indidental broadband traffic ?

steve2000x

Member
Mar 11, 2000
75
0
0
The data led flashes almost constantly on my toshiba pcx2200 usb cable modem. Is this normal?

What is the normal activity to see in Windows (XP) Task Manager/Networking ? Typically the displayed trace idles along at a very low level of .01 % 'Network Utilization' which i assume is back and forth communication to my isp for maintaining the connection...

But then on occasion I will see increased activity - in some cases a sawtooth pattern peaking at about .1 % lasting about 10 sec, or an irregular bell curve trace plateauing at about .25 %, and less frequently an isolated spike of .5% or more.

I disabled XP Firewall/ICS, installed trial version Zone Alarm - which seemed to lessen this type of activity.

Installed 'Active Ports' which indicates nothing going on for the 11 active ports displayed.

Installed 'Trojan Hunter' and 'Trojan Remover' which yielded nothing.

Installed 'Spybot Search&Destroy', Spyware Blaster, and Ad-aware which all have helped nailing unwanted stuff.

Disabled XP auto-update and Windows Time, and Help and Support in services.

Un-installed LImewire (gnutella) and several other programs I thought might be phoning home.

As I typed this there were a half dozen or so seperate incidents of the type described including the sawtooth thing peaking at ~.2 %.

What is going on, and should I be concerned ? or am I just paranoid ?

and btw why does windows media player access the i'net when i first open it up? there seems to be no option to disable this except 'update once a week' ???



 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Load up a sniffer and see what exactly is going on. Probably just some wierd Windows need to broadcast.
 

steve2000x

Member
Mar 11, 2000
75
0
0
I've installed 'EtherDetect'

trying to learn how to use it.

So far i see that 10.128.64.1:67 is a source of activity ('client') with 'server' 255.255.255.255:68...UDP...nine packets as i type this, coincident with activity traced in Task Manager...in 'data' there is a lot of hexadecimal, and some gibberish including "C.D.A." and "UnReg".

Another source (4 mins later) is my ip address port 138 as 'client', and an ip address very close to mine, but ending at 255, port 138 only 1 packet. gibberish in the 'data' box:

.........q....E...7.......Dk..Dk........ ....(Dk**UnReg**EOEFFHEOEPFCFEEIFHEPEPEECACACACA. ENFDEIEPENEFCACACACACACACACACABN..SMB%..............................!...................!.V.........2.\MAILSLOT\BROWSE.......NEWNORTHWOOD.p..........

What does this all mean?
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
port 67 is bootps (bootp server). I think that can have something to do with DHCP.

Port 138 is netbios.

Looks like this is general broadcast stuff. The DHCP traffic you can ifnore, but you might want to look into why netbios is being used...
 

Pulsar

Diamond Member
Mar 3, 2003
5,224
306
126
Windows XP connects to the internet /automatically/ in over 16 different ways.

Enjoy the love that microsoft provides. After all... they're not really tracking you... they're just sending useful non-identifying technical information about your computer.

/cough cough cough/.