Suspicious Network activity?
Results 1 to 12 of 12

Thread: Suspicious Network activity?

  1. #1
    Join Date
    Mar 2000
    Location
    Nanaimo ,B.C. Canada
    Posts
    2,337

    Suspicious Network activity?

    I've been noticing some weird activity IMO.even with NIS blocking traffic I'm still seeing network activity .(See attachments)
    Anyone see anything out of the norm ,I'll try scans (virus,spyware ,malware etc ,but thought I'd post here in hopes of getting a response sooner than all the scans are going to take .

    Cable internet and the activity stops if I physically remove the cat5 cable.


    Link to HJT file http://discussions.virtualdr.com/sho...04#post1131504
    Attached Images Attached Images
    Last edited by wonderinguy34; February 16th, 2007 at 01:38 AM.
    Win 7
    Asrock Z68 Extreme3 Gen3
    I5 2500k @4ghz
    8Gb DDR3 2133Mhz
    Crucial M4 128Gb SataIII SSd
    Sapphire Radeon 6870
    Samsung 931bf 19" LCD

  2. #2
    Join Date
    Jul 2000
    Posts
    4,765
    ?
    NIS does not offer option of blocking all network traffic then
    Displaying/pop-up any/all outgoing attempts?

    I still use an old Sygate Pro version and it sends out a pop-up every time something tries to access then net...
    Cheers.

  3. #3
    Join Date
    Mar 2000
    Location
    Nanaimo ,B.C. Canada
    Posts
    2,337
    Quote Originally Posted by Shinma
    ?
    NIS does not offer option of blocking all network traffic then
    Displaying/pop-up any/all outgoing attempts?

    I still use an old Sygate Pro version and it sends out a pop-up every time something tries to access then net...
    Yep and with it set to block all(attachment below) ,I'm still seeing "Bytes received" attachment in first post.I've cleaned up a few things via Spybot S&D and shutdown via Msconfig etc.. and still I'm recieving bytes.?


    Before and after updated HJT logfile here http://discussions.virtualdr.com/sho...25#post1131525
    Attached Images Attached Images
    Last edited by wonderinguy34; February 16th, 2007 at 03:23 AM.

  4. #4
    Join Date
    Jul 2000
    Posts
    4,765
    That does not sound right at all.
    I've just looked at my software firewall,
    and there has been no activity unless links are clicked and the like...
    Does NIS block Windows activity as well?
    I am guessing by your Task Manager list that you are running Windows Server?
    Cheers.

  5. #5
    Join Date
    Mar 2000
    Location
    Nanaimo ,B.C. Canada
    Posts
    2,337
    Quote Originally Posted by Shinma
    That does not sound right at all.
    I've just looked at my software firewall,
    and there has been no activity unless links are clicked and the like...
    Does NIS block Windows activity as well?
    I am guessing by your Task Manager list that you are running Windows Server?

    An updated Taskmanager (since I shutdown/removed some programs)
    Attached Images Attached Images

  6. #6
    Join Date
    Jul 2000
    Posts
    4,765
    Your last Task Manager list points toward regular Server activity,
    If you are running Server...
    Cheers.

  7. #7
    Join Date
    Mar 2000
    Location
    Nanaimo ,B.C. Canada
    Posts
    2,337
    I'm not running any Server that I know of and I'm the only user/admin access accounts. The second attachment in my first post shows its only "received Bytes" .Most of the contents of the taskmanager are my Norton Firewall (NIS) and Norton AV ,those are the only things in my taskbar,Prevx and logitech are shutdown (not sure why they are still showing as I've rebooted )
    Win 7
    Asrock Z68 Extreme3 Gen3
    I5 2500k @4ghz
    8Gb DDR3 2133Mhz
    Crucial M4 128Gb SataIII SSd
    Sapphire Radeon 6870
    Samsung 931bf 19" LCD

  8. #8
    Join Date
    Mar 2000
    Location
    Nanaimo ,B.C. Canada
    Posts
    2,337
    Is it posible to see where that activity is coming from?I'm wondering if my ISP is pinging to see if the signal is strong,I had some issues early Dec. that they said showed a weak signal and were out doing line work in the area.I'm now wondering if this may be something of their doing.

    Motorola Surfboard SB5101 anyway to access an onboard menu?(off to google)

  9. #9
    Join Date
    Jul 2000
    Posts
    4,765
    Sorry, not familiar with NIS.
    My old Sygate Pro can display all inbound, outbound connections, apps attempting to access net and backtraces IPs if desired.

    Just downloaded and quick browse of the NIS 2006 manual.
    It does not appear to have advanced controls.

    If you are using a router,
    You could enable/check its' logs to see the IPs involved.
    Once that is done,
    You can do a corresponding IP search as to where/what is involved.

    If not,
    All I can suggest at this point in time is to use another software firewall temporarily to obtain the desired info.
    Cheers.

  10. #10
    Join Date
    Mar 2000
    Location
    Nanaimo ,B.C. Canada
    Posts
    2,337
    Well I did find more advance feature in NIS that Shows zero activity inbound or out when I "block all" or don't open a Browser window,so I'm a little more relieved.The WTM>networking shows activity of less than .2% ,with options>auto scale ,the line graph magnifies the highs/lows ,so it looks worse than it is I guess :shrug:I wouldn't think it should show any activity ,but maybe there is line noise or some such?

    Thanks for the help Shinma
    Last edited by wonderinguy34; February 16th, 2007 at 04:52 AM.

  11. #11
    Join Date
    Jul 2000
    Posts
    4,765
    No, I really don't think line noise should appear on a software firewall monitor.
    But then again, *shrug* it is NIS...
    Cheers.

  12. #12
    Join Date
    Mar 2000
    Location
    Nanaimo ,B.C. Canada
    Posts
    2,337
    Quote Originally Posted by Shinma
    No, I really don't think line noise should appear on a software firewall monitor.
    But then again, *shrug* it is NIS...
    Actually its Windows Task Manager>network thats showing activity (second attachment first post) NIS is showing zero bytes in/out,and as we all know MS isn't infallible .

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •