A lot of internet activity

  • Thread starter Thread starter Guv
  • Start date Start date

Guv

Guv

Soldato
Joined
24 Oct 2002
Posts
3,257
Location
Warwickshire
I've recently been noticing my internet bandwidth being maxed out for no apparent reason. It's affecting the upload only. No p2p or torrent software.

On my router running DD-WRT firmware I can see a pc has over 400 active connections, whereas the other computers have less than 20.

It would appear something on the PC with loads of connections is causing the problem.. but what? how can I find out?

I've run a program called wireshark.. but no idea what to do with it really, doesn't make much sense to me.

Any ideas?

PC is virus and spyware scanned regularly.
 
funny i had that on my buffalo router running that was so bad i went back to original firmware but browsing is still very slow with virgin 20mb whilst downloading is stable at 2mb/s
 
a pc? don't you know which one? are you running wireless? is it secure?

yep of course I can see which one, IP and MAC address so I know which one it is, hence I know it's always virus and spyware scanned.

Wireless is running, it's secure and currently there aren't any active wireless connections.
 
Not using something like blizzard for WoW or something is it. 400 connections is most likely one of two things, Bitorrent based file sourcing running in background or (and you hope it isn't) a botnet of some sort.
 
Not using something like blizzard for WoW or something is it. 400 connections is most likely one of two things, Bitorrent based file sourcing running in background or (and you hope it isn't) a botnet of some sort.

I don't have any games installed, so not blizzard or WoW. No torrents and no p2p software.

botnet, is that some sort of spyware?
 
Not using something like blizzard for WoW or something is it. 400 connections is most likely one of two things, Bitorrent based file sourcing running in background or (and you hope it isn't) a botnet of some sort.

This is the first thing I thought of as well. You could try disconnecting the troublesome PC from the router and see what your upload bandwidth is like on your other machines, and in the meantime check your processes and see if there are any that you don't know running.

Oh, and basically, a botnet is where your PC is taken over and used in some sort of spamming/spyware ring. My understanding of it is that it's like folding@home, only the owners of the PCs affected aren't aware the software is running.
 
This is the first thing I thought of as well. You could try disconnecting the troublesome PC from the router and see what your upload bandwidth is like on your other machines, and in the meantime check your processes and see if there are any that you don't know running.

Yep tried that as well. Before I noticed the number of connections I was disconnecting each PC 1 by 1 and also limiting upload/download speeds by MAC address to identify which PC was the problem.

Today the upload hasn't been too bad but the number of connections is still very high.

I've been through the processes and checked anything I wasn't sure about - all looks ok.

Thanks for all the suggestions.. keep them coming :)
 
run a full spyware check..

nod32
malware bytes antimalware

if it's still a problem, the install comodo firewall, and that'll ask you for each app
 
Just a thought, have you tried restarting the router? I remember a while back reading something about a belikin router that suffered some weird NAT issue where it didn't drop connections and left them open but idle. Though I think in that case they were all to the same known endpoints.

It might possibly be malfunctioning uPnP but again you'd expect multiple open connections to the same remote addresses. Could try disabling it anyway as it might inadvertently kill any inbound botnet connections as a temporary fix.
I would still do a full scan with as many AV/antispy apps as possible, treat these suggestions as "something to do while the scan is running".

Besides obviously making a cuppa and grabbing a biscuit.- The Industry Renound spyware troubleshooting must haves.
 
I know this might sound stupid, but is 4oD or BBC iplayer installed on your PC? I noticed my upload being saturated after I'd installed this, as it loads in the background on startup and uploads whatever you've downloaded.
 
Back
Top Bottom