Yorkshire Divers

Deep Blue Technical
Go Back   YD Scuba Diving Forums > Non-Diving Related Forums > Technology
User Name
Password

Welcome to the YD Scuba forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Technology: Discuss Somethings got hold of my computer ... in the Non-Diving Related Forums forums: ..... and I don't know what it is. For some time now I have been using been using netmeter to ...

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 27-01-08, 11:18 AM
Spacehopper's Avatar
Spacehopper Spacehopper is offline
So much more than a child's play thing!
 
Join Date: Sep 2004
Location: Back in good old Blighty :)
Posts: 1,604
Spacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold waterSpacehopper is a scuba diver - cold water
Somethings got hold of my computer ...

..... and I don't know what it is. For some time now I have been using been using netmeter to monitor traffic, upload and download speeds etc. Over the past 2 days it has shown that there is a constant upload at 4.7 Kbs and download at 5Kbs and I can't find out what it is. I have a firewall (Norton) as well as a hardware firewall built into the router. I have stopped as many processes running as possible but the activity is still there, I can only stop it by having Norton block all traffic. I've run Adaware and Spybot to no effect, my virus checker (AVG) runs every night. Obviously something has got onto my PC and has opened a hole through the firewalls but how can I find out what it is? I'm almost at the point of reformating and rebuilding.

BTW I am writing this on my laptop, traffic on the desktop is permanently blocked

Gareth
__________________
The other half of Team Rudolph
Member of the Blonde Mafia Support Team
If the next 50 years are anything like the past 50 years, I'll be an old man by the time I'm 100

Right now I'm having amnesia and deja vu at the same time. I think I've forgotten this before.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 27-01-08, 12:07 PM
Arthur Gerla's Avatar
Arthur Gerla Arthur Gerla is offline
New Member
 

Join Date: Aug 2006
Location: Utrecht
Posts: 33
Arthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the seaArthur Gerla paddles in the sea
Finding out which process is causing the traffic should narrow things down. Open a command prompt window and type

netstat /b

The output will be something like this:

Quote:
C:\Documents and Settings\Arthur>netstat /b

Active connections

Proto Local adress External adress Status PID
TCP PC-Arthur:1067 localhost:1068 ESTABLISHED 1220
[firefox.exe]

TCP PC-Arthur:1068 localhost:1067 ESTABLISHED 1220
[firefox.exe]

TCP PC-Arthur:1069 localhost:1070 ESTABLISHED 1220
[firefox.exe]

TCP PC-Arthur:1070 localhost:1069 ESTABLISHED 1220
[firefox.exe]

TCP PC-Arthur:1590 192.168.2.10:1026 ESTABLISHED 3100
[OUTLOOK.EXE]

TCP PC-Arthur:1593 192.168.2.10:1135 ESTABLISHED 3100
[OUTLOOK.EXE]

TCP PC-Arthur:1820 82.199.131.203:19931 ESTABLISHED 2312
[Skype.exe]

TCP PC-Arthur:2680 gerla.demon.nl:http ESTABLISHED 3708
[iexplore.exe]

TCP PC-Arthur:2835 a194-109-192-9.deploy.akamaitechnologies.com:http
ESTABLISHED 2128
[jusched.exe]

TCP PC-Arthur:3323 192.168.2.100:netbios-ssn ESTABLISHED 4
[System]

TCP PC-Arthur:2663 xs4all.nl:http TIME_WAIT 0
TCP PC-Arthur:2679 xs4all.nl:http TIME_WAIT 0

C:\Documents and Settings\Arthur>


This reveals the process for every active network connection on your system. As you can see I'm running firefox, outlook, skype and internet exploder. jusched.exe is the Java update scheduler.

Alternatively, install Currports from Nirsoft.

Good luck,

Arthur
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 29-01-08, 10:38 PM
Air Guzzler's Avatar
Air Guzzler Air Guzzler is offline
Posting Shite since 19:31
 

Join Date: Jan 2006
Location: St Helens by the sea :(
Posts: 518
Air Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold waterAir Guzzler swims in cold water
I tried that arthur to see why mine was so slow it opens runs that fast i cannot see it then closes ?
__________________
I've payed for my air ill breath as fast as i wont to


Due to financial problems the light at the end of the tunnel will be switched off between 6am - 6pm Mon - Fri


http://s214.photobucket.com/albums/cc204/Air-Guzzler/
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 29-01-08, 11:00 PM
weazelz's Avatar
weazelz weazelz is online now
DUE neophyte
 

Join Date: Oct 2005
Location: North London
Posts: 1,068
weazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the waterweazelz is never out of the water
Quote:
Originally Posted by Air Guzzler
I tried that arthur to see why mine was so slow it opens runs that fast i cannot see it then closes ?
open a command prompt:

start->run->"cmd"

then run "netstat /b"
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 29-01-08, 11:56 PM
TDonald TDonald is offline
New Member
 

Join Date: Jun 2006
Posts: 14
TDonald saw the sea in a book once
Here goes...

My basic virus/spyware routine.....

Unplug network connection.
Remove, restart, then reinstall AVG, adaware and spybot.

Use your faithful laptop to locate updates for the above, and the remarkably funny sounding SuperAntiSpyware, Hijackthis and McAfee Stinger [standalone virus scanner]. All should be free and easy to find on google. Transfer over and install with a pendrive.

Restart in safemode [tap f8 when the manufacterers splash screen displays on reboot]. Scan with AVG, Stinger, AdAware, SB, SAS.

Reboot to normal windows.

Test to see if this has solved the problem.

If not, Hijackthis is fairly useful also, but can have some negative results. Run Hijack this, select scan and save logfile, save it to the pendrive. Use laptop to analyse logfile with hijackthis.de . This will suggest some potential nasty registry entries which can be removed with HJT. Now, if you remove something you shouldn't with HJT, you can cause some fairly catastrophic problems. If there's something you're unsure about, send me a PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Sponsored Links

Yorkshire Divers - RSS Feed
All times are GMT +1. The time now is 11:03 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0 RC6
Trademark and all rights reserved : © YD.com Ltd (2006)
YD.com Ltd (Registered in England - 05886696)
Other sites : Golf Clubs | New Premiership Football Kits | MP3 Portable Players | MP3 Players For Sale | Replica Football Kits

Forums Directory