Page 1 of 3 123 LastLast
Results 1 to 16 of 45

Thread: Someone is stealing my bandwith ????

  1. #1
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Someone is stealing my bandwith ????

    According to my ISP someone is uploading constant amounts of data using my bandwith ( from possibly some tunneling program or vpn )

    The problem is I dont use wireless ( I have an old adsl modem ) so I dont see how they could be doing it , unless theres some program on my pc doing it I am unaware of , does any one have any suggestions ?



    m

  2. #2
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Someone is stealing my bandwith ????

    netstat -a
    throw new ArgumentException (String, String, Exception)

  3. Received thanks from:

    melon (08-03-2012)

  4. #3
    Anthropomorphic Personification shaithis's Avatar
    Join Date
    Apr 2004
    Location
    The Last Aerie
    Posts
    10,857
    Thanks
    645
    Thanked
    872 times in 736 posts
    • shaithis's system
      • Motherboard:
      • Asus P8Z77 WS
      • CPU:
      • i7 3770k @ 4.5GHz
      • Memory:
      • 32GB HyperX 1866
      • Storage:
      • Lots!
      • Graphics card(s):
      • Sapphire Fury X
      • PSU:
      • Corsair HX850
      • Case:
      • Corsair 600T (White)
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • 2 x Dell 3007
      • Internet:
      • Zen 80Mb Fibre

    Re: Someone is stealing my bandwith ????

    Start > Run > ResMon

    Go to the network tab and have a snoop around at the bandwidth and tcp connections.
    Main PC: Asus Rampage IV Extreme / 3960X@4.5GHz / Antec H1200 Pro / 32GB DDR3-1866 Quad Channel / Sapphire Fury X / Areca 1680 / 850W EVGA SuperNOVA Gold 2 / Corsair 600T / 2x Dell 3007 / 4 x 250GB SSD + 2 x 80GB SSD / 4 x 1TB HDD (RAID 10) / Windows 10 Pro, Yosemite & Ubuntu
    HTPC: AsRock Z77 Pro 4 / 3770K@4.2GHz / 24GB / GTX 1080 / SST-LC20 / Antec TP-550 / Hisense 65k5510 4K TV / HTC Vive / 2 x 240GB SSD + 12TB HDD Space / Race Seat / Logitech G29 / Win 10 Pro
    HTPC2: Asus AM1I-A / 5150 / 4GB / Corsair Force 3 240GB / Silverstone SST-ML05B + ST30SF / Samsung UE60H6200 TV / Windows 10 Pro
    Spare/Loaner: Gigabyte EX58-UD5 / i950 / 12GB / HD7870 / Corsair 300R / Silverpower 700W modular
    NAS 1: HP N40L / 12GB ECC RAM / 2 x 3TB Arrays || NAS 2: Dell PowerEdge T110 II / 24GB ECC RAM / 2 x 3TB Hybrid arrays || Network:Buffalo WZR-1166DHP w/DD-WRT + HP ProCurve 1800-24G
    Laptop: Dell Precision 5510 Printer: HP CP1515n || Phone: Huawei P30 || Other: Samsung Galaxy Tab 4 Pro 10.1 CM14 / Playstation 4 + G29 + 2TB Hybrid drive

  5. Received thanks from:

    melon (08-03-2012)

  6. #4
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,231
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Someone is stealing my bandwith ????

    You don't have a torrent client or somesuch do you? if you don't have wireless the chances are there's something on your computer doing it, so I'd check that first. I've used wireshark to monitor network traffic before - should tell you if there's any rogue programs on your PC sending out masses of data. Otherwise, log in to your router and there should be a page that tells you what computers are attached to it, and make sure the router itself doesn't have any kind of torrent client or something odd like that on it.

  7. Received thanks from:

    melon (08-03-2012)

  8. #5
    ALT0153™ Rob_B's Avatar
    Join Date
    Jul 2006
    Posts
    6,751
    Thanks
    468
    Thanked
    1,070 times in 695 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by melon View Post
    According to my ISP someone is uploading constant amounts of data using my bandwith...
    Up or down?

  9. Received thanks from:

    melon (08-03-2012)

  10. #6
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by scaryjim View Post
    You don't have a torrent client or somesuch do you? if you don't have wireless the chances are there's something on your computer doing it, so I'd check that first. I've used wireshark to monitor network traffic before - should tell you if there's any rogue programs on your PC sending out masses of data. Otherwise, log in to your router and there should be a page that tells you what computers are attached to it, and make sure the router itself doesn't have any kind of torrent client or something odd like that on it.
    excuse brief rundown ( hands bad )

    I tried wireshark but saw only my 1 device ( my wireless lan driver listed ) 0 packets and an unkown ip address under the interface tab , or do I need to setup this up some other way ?

    tried netstat -a but not really sure what im looking for , when i tried -e i noticed all the bytes being sent were non-unicast and that the following address with 127.0.0.1 keeps showing up when I tried -ano


    TCP 78.33.152.54:57710 216.36.172.215:1247 TIME_WAIT 0
    TCP 78.33.152.54:57710 217.137.152.40:51240 TIME_WAIT 0
    TCP 78.33.152.54:57710 217.137.152.40:52044 TIME_WAIT 0
    TCP 78.33.152.54:57710 220.253.81.208:53955 TIME_WAIT 0
    TCP 127.0.0.1:1025 127.0.0.1:2001 ESTABLISHED 2020
    TCP 127.0.0.1:1032 0.0.0.0:0 LISTENING 3784
    TCP 127.0.0.1:1073 127.0.0.1:1074 ESTABLISHED 1860
    TCP 127.0.0.1:1074 127.0.0.1:1073 ESTABLISHED 1860
    TCP 127.0.0.1:1075 127.0.0.1:1076 ESTABLISHED 1860
    TCP 127.0.0.1:1076 127.0.0.1:1075 ESTABLISHED 1860
    TCP 127.0.0.1:1077 127.0.0.1:1078 ESTABLISHED 1860
    TCP 127.0.0.1:1078 127.0.0.1:1077 ESTABLISHED 1860
    TCP 127.0.0.1:1079 127.0.0.1:1080 ESTABLISHED 1860
    TCP 127.0.0.1:1080 127.0.0.1:1079 ESTABLISHED 1860
    TCP 127.0.0.1:1081 127.0.0.1:1082 ESTABLISHED 1860
    TCP 127.0.0.1:1082 127.0.0.1:1081 ESTABLISHED 1860
    TCP 127.0.0.1:1154 127.0.0.1:1155 ESTABLISHED 3676
    TCP 127.0.0.1:1155 127.0.0.1:1154 ESTABLISHED 3676
    TCP 127.0.0.1:1156 127.0.0.1:1157 ESTABLISHED 3676
    TCP 127.0.0.1:1157 127.0.0.1:1156 ESTABLISHED 3676
    TCP 127.0.0.1:1624 127.0.0.1:12080 ESTABLISHED 3676
    TCP 127.0.0.1:2001 127.0.0.1:1025 ESTABLISHED 1392
    TCP 127.0.0.1:2247 127.0.0.1:12080 ESTABLISHED 3676
    TCP 127.0.0.1:2261 127.0.0.1:12080 ESTABLISHED 3676
    TCP 127.0.0.1:2262 127.0.0.1:12080 ESTABLISHED 3676
    TCP 127.0.0.1:2267 127.0.0.1:12080 ESTABLISHED 3676
    TCP 127.0.0.1:2268 127.0.0.1:12080 ESTABLISHED 3676
    TCP 127.0.0.1:2269 127.0.0.1:12080 CLOSE_WAIT 220
    TCP 127.0.0.1:5152 0.0.0.0:0 LISTENING 2700
    TCP 127.0.0.1:12025 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12080 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12080 127.0.0.1:1624 ESTABLISHED 1964
    TCP 127.0.0.1:12080 127.0.0.1:2247 ESTABLISHED 1964
    TCP 127.0.0.1:12080 127.0.0.1:2261 ESTABLISHED 1964
    TCP 127.0.0.1:12080 127.0.0.1:2262 ESTABLISHED 1964
    TCP 127.0.0.1:12080 127.0.0.1:2267 ESTABLISHED 1964
    TCP 127.0.0.1:12080 127.0.0.1:2268 ESTABLISHED 1964
    TCP 127.0.0.1:12110 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12119 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12143 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12465 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12563 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12993 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:12995 0.0.0.0:0 LISTENING 1964
    TCP 127.0.0.1:15342 0.0.0.0:0 LISTENING 3676
    TCP 127.0.0.1:15342 127.0.0.1:2241 TIME_WAIT 0
    TCP 127.0.0.1:60524 0.0.0.0:0 LISTENING 1860
    UDP 0.0.0.0:445 *:* 4
    UDP 0.0.0.0:500 *:* 1036
    UDP 0.0.0.0:1432 *:* 1860
    UDP 0.0.0.0:1890 *:* 1860
    UDP 0.0.0.0:2093 *:* 1860
    UDP 0.0.0.0:2113 *:* 1860
    UDP 0.0.0.0:2127 *:* 1860
    UDP 0.0.0.0:2132 *:* 1860
    UDP 0.0.0.0:2141 *:* 1860
    UDP 0.0.0.0:2144 *:* 1860
    UDP 0.0.0.0:2145 *:* 1860
    UDP 0.0.0.0:2171 *:* 1860
    UDP 0.0.0.0:2174 *:* 1860
    UDP 0.0.0.0:2211 *:* 1860
    UDP 0.0.0.0:2245 *:* 1860
    UDP 0.0.0.0:2317 *:* 1860
    UDP 0.0.0.0:2324 *:* 1860
    UDP 0.0.0.0:2358 *:* 1860
    UDP 0.0.0.0:2367 *:* 1860
    UDP 0.0.0.0:2379 *:* 1860
    UDP 0.0.0.0:2380 *:* 1860
    UDP 0.0.0.0:2392 *:* 1860
    UDP 0.0.0.0:2395 *:* 1860
    UDP 0.0.0.0:2407 *:* 1860
    UDP 0.0.0.0:4500 *:* 1036
    UDP 78.33.152.54:123 *:* 1344
    UDP 78.33.152.54:137 *:* 1344
    UDP 78.33.152.54:138 *:* 1344
    UDP 78.33.152.54:1057 *:* 2068
    UDP 78.33.152.54:1900 *:* 1576
    UDP 78.33.152.54:3235 *:* 2068
    UDP 127.0.0.1:123 *:* 1344
    UDP 127.0.0.1:1035 *:* 356
    UDP 127.0.0.1:1900 *:* 1576

    C:\Documents and Settings\melon>

    No router to connect too just this old thomson speedtouch330

    could it be a rootkit ?? see here

    m
    Last edited by melon; 08-03-2012 at 10:35 PM.

  11. #7
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,025
    Thanks
    1,871
    Thanked
    3,383 times in 2,720 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by shaithis View Post
    Start > Run > ResMon

    Go to the network tab and have a snoop around at the bandwidth and tcp connections.
    This. The first window will show processes with network activity, so you can see what programs are sending data from your PC. There will be lots of svchost ones, which you can probably ignore, you're really looking for any obvious programs that you didn't know you were running like torrent programs.

    If there is something obvious then right click->end process, and then uninstall it from control panel add/remove programs.

    Finally download the free version of MBAM anti malaware and do a full scan:
    http://www.malwarebytes.org/

  12. Received thanks from:

    melon (08-03-2012)

  13. #8
    blueball
    Guest

    Re: Someone is stealing my bandwith ????

    I use Currports and IPNetInfo to monitor what is going on as it resolves endpoints for you with minimal hassle.

  14. Received thanks from:

    melon (08-03-2012)

  15. #9
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by kalniel View Post
    This. The first window will show processes with network activity, so you can see what programs are sending data from your PC. There will be lots of svchost ones, which you can probably ignore, you're really looking for any obvious programs that you didn't know you were running like torrent programs.

    If there is something obvious then right click->end process, and then uninstall it from control panel add/remove programs.

    Finally download the free version of MBAM anti malaware and do a full scan:
    http://www.malwarebytes.org/
    I only used bit torrent ( unistalled now )
    windows cant find resmon at all

    m

  16. #10
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by blueball View Post
    I use Currports and IPNetInfo to monitor what is going on as it resolves endpoints for you with minimal hassle.
    tried some addresses but nothing came up ...

    m

  17. #11
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Re: Someone is stealing my bandwith ????

    Just noticed my servers jumped from one 250 miles away !! on my speed tests to one 50 after removing the silverlight plugin on FF, with notable improvement in speed.

    m

  18. #12
    . bledd's Avatar
    Join Date
    Jul 2003
    Posts
    1,886
    Thanks
    22
    Thanked
    135 times in 85 posts

    Re: Someone is stealing my bandwith ????


  19. Received thanks from:

    melon (09-03-2012)

  20. #13
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by kalniel View Post
    This. The first window will show processes with network activity, so you can see what programs are sending data from your PC. There will be lots of svchost ones, which you can probably ignore, you're really looking for any obvious programs that you didn't know you were running like torrent programs.

    If there is something obvious then right click->end process, and then uninstall it from control panel add/remove programs.

    Finally download the free version of MBAM anti malaware and do a full scan:
    http://www.malwarebytes.org/
    Update: 5:47am
    Weather: Hostile as a Moose's fart ( Solar Storm ?? )

    Downloaded Emsisoft Anti Malware ( heard it was best - sry kal )
    detected and quarantined 35 objects
    trying to manually remove one called spigot

    m

  21. #14
    . bledd's Avatar
    Join Date
    Jul 2003
    Posts
    1,886
    Thanks
    22
    Thanked
    135 times in 85 posts

    Re: Someone is stealing my bandwith ????

    How did you get malware? Do you visit weird sites??

    Do you have UAC enabled?

  22. #15
    Member
    Join Date
    Jun 2010
    Posts
    1,254
    Thanks
    132
    Thanked
    213 times in 114 posts
    • roachcoach's system
      • Motherboard:
      • ASUS P6X58D Premium
      • CPU:
      • Intel Core i7 930 2.8G s1366. Coolermaster Hyper 212 Plus
      • Memory:
      • Corsair 6GB (3x2GB) DDR3 1600
      • Storage:
      • 2x 1TB WD Caviar Black, 4x 1 TB Seagate
      • Graphics card(s):
      • 1GB XFX HD5850 BlackEd. 765MHz
      • PSU:
      • Corsair 950W CMPSU-950TXUK
      • Case:
      • Antec 1200
      • Operating System:
      • Win7
      • Monitor(s):
      • ASUS MW221u

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by melon View Post
    I only used bit torrent ( unistalled now )
    windows cant find resmon at all

    m
    What windows version?

  23. #16
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Someone is stealing my bandwith ????

    Wait, back it up...
    Spigot?

    That is a nasty trojan granting full access to your machine. I would recommend taking a more drastic step of copying only the files you need off on to an external drive, reformatting, then installing from a known good source. Applying all security patches, creating a restricted user, then copying acros in that user account and restricted space all files, scanning them as you go.
    throw new ArgumentException (String, String, Exception)

Page 1 of 3 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •