What does Windows error code 795 (ERROR_CORRUPT_LOG_CORRUPTED) mean?

 
Previous Next
ERROR_CORRUPT_LOG_OVERFULL ERROR_CORRUPT_LOG_UNAVAILABLE

ERROR_CORRUPT_LOG_CORRUPTED

the volume corruption log is itself damaged and must be recreated.

ERROR_CORRUPT_LOG_CORRUPTED means that this condition The structure used to record file-system corruption can no longer be trusted. Because the log may have lost or misrepresented entries, Windows warns that the volume can contain additional damage not reflected in the surviving records.

Where the result appears

  • file-system health checks that open the corruption log.
  • online repair infrastructure after metadata damage.
  • storage telemetry following an unclean shutdown or I/O failure.
  • maintenance operations that attempt to enumerate pending corruptions.

What the result tells you

The value identifies a specific Windows state, but it does not by itself identify the component that introduced that state. Preserve the original this result value, the API or subsystem that produced it, and the object being operated on. A wrapper that replaces it with a generic exception or Boolean failure removes the distinction needed to choose the correct recovery path.

Diagnostic evidence to collect

  • the file-system event describing why the log was rejected.
  • volume dirty state and scan history.
  • underlying disk, controller, and power-loss events.
  • results of a complete read-only scan after the log is recreated.

Correlate the result evidence on one timeline. The first event that changes the state associated with this result is usually more valuable than later retries returning the same code. Record process and thread identity, session, timestamp, API parameters, and the immediately preceding successful operation.

Handling and recovery

Recreate the log through the supported file-system maintenance path, then scan the entire volume. Back up data before invasive repair, especially when other metadata errors or storage faults are present.

Retry after this result only when the evidence shows that an external condition can change. When it is caused by malformed input, revoked authority, unsupported state, hardware damage, or an offline maintenance requirement, an unchanged retry adds noise and can overwrite the earliest useful diagnostics.

Common misinterpretation

Recreating the corruption log restores tracking, not necessarily the files or metadata that were already damaged.

Guidance for developers

Keep it in its Win32/LRESULT domain in structured telemetry. When converting it to an HRESULT, exception, RPC response, or JSON field, retain the source domain and numeric value alongside the human-readable text. Do not branch on the localized message string for it.

A it test should construct the specific state, assert the exact result, and verify that partial resources are released. The recovery test for it should prove that the operation is either deferred until a measurable state change or fails without an uncontrolled retry loop.

References


Looking for a different code? Search another status or error code.