Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

slow performance with xp pc


  • Please log in to reply

#76
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Now that we have reset TCPIP can you run the program you ran back on #43
http://www.geekstogo...ost__p__2118243

Is NDIS still the top problem?
  • 0

Advertisements


#77
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
yes NDIS is still the main resource user. in the Interrupt counts:

NDIS.sys 49,542
sdbus.sys 24,771
pcmcia.sys 24,771
USBPORT.SYS 24,771
portcls.sys 24,771

atapi.sys is there too but way down the list at 1,328


DPCs:

NDIS.sys 26,254
ntoskml.exe 12,509
atapi.sys idle port completionDpc 840
i8024prt.sys 803
tcpip.sys TCBTimeoutdpc 1.214
rdbss.sys 2.023
  • 0

#78
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Do you have any PCMCIA cards installed in your laptop? (These are small cards like a super thick credit card - they do different things - maybe a reader for camera cards?)

Anything that attached via USB?

If so please disconnect them, Close all browsers. and run your test again.


Close all browsers. Wait 2 minutes.

Start, Run, cmd, OK. Type with an Enter after each line.

netstat  -an  >  \junk.txt

netstat -s  >>  \junk.txt

notepad  \junk.txt

  • 0

#79
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
i don't have any PCMCIA cards installed. there is a PCMCIA device in device manager. the only usb i had plugged in was the fan, so i unplugged it before running these tests.

DPC

NDIS.sys 15.927
ntoskml.sys 6290

HI

NDIS.sys 30.386
sdbus.sys 15,193
pcmcia 15.193
etc. 15,193

NDIS.sys - the site where i downloaded the viewer says this is a network problem and to replace my network drivers.

here's the junk.log


Active Connections

Proto Local Address Foreign Address State
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 127.0.0.1:1025 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12025 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12080 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12110 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12119 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12143 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12465 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12563 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12993 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12995 0.0.0.0:0 LISTENING
TCP 192.168.1.106:139 0.0.0.0:0 LISTENING
UDP 0.0.0.0:445 *:*
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:4500 *:*
UDP 127.0.0.1:1377 *:*
UDP 127.0.0.1:1900 *:*
UDP 192.168.1.106:137 *:*
UDP 192.168.1.106:138 *:*
UDP 192.168.1.106:1900 *:*

IPv4 Statistics

Packets Received = 12534
Received Header Errors = 0
Received Address Errors = 3408
Datagrams Forwarded = 0
Unknown Protocols Received = 0
Received Packets Discarded = 116
Received Packets Delivered = 12418
Output Requests = 8897
Routing Discards = 0
Discarded Output Packets = 0
Output Packet No Route = 0
Reassembly Required = 0
Reassembly Successful = 0
Reassembly Failures = 0
Datagrams Successfully Fragmented = 0
Datagrams Failing Fragmentation = 0
Fragments Created = 0

ICMPv4 Statistics

Received Sent
Messages 2 2
Errors 0 0
Destination Unreachable 1 1
Time Exceeded 0 0
Parameter Problems 0 0
Source Quenches 0 0
Redirects 0 0
Echos 0 1
Echo Replies 1 0
Timestamps 0 0
Timestamp Replies 0 0
Address Masks 0 0
Address Mask Replies 0 0

TCP Statistics for IPv4

Active Opens = 337
Passive Opens = 108
Failed Connection Attempts = 1
Reset Connections = 194
Current Connections = 0
Segments Received = 8711
Segments Sent = 8573
Segments Retransmitted = 12

UDP Statistics for IPv4

Datagrams Received = 3704
No Ports = 4
Receive Errors = 0
Datagrams Sent = 308
  • 0

#80
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Go into Device Manager, View, Show Hidden Devices. Then under Non-Plug and Play there should be 2 drivers that start with NDIS. Right click on each and Uninstall. Then go to Universal Serial Bus Controllers and open it up and then right click on each and Uninstall.

Reboot. Windows should find and reinstall them. Run your test again.
  • 0

#81
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
ok. drivers were uninstalled and reinstalled.

DPC is still hovering at 1 and there was one spike to 2.5 where we find:

NDIS.sys 25,579
ntoskml.exe 4,202
etc.

HIs hovering in the 1.8 range with a spike to just over 3 where we find:

NDIS.sys 50.188
sdbus.sys 25,094
pcmcia.sys " "
VIDEOPRT.SYS " "
portcls.sys " "

in the same folder with non-plug and play drivers there was one driver named "serial" that had a yellow "!". there was also another folder labelled "other devices" which has a yellow "?" and in subfolders two devices, one with "?" the other with "?" and "!". there was no info in properties
  • 0

#82
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
serial is not a problem. Most PCs do not have a serial port any more but there is still a driver for it. You can Right click on it and Disable it.

The "other devices" thing is interesting. Usually we see Unknown Devices. This isn't your fan is it?

Right click on them and Uninstall. Reboot. Do they come back?
  • 0

#83
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
i did a bit of browsing and it's not unusual to find "other devices" in here. i looked in properties/details and these are ACPI devices TOS6200 and TOS6202. possibly some old toshiba drivers.

i don't want to uninstall them unless absolutely necessary.

there's a ACPI flash bios update on the toshiba site, but if this is not neccesary, i would rather not resort to this either.

unless you feel that this is important perhaps we could move onto another option. the NDIS driver reinstall did not seem to help.

a couple of things to add...

i disabled the atheros wireless network adapter and ran the event viewer. the DPC dropped to 0.1 with a spike every 1/2 sec to 0.4. i looked at the spikes and the sources are:

ntoskml.exe 4,525
USBPORT.SYS 648
atapi.exe 274
rdbss.sys 723
tcpip.sys 434

NDIS.sys is way down the list at 67

HIs were similarly down to 0.1 with spikes to 0.4 every sec or less:

atapi.sys IdePortInterrupt 446
USBPORT.SYS 528
sdbus.sys 176
pcmcia 176
VIDEOPRT.SYS 176
NDIS.sys 176
portcls 176

i don't know if these rapid spikes indicate a problem, but the overall count has dropped. does this indicate a problem with the wireless adapter?

also the dchp warnings have reappeared.

Edited by benny_b, 15 February 2012 - 02:42 PM.

  • 0

#84
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Uninstalling them won't hurt anything. They don't work now and Windows will just try and reinstall them if it thinks they are still needed.

Can you connect with a cable and disable the wireless?
  • 0

#85
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
yes i can connect with cat5 use ethernet.
  • 0

Advertisements


#86
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Why don't you try that and see if it makes any difference. Disable the wireless so it won't also try to connect. Does it seem faster now? What does your test say?
  • 0

#87
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
eventually i will need to use this laptop wirelessly, but peformance may have improved somewhat with the wire. seems to be a bit more responsive, although browsing is still sluggish.

i uninstalled the unknown devices and windows was unable to find the hardware to reinstall them so the "?" has returned.

the error and warning messages returned yesterday:

Log: 'System' Date/Time: 16/02/2012 8:47:12 AM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.106 for the Network Card with network address 009096726AB2 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).


Log: 'System' Date/Time: 15/02/2012 6:02:05 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. .
Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.


Log: 'System' Date/Time: 15/02/2012 1:10:48 PM
Type: warning Category: 0
Event: 1009 Source: Dhcp
A network error occurred when trying to send a message. The error code is: A blocking operation was interrupted by a call to WSACancelBlockingCall. .

i ran the event viewer on the wire:

DPC averaging .04 with spikes every 30 sec to 0.17

ntoskml.exe 8.025
atapi.sys 445
USBPORT.SYS 453
tcpip.sys 770
rdbss.sys 1.283
TDL.SYS 400
NDIS.SYS 157

HI spiking to 0.07 every 30 sec.

atapi.sys 753
ACPI.sys 41
i8042prt.sys 56
sdbus 42
NDIS.SYS 42
pcmcia.sys 42
VIDEOPRT.SYS 42
portcls.sys 42

so i guess the wireless is a problem and wired is better. unfortunately, i will need some wireless eventually.
also these errors and warnings keep returning.
  • 0

#88
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Run Process Explorer as before. Want to see what it looks like now.

Go to http://www.speedtest.net/ and click on Begin Test

When the Test finishes click on Share This Result and then select Forum then Copy then move to a reply and Ctrl + v
  • 0

#89
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
Posted Image

Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 92.08 0 K 16 K
Interrupts n/a 2.97 0 K 0 K Hardware Interrupts
procexp.exe 364 1.98 11,592 K 15,548 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
services.exe 524 0.99 1,884 K 3,736 K Services and Controller app Microsoft Corporation
DPCs n/a 0.99 0 K 0 K Deferred Procedure Calls
csrss.exe 456 0.99 1,400 K 3,144 K Client Server Runtime Process Microsoft Corporation
wmiprvse.exe 268 2,404 K 5,684 K WMI Microsoft Corporation
winlogon.exe 480 6,380 K 1,840 K Windows NT Logon Application Microsoft Corporation
System 4 0 K 228 K
svchost.exe 1300 2,712 K 4,708 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 820 14,272 K 21,900 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1148 1,516 K 4,116 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 932 5,388 K 7,964 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 684 1,556 K 3,864 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 768 1,948 K 4,612 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 860 2,612 K 3,768 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 968 1,808 K 4,420 K Generic Host Process for Win32 Services Microsoft Corporation
spoolsv.exe 1036 3,720 K 5,744 K Spooler SubSystem App Microsoft Corporation
smss.exe 352 172 K 416 K Windows NT Session Manager Microsoft Corporation
lsass.exe 536 3,988 K 1,600 K LSA Shell (Export Version) Microsoft Corporation
explorer.exe 1996 18,376 K 24,628 K Windows Explorer Microsoft Corporation
ctfmon.exe 408 1,140 K 3,584 K CTF Loader Microsoft Corporation
AvastUI.exe 388 4,828 K 5,892 K avast! Antivirus AVAST Software
AvastSvc.exe 1208 17,308 K 1,276 K avast! Service AVAST Software
alg.exe 1820 1,408 K 3,984 K Application Layer Gateway Service Microsoft Corporation
  • 0

#90
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
sorry that was with wireless. here's the tests with wireless disabled.

http://www.speedtest.../1777833497.png

Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 97.03 0 K 16 K
procexp.exe 692 1.98 11,556 K 15,376 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
services.exe 524 0.99 1,908 K 3,752 K Services and Controller app Microsoft Corporation
wmiprvse.exe 2740 2,632 K 5,284 K WMI Microsoft Corporation
winlogon.exe 480 6,380 K 1,892 K Windows NT Logon Application Microsoft Corporation
System 4 0 K 228 K
svchost.exe 1300 2,712 K 4,704 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 820 15,904 K 25,984 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 684 1,556 K 3,864 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 768 1,976 K 4,628 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 860 2,612 K 3,768 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 932 3,820 K 6,500 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 968 1,808 K 4,420 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1148 1,540 K 4,124 K Generic Host Process for Win32 Services Microsoft Corporation
spoolsv.exe 1036 3,680 K 5,736 K Spooler SubSystem App Microsoft Corporation
smss.exe 352 172 K 416 K Windows NT Session Manager Microsoft Corporation
lsass.exe 536 4,020 K 1,148 K LSA Shell (Export Version) Microsoft Corporation
Interrupts n/a 0 K 0 K Hardware Interrupts
explorer.exe 1996 26,008 K 32,944 K Windows Explorer Microsoft Corporation
DPCs n/a 0 K 0 K Deferred Procedure Calls
ctfmon.exe 408 1,140 K 3,584 K CTF Loader Microsoft Corporation
csrss.exe 456 1,420 K 3,440 K Client Server Runtime Process Microsoft Corporation
AvastUI.exe 388 4,828 K 5,892 K avast! Antivirus AVAST Software
AvastSvc.exe 1208 19,088 K 1,856 K avast! Service AVAST Software
alg.exe 1820 1,408 K 3,984 K Application Layer Gateway Service Microsoft Corporation



the HIs jump up to 0.99 once in a while, but overall the system is more stable.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP