Daily uploading taking place on Afrihost ADSL Connection (Between 400 and 700 megs!)

mdma-zn

New Member
Joined
Dec 7, 2009
Messages
1
W32/Sdbot-CWP worm

i had a similar prob...
cntrl alt del.... task manager process showed qxchost.exe (at least a 100 identical processes)...
Used scanspyware and removed the pest = W32/Sdbot-CWP worm.
 

sh4rpz

Senior Member
Joined
Oct 6, 2009
Messages
895
sounds like malware - try running a process explorer (tcpmon would be better tho), and also download and run CCleaner. Should help.
 

Pada

Executive Member
Joined
Feb 18, 2009
Messages
8,189
To be honest: I've never even heard of the software called scanspyware. Rather use anti-spyware that you trust or heard from people with lots of technical experience actually used the application on more than one occasion.

If you ever consider formatting, I would suggest that you partition your drive into 2 partitions, unless you have 2 separate drives already. That would allow you to have your windows & other unimportant stuff on your Windows partition, and leave your data & other important files that you cannot lose on your second partition. That way you could format/reinstall fairly easily :)

Process Explorer NT is a must to have, even if you don't have spyware on your PC.

Windows Firewall only blocks incoming connections, so you would have to resort to alternative firewalls if you want to prevent the uploads if the antispyware/antivirus apps didn't detect anything.
Most modern antivirus/security suites includes decent firewalls if you configure them correctly. The ones I've used an were quite pleased with are: NetLimiter, Comodo, BitDefender & Zone Alarm. All of them can show the traffic per application and also block outgoing connections.
 

alkit

Senior Member
Joined
Mar 8, 2009
Messages
790
Im not really sure why no body has offered the following SIMPLE solution:

Install 'netlimiter monitor' on the affected computer and let it run for a day.
Then, take a look at which program is doing all the uploading. So easy!

Btw, had a friend with the exact problem as urs and put netlimiter on their computer. Turns out 'Outlook Express' was the cause. On further invetigation, I found out they were trying to send a 100mb video file over email, so it would try send, get rejected, and stay in the outbox. Therefore, whenever he opened outlook express again, it tried in vain every time to send the same file...
 

Pada

Executive Member
Joined
Feb 18, 2009
Messages
8,189
alkit: because NetLimiter 2 didn't support Windows 7...

Now you can install it on Windows 7, but you have to install it using the compatibility settings for XP AFAIK. I'm actually running NetLimiter 2 Pro on Win7 x64 without any issues at this moment.
 

W0NDERBOY

Active Member
Joined
Jul 29, 2010
Messages
32
I'm currently experiencing similar problems, last week I added another Gig to my Telkom account, that night I didn't download or upload anything, only played online game Astro Empires for a while then switched my PC off. The next morning when I tried to go online my Gig was finished, so I thought maybe auto updates was maybe on or something. Because I use the internet for my work I had to get another Gig and the exact same thing happened again, within 1 day my time was finished so I went to telkom's adsl site to see what bandwidth usage shows. During the time i was online (from say 10:00 to 15:00) it shows I downloaded 807Mb and uploaded 324mb, although I only checked emails and worked on some designs on the internet. I called telkom technical and they looked and said they cant see anything and that everything was done from my PC as they checked the IP or something.
I then formatted all my drives and did a fresh installation of windows as I thought it might be a virus or something that going through my airtime, that was yesterday. After I was done I got yet another gig top-up from Telkom, that was yesterday afternoon, last night I uploaded 10 designs of about 1Mb each and then I played some poker on facebook. This morning I just checked my email then when I tried to go onto the internet my gig was finished again...=(
Telkom said they will cancel my current account and start a new 1 and I must also go get a different router from them tomorrow morning which they say is more secure than the 105 from them I'm currently using.
I connect to the router with a wireless card so I'm also wondering if its possible that the problem might be coming from the outside, some1 maybe got around the security of the router?
Is there maybe somewhere or some way to get a detailed account of whats been up/downloaded or even just info on where its been up/downloading from. Or the software you mentioned above will that only work to determine uploads or will it work for both?
 

Pada

Executive Member
Joined
Feb 18, 2009
Messages
8,189
NetLimiter 2 Monitor will only show the uploads & downloads on your PC alone. Having an open (as in no security features enabled: no WPA2
/ no MAC filtering) wireless ADSL2+ router is just stupid, because odds are that someone will abuse it...

If you router supports SNMP (Simple Network Management Protocol), then you can track your total (upload & download separately) Internet usage with something like PRTG Traffic Grapher (which is free). SNMP will not show you from where the traffic came, however it will be able to show you that it came from the LAN / Wireless interface of the router.

The first thing that you should do is to ensure that your router's wireless AP is password protected or at least with MAC filtering enabled. Secondly: install NetLimiter 2 Monitor on your own PC, so that you can track which applications are using your Internet cap.
 
Top