve the first two tests.

Run mdsched.exe, reset memory overclocking, and check whether the crash dump or screen names a driver. Remove or update third-party security suites, disk encryption or "cleaning" tools you recently installed. Run chkdsk C: /f /r and sfc. If you recently added RAM, remove the new stick and test each stick alone, because mixing different kits is a classic cause. The fuller walkthrough is on our 0x00000050 page.

SYSTEM_SERVICE_EXCEPTION (0x3B)

This stop code means an exception occurred while Windows was transitioning from user-mode code to kernel code to perform a system service, and nothing handled it. It is very often a driver problem, with graphics drivers the most frequent suspect. It can also follow antivirus or overlay software that hooks deeply into the system.

Check the screen or dump for a file name. If it names a graphics driver, do a clean install: download the current driver from the maker, use the vendor's clean installation option, and restart. If it names a security or VPN driver, update or remove that product. If no file is named, run sfc, DISM and a memory test. After the fix, keep the crash log for a week to confirm stability.

DRIVER_IRQL_NOT_LESS_OR_EQUAL (0xD1)

This stop code means a kernel-mode driver tried to access pageable memory at a process level that does not allow it, which is almost always a driver bug. The named file on the screen is usually the best clue you will get. Network drivers (Wi-Fi and Ethernet), graphics drivers, storage drivers and virtualization or VPN drivers appear often.

Match the name to its owner, boot into Safe Mode if the crash prevents normal use, and update, roll back or uninstall that driver. Wireless adapters are frequent offenders after a Windows update; the maker's own driver is often newer than the one Windows offers. If the dump names several unrelated drivers, suspect memory corruption and test RAM. For the general method, see how to update drivers safely.

MEMORY_MANAGEMENT (0x1A)

This stop code reports a severe memory management error, with parameter 1 identifying the exact kind of failure. Faulty RAM, an unstable memory profile, a failing drive used as a page file, or a driver that corrupts memory are the typical causes.

Reset XMP or EXPO to defaults in the BIOS, then run mdsched.exe. If the test passes but the crashes continue, remove all but one stick and test each stick in each slot. A stick that fails in every slot is bad, and a slot that fails with every stick suggests a motherboard problem. Laptops with soldered memory cannot be swapped this way and are a case for professional diagnosis. In WinDbg, parameter 1 from !analyze -v can narrow the cause; look it up on Microsoft's bug check 0x1A page.

UNEXPECTED_STORE_EXCEPTION (0x154)

This stop code means the store component, which manages memory compression and paging, hit an unexpected exception. In practice it often points to a storage device or storage driver problem, and sometimes to antivirus software interfering. It is a favorite on laptops with aging drives or SSDs with outdated firmware.

Check drive health first: run chkdsk C: /f /r, use the SSD maker's health tool, and read SMART data. Update the SSD firmware and the storage and chipset drivers from the PC maker. If you use third-party antivirus, temporarily switch to Microsoft Defender as a test. Disable Fast Startup with powercfg /h off for a clean test. If the drive reports reallocated or pending sectors, plan replacement and back up now. Our SSD vs HDD upgrade and repair cost guide helps you weigh a replacement.

IRQL_NOT_LESS_OR_EQUAL (0xA)

This stop code means kernel-mode code tried to access memory with an interrupt level that was too high for that memory. The causes are similar to 0xD1: a faulty driver, faulty memory, or software that hooks into the kernel. It is one of the oldest codes on Windows, so many guides about it are outdated.

Start with what changed. Remove new hardware, roll back the latest driver, and run the memory test. If the crash happens when using a specific device (a USB dock, a Bluetooth adapter, a webcam), unplug it and test. If it only happens after sleep or wake, update chipset and power management drivers and compare. If you cannot trace it after the driver and memory steps, treat it as a candidate for expert help.

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (0x7E)

This stop code means a system thread generated an exception that the error handler did not catch, and the screen frequently names the driver file responsible, for example one ending in .sys. That name is the single most valuable detail, so photograph it.

Search for the file name to find which driver or software owns it. Then update or roll back that component. If the PC crashes before you can log in, use Safe Mode or recovery, where problem drivers do not load. A graphics driver is the most common owner on desktops; network and storage drivers are the usual ones on laptops. The fuller guide is on the 0x0000007E page.

What about 0xc0000142?

The error 0xc0000142 is not a blue screen stop code. It is an application error that appears when one program cannot start correctly, usually because of damaged runtime libraries, a blocked DLL or a mismatched installation. Windows keeps running when it appears. Because many people search for it alongside blue screen terms, it deserves a clear boundary: if only one program fails, follow our 0xc0000142 guide; if the whole PC halts, use this page.

Hardware versus software triage: a table you can follow

To separate hardware from software, change one thing at a time in order of cost: repair software first (sfc, DISM, drivers, updates), then test the cheap hardware (memory, drive, temperatures, power), then isolate parts by removing or swapping them. If the crashes stop in a clean environment, the cause is software; if they continue, it is hardware.

StepWhat you doIf crashes stopIf crashes continue
1. Repairsfc, DISM, chkdskCorrupted files were the causeGo to step 2
2. Roll back changesRoll back driver, uninstall latest update, remove new softwareDriver or update conflict; wait for a fixed versionGo to step 3
3. Safe Mode testUse the PC in Safe Mode for a day or the same task that crashesA third-party driver or program causes it; use clean boot to find whichHardware or a core driver; go to step 4
4. Reset firmware settingsBIOS defaults, no XMP or overclock, update BIOSUnstable tuning or firmware bugGo to step 5
5. Memory testmdsched, then MemTest86; test sticks individuallyA stick or slot was faulty; replace itGo to step 6
6. Drive testVendor tool, SMART, chkdsk, cable check; try another driveFailing drive; clone and replaceGo to step 7
7. Heat and powerClean dust, watch temperatures, try another power supply or chargerCooling or power was the causeGo to step 8
8. Clean Windows testBack up, then try a fresh Windows install or boot another OS from USBWindows installation was damagedCPU, motherboard or other component; get a pro

A key idea in this table is the clean test in step 8: if a freshly installed Windows crashes with the same stop code, no amount of software repair will help. Only do it after a verified backup, and prefer a technician if you do not have one. Our guide on data recovery versus data backup explains why a tested backup is the safest foundation for any repair.

Three realistic scenarios (illustrative)

These examples are illustrative composites, not real client cases. They show how the stop code, the timing and one change at a time lead to a fix, and how long each path typically takes. Costs and times are rough estimates for planning.

Scenario 1: CRITICAL_PROCESS_DIED after a graphics driver update

A freelancer with a three-year-old laptop installs a new graphics driver on Monday evening. On Tuesday morning the laptop shows CRITICAL_PROCESS_DIED twice within an hour. The timing points to the driver. She boots to Safe Mode by interrupting startup, opens Device Manager, rolls back the display driver, restarts, and runs sfc /scannow and DISM. No crashes appear over the next week. Total time: about 50 minutes, cost: nothing. She waits two weeks before trying the newer driver, then installs the maker's clean version.

Scenario 2: Random codes on a gaming desktop

A desktop shows MEMORY_MANAGEMENT on Friday, PAGE_FAULT_IN_NONPAGED_AREA on Saturday and KERNEL_SECURITY_CHECK_FAILURE on Sunday. Three codes in three days is the memory or power signature. The owner resets the BIOS to defaults, which removes the XMP profile, and the crashes stop for four days, then return. A mdsched.exe pass reports errors. Testing the two sticks one at a time shows that one fails in both slots. A replacement 16 GB kit costs roughly 60 to 120 CAD depending on the market and speed, and the crashes end. Total time: a weekend, mostly waiting on tests.

Scenario 3: INACCESSIBLE_BOOT_DEVICE after a BIOS update

A small office PC shows INACCESSIBLE_BOOT_DEVICE right after a BIOS update. The update reset the storage mode from AHCI to RAID, so Windows no longer finds its drive. The user opens the BIOS, sets the storage mode back, saves and boots into Windows. Because the drive is encrypted, the BitLocker recovery key screen appears once; the key is retrieved from the company Microsoft account. Total time: 30 minutes. The lesson is to note the storage setting and have the key at hand before changing firmware.

What blue screen fixes cost in CAD: DIY versus a technician

Software-side fixes (sfc, DISM, driver rollback, update removal) cost nothing but time. Hardware fixes depend on the part: memory is often the cheapest, an SSD is moderate, and a motherboard or processor is the most expensive. Prices vary by market and model, so treat these as planning ranges.

Cause foundDIY cost (CAD, rough)TimeWhen a technician saves money
Corrupt files or bad driver01 to 2 hoursWhen you are unsure which driver or are locked out of Windows
Faulty RAMAbout 60 to 150 for a replacement kit1 hour plus testsOn laptops with soldered or hard-to-reach memory
Failing SSD or hard driveAbout 80 to 250 for a replacement drive2 to 4 hours with cloningWhen the drive holds data you must save
Overheating0 to 30 for compressed air or thermal paste1 hourOn laptops that need disassembly
Power supply or chargerAbout 80 to 2001 hourWhen you cannot test with a known-good unit
Motherboard or CPUOften several hundredVariesAlways get a diagnosis before buying

The IT Cares Expert Consultation is a single 60 minute session at 119.99$ CAD. For a blue screen, a session usually covers reading your dumps, running the repair sequence together with you, and telling you whether a hardware part is likely at fault so you do not buy the wrong one. It is often cheaper than replacing a component by guesswork. For large drives that need cloning or a possible recovery, the cost of data recovery varies by case; the page on hard drive data recovery explains what affects it.

Prevent repeat blue screens

The best prevention is a short routine: keep a tested backup, create a restore point before big changes, get drivers only from trusted sources, avoid overclocking on a work machine, and keep dust and heat under control. These habits take minutes and turn a blue screen from a crisis into an inconvenience.

Blue screen checklist (screenshot or print this)

  • I photographed the screen and wrote down the stop code name and any .sys file.
  • I noted what changed in the last two weeks (update, driver, hardware, BIOS, software).
  • My important files exist in two places, and I opened the second copy to check.
  • I know where my BitLocker recovery key is saved.
  • I ran sfc /scannow and DISM /Online /Cleanup-Image /RestoreHealth.
  • I rolled back the most recently changed driver or uninstalled the latest update.
  • I ran mdsched.exe and reset any memory overclock or XMP profile.
  • I ran chkdsk C: /f /r and checked drive health.
  • I copied C:\Windows\Minidump to my desktop and looked for a repeating driver.
  • I checked temperatures and cleaned dust from vents and fans.
  • I stopped when the PC would not boot or the drive showed warning signs, and asked for help.

Habits that keep stop codes away

Official resources

Microsoft's own documents are the authority on the meaning of each stop code. This guide's names and hex values were checked against the Microsoft Learn bug check reference, and the description of 0x124 against its dedicated Microsoft page. For deeper work, Microsoft Learn also documents WinDbg, crash dump analysis and per-code pages for every bug check listed above, and the Windows support site has a consumer-oriented guide to resolving blue screen errors. The links at the end of this article list the pages that were opened for verification.

When to stop and call a professional

Call a technician if the PC will not boot, if crashes continue after the repair, driver and memory steps, if you hear clicking from a drive, if there is a burning smell or severe heat, or if the machine holds data you cannot afford to lose and has no backup. Stopping early is cheaper than repeated forced restarts, which can damage the file system and turn a repairable problem into a recovery job.

IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. A remote session lets a technician connect to your PC while you watch, read the dumps, run the repair sequence, and explain which part is likely failing. If the computer cannot start at all, an on-site visit in Quebec or a lab diagnosis may be the right path. To talk to someone now, call 1 (888) 711-9428 or book a remote session. Mention the stop code and when it started; it helps us prepare.

Still stuck? Get a technician on it now

Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.

Frequently asked questions

What is a stop code on a Windows 11 blue screen?
A stop code is the name (and often a hex number) Windows shows when it halts to prevent damage, for example CRITICAL_PROCESS_DIED, which is bug check 0xEF. Microsoft calls it a bug check. The name tells you what kind of failure the kernel detected, which narrows the search to drivers, memory, storage or hardware.
Where can I find the stop code after the PC restarts?
Open Event Viewer, then Windows Logs, then System, and look for a BugCheck event (event ID 1001), which records the code and the dump file path. You can also open the minidump files in C:\Windows\Minidump with BlueScreenView or WinDbg. If automatic restart hides the screen, you can turn it off in Startup and Recovery settings.
Is CRITICAL_PROCESS_DIED a hardware or software problem?
It is usually software or driver related, but it can be triggered by a failing drive or bad memory that corrupts a system process. Start with sfc, DISM, a driver rollback and a check of recent updates. If those do not help, test the drive and the memory. Our dedicated CRITICAL_PROCESS_DIED page covers ten fixes in order.
What does WHEA_UNCORRECTABLE_ERROR 0x124 mean?
Microsoft documents it as a fatal hardware error reported through the Windows Hardware Error Architecture, typically related to physical hardware problems such as heat, defective memory, a failing processor or overclocking. A driver is a less likely cause. Remove overclocking, check fans and temperatures and test memory first.
Can a bad Windows update cause a blue screen?
Yes. A cumulative update or a driver delivered through Windows Update can conflict with specific hardware. If crashes began right after an update, uninstall that update from Settings, Windows Update, Update history, Uninstall updates, and pause updates for a few days while checking the manufacturer's site for new drivers.
Can I fix a blue screen without losing my files?
Almost always yes. Repair commands (sfc, DISM, chkdsk) and driver rollbacks do not touch your documents. Use Reset this PC with Keep my files only as a late option, and back up first if you can reach the drive. If the drive itself is failing, stop experimenting and copy data off before anything else.
Why do I get different stop codes each time?
Different codes on different crashes usually point to a shared underlying cause rather than many problems. Random memory corruption from faulty RAM, an unstable overclock or XMP profile, or a failing power supply or SSD can show up as 0x1A, 0x50, 0x3B, 0xD1 and others in turn. Test memory and storage first.
What is INACCESSIBLE_BOOT_DEVICE 0x7B?
It means Windows could not read the system drive during startup. Common triggers include a changed storage mode in the BIOS (AHCI, RAID or Intel VMD), a failing drive, a corrupted boot configuration or a storage driver problem after an update. Check the BIOS storage mode before reinstalling anything, and have your BitLocker key ready.
How do I read a minidump file?
Install BlueScreenView (a free utility by NirSoft) and point it at C:\Windows\Minidump. It lists each crash with its stop code and the drivers found in memory. For deeper analysis, open the .dmp file in WinDbg, load symbols and run !analyze -v. A single driver repeating across several dumps is a strong lead.
How many blue screens are normal?
One isolated blue screen that never returns is usually not a concern, and many machines see one after a power loss or a driver glitch. Two or more in a week, or any blue screen that repeats the same code, deserves investigation. Back up your data when crashes become a pattern.
Can overheating or a failing power supply cause stop codes?
Yes. Heat can trigger WHEA errors and random crashes, and an unstable power supply can cause crashes with no consistent code. Clean dust from vents, check temperatures with a monitoring tool and make sure fans spin. A desktop that crashes only under load is a classic power or cooling signal.
Is it safe to use driver updater or registry cleaner tools to fix a blue screen?
Usually not. Generic driver updaters may install the wrong driver and registry cleaners rarely help with kernel crashes. Prefer drivers from the PC or component maker, or Windows Update, and roll back the one that changed before the crashes started.
When should I call a professional about a blue screen?
Call when the PC will not start, when crashes repeat after sfc, DISM and driver steps, when you hear clicking from a drive, or when the computer holds data you cannot lose. IT Cares offers remote support and on-site help in Quebec. A 60 minute Expert Consultation is 119.99$ CAD.

Sources and official references

Last verified: October 1, 2026

Need Help?