Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
100M Ethernet activity LED flickering like crazy, but I didn't ask the PC to send anything, and the network activity is not visible to task manager, icon tray icon doesn't show the traffic, netstat doesn't show the traffic. No unbidden programs using cycles in the performance monitor windows. But network status window (the one that comes up when you right click the network icon and select status) does show prodigious amounts of packets being sent, around 4M every 5-6 sec. This keeps on going and going. If the LED on the back of the PC weren't flashing, I'd think someone put a joke "packets sent" counter on my machine, but the traffic seems to be real. I don't have a network analyser to see where the packets are going. Am I paranoid to imagine that there is a stealth program using my network port for someting, staying out of view of the Windows statistics-gathering engines, maybe part of a denial-of-service attack? Anyone have any ideas about how to track this down and kill whatever is doing this? (I've run the latest McAfee virus scan, nothing showed up, also HijackThis didn't turn up anything obvious). Note this only affects the 100M ethernet network, my WLAN doesn't show this behavior. So I'm keeping the ethernet disabled until I can stop the unwanted transmissions.

Go Get Ethereal so you can sniff packets from your own system and also go and get Port Scanner 1.2.2 and scan your system for open ports.
KTTD

You might be infected with Mydoom backdoor. it will send lot of data packets to MS site. Try Solo antivirus from www.srnmicro.com

Thanks for the referral to Ethereal, it's a nice tool. It confirmed that my machine is not actually sending out any packets. That means the outgoing packet counter in the status display window is wrong. The counter in the performance monitor is fine.
I really appreciate your help, I was able to set my mind at ease (somewhat). At this time I'm going to put this on the back burner. But I'd still appreciate hearing any ideas on this strange behavior in the status window.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |