svchost.exe + NTDLL.DLL Causing high CPU Usage

Satanical Eve

New member
Local time
1:42 PM
Messages
45
Computer stats
Windows 7 Pro 64 Bit
Gigabyte Socket 775 Mobo
Intel Core 2 Duo 3.0 CPU
Nvidia 8800GT
4 GB DDR2 Ram
MSI TV Anywhere PCI TV Tuner
Soundblaster Audigy 2 ZS

I have recently beginning with last Thursday been experiencing after a good 4-7 hours of the computer being on a massive spike in CPU usage, it goes from 40%-60% and stays. I narrowed it down using Process Explorer to svchost with the culprit being ntdll.dll underneath it. Here is the picture of it
svchost.jpg

Its TID 752 that does it. The only way to stop the spike is by suspending the thread. If I do that it temporarily fixes the issue. Within a few hours it spikes back up again. Also sometimes if I suspend the thread I cannot load any new programs and Windows 7 ends up stalling. I don't know why it does this or how to resolve the issue. Can anyone help me as to the exact cause and how to resolve it. Thank you very much
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX
I'm not the right person to talk to about this, but that dll is a required one used by the kernel. I'm guessing, but I think that both of the processes that you mentioned may indicate that the problem is being caused by some other third party software on your system If that be the case, you would need to locate it by a process of elimination. Go into msconfig and using selective startup, disable everything listed on the startup tab window, and run it that way long enough to see if the problem reappears. If it does, then you might have to consider other possibilities, like a system restore or repair install.
 

My Computer My Computer

At a glance

W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCEPhenom II 1090T w/Noctua NH-D14 /**4400+ X2 w...2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsai...EVGA GTX460 SC/**EVGA 8800GTS
Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
I'm gonna do that. I disabled my tuner card just to make sure that isn't causing the issue. But I doubt thats the cause because it happens regardless of if I use it or not
 

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX
did you happen to setup windows media experience recently ?

I had the same issue you are describing shortly after setting up the media experience feature. De-installing it sadly did not resolve the issue. After troubleshooting for a few hours i decided to restore my windows from a previous automatic backup from the day before, which resolved the issue.

So I'm still not 100% certain about the cause, but my issue was resolved by restoring windows to a previous automatic backup.
 

My Computer My Computer

At a glance

Windows 7 Pro x64Intel Core 2 Quad Q9550 Yorkfield 2.83GhzCorsair 4GB 800MhzeVGA 280GTX
OS
Windows 7 Pro x64
CPU
Intel Core 2 Quad Q9550 Yorkfield 2.83Ghz
Motherboard
eVGA 780i FTW
Memory
Corsair 4GB 800Mhz
Graphics Card(s)
eVGA 280GTX
Sound Card
onboard
Monitor(s) Displays
2x Dell Ultrasharp 2408WFP
Screen Resolution
dual 1920x1200 (3840x1200)
Hard Drives
60GB OCZ SSD Vertex (OS / Applications) &
1TB Samsung (Data)
PSU
Corsair 1000HX
Case
Ultra m998 ULT40069 Mid-Tower ATX Case
Cooling
Zalman 9700 LED 110mm 2 Ball CPU Cooler
Keyboard
Logitech Illuminated Keyboard
Mouse
Logitech MX Revolution
did you happen to setup windows media experience recently ?

I had the same issue you are describing shortly after setting up the media experience feature. De-installing it sadly did not resolve the issue. After troubleshooting for a few hours i decided to restore my windows from a previous automatic backup from the day before, which resolved the issue.

So I'm still not 100% certain about the cause, but my issue was resolved by restoring windows to a previous automatic backup.

Hello cosomotion,

What kind of backup did you restore?
- A system image?
- System recovery point?

Just so we know how you solved this. ;-)

Best regards,

zx81
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64Intel 1720 Core 2 Duo 2.00GHz,800,2M4GB 667MHz DDR2 SDRAM (2x2048)NVIDIA Geforce Go 8600M GT 256MB DDR2
Computer Manufacturer/Model Number
Dell Inpspiron 1720
OS
Windows 7 Home Premium x64
CPU
Intel 1720 Core 2 Duo 2.00GHz,800,2M
Memory
4GB 667MHz DDR2 SDRAM (2x2048)
Graphics Card(s)
NVIDIA Geforce Go 8600M GT 256MB DDR2
Sound Card
SigmaTel
Monitor(s) Displays
17.0" Widescreen WXGA+ (1440x900) TFT with TrueLife
Screen Resolution
1440x900
Hard Drives
2x160GB 5400RPM Serial ATA
Mouse
Logitech
... Can anyone help me as to the exact cause and how to resolve it. Thank you very much

Nice job on the troubleshooting :)

The function names displayed for the ntoskrnl image are mostly wrong because there's no symbolic info. To get a more accurate stack representation, in Process Explorer, under Options, Configure symbols, put this into the "Symbols path:" field:

SRV*c:\SymCache*http://msdl.microsoft.com/download/symbol

Then restart ProcExp, repeat the procedure to find the offending thread, and copy it's stack once more (that "copy" button copies text to the clipboard so you don't have to bother with the screenshots).

An accurate stack representation of the busy thread should help in diagnosing the issue.
 

My Computer My Computer

At a glance

Win7x64
Computer Manufacturer/Model Number
Multiple machines in various stages of decomposition.
OS
Win7x64
... Can anyone help me as to the exact cause and how to resolve it. Thank you very much

Nice job on the troubleshooting :)

The function names displayed for the ntoskrnl image are mostly wrong because there's no symbolic info. To get a more accurate stack representation, in Process Explorer, under Options, Configure symbols, put this into the "Symbols path:" field:

SRV*c:\SymCache*http://msdl.microsoft.com/download/symbol

Then restart ProcExp, repeat the procedure to find the offending thread, and copy it's stack once more (that "copy" button copies text to the clipboard so you don't have to bother with the screenshots).

An accurate stack representation of the busy thread should help in diagnosing the issue.
I did it
Thread 752 - ntdll.dll!tppwaiterpthread

Thats exactly what appears for it. With the same information for the stack as before
 

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX

My Computer My Computer

At a glance

Windows 10 Pro (x64)Intel Core i7-3930K (3.2GHz - 4.5GHz)4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)Nvidia Geforce GTX 690
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Not going to state anything conclusive. But NTDLL is not the cause. But what is interesting is that this svhost has Power Management, and Plug and Play Management. Something tells me it might have something to do with PnP and something (hardware) you have plugged in.

User-mode Power Service: Windows 7 DLL File Information - umpo.dll
User-mode Plug-and-Play Service: Windows 7 DLL File Information - umpnpmgr.dll
Well the only PNP devices I have installed are my webcam(Logitech Pro 4000), My Tuner Card(MSI TV Anywhere PCI). HP Printer, and my Bluetooth Adapter.

Thanks for the help guys.
 

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX
It just started doing it again. svchost.exe is at 49% right now. ntdll.dll!Tppworkerthread is at 48%. I have disabled most all of my PNP devices. My capture card is disabled and its not causing the issue. Im frustrated as to what device or thing is causing this.

I had to restart the PC because it stopped doing it for a minute or so then suddenly spiked back up. I don't know if it has to do with the PNP devices I have or if its the Power portion underneath svchost
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX
It just started doing it again. svchost.exe is at 49% right now. ntdll.dll!Tppworkerthread is at 48%. I have disabled most all of my PNP devices. My capture card is disabled and its not causing the issue. Im frustrated as to what device or thing is causing this.

I had to restart the PC because it stopped doing it for a minute or so then suddenly spiked back up. I don't know if it has to do with the PNP devices I have or if its the Power portion underneath svchost

Can you paste the stack of the offending thread now that you've configured ProcExp with the symbol path?
 

My Computer My Computer

At a glance

Win7x64
Computer Manufacturer/Model Number
Multiple machines in various stages of decomposition.
OS
Win7x64
It is not clear to me, everything that you said that you disabled is hardware. Did you disable all of the items that I mentioned in msconfig's startup tab? You might also install StartupCPL so that you can disable software items that are intialized by registry entries also.
 

My Computer My Computer

At a glance

W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCEPhenom II 1090T w/Noctua NH-D14 /**4400+ X2 w...2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsai...EVGA GTX460 SC/**EVGA 8800GTS
Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
ntdll.dll!TPPWaiterpthread
Threads for it
ntoskrnl.exe!KiSwapContext+0x7a
ntoskrnl.exe!KiCommitThreadWait+0x1d2
ntoskrnl.exe!KeWaitForSingleObject+0x19f
ntoskrnl.exe!KiSuspendThread+0x54
ntoskrnl.exe!KiDeliverApc+0x211
ntoskrnl.exe!KiCommitThreadWait+0x3dd
ntoskrnl.exe!KeWaitForMultipleObjects+0x271
ntoskrnl.exe!ObpWaitForMultipleObjects+0x294
ntoskrnl.exe!NtWaitForMultipleObjects+0xe5
ntoskrnl.exe!KiSystemServiceCopyEnd+0x13
ntdll.dll!NtWaitForMultipleObjects+0xa
ntdll.dll!TppWaiterpThread+0x14d
kernel32.dll!BaseThreadInitThunk+0xd
ntdll.dll!RtlUserThreadStart+0x1d
-----------------------------------------------

For startup. I booted up with the minimum needed to run Windows and I still had the issue. I was wondering I have a Logitech EX110 series wireless keyboard and mouse, Could that be possibly causing the issue. Because if I totally disable svchost. The volume buttons on the keyboard do not work. Could that be the culprit all along or am I just looking in the wrong direction. Since the keyboards multimedia functions are running on the same svchost where the uh problem with the spike happens and I do notice when I use them my cpu does spike up to around 35-40%
 

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX
Logitech likes to "call home" ....

My curiosity is getting the best of me. I'd like to see a HJT log, please.
Download HijackThis!
HijackThis - Trend Micro USA

Run as Administrator, save the log (it will be on a notepad.txt) and post it here please.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Could try a simple keyboard and mouse, just to make sure it is not the current set.
 

My Computer My Computer

At a glance

Windows 10 Pro (x64)Intel Core i7-3930K (3.2GHz - 4.5GHz)4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)Nvidia Geforce GTX 690
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Here you go guys.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:11:32 PM, on 11/10/2009
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Creative\Shared Files\CTSched.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files (x86)\ooVoo\ooVoo.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\mIRC\mirc.exe
D:\dvbot\mirc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\EvilLyrics\EvilLyrics.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\MSI\TV@Anywhere Plus\PVR Plus\TVPlus.exe
C:\Program Files (x86)\Pidgin\pidgin.exe
C:\processexplorer\procexp.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15187&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files (x86)\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files (x86)\ooVoo\ooVoo.exe /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: navnet - {AD6E5643-7B0C-46AA-95AD-9773FF2A857A} - C:\Program Files (x86)\NavNetApp\ComUtilities.dll
O20 - AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: GB-PVR Recording Service - WelltonWay - C:\Program Files (x86)\Devnz\GBPVR\GBPVRRecordingService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10630 bytes


Thats the whole entire log file
 

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX
Did you install the "Ask Toolbar" on purpose? :shock: It does send and download advertizing to your computer ... I would uninstall it, then delete this folder:
C:\Program Files\Ask.com

You have quite a bit of Logitech running ... Go into services and set all instances to 'manual' (see if this helps the high CPU usage)

Rescan with HJT and place a check mark next to these items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Ask.com Search Engine - Better Web Search

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - Global Startup: Logitech SetPoint.lnk = ?


Click 'fix checked' then exit out of HJT.

Reboot and see if you're running any better.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
You might also be interested in this (doesn't sound good to me :eek::
EVILLYRICS.EXE (Derivative 1668831821), Prevx
Thats just a winamp lyrics addon. It browses for lyrics to songs. Been using it since 2002 but I removed it.

I also removed all the other stuff you checkmarked. Hopefully that'll fix it. I'll check back later if and when it starts acting up again. If it continues to work fine into tomorrow morning Ill come back and say its resolved
 

My Computer My Computer

At a glance

Windows 7 Professional 64 BITIntel Core 2 Duo Extreme 3.0 ghz8 GBNvidia 8800GT
Computer Manufacturer/Model Number
None
OS
Windows 7 Professional 64 BIT
CPU
Intel Core 2 Duo Extreme 3.0 ghz
Motherboard
Gigabyte LG775
Memory
8 GB
Graphics Card(s)
Nvidia 8800GT
Sound Card
Creative Audigy 2 ZS
Monitor(s) Displays
Dell 25' LCD, Dell 19' LCD
Hard Drives
Western Digital Caviar SE 200GB SATA
Western Digital External 1 TB USB
Western Digital WD5000 500 GB SATA
PSU
Corsair 650 TX
Thanks, I'd appreciate it one way or the other .... we could find that the problem still exists and try a couple of other things :)
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top