Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Weird net activity

Options
  • 14-09-2004 3:12pm
    #1
    Registered Users Posts: 3,330 ✭✭✭


    I'm using Clicksilver, and this morning I noticed a steady flow of net traffic in DUMeter.

    I closed all of my net applications (browser, eMule, MSN, etc...) but it was still there. Uploads were at a full 12 or 13kB/sec, and downloads were around 9 or 10kB/sec. I can't find what application is sending this data, or where?

    I installed NetLimiter, but it reports that there is no traffic. My router lights are flashing also.

    There's a screenshot here: http://tinypic.com/548hz

    I've tried rebooting both my router and my PC, but it still comes back. The other PC on the same router is not having this problem. It's been going for a few hours now and I can't stop it.

    Could this be a virus or spyware?


Comments

  • Registered Users Posts: 14,317 ✭✭✭✭Raam


    could it be windows update?


  • Registered Users Posts: 3,330 ✭✭✭radiospan


    No, I've automatic updates turned off.

    I ran "netstat 5" from the command line and there doesn't seem to be anything weird, just connections to localhost and 192.168.0.1


  • Closed Accounts Posts: 2,188 ✭✭✭Ripwave


    plazzTT wrote:
    I'm using Clicksilver, and this morning I noticed a steady flow of net traffic in DUMeter.
    If you're running XP, open a command prompt and run

    NETSTAT -o

    This will show you what applications have ports open. Use the Task Manager to find out the name of the application (Netstat only shows the processID).


  • Registered Users Posts: 3,330 ✭✭✭radiospan


    The only two connections that are there have PID 0 (System Idle Process) ?

    Could it be a bug in DUMeter, recording something thats not really there?

    Although my router lights are flashing, and DUMeter goes to zero when I plug out the router...


  • Registered Users Posts: 926 ✭✭✭Cal


    Set your DU meter to only monitor your bb connection. It may be other internal traffic that you are seeing.

    Cal


  • Advertisement
  • Registered Users Posts: 3,330 ✭✭✭radiospan


    It's monitoring my network card only, that's the best I can do.

    But this activity started suddenly this morning, I wasn't changing any settings or anything.

    Two connections are always there when I use netstat. They are:

    TCP john:1624 localhost:1625 ESTABLISHED
    TCP john:1625 localhost:1624 ESTABLISHED

    Could this be it? Are those connections normal?


  • Registered Users Posts: 3,330 ✭✭✭radiospan


    Is there anything else I could try to stop this? Any settings I could change?

    It's definately affecting my download speeds (I'm only getting 30-40K max now because the other 10k is constantly being used by this thing) so it's probably counting towards my download cap too.

    I'll have to disconnect my net for a while now.


  • Registered Users Posts: 1,193 ✭✭✭liamo


    Two connections are always there when I use netstat. They are:

    TCP john:1624 localhost:1625 ESTABLISHED
    TCP john:1625 localhost:1624 ESTABLISHED
    I don't recognise those ports. And what machine is "john"? Try pinging "john" and see what ip address replies - might it be another machine on your network?

    You could try installing Ethereal on your machine. This will capture all traffic that it sees on the network. Traffic on your router is no doubt switched so all you'll see is traffic to and from the PC but that's all you need. It will show you the port and IP address of both ends of all traffic. And, if you need, you can examine the contents of the packets. That should give you the answer to your question.

    Regards,

    Liam


  • Registered Users Posts: 3,330 ✭✭✭radiospan


    Thanks, I'm downloading Ethereal now. I changed my IP address on my local network from 192.168.0.3 to 192.168.0.9, I left the router disconnected for about half an hour, and I changed the network port that my LAN cable was going into on the router.

    One of those changes might have done the trick, theres no mystery traffic now, although it might come back later. (john is the name of my PC, btw :) )


  • Registered Users Posts: 6,007 ✭✭✭Moriarty


    Moved to nets/comms.


  • Advertisement
Advertisement