This is a read-only archive. No new posts or registrations. Privacy Page
Software

USB 2.0 suddenly very slow XP Pro SP2

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
I'm new to this forum and I want to say hi and thanks for such a wonderful site. I'm not sure anyone can help with this problem but I'm at my wit's end.

First, my system was made in 1991 but I have upgraded many components. I have an ASUS A7M266-D mobo and 2 gigs of Crucial RAM in 4 slots. I have 2 Athlon 2600+ MP processors and temps run 48-50 degrees (I constantly monitor the temps). No overclocking of anything. I have 2 new hard drives (7200/8mb cache), a new nVidia 6800 256MB graphics card. I'm running XP SP2 and it is all up to date on windows updates. I use NOD32 as my virus scanner and regularly run AdAware and Spybot Search and Destroy. I clean dust from inside the machine regularly with compressed air. I defrag every day with DiskKeeper and regularly scan for viri. My machine is on 24/7 and is used mostly for graphics work but also some email and web browsing. I backup with Acronis True Image to a 300G Seagate HD attached to a USB 2.0 card (since the USB 2 was not functional on these boards when purchased). The USB card is ASUS USB2-PCI 4 port card.

Ok, now the problem…

For 4 years everything was great. Suddenly my USB speeds dropped. DiskSpeed32 shows that speeds went from 28MB/sec to 4.5MB/sec. I can't figure out why. I have 3 external drives and tried it with all of them. Same speed. The drives also use Firewire and when hooked up as Firewire they run at 28MB/sec. So the problem is not the drive, must be the computer. If I boot from a CD and use the USB drive to restore files I get full speed. So it must be software, not hardware. I see no errors about this in the log. I have searched the net and Microsoft's Knowledge Base and can't find the answer.

1) I tried removing the USB drivers and having windows reinstall them. No change.
2) I tried manually updating the USB drivers. No change.
3) I downloaded the latest drives from the ASUS web site and there was no change in speed (but some of my devices didn't work so I went back to the windows drivers).
4) I tried all 4 USB ports but they are all the same speed.
5) I tried a different USB 2 cable. No change.
6) I went to the hardware device manager and removed EVERYTHING with USB, unplugged all devices, reinstalled the drivers after rebooting, and plugged in ONLY the drive. No change.
7) I used 3 separate tools to clean the registry, still no change. (Registry Mechanic, RegVac, and CRC-Complete Registry Cleaner).

It's got to be a software problem since Acronis True Image can restore backups at full speed when I boot from the freshly made Acronis Boot CD, but for the life of me I can't figure it out.

Now just to throw this in there since it might be related, but recently shutdown has been VERY slow. It quickly closes all programs, saves my settings, and then says, “Windows is shutting down.” Then it hangs for 50 seconds. Eventually it closes. When I check the logs sometimes it says …


Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/31/2005
Time: 12:49:32 AM
User: NT AUTHORITY\SYSTEM
Computer: VOODOO
Description:
Windows saved user VOODOO\Ed registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.


So I went to Microsoft’s site and downloaded and installed UPHclean. After installed the log says…


The following handles in user profile hive VOODOO\Ed (S-1-5-21-2027339946-1729697498-769079328-1004) have been closed because they were preventing the profile from unloading successfully:

svchost.exe (1228)
HKCU (0x258)

… but I don’t know what that means.

Sorry to be so long winded but I wanted to give you as much info as I could. Thanks so much for any help you can offer.

Ed/deaded
I am not sure how that would have started but this right here…

Windows saved user VOODOO\Ed registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


.. is probably not good if your NOT voodoo\ed. Have you got a log to post.. (hijack this logt)

I am not sure how that would have started but this right here…

Windows saved user VOODOO\Ed registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


.. is probably not good if your NOT voodoo\ed. Have you got a log to post.. (hijack this logt)

205609


I am VOODOO\Ed (the computer is Voodoo and user Ed). Yeah, obviously something is keeping the registry open. I can't figure out what. I can narrow the process down to svchost.exe which is pretty much anything. If I could figure out what it is I could stop it at/before startup.

Would a hijack this log help? I can't imagine this is caused by adware or anything. I can do it if it would be helpful.
Well.. i am thinking maybe we can find the culprit that way, however, I am not certain thats going to have anything.. at all… to do with the lag issue
Ok, here's the log. Nothing raises a red flag for me. What do you think?

Logfile of HijackThis v1.99.1
Scan saved at 2:12:45 PM, on 9/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Motherboard Monitor 5\MBM5.EXE
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Perfect Keyboard LITE\pk32.exe
C:\Program Files\Perfect Keyboard LITE\_loader.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Perfect Keyboard LITE\_prog.exe
C:\Program Files\Perfect Keyboard LITE\_prog.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\Samurize\Client.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\MailWasher Pro\MailWasher.exe
C:\Program Files\Samurize\Client.exe
C:\Program Files\Perfect Keyboard LITE\_prog_wd.exe
C:\Program Files\YzDock-Ed\YzDock.exe
C:\Program Files\YzToolbar\YzToolBar.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.estimated.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.estimated.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: TW_BrowserHook - {1E1B2879-88FF-11D2-8D96-FFFFAC95951F} - blank (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [MBM 5] "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Perfect Keyboard LITE] "C:\Program Files\Perfect Keyboard LITE\pk32.exe" /winstart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ResChanger2004] NONE
O4 - Startup: Client weather.lnk = C:\Program Files\Samurize\Client.exe
O4 - Startup: DU Meter.lnk = C:\Program Files\DU Meter\DUMeter.exe
O4 - Startup: MailWasherPro.lnk = C:\Program Files\MailWasher Pro\MailWasher.exe
O4 - Startup: Samurize.lnk = C:\Program Files\Samurize\Client.exe
O4 - Startup: YzDock.lnk = C:\Program Files\YzDock-Ed\YzDock.exe
O4 - Startup: YzToolBar.lnk = C:\Program Files\YzToolbar\YzToolBar.exe
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: LinkStash - {4874F370-402D-4d09-A73E-FAB439934E56} - C:\Program Files\LinkStash\lsshow.exe (HKCU)
O9 - Extra 'Tools' menuitem: LinkStash - {4874F370-402D-4d09-A73E-FAB439934E56} - C:\Program Files\LinkStash\lsshow.exe (HKCU)
O9 - Extra button: Grab URLs - {957DCFA2-39F7-4443-9677-1B14E83A2F87} - C:\Program Files\LinkStash\lsgrab.exe (HKCU)
O9 - Extra 'Tools' menuitem: LinkStash GrabURLs - {957DCFA2-39F7-4443-9677-1B14E83A2F87} - C:\Program Files\LinkStash\lsgrab.exe (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://customer.voodoopc.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1118451521875
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1118472280109
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
When RT gets home from work ill ask him to look at it as I am not supposed to post to logs, however, I do see a couple of fishy ones. I had problems when trying to use this one C:\Program Files\Motherboard Monitor 5\MBM5.EXE and this looks like a remnant of hijacker O2 - BHO: TW_BrowserHook - {1E1B2879-88FF-11D2-8D96-FFFFAC95951F} - blank (file missing)
Thanks Crow. Actually, before I posted I deleted the "blank" one. And the MBM5 (motherboard monitor) is a program I use to monitor temperatures of the two processors and RAM.
Yeah, I have used MBM5 unfortunatly I hadnt had good luck with it. Course that doesnt mean anything at all. One thing, I notice there is an awfull lot of things starting up (04's). Have you tried cleaning some of those up to free up some resources?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI