PDA

View Full Version : WinXP Pro download slow


Ryland
11-08-2006, 01:20 PM
For some reason my work desktop is downloading at around 1.3Mbps whereas my laptop which is also running WinXp and is directly connected to the same physical switch (which is sitting under my desk) that the desktop is on gets 6Mbps download speeds. So far I have tried:

Swapping out the cable
Swapping out the switch
Swapping out the NIC
Scanning for virus/spyware (nothing)

And none of it helps. Does anybody have any other ideas?

tesfaye
11-08-2006, 02:27 PM
Are you sure it's a switch and not a hub? If it's a hub check to see if your NIC is set to Half-Duplex.

Also, try doing a repair on your network connection. Right click on the connection and choose the repair option. That might help. Do a NetStat in a command window and see what connections your computer is making. There might be something running in the background using the network and slowing other applications down.

Ryland
11-08-2006, 02:38 PM
I am positive that it is a switch (I just had to RMA one of them out).

Repairing the connection didn't help (same download and upload speeds)

netstat shows about 40 open TCP connections with about 30 of them to ports on my local machine:

Active Connections

Proto Local Address Foreign Address State
TCP WORK:1043 localhost:1057 ESTABLISHED
TCP WORK:1057 localhost:1043 ESTABLISHED
TCP WORK:1110 localhost:2829 ESTABLISHED
TCP WORK:1110 localhost:2830 ESTABLISHED
TCP WORK:1110 localhost:2838 ESTABLISHED
TCP WORK:1110 localhost:2856 TIME_WAIT
TCP WORK:1110 localhost:2860 TIME_WAIT
TCP WORK:1110 localhost:2883 FIN_WAIT_2
TCP WORK:1110 localhost:2885 TIME_WAIT
TCP WORK:1110 localhost:2887 FIN_WAIT_2
TCP WORK:1110 localhost:2893 TIME_WAIT
TCP WORK:1110 localhost:2895 TIME_WAIT
TCP WORK:1110 localhost:2897 FIN_WAIT_2
TCP WORK:1110 localhost:2900 TIME_WAIT
TCP WORK:1110 localhost:2903 FIN_WAIT_2
TCP WORK:1110 localhost:2906 TIME_WAIT
TCP WORK:1110 localhost:2908 TIME_WAIT
TCP WORK:1110 localhost:2912 TIME_WAIT
TCP WORK:1110 localhost:2913 TIME_WAIT
TCP WORK:2233 localhost:2234 ESTABLISHED
TCP WORK:2234 localhost:2233 ESTABLISHED
TCP WORK:2235 localhost:2236 ESTABLISHED
TCP WORK:2236 localhost:2235 ESTABLISHED
TCP WORK:2829 localhost:1110 ESTABLISHED
TCP WORK:2830 localhost:1110 ESTABLISHED
TCP WORK:2838 localhost:1110 ESTABLISHED
TCP WORK:2883 localhost:1110 CLOSE_WAIT
TCP WORK:2887 localhost:1110 CLOSE_WAIT
TCP WORK:2889 localhost:1110 TIME_WAIT
TCP WORK:2890 localhost:1110 TIME_WAIT
TCP WORK:2897 localhost:1110 CLOSE_WAIT
TCP WORK:2903 localhost:1110 CLOSE_WAIT
TCP WORK:2909 localhost:1110 TIME_WAIT
TCP WORK:2219 cs44.msg.dcn.yahoo.com:5050 ESTABLISHED
TCP WORK:2224 by1msg2245417.phx.gbl:1863 ESTABLISHED
TCP WORK:2225 205.188.9.28:5190 ESTABLISHED
TCP WORK:2226 64.12.24.29:5190 ESTABLISHED
TCP WORK:2228 oam-m07b.blue.aol.com:5190 ESTABLISHED
TCP WORK:2230 192.168.5.191:netbios-ssn ESTABLISHED
TCP WORK:2231 lapland:5903 ESTABLISHED
TCP WORK:2798 192.168.151.13:microsoft-ds ESTABLISHED
TCP WORK:2831 lei.icebase.net:http ESTABLISHED
TCP WORK:2832 www.icebase.com:http ESTABLISHED
TCP WORK:2839 208.65.201.106:http ESTABLISHED
TCP WORK:2877 205.188.5.92:5190 ESTABLISHED
TCP WORK:2882 www.bandwidth.com:http TIME_WAIT
TCP WORK:2891 www.bandwidth.com:http TIME_WAIT
TCP WORK:2892 www.bandwidth.com:http TIME_WAIT
TCP WORK:2899 www.bandwidth.com:1759 TIME_WAIT
TCP WORK:2902 www.bandwidth.com:1759 TIME_WAIT
TCP WORK:2916 static-71-250-251-251.nwrknj.east.verizon.net:99
5 TIME_WAIT

tesfaye
11-08-2006, 02:55 PM
My fault: Netstat -ao this will give you the process IDs associated with the ports.

Ryland
11-08-2006, 03:15 PM
That gets me with what the PID's refer to on the right:

Active Connections

Proto Local Address Foreign Address State PID
TCP WORK:epmap WORK:0 LISTENING 952 SVCHOST
TCP WORK:microsoft-ds WORK:0 LISTENING 4 SYSTEM
TCP WORK:1025 WORK:0 LISTENING 1500 LEXPPS
TCP WORK:1110 WORK:0 LISTENING 1660 AVP.EXE
TCP WORK:2221 WORK:0 LISTENING 3428 TRILLIAN.EXE
TCP WORK:5800 WORK:0 LISTENING 312 WINVNC
TCP WORK:5900 WORK:0 LISTENING 312 WINVNC
TCP WORK:6789 WORK:0 LISTENING 1780 DB2JDS.EXE
TCP WORK:10002 WORK:0 LISTENING 1844 RASERVER.EXE
TCP WORK:1031 WORK:0 LISTENING 400 ALG.EXE
TCP WORK:1043 WORK:0 LISTENING 3556 BOINC.EXE
TCP WORK:1043 localhost:1057 ESTABLISHED 3556 BOINC.EXE
TCP WORK:1057 localhost:1043 ESTABLISHED 3224BOINCMGR.EXE
TCP WORK:1110 localhost:2982 ESTABLISHED 1660 AVP.EXE
TCP WORK:1110 localhost:2984 ESTABLISHED 1660 AVP.EXE
TCP WORK:1110 localhost:2986 ESTABLISHED 1660 AVP.EXE
TCP WORK:1110 localhost:2990 ESTABLISHED 1660 AVP.EXE
TCP WORK:1110 localhost:2992 ESTABLISHED 1660 AVP.EXE
TCP WORK:1110 localhost:2994 ESTABLISHED 1660 AVP.EXE
TCP WORK:2233 localhost:2234 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2234 localhost:2233 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2235 localhost:2236 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2236 localhost:2235 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2887 localhost:1110 CLOSE_WAIT 2500 FIREFOX.EXE
TCP WORK:2897 localhost:1110 CLOSE_WAIT 2500 FIREFOX.EXE
TCP WORK:2903 localhost:1110 CLOSE_WAIT 2500 FIREFOX.EXE
TCP WORK:2982 localhost:1110 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2984 localhost:1110 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2985 localhost:1110 TIME_WAIT 0
TCP WORK:2986 localhost:1110 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2990 localhost:1110 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2992 localhost:1110 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:2994 localhost:1110 ESTABLISHED 2500 FIREFOX.EXE
TCP WORK:4664 WORK:0 LISTENING 2472 GOOGLEDESKTOPINDEX
TCP WORK:49213 WORK:0 LISTENING 3396 HTTPDL.EXE
TCP WORK:netbios-ssn WORK:0 LISTENING 4 SYSTEM
TCP WORK:2219 cs44.msg.dcn.yahoo.com:5050 ESTABLISHED 3428 trillian
TCP WORK:2224 by1msg2245417.phx.gbl:1863 ESTABLISHED 3428 TRILLIAN

TCP WORK:2225 205.188.9.28:5190 ESTABLISHED 3428 TRILLIAN
TCP WORK:2226 64.12.24.29:5190 ESTABLISHED 3428 TRILLIAN
TCP WORK:2228 oam-m07b.blue.aol.com:5190 ESTABLISHED 3428 TRILLIAN

TCP WORK:2230 192.168.5.191:netbios-ssn ESTABLISHED 4 SYSTEM
TCP WORK:2231 lapland:5903 ESTABLISHED 3048 VNCVIEWER
TCP WORK:2798 192.168.151.13:microsoft-ds ESTABLISHED 4 SYSTEM
TCP WORK:2970 205.188.5.92:5190 ESTABLISHED 3428 TRILLIAN
TCP WORK:2980 64.12.31.88:5190 ESTABLISHED 3428 TRILLIAN
TCP WORK:2983 www1.itotf.net:http ESTABLISHED 1660 AVP.EXE
TCP WORK:2987 www1.itotf.net:http ESTABLISHED 1660 AVP.EXE
TCP WORK:2989 rev177.asus.com:http ESTABLISHED 1660 AVP.EXE
TCP WORK:2991 205.147.80.38:http ESTABLISHED 1660 AVP.EXE
TCP WORK:2993 72.14.209.99:http ESTABLISHED 1660 AVP.EXE
TCP WORK:2995 205.147.80.38:http ESTABLISHED 1660 AVP.EXE
UDP WORK:microsoft-ds *:* 4 SYSTEM
UDP WORK:1032 *:* 1204 SVCHOST.EXE
UDP WORK:1133 *:* 1204 SVCHOST.EXE
UDP WORK:1718 *:* 1204 SVCHOST.EXE
UDP WORK:ntp *:* 1056 SVCHOST.EXE
UDP WORK:1041 *:* 2268 SHOPSAFE.EXE
UDP WORK:1076 *:* 932 OUTLOOK
UDP WORK:1900 *:* 1280 SVCHOST
UDP WORK:ntp *:* 1056 SVCHOST.EXE
UDP WORK:netbios-ns *:* 4 SYSTEM
UDP WORK:netbios-dgm *:* 4 SYSTEM
UDP WORK:1900 *:* 1280 SVCHOST.EXE

tesfaye
11-08-2006, 08:53 PM
Cool. Now kill, disable, close, stop, whatever those services, apps (#) etc and see if your transfer improves. Enable each one and test to see what is killing your throughput.

BOINC.exe, is that BOINCZilla? I don't know what it is but found a bug page about it not respecting bandwidth (#) limits. http://search.live.com/results.aspx?q=BOINC.EXE&src=IE-SearchBox. It was the first result on the page.

AVP.exe, what is that? I can't find any consistent info on the file (#) but it's got a lot going on over there.

Also, have you run perfmon and checked your NIC adapter usage?

Hopefully you can get this sorted out.

Stormscape
11-08-2006, 08:59 PM
BOINC is the Berkeley Open Infrastructure for Network Computing, the thing that has stuff like SETI, Folding@Home, Rosetta@Home, Climateprediction.net, crap like that.

Ryland
11-08-2006, 09:27 PM
I have not run perfmon on it but will.

Ryland
11-09-2006, 08:51 AM
Current Bandwidth is always at 100
Bytes Received is always pretty low (less than 8) with the scale on 1.

Is there one in particular that I should be looking at?

I guess I now have to start goign on a task/app killing spree to figure out who the culprit is (if any of them are).

its not:
Boinc,
WinVNC
VncViewer
Trillian
Lexmar apps
RASERVER
DB2 apps
Googledesktop

Im not sure why AGL.EXE is showing because it is for internet connection sharing which shouldn't be being done but it might just be a "standard" component.

AVP.EXE is my virus scanner (Kaspersky) and this problem predated having it installed on here.

Ryland
11-15-2006, 03:49 PM
It ended up being that my IP Stack was corrupted. I found the solution here (http://searchwincomputing.techtarget.com/tip/0,289483,sid68_gci1193133,00.html).

The gist is to type:

netsh int ip reset [ log_file_name ]