Unwanted data download

vdvyveras

New Member
Joined
May 3, 2007
Messages
6
I would appreciate help with a problem, don't we all? I recently got a 3G/HSDPA modem from MTN. When a plug it into my PC and connect it will start recieving KB's, about 1.5MB/minute, like crazy without me doing anything like opening internet explorer or downloading something. I turned all automatic updates of programes I know of off. All the protection programs are updated (Windows Defender, Antivirus, firewals etc.) The virus program doesn't detect anything also when scanning in safe mode. Can someone assist of refer me?
 

AirWolf

Honorary Master
Joined
Aug 18, 2006
Messages
24,404
Hi. Welcome to the forum:) Use netlimiter to check which programs are downloading the data.
 

Pitbull

Verboten
Joined
Apr 8, 2006
Messages
64,307
I would appreciate help with a problem, don't we all? I recently got a 3G/HSDPA modem from MTN. When a plug it into my PC and connect it will start recieving KB's, about 1.5MB/minute, like crazy without me doing anything like opening internet explorer or downloading something. I turned all automatic updates of programes I know of off. All the protection programs are updated (Windows Defender, Antivirus, firewals etc.) The virus program doesn't detect anything also when scanning in safe mode. Can someone assist of refer me?

How long ago did u connect to the net with that specific Laptop/Desktop ?

edit:

The reason I'm asking is because it could be Windows updates from when ever last you where connected to the net.
 
Last edited:

Deenem

Expert Member
Joined
Apr 20, 2005
Messages
1,724
I have Sunbelt Kerio Personal Firewall installed.

The main screen has a 'Task Manager' type view of all running programs showing the In and Out speed in KB/s for each running program. You can then expand each entry to see the IP address or domain that is being connected to/from and the In/Out speed of each connection.

Very useful for checking where your bandwidth is going.
 

skrokievoks

Member
Joined
Nov 28, 2006
Messages
27
How long since you last cleaned up and reinstalled?
Maybe you got spyware and crap you dont know of.

I do a backup and reinstall every few months, keeps the doctor away.
Maybe that can be your last option if nothing else works.
 

CellBel

Expert Member
Joined
Dec 26, 2006
Messages
2,289
How long since you last cleaned up and reinstalled?
Maybe you got spyware and crap you dont know of.

I do a backup and reinstall every few months, keeps the doctor away.
Maybe that can be your last option if nothing else works.

I don't know if a reinstall will help, because i having the same problem and formatted and clean installed without any backups about 2 months ago. Because of VM's slow speed i bought a 100Mb from MTN and later another 100Mb, but everytime these bundles does'nt even go to the 15th. So i bought a 350 Mb bundle last month and by the 18th it was gone. I did not download a lot and it was more browsing.
To come to the point about what vdvyveras mentioned, i saw the same thing that even with my browser closed the "sent" counter is running like mad. But this is not always the same, but i still did not find the problem.
Google Earth can catch you with the same trick when you exit GE and keep on browsing without logging off google's server first.
But i will keep watching this space to see if more users complain about this, and how to fix this.
 

demon angel

Expert Member
Joined
Nov 29, 2006
Messages
1,930
A copy of Zone labs firewall,avg free and super anti-spyware(brilliant)
solved the EXACT same problem for me 2 months ago.I had to run windows in safe mode with system restore turned off,and only then did i beat the snot out of the little bugger!
 

AirWolf

Honorary Master
Joined
Aug 18, 2006
Messages
24,404
A copy of Zone labs firewall,avg free and super anti-spyware(brilliant)
solved the EXACT same problem for me 2 months ago.I had to run windows in safe mode with system restore turned off,and only then did i beat the snot out of the little bugger!

What was it - virus/worm/spyware/root kit?
 

vdvyveras

New Member
Joined
May 3, 2007
Messages
6
Thank you all for the input, I am surprised! Still figuring things out. It troubles me that although I have the latest updates for the protection programs it still doesn't get detected?!
 

CellBel

Expert Member
Joined
Dec 26, 2006
Messages
2,289
Thank you all for the input, I am surprised! Still figuring things out. It troubles me that although I have the latest updates for the protection programs it still doesn't get detected?!

vdvyveras i found my "data sent" problem. It was Agent Trojan. What i did was to schedule a boot time scan with Avast home ed and Agent Trojan was found in the pagefile of my E: I've got a 40gig HD devided as C: & E: and that's the reason why the trojan was still there after formatting C:
OK now Avast could not delete neither move the culprit, so i went to System Properties > Advanced Tab > Performance > settings > Performance Options > Advanced tab > Virtual memory > Change > Highligted my E: and tick "No paging file" > Set > OK. Now with no pagefile on E: anymore, the trojan moved and then i picked it up with AdAware and delete it.
I've just checked and my "sent" is back to normal eg. with browsing i recieve 3.6 Mb and sent 550 Kb, while with the trojan i recieved 1.8 Mb and sent 1.1 Mb.
So i guess this is why i've lost such a lot of data the past 2 months, and i think you might find something similar.
Good Luck.

:D :D
 

vdvyveras

New Member
Joined
May 3, 2007
Messages
6
Thank you all for the advice. Didn't find anything. Just formatted and reinstalled EVERYTHING! Problem solved
 

CellBel

Expert Member
Joined
Dec 26, 2006
Messages
2,289
Thank you all for the advice. Didn't find anything. Just formatted and reinstalled EVERYTHING! Problem solved

Good to see your system is running again. Please take a look at the following link to info regarding rootkit variants i found on Microsoft's site this weekend.

http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx

It seems to me that it is not always possible to remove this stuff easily, and at the end of the day formatting is the quickest option. I've installed FireFox 2.0 now to see how safe this is against attacks like this.

:cool:
 

caspa

Expert Member
Joined
Jan 26, 2005
Messages
1,374
Thank you all for the advice. Didn't find anything. Just formatted and reinstalled EVERYTHING! Problem solved

next time you have any data eating issues....just install "zone alarm" it will tell you exactly whats potting in what port etc...
 
Top