I restarted the pc last night and now Its starting that issue again 49%. Its the Plug And Play thats causing it. umpnpmgr.dll with ntdll.dll!tppwaiterp thread that makes the CPU spike. If I suspend the ntdll.dll thread thats causing it. the cpu goes back to normal BUT it comes back within a few hours. Now thats a work around right now but I do not want to continue doing that
Can you post the stacks of the threads in the PnP svchost at the point where the problem occurs again? I gather that you're observing involvement from multiple threads in that process, even if suspending one of them temporarily does the trick.
If you haven't already done so, I'd suggest testing what happens with your anti-virus completely uninstalled, not just disabled. The previous thread stack you posted is indicative of retry behaviour which may be caused by some type of interference from another component - possibly the AV.
I'll definitely do that. Well Kaspersky I never had issues with it when I got it installed with Windows 7 BUT Ill take the risk without the antivirus. If indeed it happens again. Ill post the stacks as well
Also did mailware bytes from the other poster.
Malwarebytes' Anti-Malware 1.41
Database version: 3149
Windows 6.1.7600
11/11/2009 5:17:16 PM
mbam-log-2009-11-11 (17-17-16).txt
Scan type: Quick Scan
Objects scanned: 89895
Time elapsed: 3 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Brian\downloads\sopfilter.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Brian\Desktop\Download 100,000 Emoticons!.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\Brian\Desktop\Sherv.NET - Animated Emoticons, Winks, Display Pics, plus more!.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\Brian\Local Settings\Temporary Internet Files\udRemove.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Found five instances. of errors and removed them