Here is my system info export: https://www.dropbox.com/s/dalj88o21w0s7sc/DEJ%20system%20info.txt?dl=0
It just happened again when I was exporting this the first time, eeek!
Thanks!!
Daniel
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello!
I manage a small team of users running Windows 7 on a network and one of them is getting the BSOD with error "The bugcheck was: 0x000000df".
I tried various things to fix it and using Norton to clean everything up, and uninstalled various useless programmes. The problem seems to have subsided for her.
Then... I changed my own Norton installation from Norton Internet Security to Norton Security with Backup.. and five minutes after I do this I get the same BSOD with the same bugcheck!!
From what I can tell the 0xdf error seems to be a "IMPERSONATING WORKER THREAD" error but I cannot find out how fix this other than usual update drivers etc. Can I find out exactly which programme is causing this? Could it really be Norton or is that just a coincidence? I really don't want to have to do a clean Windows install.
The full error is The bugcheck was: 0x000000df (0xfffff800033b56c0, 0xfffffa800778cf40, 0xfffffa800778cf40, 0x0000000000000000).
Any help would be greatly appreciated. I am downloading the Windows 7 SDK to be able to open the memory.dmp file now.
Here is a link to the dmp file: https://www.dropbox.com/s/f4qt2xojeadmxcu/MEMORY.zip?dl=0
Thanks!
Daniel
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Here is my system info export: https://www.dropbox.com/s/dalj88o21w0s7sc/DEJ%20system%20info.txt?dl=0
It just happened again when I was exporting this the first time, eeek!
Thanks!!
Daniel
Here is a link to the dmp file: https://www.dropbox.com/s/f4qt2xojeadmxcu/MEMORY.zip?dl=0
Thanks
We need the actual DMP file. We cant analyze your text from it
Here is the full dump:
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.23418.amd64fre.win7sp1_ldr.160408-2045
Machine Name:
Kernel base = 0xfffff8000304d000 PsLoadedModuleList = 0xfffff8000328f730
Debug session time: Tue Jun 28 12:53:10.430 2016 (UTC + 1:00)
System Uptime: 0 days 1:16:38.616
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck DF, {fffff800033b56c0, fffffa800778cf40, fffffa800778cf40, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+50328 )
Followup: MachineOwner
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IMPERSONATING_WORKER_THREAD (df)
A workitem forgot to disable impersonation before it completed.
Arguments:
Arg1: fffff800033b56c0, Worker Routine that caused this bugcheck.
Arg2: fffffa800778cf40, Parameter passed to this worker routine.
Arg3: fffffa800778cf40, Pointer to the Workitem.
Arg4: 0000000000000000
Debugging Details:
DUMP_CLASS: 1
DUMP_QUALIFIER: 401
BUILD_VERSION_STRING: 7601.23418.amd64fre.win7sp1_ldr.160408-2045
SYSTEM_MANUFACTURER: Dell Inc.
SYSTEM_PRODUCT_NAME: OptiPlex 7020
SYSTEM_SKU: OptiPlex 7020
SYSTEM_VERSION: 01
BIOS_VENDOR: Dell Inc.
BIOS_VERSION: A00
BIOS_DATE: 04/25/2014
BASEBOARD_MANUFACTURER: Dell Inc.
BASEBOARD_PRODUCT: 02YYK5
BASEBOARD_VERSION: A00
DUMP_TYPE: 1
BUGCHECK_P1: fffff800033b56c0
BUGCHECK_P2: fffffa800778cf40
BUGCHECK_P3: fffffa800778cf40
BUGCHECK_P4: 0
CPU_COUNT: 4
CPU_MHZ: cdc
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3c
CPU_STEPPING: 3
CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1C'00000000 (cache) 17'00000000 (init)
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xDF
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DANIEL-PC
ANALYSIS_SESSION_TIME: 06-28-2016 13:28:59.0993
ANALYSIS_VERSION: 10.0.10586.567 amd64fre
LAST_CONTROL_TRANSFER: from fffff800031488a0 to fffff800030bc400
STACK_TEXT:
fffff88003308b68 fffff800031488a0 : 00000000000000df fffff800033b56c0 fffffa800778cf40 fffffa800778cf40 : nt!KeBugCheckEx
fffff88003308b70 fffff80003354bc6 : 0000000000000000 fffffa80066e2660 0000000000000080 fffffa80066ce9c0 : nt! ?? ::FNODOBFM::`string'+0x50328
fffff88003308c00 fffff800030ae6a6 : fffff88002f65180 fffffa80066e2660 fffff88002f6ffc0 2aceaf39f8f092e2 : nt!PspSystemThreadStartup+0x5a
fffff88003308c40 0000000000000000 : fffff88003309000 fffff88003303000 fffff88003307e20 0000000000000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
THREAD_SHA1_HASH_MOD_FUNC: d1f29412959189b3afdbe9027aabb0d9f3cc18ee
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6715ddb151464496fffbf7e29c55aef80932b978
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+50328
fffff800`031488a0 cc int 3
FAULT_INSTR_CODE: 200f44cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+50328
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5708972e
IMAGE_VERSION: 6.1.7601.23418
FAILURE_BUCKET_ID: X64_0xDF_nt!_??_::FNODOBFM::_string_+50328
BUCKET_ID: X64_0xDF_nt!_??_::FNODOBFM::_string_+50328
PRIMARY_PROBLEM_CLASS: X64_0xDF_nt!_??_::FNODOBFM::_string_+50328
TARGET_TIME: 2016-06-28T11:53:10.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2016-04-09 06:46:22
BUILDDATESTAMP_STR: 160408-2045
BUILDLAB_STR: win7sp1_ldr
BUILDOSVER_STR: 6.1.7601.23418.amd64fre.win7sp1_ldr.160408-2045
ANALYSIS_SESSION_ELAPSED_TIME: 70b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0xdf_nt!_??_::fnodobfm::_string_+50328
FAILURE_ID_HASH: {23bc9582-28e0-c7a3-ff1f-10beb2d4fe7b}
Followup: MachineOwner
We do need the actual log files (called a DMP files) as they contain the only record of the sequence of events leading up to the crash, what drivers were loaded, and what was responsible.
Please follow our instructions for finding and uploading the files we need to help you fix your computer. They can be found here
If you have any questions about the procedure please ask