BSOD: The bugcheck was: 0x000000df

Anonymous
2016-06-28T12:15:13+00:00

Hello!

I manage a small team of users running Windows 7 on a network and one of them is getting the BSOD with error "The bugcheck was: 0x000000df".

I tried various things to fix it and using Norton to clean everything up, and uninstalled various useless programmes. The problem seems to have subsided for her.

Then... I changed my own Norton installation from Norton Internet Security to Norton Security with Backup.. and five minutes after I do this I get the same BSOD with the same bugcheck!!

From what I can tell the 0xdf error seems to be a "IMPERSONATING WORKER THREAD" error but I cannot find out how fix this other than usual update drivers etc. Can I find out exactly which programme is causing this? Could it really be Norton or is that just a coincidence? I really don't want to have to do a clean Windows install. 

The full error is The bugcheck was: 0x000000df (0xfffff800033b56c0, 0xfffffa800778cf40, 0xfffffa800778cf40, 0x0000000000000000). 

Any help would be greatly appreciated. I am downloading the Windows 7 SDK to be able to open the memory.dmp file now.

Here is a link to the dmp file: https://www.dropbox.com/s/f4qt2xojeadmxcu/MEMORY.zip?dl=0

Thanks!

Daniel

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

42 answers

Sort by: Oldest
  1. Anonymous
    2016-06-28T12:26:18+00:00

    We do need the actual log files (called a DMP files) as they contain the only record of the sequence of events leading up to the crash, what drivers were loaded, and what was responsible.

    Please follow our instructions for finding and uploading the files we need to help you fix your computer. They can be found here

    If you have any questions about the procedure please ask

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-06-28T12:31:00+00:00

    Here is the full dump:

    ************* Symbol Path validation summary **************

    Response                         Time (ms)     Location

    Deferred                                       SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols

    Symbol search path is: SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols

    Executable search path is: 

    Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64

    Product: WinNt, suite: TerminalServer SingleUserTS

    Built by: 7601.23418.amd64fre.win7sp1_ldr.160408-2045

    Machine Name:

    Kernel base = 0xfffff8000304d000 PsLoadedModuleList = 0xfffff8000328f730

    Debug session time: Tue Jun 28 12:53:10.430 2016 (UTC + 1:00)

    System Uptime: 0 days 1:16:38.616

    Loading Kernel Symbols

    ...............................................................

    ................................................................

    ........................

    Loading User Symbols

    Loading unloaded module list

    ......

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck DF, {fffff800033b56c0, fffffa800778cf40, fffffa800778cf40, 0}

    Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+50328 )

    Followup:     MachineOwner


    2: kd> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Bugcheck Analysis                                    *

    *                                                                             *

    *******************************************************************************

    IMPERSONATING_WORKER_THREAD (df)

    A workitem forgot to disable impersonation before it completed.

    Arguments:

    Arg1: fffff800033b56c0, Worker Routine that caused this bugcheck.

    Arg2: fffffa800778cf40, Parameter passed to this worker routine.

    Arg3: fffffa800778cf40, Pointer to the Workitem.

    Arg4: 0000000000000000

    Debugging Details:


    DUMP_CLASS: 1

    DUMP_QUALIFIER: 401

    BUILD_VERSION_STRING:  7601.23418.amd64fre.win7sp1_ldr.160408-2045

    SYSTEM_MANUFACTURER:  Dell Inc.

    SYSTEM_PRODUCT_NAME:  OptiPlex 7020

    SYSTEM_SKU:  OptiPlex 7020

    SYSTEM_VERSION:  01

    BIOS_VENDOR:  Dell Inc.

    BIOS_VERSION:  A00

    BIOS_DATE:  04/25/2014

    BASEBOARD_MANUFACTURER:  Dell Inc.

    BASEBOARD_PRODUCT:  02YYK5

    BASEBOARD_VERSION:  A00

    DUMP_TYPE:  1

    BUGCHECK_P1: fffff800033b56c0

    BUGCHECK_P2: fffffa800778cf40

    BUGCHECK_P3: fffffa800778cf40

    BUGCHECK_P4: 0

    CPU_COUNT: 4

    CPU_MHZ: cdc

    CPU_VENDOR:  GenuineIntel

    CPU_FAMILY: 6

    CPU_MODEL: 3c

    CPU_STEPPING: 3

    CPU_MICROCODE: 6,3c,3,0 (F,M,S,R)  SIG: 1C'00000000 (cache) 17'00000000 (init)

    DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

    BUGCHECK_STR:  0xDF

    PROCESS_NAME:  System

    CURRENT_IRQL:  0

    ANALYSIS_SESSION_HOST:  DANIEL-PC

    ANALYSIS_SESSION_TIME:  06-28-2016 13:28:59.0993

    ANALYSIS_VERSION: 10.0.10586.567 amd64fre

    LAST_CONTROL_TRANSFER:  from fffff800031488a0 to fffff800030bc400

    STACK_TEXT:  

    fffff88003308b68 fffff800031488a0 : 00000000000000df fffff800033b56c0 fffffa800778cf40 fffffa800778cf40 : nt!KeBugCheckEx

    fffff88003308b70 fffff80003354bc6 : 0000000000000000 fffffa80066e2660 0000000000000080 fffffa80066ce9c0 : nt! ?? ::FNODOBFM::`string'+0x50328

    fffff88003308c00 fffff800030ae6a6 : fffff88002f65180 fffffa80066e2660 fffff88002f6ffc0 2aceaf39f8f092e2 : nt!PspSystemThreadStartup+0x5a

    fffff88003308c40 0000000000000000 : fffff88003309000 fffff88003303000 fffff88003307e20 0000000000000000 : nt!KxStartSystemThread+0x16

    STACK_COMMAND:  kb

    THREAD_SHA1_HASH_MOD_FUNC:  d1f29412959189b3afdbe9027aabb0d9f3cc18ee

    THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  6715ddb151464496fffbf7e29c55aef80932b978

    THREAD_SHA1_HASH_MOD:  d084f7dfa548ce4e51810e4fd5914176ebc66791

    FOLLOWUP_IP: 

    nt! ?? ::FNODOBFM::`string'+50328

    fffff800`031488a0 cc              int     3

    FAULT_INSTR_CODE:  200f44cc

    SYMBOL_STACK_INDEX:  1

    SYMBOL_NAME:  nt! ?? ::FNODOBFM::`string'+50328

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: nt

    IMAGE_NAME:  ntkrnlmp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP:  5708972e

    IMAGE_VERSION:  6.1.7601.23418

    FAILURE_BUCKET_ID:  X64_0xDF_nt!_??_::FNODOBFM::_string_+50328

    BUCKET_ID:  X64_0xDF_nt!_??_::FNODOBFM::_string_+50328

    PRIMARY_PROBLEM_CLASS:  X64_0xDF_nt!_??_::FNODOBFM::_string_+50328

    TARGET_TIME:  2016-06-28T11:53:10.000Z

    OSBUILD:  7601

    OSSERVICEPACK:  1000

    SERVICEPACK_NUMBER: 0

    OS_REVISION: 0

    SUITE_MASK:  272

    PRODUCT_TYPE:  1

    OSPLATFORM_TYPE:  x64

    OSNAME:  Windows 7

    OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS

    OS_LOCALE:  

    USER_LCID:  0

    OSBUILD_TIMESTAMP:  2016-04-09 06:46:22

    BUILDDATESTAMP_STR:  160408-2045

    BUILDLAB_STR:  win7sp1_ldr

    BUILDOSVER_STR:  6.1.7601.23418.amd64fre.win7sp1_ldr.160408-2045

    ANALYSIS_SESSION_ELAPSED_TIME: 70b

    ANALYSIS_SOURCE:  KM

    FAILURE_ID_HASH_STRING:  km:x64_0xdf_nt!_??_::fnodobfm::_string_+50328

    FAILURE_ID_HASH:  {23bc9582-28e0-c7a3-ff1f-10beb2d4fe7b}

    Followup:     MachineOwner

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-06-28T13:04:49+00:00

    We need the actual DMP file.  We cant analyze your text from it

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-06-28T13:13:00+00:00

    Here is a link to the dmp file: https://www.dropbox.com/s/f4qt2xojeadmxcu/MEMORY.zip?dl=0

    Thanks

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-06-28T13:30:04+00:00

    Here is my system info export: https://www.dropbox.com/s/dalj88o21w0s7sc/DEJ%20system%20info.txt?dl=0

    It just happened again when I was exporting this the first time, eeek!

    Thanks!!

    Daniel

    Was this answer helpful?

    0 comments No comments