Constant network transfers, can't tell what it is
Constant network transfers, can't tell what it is
Anyone know a sniffer program or other way within WinXP to tell what data transfers are due to? after reinstalling all wireless related software now i see constant transfers at 2-5 packets/second received and 1 packet/minute sent. no idea what is from. windows update shouldn't be downloading anything, system update is not scheduled to run, and nothing else is open. i ran Avira Antivirus and the next step is to run a spyware scan.
now: X61, T42p
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
ok this is really bizarre. in Network Connections, there is a connection "Internet Connection" in group Internet Gateway.
i've never seen this on any other computer. if i go through network setup wizard it asks me if i want to connect through the "internet sharing device". if i disable this connection, the wireless card is still connected but cannot get internet traffic and my OTHER computer on the network cannot get internet traffic. however if this computer or the wireless card is completely shut off, and the "internet connection" disappears, the other computer still gets internet.
i see a bunch of packets in wireshark but i don't know what they mean. most of it is between this computer and the router with a few packages from this computer to does this sound like malware?
i've never seen this on any other computer. if i go through network setup wizard it asks me if i want to connect through the "internet sharing device". if i disable this connection, the wireless card is still connected but cannot get internet traffic and my OTHER computer on the network cannot get internet traffic. however if this computer or the wireless card is completely shut off, and the "internet connection" disappears, the other computer still gets internet.
i see a bunch of packets in wireshark but i don't know what they mean. most of it is between this computer and the router with a few packages from this computer to does this sound like malware?
now: X61, T42p
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
it's the router as it's your "Internet Connection." You have uPnP turned on and you can manage it's firewall and other ports thru that icon. Just right click and choose properties.
Disabling your internet turns off the WAN port on the router.
You could install some programs like Zonealarm or something but basically anyfirewall that blocks outgoing traffic. With that it would then prompt you to allow it and you'd see the program name and ip it's going to and all that.
Disabling your internet turns off the WAN port on the router.
You could install some programs like Zonealarm or something but basically anyfirewall that blocks outgoing traffic. With that it would then prompt you to allow it and you'd see the program name and ip it's going to and all that.
Current - Thinkpad T410si - Core i3 330m, 4GB, 250GB 5400RPM, WXGA+, FPR, BT, Camera, DVDRW, Gobi2000, Win7 Pro x32
Past - Thinkpad T410 - T400 - T61 - T60 - T43 - T42 - T41 - T40 - T23 - 600X
Past - Thinkpad T410 - T400 - T61 - T60 - T43 - T42 - T41 - T40 - T23 - 600X
oh i didn't know exactly what uPnP was but at least i thought it wasn't installed by default. i'm installing adaware, spybot, and symantec firewall now, will see what they say.
now: X61, T42p
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
how do i turn off uPnP?
now: X61, T42p
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
you gotta go in the admin menu (administration page from Linksys or others) and then turn it off. Why would you though? Lots of programs use it so you can communicate with the outside world and share files easier
.
Current - Thinkpad T410si - Core i3 330m, 4GB, 250GB 5400RPM, WXGA+, FPR, BT, Camera, DVDRW, Gobi2000, Win7 Pro x32
Past - Thinkpad T410 - T400 - T61 - T60 - T43 - T42 - T41 - T40 - T23 - 600X
Past - Thinkpad T410 - T400 - T61 - T60 - T43 - T42 - T41 - T40 - T23 - 600X
i mean turn it off on my computer, i've never had it enabled on other computers before. i went ahead and disabled it on the router. prob not the issue though because ...
i think i've found the culprit. on our router there is a port forwarding rule set to the IP this computer is using:
"utorrent - TCP Any -> 21889"
i don't torrent but my impression is that torrenters from around the world are trying to ping this computer to see what files it's hosting. i don't know who is messing with our router, it's def not one of my roommates because they don't even know how to log in.
there are also a ton of rules forwarding to other IP addresses within our local net with something like the following:
"msmsgs (192.168.1.8:13115) 39922 TCP - TCP Any -> 39922"
does this look like someone is sitting outside our house misusing our internet connection? do i need to secure our router better? do i need to worry about all those bits that have been already sent to this computer from torrenters or are they automatically trashed
i think i've found the culprit. on our router there is a port forwarding rule set to the IP this computer is using:
"utorrent - TCP Any -> 21889"
i don't torrent but my impression is that torrenters from around the world are trying to ping this computer to see what files it's hosting. i don't know who is messing with our router, it's def not one of my roommates because they don't even know how to log in.
there are also a ton of rules forwarding to other IP addresses within our local net with something like the following:
"msmsgs (192.168.1.8:13115) 39922 TCP - TCP Any -> 39922"
does this look like someone is sitting outside our house misusing our internet connection? do i need to secure our router better? do i need to worry about all those bits that have been already sent to this computer from torrenters or are they automatically trashed
now: X61, T42p
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
Regarding turning off uPnP, if I remember correctly you go to Control Panel-> Add/Remove Software -> Remove Windows Components (or something like that) and there should be option for uPnP. Also you can go into services and disable it.
W510: i7-820QM / 8GB 1066 RAM/ 1 GB NVIDIA Quadro FX 880M / 500GB 7200rpm / 15.6" HD 1080 / Arch Linux
-
davidspalding
- ThinkPadder

- Posts: 1593
- Joined: Mon Nov 14, 2005 2:39 pm
- Location: Durham, NC
- Contact:
Re: Constant network transfers, can't tell what it is
I've had to surveill this several times. At one time or another, I've found WUAU (Windows Update Automatic Updates) the culprit. I've had other things hogging CPU cycles and slowing my system.bri wrote:Anyone know a sniffer program or other way within WinXP to tell what data transfers are due to?
In the last couple of years, I've used SysInternals' Process Explorer, which is a pumped up, marvelous alternative (or replacement) for Task Manager. It will identify exactly what is doing what at any given time. Very easy to pinpoint background services using 38% of resources in the background.
Also, ensure you don't have content indexing turned on for any network shared drives.
2668-75U T43, 2GB RAM, 2nd hand NMB kybd, Dock II, spare Mini-Dock, and spare Port Replicators. Wacom BT tablet. Ultrabay 2nd HDD.
2672-KBU X32, 1.5GB RAM, 7200 rpm TravelStar HDD.
2672-KBU X32, 1.5GB RAM, 7200 rpm TravelStar HDD.
I've done a bit of P2P sharing to check it out, and I would offer these questions:bri wrote:does this look like someone is sitting outside our house misusing our internet connection? do i need to secure our router better? do i need to worry about all those bits that have been already sent to this computer from torrenters or are they automatically trashed
1.) What security do you have on the router?
2.)Just how secure is your password?
I would consider a really tough mix of characters and numbers as a new password (for God's sakes write it down) and change it.
Example: 1Gh7wx92Mz2
The less sense and bigger mix, the longer to crack with software. Simple word or phrase passwords can be hacked in minutes.
Disable all torrent related options, and lock down access if you are concerned.
As far as someone pinging you computer to see what files you have, anything is possible, but most torrent software requires a target folder to share files. Anything outside that folder is suposedly not accessible to the software.
As far as the ton of:
"msmsgs (192.168.1.8:13115) 39922 TCP - TCP Any -> 39922"
is concerned, this is a record of all sharing activity. The computer with the IP of 192.168.1.8 used port 39922 to share file packets.
If you have dedicated IP's in your network (my advice is to spend the time and do this) you can easily go to IP #8 and see what's going on.
My network has locked out IP's except for the dedicated ones and a few open one's for visitors. My intent is to eventually require a login for access to the internet and network like found in most WiFi equipped hotels.
Joe
Common sense to some of us is unfortunately the higher education others strive to attain.
I turn this off on all my computers running XP. To to Control Panel -> Performance and Maintenance (or Administrative Tools depending on your setup) -> Services->Scroll down to Universal Plug and Play -> select "Disable" or "Manual." You can reboot or just stop it from there.bri wrote:how do i turn off uPnP?
I've never run into any programs that ask for me to turn this service on, but use disable at your own risk of course.
Andy
Current Thinkpads: 600E, 600X, 701C, A31 (Flexview), R51 (Flexview), R60, T42P (Flexview), TR50E, T60 (Flexview), X61s (Ultralight), Z61m (Ti) Non-Thinkpad: Toshiba 100ct
-
RealBlackStuff
- Admin
- Posts: 17518
- Joined: Mon Sep 18, 2006 5:17 am
- Location: Mt. Cobb, PA USA
- Contact:
My upnp has been disabled for at least 3 years. Never a problem.
Lovely day for a Guinness! (The Real Black Stuff)
Check out The Boardroom for Parts, Mods and Other Services.
Check out The Boardroom for Parts, Mods and Other Services.
joester: my concern was more along the lines of someone logging in remotely to the router because we're in a house and the signal barely goes beyond our property (though i guess it would be possible with a good card). that has been debunked though because i found that remote log-in is disabled. i'm still puzzled by how those firewall rules were entered though. i don't understand what you said about the msmsgs entries being records of sharing activity; those were in the firewall rule set, not a log. i guess the best thing would still be to change the wireless security to WPA from WEP but it's going a pain to coordinate with all my roomates.
now: X61, T42p
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
before: 600E, T23, X20, T40, X40, X31, T60
FS: Travel Bezel, 100GB drive (OEM Lenovo)
-
- Similar Topics
- Replies
- Views
- Last post
-
-
How Can I Tell If T400 is in "Dual Channel Mode"?
by jimwg » Sat Apr 15, 2017 3:36 am » in ThinkPad R, A, G and Z Series - 6 Replies
- 776 Views
-
Last post by shawross
Sat Apr 15, 2017 8:08 pm
-
-
-
How can I tell if my T60 running BIOS 2.27 already has the Zender SLIC2.1 no-whitelist BIOS?
by Muse » Fri Apr 21, 2017 2:42 pm » in ThinkPad T6x Series - 4 Replies
- 826 Views
-
Last post by axur-delmeria
Sun Apr 23, 2017 11:47 am
-
-
- 15 Replies
- 1864 Views
-
Last post by Mike Pickwick
Thu Apr 06, 2017 8:12 pm
-
-
Network Card Conundrum
by gicos73 » Sat Jan 21, 2017 2:57 pm » in Thinkpad X6x Series incl. X6x Tablet - 1 Replies
- 1369 Views
-
Last post by jaspen-meyer
Thu Jan 26, 2017 2:51 pm
-
Who is online
Users browsing this forum: No registered users and 4 guests






